Nortel Networks Nortel Secure Network Access Switch 4050 Manual de usuario Pagina 1

Busca en linea o descarga Manual de usuario para Software Nortel Networks Nortel Secure Network Access Switch 4050. Nortel Networks Nortel Secure Network Access Switch 4050 User's Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 922
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
Part No. 320818-A
December 2005
4655 Great America Parkway
Santa Clara, CA 95054
*320818-A*
Nortel Secure Network Access
Switch 4050 User Guide
Nortel Secure Network Access Switch
Software Release 1.0
Vista de pagina 0
1 2 3 4 5 6 ... 921 922

Indice de contenidos

Pagina 1 - Switch 4050 User Guide

Part No. 320818-ADecember 20054655 Great America ParkwaySanta Clara, CA 95054*320818-A*Nortel Secure Network Access Switch 4050 User GuideNortel Secu

Pagina 2 - Statement of conditions

10 Contents320818-A Modifying RADIUS configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273Managing additional RADIUS s

Pagina 3 - Licensing

100 Chapter 3 Managing the network access devices320818-A Mapping VLANs by switchTo map VLANs by switch, you must first disable the network access dev

Pagina 4

Chapter 3 Managing the network access devices 101Nortel Secure Network Access Switch 4050 User Guide • “Removing VLANs from a switch” on page 102Addin

Pagina 5 - Contents

102 Chapter 3 Managing the network access devices320818-A Removing VLANs from a switchTo remove existing VLANs from the switch, complete the following

Pagina 6

Chapter 3 Managing the network access devices 103Nortel Secure Network Access Switch 4050 User Guide If you created the domain manually, the SSH key w

Pagina 7

104 Chapter 3 Managing the network access devices320818-A If the network access device defaults, it generates a new public key. You must reimport the

Pagina 8

Chapter 3 Managing the network access devices 105Nortel Secure Network Access Switch 4050 User Guide Generating SSH keys for the domain using the SREM

Pagina 9

106 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Pagina 10

Chapter 3 Managing the network access devices 107Nortel Secure Network Access Switch 4050 User Guide The Export Key screen appears (see Figure 13).Fig

Pagina 11

108 Chapter 3 Managing the network access devices320818-A 2 Enter the export information in the applicable fields. Table 8 describes the fields availa

Pagina 12

Chapter 3 Managing the network access devices 109Nortel Secure Network Access Switch 4050 User Guide Managing SSH keys for Nortel SNA communication us

Pagina 13

Contents 11Nortel Secure Network Access Switch 4050 User Guide SRS Rule Expression Constructor . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 14

110 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Pagina 15

Chapter 3 Managing the network access devices 111Nortel Secure Network Access Switch 4050 User Guide The switch SSH Key screen appears (see Figure 14

Pagina 16

112 Chapter 3 Managing the network access devices320818-A The Health Check screen appears (see Figure 15).Figure 15 Health Check screen

Pagina 17

Chapter 3 Managing the network access devices 113Nortel Secure Network Access Switch 4050 User Guide 2 Enter the health check information in the appli

Pagina 18

114 Chapter 3 Managing the network access devices320818-A The Connected Clients screen appears, displaying information about the connection status and

Pagina 19

Chapter 3 Managing the network access devices 115Nortel Secure Network Access Switch 4050 User Guide Controlling communication with the network access

Pagina 20

116 Chapter 3 Managing the network access devices320818-A To disable or enable the network access device, perform the following steps:1 Select the Sec

Pagina 21

117Nortel Secure Network Access Switch 4050 User Guide Chapter 4 Configuring the domainThis chapter includes the following topics:Topic PageConfigurin

Pagina 22

118 Chapter 4 Configuring the domain320818-A A Nortel SNAS 4050 domain encompasses all the switches, authentication servers, and remediation servers a

Pagina 23

Chapter 4 Configuring the domain 119Nortel Secure Network Access Switch 4050 User Guide • logging traffic with syslog messages• portal settings (see “

Pagina 24 - 24 Contents

12 Contents320818-A Changing a user’s group assignment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365Changing passwords . . . . . .

Pagina 25

120 Chapter 4 Configuring the domain320818-A details on|offloglevel fatal|error|warning| info|debug/cfg/domain #/aaa/tg/quick/cfg/domain #/server port

Pagina 26

Chapter 4 Configuring the domain 121Nortel Secure Network Access Switch 4050 User Guide Creating a domain using the CLIYou can create a domain in two

Pagina 27 - Text conventions

122 Chapter 4 Configuring the domain320818-A When you first create the domain, you are prompted to enter the following parameters:• domain name — a st

Pagina 28 - Related information

Chapter 4 Configuring the domain 123Nortel Secure Network Access Switch 4050 User Guide Figure 17 Creating a domainUsing the Nortel SNAS 4050 domain

Pagina 29 - How to get help

124 Chapter 4 Configuring the domain320818-A Depending on the options you select in connection with certificates and creating a test user, the two wiz

Pagina 30 - 30 Preface

Chapter 4 Configuring the domain 125Nortel Secure Network Access Switch 4050 User Guide c To use an existing certificate, enter the applicable certifi

Pagina 31 - Chapter 1

126 Chapter 4 Configuring the domain320818-A c To continue, go to step 8 on page 126.8 Specify whether the SSL server uses chain certificates. 9 If yo

Pagina 32 - Supported users

Chapter 4 Configuring the domain 127Nortel Secure Network Access Switch 4050 User Guide 11 To add a network access device, enter the required informat

Pagina 33 - Role of the Nortel SNAS 4050

128 Chapter 4 Configuring the domain320818-A The wizard assigns the following default VLAN IDs:• Green VLAN = VLAN ID 110• Yellow VLAN = VLAN ID 120Yo

Pagina 34 - Nortel SNA VLANs and filters

Chapter 4 Configuring the domain 129Nortel Secure Network Access Switch 4050 User Guide Deleting a domain using the CLITo delete a domain, use the fol

Pagina 35 - Groups and profiles

Contents 13Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the CLI . . . . . . . . . . . . . . . . . . .

Pagina 36 - Authentication methods

130 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the CLITo configure the domain, use the following command:/cfg/domain

Pagina 37 - Chapter 1 Overview 37

Chapter 4 Configuring the domain 131Nortel Secure Network Access Switch 4050 User Guide portalAccesses the Portal menu, in order to customize the port

Pagina 38 - About SSH

132 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the CLIBefore an authenticated client is allowed into the network

Pagina 39 - Nortel SNAS 4050 clusters

Chapter 4 Configuring the domain 133Nortel Secure Network Access Switch 4050 User Guide heartbeat <interval>Sets the time interval between check

Pagina 40 - 40 Chapter 1 Overview

134 Chapter 4 Configuring the domain320818-A Using the quick TunnelGuard setup wizard in the CLITo configure the settings for the SRS rule check using

Pagina 41 - Two-armed configuration

Chapter 4 Configuring the domain 135Nortel Secure Network Access Switch 4050 User Guide The TunnelGuard quick setup wizard creates a default SRS rule

Pagina 42 - 42 Chapter 1 Overview

136 Chapter 4 Configuring the domain320818-A The Server 1001 menu includes the following options:Tracing SSL traffic using the CLITo verify connectivi

Pagina 43 - Chapter 1 Overview 43

Chapter 4 Configuring the domain 137Nortel Secure Network Access Switch 4050 User Guide The Trace menu displays.The Trace menu includes the following

Pagina 44 - 44 Chapter 1 Overview

138 Chapter 4 Configuring the domain320818-A tcpdumpCreates a dump of the TCP traffic flowing between clients and the virtual SSL server. You are prom

Pagina 45 - Chapter 1 Overview 45

Chapter 4 Configuring the domain 139Nortel Secure Network Access Switch 4050 User Guide Configuring SSL settings using the CLITo configure SSL-specifi

Pagina 46 - 46 Chapter 1 Overview

14 Contents320818-A Chapter 10: Configuring system settings . . . . . . . . . . . . . . . . . . . . . . . . . 457Configuring the cluster using the CLI

Pagina 47 - Chapter 1 Overview 47

140 Chapter 4 Configuring the domain320818-A The SSL Settings menu includes the following options:/cfg/domain #/server/sslfollowed by:cert <certifi

Pagina 48 - 48 Chapter 1 Overview

Chapter 4 Configuring the domain 141Nortel Secure Network Access Switch 4050 User Guide cachain <certificate index list>Specifies the CA certifi

Pagina 49 - Initial setup

142 Chapter 4 Configuring the domain320818-A Configuring traffic log settings using the CLIYou can configure a syslog server to receive User Datagram

Pagina 50

Chapter 4 Configuring the domain 143Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Pagina 51 - About the IP addresses

144 Chapter 4 Configuring the domain320818-A Configuring HTTP redirect using the CLIYou can configure the Nortel SNAS 4050 domain to automatically red

Pagina 52

Chapter 4 Configuring the domain 145Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configure t

Pagina 53

146 Chapter 4 Configuring the domain320818-A Configuring RADIUS accounting using the CLIThe Nortel SNAS 4050 can be configured to provide support for

Pagina 54

Chapter 4 Configuring the domain 147Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS accounting server to the confi

Pagina 55

148 Chapter 4 Configuring the domain320818-A The Radius Accounting Servers menu includes the following options:/cfg/domain #/aaa/radacct/serversfollow

Pagina 56

Chapter 4 Configuring the domain 149Nortel Secure Network Access Switch 4050 User Guide Configuring Nortel SNAS 4050-specific attributes using the CLI

Pagina 57

Contents 15Nortel Secure Network Access Switch 4050 User Guide Adding a host interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 58

150 Chapter 4 Configuring the domain320818-A The VPN Attribute menu includes the following options:Configuring the domain using the SREMTo configure t

Pagina 59

Chapter 4 Configuring the domain 151Nortel Secure Network Access Switch 4050 User Guide • portal settings (see “Customizing the portal and user logon”

Pagina 60

152 Chapter 4 Configuring the domain320818-A Manually creating a domain using the SREMTo create and configure a domain manually, perform the following

Pagina 61 - Extended profile details

Chapter 4 Configuring the domain 153Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Secure Access Domain dialog box appears

Pagina 62

154 Chapter 4 Configuring the domain320818-A Using the SREM Domain Quick WizardThe Nortel SNAS 4050 quick setup wizard is similar to the quick setup w

Pagina 63 - Joining a cluster

Chapter 4 Configuring the domain 155Nortel Secure Network Access Switch 4050 User Guide To create a domain using the Nortel SNAS 4050 quick setup wiza

Pagina 64

156 Chapter 4 Configuring the domain320818-A 2 Click Domain Quick Wizard.The Domain Quick Wizard — General Settings dialog box appears (see Figure 22)

Pagina 65

Chapter 4 Configuring the domain 157Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate dialog box appears (see

Pagina 66

158 Chapter 4 Configuring the domain320818-A 6 Click Next.Organization Name Specifies the registered name of the organization. The organization must o

Pagina 67 - Chapter 2 Initial setup 67

Chapter 4 Configuring the domain 159Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate Chain dialog box appears

Pagina 68

16 Contents320818-A Managing RADIUS audit servers using the SREM . . . . . . . . . . . . . . . . . . . . 559Managing RADIUS authentication of system

Pagina 69 - Figure 3

160 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Server dialog box appears (see Figure 25).Figure 25 Domain Quick Wizard – Ser

Pagina 70 - 70 Chapter 2 Initial setup

Chapter 4 Configuring the domain 161Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Switch dialog box appears (see Figur

Pagina 71 - Chapter 3

162 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Tunnel Guard dialog box appears (see Figure 27).Figure 27 Domain Quick Wizard

Pagina 72

Chapter 4 Configuring the domain 163Nortel Secure Network Access Switch 4050 User Guide If there are no problems, then a dialog appears to indicate th

Pagina 73

164 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the SREMTo configure a domain, perform the following steps:1 Select t

Pagina 74

Chapter 4 Configuring the domain 165Nortel Secure Network Access Switch 4050 User Guide 2 Enter the domain information in the applicable fields. Table

Pagina 75

166 Chapter 4 Configuring the domain320818-A Additional domain configuration in the SREMTo configure additional domain settings, there are tabs and tr

Pagina 76

Chapter 4 Configuring the domain 167Nortel Secure Network Access Switch 4050 User Guide Table 21 describes the purpose of additional tree components f

Pagina 77 - >

168 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the SREMBefore an authenticated client is allowed into the networ

Pagina 78 - Manually adding a switch

Chapter 4 Configuring the domain 169Nortel Secure Network Access Switch 4050 User Guide To configure settings for the TunnelGuard host integrity check

Pagina 79

Contents 17Nortel Secure Network Access Switch 4050 User Guide Chapter 12: Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 80

170 Chapter 4 Configuring the domain320818-A 2 Enter the TunnelGuard information in the applicable fields. Table 22 describes the TunnelGuard Configur

Pagina 81

Chapter 4 Configuring the domain 171Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes to th

Pagina 82

172 Chapter 4 Configuring the domain320818-A Using the TunnelGuard Quick Setup in the SREMTo configure settings for the TunnelGuard host integrity che

Pagina 83

Chapter 4 Configuring the domain 173Nortel Secure Network Access Switch 4050 User Guide 2 Enter the TunnelGuard information in the applicable fields.

Pagina 84

174 Chapter 4 Configuring the domain320818-A Configuring the SSL server using the SREMTo configure settings for the SSL server, perform the following

Pagina 85

Chapter 4 Configuring the domain 175Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Pagina 86

176 Chapter 4 Configuring the domain320818-A Configuring SSL settings using the SREMTo configure SSL-specific settings for the portal server, perform

Pagina 87 - Figure 5

Chapter 4 Configuring the domain 177Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Pagina 88 - The SSH Key menu displays

178 Chapter 4 Configuring the domain320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Pagina 89

Chapter 4 Configuring the domain 179Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Pagina 90

18 Contents320818-A Viewing SONMP topology information using the SREM . . . . . . . . . . . . . . . . 675Viewing switch distribution using the SREM

Pagina 91 - /cfg/domain #/switch #/ena

180 Chapter 4 Configuring the domain320818-A 2 Enter the traffic log information in the applicable fields. Table 26 describes the Traffic Log Syslog S

Pagina 92 - Add a Switch fields

Chapter 4 Configuring the domain 181Nortel Secure Network Access Switch 4050 User Guide Tracing SSL traffic using the SREMTo verify connectivity and t

Pagina 93

182 Chapter 4 Configuring the domain320818-A To configure the domain to automatically redirect HTTP requests to the HTTPS server specified for the dom

Pagina 94

Chapter 4 Configuring the domain 183Nortel Secure Network Access Switch 4050 User Guide 2 Enter the redirection information in the applicable fields.

Pagina 95 - Table 4

184 Chapter 4 Configuring the domain320818-A • cause of terminationConfigure the RADIUS server in accordance with the recommendations in RFC 2866. Cer

Pagina 96

Chapter 4 Configuring the domain 185Nortel Secure Network Access Switch 4050 User Guide Contact your RADIUS system administrator for information about

Pagina 97 - Mapping VLANs by domain

186 Chapter 4 Configuring the domain320818-A 2 Enter the RADIUS accounting information in the applicable fields. Table 27 describes the RADIUS account

Pagina 98 - Adding VLANs to a domain

Chapter 4 Configuring the domain 187Nortel Secure Network Access Switch 4050 User Guide The Radius Accounting Servers screen appears (see Figure 36).F

Pagina 99 - Removing VLANs from a domain

188 Chapter 4 Configuring the domain320818-A 3 Enter the RADIUS accounting server information in the applicable fields. Table 29 describes the Radius

Pagina 100 - Mapping VLANs by switch

Chapter 4 Configuring the domain 189Nortel Secure Network Access Switch 4050 User Guide Deleting a RADIUS accounting server using the SREMTo delete a

Pagina 101 - Adding VLANs to a switch

Contents 19Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices and software using the SREM . . . . . . . . . 743Mana

Pagina 102 - Removing VLANs from a switch

190 Chapter 4 Configuring the domain320818-A

Pagina 103

191Nortel Secure Network Access Switch 4050 User Guide Chapter 5 Configuring groups and profilesThis chapter includes the following topics:Topic PageO

Pagina 104 - 320818-A

192 Chapter 5 Configuring groups and profiles320818-A OverviewThis section includes the following topics:• “Groups” on page 192• “Linksets” on page 19

Pagina 105 - Key Generation screen

Chapter 5 Configuring groups and profiles 193Nortel Secure Network Access Switch 4050 User Guide Each group’s data include the following configurable

Pagina 106 - Switch SSH Key fields

194 Chapter 5 Configuring groups and profiles320818-A LinksetsA linkset is a set of links that display on the portal page, so that the user can easily

Pagina 107 - Figure 13

Chapter 5 Configuring groups and profiles 195Nortel Secure Network Access Switch 4050 User Guide Extended profilesPassing or failing the SRS rule chec

Pagina 108 - Table 8

196 Chapter 5 Configuring groups and profiles320818-A Before you beginBefore you configure groups, client filters, and extended profiles on the Nortel

Pagina 109 - Switch SSH Key screen

Chapter 5 Configuring groups and profiles 197Nortel Secure Network Access Switch 4050 User Guide 3 Configure the extended profiles for the group (see

Pagina 110

198 Chapter 5 Configuring groups and profiles320818-A Configuring groups using the CLITo create and configure a group, use the following command:/cfg/

Pagina 111

Chapter 5 Configuring groups and profiles 199Nortel Secure Network Access Switch 4050 User Guide • number of sessions — the maximum number of simultan

Pagina 112 - Figure 15

2320818-A Copyright © Nortel Networks Limited 2005. All rights reserved.The information in this document is subject to change without notice. The stat

Pagina 113

20 Contents320818-A Configure the network DNS server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 782Configure the network D

Pagina 114 - Table 11

200 Chapter 5 Configuring groups and profiles320818-A Figure 38 shows sample output for the /cfg/domain 1/aaa/group <group ID> command and comma

Pagina 115

Chapter 5 Configuring groups and profiles 201Nortel Secure Network Access Switch 4050 User Guide Configuring client filters using the CLITo create and

Pagina 116 - Switch Configuration screen

202 Chapter 5 Configuring groups and profiles320818-A The Client Filter menu includes the following options:/cfg/domain 1/aaa/filter <filter ID>

Pagina 117 - Configuring the domain

Chapter 5 Configuring groups and profiles 203Nortel Secure Network Access Switch 4050 User Guide Figure 39 shows sample output for the /cfg/domain 1/a

Pagina 118 - /cfg/domain

204 Chapter 5 Configuring groups and profiles320818-A When you first create the profile, you are prompted to enter the following parameters:• client f

Pagina 119 - Roadmap of domain commands

Chapter 5 Configuring groups and profiles 205Nortel Secure Network Access Switch 4050 User Guide Figure 40 shows sample output for the /cfg/domain 1/a

Pagina 120

206 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a group or profile using the CLIYou can tailor the portal page for different

Pagina 121

Chapter 5 Configuring groups and profiles 207Nortel Secure Network Access Switch 4050 User Guide Figure 41 shows sample output for the /cfg/domain 1/a

Pagina 122 - <domain ID>

208 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the CLITo create a default group, first create a group with exten

Pagina 123 - Figure 17 Creating a domain

Chapter 5 Configuring groups and profiles 209Nortel Secure Network Access Switch 4050 User Guide Using the guide for creating groups If you desire add

Pagina 124

Contents 21Nortel Secure Network Access Switch 4050 User Guide CLI shortcuts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 125

210 Chapter 5 Configuring groups and profiles320818-A Adding a group To create and configure a group, perform the following steps:1 Select the Secure

Pagina 126

Chapter 5 Configuring groups and profiles 211Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Group dialog box appears (see

Pagina 127

212 Chapter 5 Configuring groups and profiles320818-A Modifying a groupTo configure a group, perform the following steps:1 Select the Secure Access Do

Pagina 128

Chapter 5 Configuring groups and profiles 213Nortel Secure Network Access Switch 4050 User Guide 2 Enter the group information in the applicable field

Pagina 129

214 Chapter 5 Configuring groups and profiles320818-A Adding a client filter To create and configure a client filter, perform the following steps:1 Se

Pagina 130

Chapter 5 Configuring groups and profiles 215Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Client Filter dialog box appear

Pagina 131

216 Chapter 5 Configuring groups and profiles320818-A 4 Click Apply.The new client filter now appears in the Client Filters table.5 Click Apply on the

Pagina 132

Chapter 5 Configuring groups and profiles 217Nortel Secure Network Access Switch 4050 User Guide Modifying a client filterTo configure a client filter

Pagina 133

218 Chapter 5 Configuring groups and profiles320818-A 2 Enter the Client Filter information in the applicable fields. Table 34 describes the Client Fi

Pagina 134

Chapter 5 Configuring groups and profiles 219Nortel Secure Network Access Switch 4050 User Guide Configuring extended profiles using the SREMTo view t

Pagina 135

22 Contents320818-A Root user password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 844Boot user password .

Pagina 136

220 Chapter 5 Configuring groups and profiles320818-A Adding an extended profile To create an extended profile for a group, perform the following step

Pagina 137 - The Trace menu displays

Chapter 5 Configuring groups and profiles 221Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add an Extended Profile dialog box o

Pagina 138

222 Chapter 5 Configuring groups and profiles320818-A Modifying an extended profileTo modify an extended profile for a group, perform the following st

Pagina 139

Chapter 5 Configuring groups and profiles 223Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Extended Profile information in the appli

Pagina 140

224 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a groupTo map a linkset to a group, select the Secure Access Domain > dom

Pagina 141

Chapter 5 Configuring groups and profiles 225Nortel Secure Network Access Switch 4050 User Guide Adding linksets to a groupTo add a linkset to a group

Pagina 142 - SSL is enabled by default

226 Chapter 5 Configuring groups and profiles320818-A Removing linksets from a groupTo remove a linkset from a group, perform the following steps:1 Se

Pagina 143

Chapter 5 Configuring groups and profiles 227Nortel Secure Network Access Switch 4050 User Guide Mapping linksets to a profileTo map a linkset to an e

Pagina 144

228 Chapter 5 Configuring groups and profiles320818-A Adding linksets to an extended profileTo add a linkset to an extended profile, perform the follo

Pagina 145

Chapter 5 Configuring groups and profiles 229Nortel Secure Network Access Switch 4050 User Guide Removing linksets from an extended profileTo remove a

Pagina 146

Contents 23Nortel Secure Network Access Switch 4050 User Guide Create a new attribute(Windows 2000 Server and Windows Server 2003) . . . . . . . . . .

Pagina 147

230 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the SREM To create a default group, first create a group with ext

Pagina 148

Chapter 5 Configuring groups and profiles 231Nortel Secure Network Access Switch 4050 User Guide 2 Enter the AAA information in the applicable fields.

Pagina 149 - NSNAS-Portal-ID)

232 Chapter 5 Configuring groups and profiles320818-A

Pagina 150

233Nortel Secure Network Access Switch 4050 User Guide Chapter 6 Configuring authenticationThis chapter includes the following topics:Topic PageOvervi

Pagina 151

234 Chapter 6 Configuring authentication320818-A OverviewThe Nortel SNAS 4050 controls authentication of clients when they log on to the network.The N

Pagina 152 - Figure 19

Chapter 6 Configuring authentication 235Nortel Secure Network Access Switch 4050 User Guide Before you beginBefore you configure authentication on the

Pagina 153 - Add a Secure Access Domain

236 Chapter 6 Configuring authentication320818-A — Vendor-Typeb LDAP servers:— server IP address— port number used for the service— configured account

Pagina 154

Chapter 6 Configuring authentication 237Nortel Secure Network Access Switch 4050 User Guide 3 Specify the order in which the authentication methods wi

Pagina 155 - Figure 21

238 Chapter 6 Configuring authentication320818-A domainid <domain ID>domaintype <domain type>authproto pap|chapv2timeout <interval>/

Pagina 156

Chapter 6 Configuring authentication 239Nortel Secure Network Access Switch 4050 User Guide Configuring authentication methods using the CLITo create

Pagina 157

24 Contents320818-A

Pagina 158 - 6 Click Next

240 Chapter 6 Configuring authentication320818-A When you first create the method, you are prompted to specify the type. For Nortel Secure Network Acc

Pagina 159 - Field Description

Chapter 6 Configuring authentication 241Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configu

Pagina 160 - Domain Quick Wizard – Server

242 Chapter 6 Configuring authentication320818-A To configure the current authentication scheme to retrieve user group information from a different au

Pagina 161 - Domain Quick Wizard – Switch

Chapter 6 Configuring authentication 243Nortel Secure Network Access Switch 4050 User Guide You can perform the following configuration tasks:• “Addin

Pagina 162

244 Chapter 6 Configuring authentication320818-A • vendor type for group — corresponds to the Vendor-Type value used in combination with the Vendor-Id

Pagina 163

Chapter 6 Configuring authentication 245Nortel Secure Network Access Switch 4050 User Guide Figure 56 shows sample output for the RADIUS method for th

Pagina 164 - Figure 28

246 Chapter 6 Configuring authentication320818-A The RADIUS menu displays.The RADIUS menu includes the following options:/cfg/domain 1/aaa/auth #/radi

Pagina 165 - Table 19

Chapter 6 Configuring authentication 247Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLIYou ca

Pagina 166 - Table 20

248 Chapter 6 Configuring authentication320818-A The Radius servers menu includes the following options:/cfg/domain 1/aaa/auth #/radius/serversfollowe

Pagina 167 - Table 21

Chapter 6 Configuring authentication 249Nortel Secure Network Access Switch 4050 User Guide Configuring session timeout using the CLIYou can configure

Pagina 168

25Nortel Secure Network Access Switch 4050 User Guide PrefaceNortel* Secure Network Access (Nortel SNA) is a clientless solution that provides seamles

Pagina 169

250 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Pagina 170 - Table 22

Chapter 6 Configuring authentication 251Nortel Secure Network Access Switch 4050 User Guide • if user entries are located in several places in the LDA

Pagina 171

252 Chapter 6 Configuring authentication320818-A Figure 57 shows sample output for the LDAP method for the /cfg/domain 1/aaa/auth <auth ID> comm

Pagina 172

Chapter 6 Configuring authentication 253Nortel Secure Network Access Switch 4050 User Guide The LDAP menu displays.The LDAP menu includes the followin

Pagina 173 - Table 23

254 Chapter 6 Configuring authentication320818-A userattr <names>Refers to one of the following:1. the LDAP attribute that contains the user nam

Pagina 174 - Figure 31

Chapter 6 Configuring authentication 255Nortel Secure Network Access Switch 4050 User Guide enaldaps true|falseIf true, makes LDAP requests between th

Pagina 175 - Table 24

256 Chapter 6 Configuring authentication320818-A Managing LDAP authentication servers using the CLIYou can configure additional LDAP servers for the d

Pagina 176 - Figure 32

Chapter 6 Configuring authentication 257Nortel Secure Network Access Switch 4050 User Guide del <index number>Removes the specified LDAP server

Pagina 177 - Table 25

258 Chapter 6 Configuring authentication320818-A Managing LDAP macros using the CLIYou can create your own macros (or variables), to allow you to retr

Pagina 178

Chapter 6 Configuring authentication 259Nortel Secure Network Access Switch 4050 User Guide add <variable name> <LDAP attribute> [<pref

Pagina 179

26 Preface320818-A The document provides instructions for initializing and customizing the features using the Command Line Interface (CLI). To learn t

Pagina 180 - Table 26

260 Chapter 6 Configuring authentication320818-A Managing Active Directory passwords using the CLIYou can set up a mechanism for clients to change the

Pagina 181

Chapter 6 Configuring authentication 261Nortel Secure Network Access Switch 4050 User Guide Configuring local database authentication using the CLIYou

Pagina 182 - Figure 34

262 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Pagina 183 - HTTP Redirect fields

Chapter 6 Configuring authentication 263Nortel Secure Network Access Switch 4050 User Guide • group name — the name of the group to which the specifie

Pagina 184

264 Chapter 6 Configuring authentication320818-A Managing the local database using the CLIYou can add users to the database in two ways:• manually, us

Pagina 185

Chapter 6 Configuring authentication 265Nortel Secure Network Access Switch 4050 User Guide The Local database menu includes the following options:/cf

Pagina 186

266 Chapter 6 Configuring authentication320818-A import <protocol> <server> <filename> <key>Imports a database from the specif

Pagina 187 - Figure 37

Chapter 6 Configuring authentication 267Nortel Secure Network Access Switch 4050 User Guide Specifying authentication fallback order using the CLIAuth

Pagina 188

268 Chapter 6 Configuring authentication320818-A Perform this step even if there is only one method defined on the Nortel SNAS 4050.To specify the aut

Pagina 189

Chapter 6 Configuring authentication 269Nortel Secure Network Access Switch 4050 User Guide Configuring authentication using the SREMThe basic steps f

Pagina 190

Preface 27Nortel Secure Network Access Switch 4050 User Guide Text conventionsThis guide uses the following text conventions:angle brackets (< >

Pagina 191 - Chapter 5

270 Chapter 6 Configuring authentication320818-A Configuring authentication methods using the SREMTo create and configure an authentication method, pe

Pagina 192 - Overview

Chapter 6 Configuring authentication 271Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add an Authentication Server dialog box op

Pagina 193 - Default group

272 Chapter 6 Configuring authentication320818-A Adding the RADIUS method and serverTo configure the Nortel SNAS 4050 to use an external RADIUS or Ste

Pagina 194 - TunnelGuard SRS rule

Chapter 6 Configuring authentication 273Nortel Secure Network Access Switch 4050 User Guide 2 Enter the authentication server information in the appli

Pagina 195 - Extended profiles

274 Chapter 6 Configuring authentication320818-A • Modify settings for the specific RADIUS configuration (see “Modifying RADIUS configuration settings

Pagina 196 - Before you begin

Chapter 6 Configuring authentication 275Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Pagina 197

276 Chapter 6 Configuring authentication320818-A Modifying RADIUS configuration settingsTo modify the RADIUS method configuration, perform the followi

Pagina 198

Chapter 6 Configuring authentication 277Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the RADIUS configuration as necessar

Pagina 199

278 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Pagina 200 - Figure 38

Chapter 6 Configuring authentication 279Nortel Secure Network Access Switch 4050 User Guide Managing additional RADIUS serversAdditional RADIUS server

Pagina 201

28 Preface320818-A Related informationThis section lists information sources that relate to this document.PublicationsRefer to the following publicati

Pagina 202

280 Chapter 6 Configuring authentication320818-A The RADIUS Server Table allows you to manage additional RADIUS servers by performing any of the follo

Pagina 203

Chapter 6 Configuring authentication 281Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new RADIUS server is automatically assig

Pagina 204

282 Chapter 6 Configuring authentication320818-A The RADIUS Servers screen appears (see Figure 69 on page 291).2 Select an RADIUS server entry from th

Pagina 205 - Figure 40

Chapter 6 Configuring authentication 283Nortel Secure Network Access Switch 4050 User Guide Adding the LDAP method and serverTo configure the Nortel S

Pagina 206

284 Chapter 6 Configuring authentication320818-A 3 Click Apply.The LDAP authentication method displays in the Authentication Server Table.4 Click Appl

Pagina 207 - Figure 41

Chapter 6 Configuring authentication 285Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP method settingsTo modify settings for an ex

Pagina 208

286 Chapter 6 Configuring authentication320818-A 2 Modify settings for the authentication method as necessary.Table 45 describes the Configuration fie

Pagina 209

Chapter 6 Configuring authentication 287Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP configuration settingsTo modify the LDAP me

Pagina 210 - Adding a group

288 Chapter 6 Configuring authentication320818-A 2 Modify settings for the LDAP configuration as necessary.Table 46 describes the LDAP Configuration f

Pagina 211 - Add a Group fields

Chapter 6 Configuring authentication 289Nortel Secure Network Access Switch 4050 User Guide User Attribute Refers to one of the following:1. the LDAP

Pagina 212 - Modifying a group

Preface 29Nortel Secure Network Access Switch 4050 User Guide • Release Notes for Nortel Ethernet Routing Switch 5500 Series, Software Release 4.3 (21

Pagina 213 - Group Configuration fields

290 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Pagina 214 - Adding a client filter

Chapter 6 Configuring authentication 291Nortel Secure Network Access Switch 4050 User Guide Managing additional LDAP serversAdditional LDAP servers ca

Pagina 215 - Adding a Client Filter screen

292 Chapter 6 Configuring authentication320818-A The LDAP Server Table allows you to manage additional LDAP servers by performing any of the following

Pagina 216 - 4 Click Apply

Chapter 6 Configuring authentication 293Nortel Secure Network Access Switch 4050 User Guide The new LDAP server is automatically assigned a unique ind

Pagina 217 - Modifying a client filter

294 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Pagina 218 - Table 34

Chapter 6 Configuring authentication 295Nortel Secure Network Access Switch 4050 User Guide To manage LDAP macro variables, select the Secure Access D

Pagina 219

296 Chapter 6 Configuring authentication320818-A Adding LDAP macrosTo create an LDAP macro variable, perform the following steps:1 Select the Secure A

Pagina 220 - Adding an extended profile

Chapter 6 Configuring authentication 297Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new LDAP macro is automatically assigned

Pagina 221

298 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Pagina 222 - Modifying an extended profile

Chapter 6 Configuring authentication 299Nortel Secure Network Access Switch 4050 User Guide Adding the Local methodTo configure the Nortel SNAS 4050 t

Pagina 223

3Nortel Secure Network Access Switch 4050 User Guide In addition, the program and information contained herein are licensed only pursuant to a license

Pagina 224 - Mapping linksets to a group

30 Preface320818-A • To call a Nortel Technical Solutions Center for assistance, click the CALL US link on the left side of the page to find the telep

Pagina 225 - Adding linksets to a group

300 Chapter 6 Configuring authentication320818-A 2 Enter the authentication server information in the applicable fields.Table 49 describes the Add an

Pagina 226

Chapter 6 Configuring authentication 301Nortel Secure Network Access Switch 4050 User Guide Populating the databaseYou can populate the Local database

Pagina 227 - Mapping linksets to a profile

302 Chapter 6 Configuring authentication320818-A 2 Click Add.The Add a Local User dialog box appears (see Figure 75).Figure 75 Add a Local User3 Ent

Pagina 228 - Add a Linkset fields

Chapter 6 Configuring authentication 303Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new user entry appears in the list of lo

Pagina 229

304 Chapter 6 Configuring authentication320818-A Importing a database To import a database of local users, perform the following steps.1 Select the Se

Pagina 230 - AAA Configuration screen

Chapter 6 Configuring authentication 305Nortel Secure Network Access Switch 4050 User Guide 2 Enter the import information in the applicable fields.Ta

Pagina 231 - Table 39

306 Chapter 6 Configuring authentication320818-A Modifying Local method settingsTo modify settings for an existing local or LDAP authentication method

Pagina 232

Chapter 6 Configuring authentication 307Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Pagina 233 - Configuring authentication

308 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Pagina 234

Chapter 6 Configuring authentication 309Nortel Secure Network Access Switch 4050 User Guide 3 Modify the local user information in the applicable fiel

Pagina 235

31Nortel Secure Network Access Switch 4050 User Guide Chapter 1 OverviewThis chapter includes the following topics:The Nortel SNA solutionNortel Secur

Pagina 236

310 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Pagina 237

Chapter 6 Configuring authentication 311Nortel Secure Network Access Switch 4050 User Guide 4 Modify the local user information in the applicable fiel

Pagina 238

312 Chapter 6 Configuring authentication320818-A Exporting the databaseTo export the database of local users, perform the following steps:1 Select the

Pagina 239

Chapter 6 Configuring authentication 313Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields.Ta

Pagina 240

314 Chapter 6 Configuring authentication320818-A Specifying authentication fallback order using the SREMAuthentication in the Nortel SNAS 4050 solutio

Pagina 241

Chapter 6 Configuring authentication 315Nortel Secure Network Access Switch 4050 User Guide To specify authentication fallback order, perform these st

Pagina 242

316 Chapter 6 Configuring authentication320818-A 3 Rearrange the list so that the methods appear in the desired order.a Click on a method to select it

Pagina 243

317Nortel Secure Network Access Switch 4050 User Guide Chapter 7 TunnelGuard SRS BuilderThis chapter includes the following topics:Topic PageConfiguri

Pagina 244 - 1/aaa/group <group ID>

318 Chapter 7 TunnelGuard SRS Builder320818-A Configuring SRS rulesThe building blocks used to construct the Software Requirement Set (SRS) are files

Pagina 245

Chapter 7 TunnelGuard SRS Builder 319Nortel Secure Network Access Switch 4050 User Guide • “Software Definition — Available SRS list” on page 323• “Me

Pagina 246 - The RADIUS menu displays

32 Chapter 1 Overview320818-A For Nortel, success is delivering technologies providing secure access to your information using security-compliant syst

Pagina 247

320 Chapter 7 TunnelGuard SRS Builder320818-A Software Definition Entry menuTable 58 describes important items from the Software Definition Entry menu

Pagina 248

Chapter 7 TunnelGuard SRS Builder 321Nortel Secure Network Access Switch 4050 User Guide TunnelGuard Rule menuTable 59 describes important items from

Pagina 249

322 Chapter 7 TunnelGuard SRS Builder320818-A SRS definition toolbarThe buttons on the SRS definition toolbar allow you to create, delete, and manage

Pagina 250

Chapter 7 TunnelGuard SRS Builder 323Nortel Secure Network Access Switch 4050 User Guide Software Definition — Available SRS listThe available SRS lis

Pagina 251

324 Chapter 7 TunnelGuard SRS Builder320818-A Customizing a componentWhen an SRS component is selected by clicking on it, you can customize it using t

Pagina 252

Chapter 7 TunnelGuard SRS Builder 325Nortel Secure Network Access Switch 4050 User Guide Memory snapshotThe memory snapshot section in the lower half

Pagina 253 - The LDAP menu displays

326 Chapter 7 TunnelGuard SRS Builder320818-A SRS Rule listThe SRS Rule list shows the existing SRS rules. These rules are retrieved from the Nortel S

Pagina 254

Chapter 7 TunnelGuard SRS Builder 327Nortel Secure Network Access Switch 4050 User Guide Once the expression is formed, it is available for rule defin

Pagina 255

328 Chapter 7 TunnelGuard SRS Builder320818-A Figure 84 The New SRS window2 Enter a name for the software definition and click OK.For example, to cr

Pagina 256

Chapter 7 TunnelGuard SRS Builder 329Nortel Secure Network Access Switch 4050 User Guide Figure 85 The Create New Memory Module SRS window3 In the F

Pagina 257

Chapter 1 Overview 33Nortel Secure Network Access Switch 4050 User Guide Java Runtime Environment (JRE) for all browsers:— JRE 1.5.0_04 or later• VoIP

Pagina 258

330 Chapter 7 TunnelGuard SRS Builder320818-A If enabled, the client system will be searched for the specified file name, irrespective of path to fold

Pagina 259

Chapter 7 TunnelGuard SRS Builder 331Nortel Secure Network Access Switch 4050 User Guide The file/module is added as an entry in the selected software

Pagina 260

332 Chapter 7 TunnelGuard SRS Builder320818-A To create a software definition entry for a file not shown in the memory snapshot, perform the following

Pagina 261

Chapter 7 TunnelGuard SRS Builder 333Nortel Secure Network Access Switch 4050 User Guide 3 Select the Fetch Module Path from Registry Entry check box,

Pagina 262

334 Chapter 7 TunnelGuard SRS Builder320818-A 2 Click the TunnelGuard Rule Definition tab.TunnelGuard rules and expressions with the same names as the

Pagina 263

Chapter 7 TunnelGuard SRS Builder 335Nortel Secure Network Access Switch 4050 User Guide 4 Select another expression that you will use to form a new l

Pagina 264

336 Chapter 7 TunnelGuard SRS Builder320818-A Figure 88 The Available Expressions screen7 Create a new TunnelGuard Rule.On the TunnelGuard Rule menu

Pagina 265

Chapter 7 TunnelGuard SRS Builder 337Nortel Secure Network Access Switch 4050 User Guide The new rule name appears in the TunnelGuard Rule Name column

Pagina 266

338 Chapter 7 TunnelGuard SRS Builder320818-A Registry-based rulesTunnelGuard Agent supports checking of on-disk files, running processes, hash checki

Pagina 267

Chapter 7 TunnelGuard SRS Builder 339Nortel Secure Network Access Switch 4050 User Guide Table 66 describes supported operands for integer values.The

Pagina 268

34 Chapter 1 Overview320818-A Nortel SNAS 4050 functionsThe Nortel SNAS 4050 performs the following functions:• Acts as a web server portal, which is

Pagina 269

340 Chapter 7 TunnelGuard SRS Builder320818-A Table 67 describes supported constructs for string-based regular expressions.Table 67 Constructs for s

Pagina 270 - Figure 60

Chapter 7 TunnelGuard SRS Builder 341Nortel Secure Network Access Switch 4050 User Guide The following are examples of regular expressions for string-

Pagina 271

342 Chapter 7 TunnelGuard SRS Builder320818-A Figure 91 Registry Entry page3 Select the Registry Key Path from the Registry Editor.4 Select the Key

Pagina 272

Chapter 7 TunnelGuard SRS Builder 343Nortel Secure Network Access Switch 4050 User Guide Manually creating SRS entriesThe administrator tool applet pr

Pagina 273

344 Chapter 7 TunnelGuard SRS Builder320818-A Figure 92 Create new OnDisk SRS Entry3 Click Browse Local System to select the File or Module Path. Th

Pagina 274 - Configuration

Chapter 7 TunnelGuard SRS Builder 345Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for either Relative Date/Time Range

Pagina 275 - Table 41

346 Chapter 7 TunnelGuard SRS Builder320818-A Figure 93 Create new Memory Module SRS entry3 Click Browse Local System to select the File or Module P

Pagina 276 - Figure 63

Chapter 7 TunnelGuard SRS Builder 347Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for Max Version.7 Click an option bu

Pagina 277 - Table 42

348 Chapter 7 TunnelGuard SRS Builder320818-A Figure 94 Date/Time RangeAdding comments• “Adding a TunnelGuard rule comment” on page 348• “Adding a s

Pagina 278

Chapter 7 TunnelGuard SRS Builder 349Nortel Secure Network Access Switch 4050 User Guide 3 Click the button to display the Rule Comment window (see Fi

Pagina 279 - Radius Servers

Chapter 1 Overview 35Nortel Secure Network Access Switch 4050 User Guide • VoIP — automatic access for VoIP traffic. The network access device places

Pagina 280 - Adding a RADIUS server

350 Chapter 7 TunnelGuard SRS Builder320818-A Deleting a software definition1 Click the Software Definition tab.2 In the Software Definition column, s

Pagina 281 - Removing a RADIUS server

Chapter 7 TunnelGuard SRS Builder 351Nortel Secure Network Access Switch 4050 User Guide 2 In the Available Expressions area, select the desired expre

Pagina 282 - Next steps

352 Chapter 7 TunnelGuard SRS Builder320818-A

Pagina 283

353Nortel Secure Network Access Switch 4050 User Guide Chapter 8 Managing system users and groupsThis chapter includes the following topics:Topic Page

Pagina 284 - Modifying LDAP configuration

354 Chapter 8 Managing system users and groups320818-A User rights and group membershipThere are three groups of system users who routinely access the

Pagina 285

Chapter 8 Managing system users and groups 355Nortel Secure Network Access Switch 4050 User Guide Managing system users and groups using the CLITo man

Pagina 286 - Table 45

356 Chapter 8 Managing system users and groups320818-A Managing user accounts and passwords using the CLITo change the password for the currently logg

Pagina 287 - Figure 68

Chapter 8 Managing system users and groups 357Nortel Secure Network Access Switch 4050 User Guide del <username>Removes the specified user accou

Pagina 288 - Table 46

358 Chapter 8 Managing system users and groups320818-A Managing user settings using the CLIYou must have administrator rights in order to change a use

Pagina 289

Chapter 8 Managing system users and groups 359Nortel Secure Network Access Switch 4050 User Guide To set or change the login password for a specified

Pagina 290

36 Chapter 1 Overview320818-A Authentication methodsYou can configure more than one authentication method within a Nortel SNAS 4050 domain. Nortel Sec

Pagina 291 - LDAP Servers

360 Chapter 8 Managing system users and groups320818-A To set or change a user’s group assignment, access the Groups menu by using the following comma

Pagina 292 - Adding an LDAP server

Chapter 8 Managing system users and groups 361Nortel Secure Network Access Switch 4050 User Guide In this configuration example, a certificate adminis

Pagina 293 - Removing an LDAP server

362 Chapter 8 Managing system users and groups320818-A —oper—admin— certadminBy default, the admin user is a member of all groups above, and can there

Pagina 294 - Managing LDAP macros

Chapter 8 Managing system users and groups 363Nortel Secure Network Access Switch 4050 User Guide 7 Apply the changes.8 Let the Certificate Administra

Pagina 295 - LDAP Macros

364 Chapter 8 Managing system users and groups320818-A 9 Remove the admin user from the certadmin group.Again, this step is only necessary if you want

Pagina 296 - Adding LDAP macros

Chapter 8 Managing system users and groups 365Nortel Secure Network Access Switch 4050 User Guide Changing a user’s group assignmentOnly users who are

Pagina 297 - Removing LDAP macros

366 Chapter 8 Managing system users and groups320818-A 4 Verify and apply the changes.Changing passwordsChanging your own passwordAll users can change

Pagina 298

Chapter 8 Managing system users and groups 367Nortel Secure Network Access Switch 4050 User Guide 2 Access the User Menu.Type the passwd command to ch

Pagina 299 - Adding the Local method

368 Chapter 8 Managing system users and groups320818-A 2 Access the User Menu.3 Specify the user name of the user whose password you want to change.4

Pagina 300

Chapter 8 Managing system users and groups 369Nortel Secure Network Access Switch 4050 User Guide Deleting a userTo delete a user from the system, you

Pagina 301 - Populating the database

Chapter 1 Overview 37Nortel Secure Network Access Switch 4050 User Guide TunnelGuard host integrity checkThe TunnelGuard application checks client hos

Pagina 302 - Add a Local User fields

370 Chapter 8 Managing system users and groups320818-A The imminent removal of the cert_admin user is indicated as a pending configuration change by t

Pagina 303

Chapter 8 Managing system users and groups 371Nortel Secure Network Access Switch 4050 User Guide The User Table appears (see Figure 96), displaying a

Pagina 304 - Importing a database

372 Chapter 8 Managing system users and groups320818-A Only the admin user can delete users from the system. Of the three built-in users (admin, oper,

Pagina 305

Chapter 8 Managing system users and groups 373Nortel Secure Network Access Switch 4050 User Guide 3 Enter the user information in the applicable field

Pagina 306

374 Chapter 8 Managing system users and groups320818-A Setting password expiry using the SREMTo set a password expiry date for all passwords in the sy

Pagina 307 - Modifying local users

Chapter 8 Managing system users and groups 375Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Password Setting information in the appl

Pagina 308 - Figure 78

376 Chapter 8 Managing system users and groups320818-A Changing your password using the SREMOnly the admin user can change the passwords of other user

Pagina 309

Chapter 8 Managing system users and groups 377Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Pagina 310

378 Chapter 8 Managing system users and groups320818-A To change the password for another user, perform the following steps:1 Select the System > M

Pagina 311 - Table 54

Chapter 8 Managing system users and groups 379Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Pagina 312 - Exporting the database

38 Chapter 1 Overview320818-A Communication channelsCommunications between the Nortel SNAS 4050 and key elements of the Nortel SNA solution are secure

Pagina 313

380 Chapter 8 Managing system users and groups320818-A To set a certificate export pass phrase, perform the following steps:1 Select the System > M

Pagina 314

Chapter 8 Managing system users and groups 381Nortel Secure Network Access Switch 4050 User Guide 2 Enter the PassPhrase information in the applicable

Pagina 315 - Authentication Server Order

382 Chapter 8 Managing system users and groups320818-A To manage the group to which a user belongs, select the System > Manage Users > user >

Pagina 316

Chapter 8 Managing system users and groups 383Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a User Group dialog box appears

Pagina 317 - TunnelGuard SRS Builder

384 Chapter 8 Managing system users and groups320818-A The user group is immediately removed from the User Group Table.5 Click Apply on the toolbar to

Pagina 318 - Configuring SRS rules

385Nortel Secure Network Access Switch 4050 User Guide Chapter 9 Customizing the portal and user logonThis chapter includes the following topics:Topic

Pagina 319 - Menu commands

386 Chapter 9 Customizing the portal and user logon320818-A OverviewThe end user accesses the Nortel SNA network through the Nortel SNAS 4050 portal.

Pagina 320

Chapter 9 Customizing the portal and user logon 387Nortel Secure Network Access Switch 4050 User Guide • redirects client requests to an authenticatio

Pagina 321 - Tool menu

388 Chapter 9 Customizing the portal and user logon320818-A Table 75 lists the regular expressions and escape sequences you can use in an Exclude List

Pagina 322 - SRS definition toolbar

Chapter 9 Customizing the portal and user logon 389Nortel Secure Network Access Switch 4050 User Guide Portal displayYou can modify the following feat

Pagina 323 - SRS Components table

Chapter 1 Overview 39Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 supports the use of three different SSH host key types:

Pagina 324 - Customizing a component

390 Chapter 9 Customizing the portal and user logon320818-A Default appearanceFigure 104 shows the default portal Home tab.Figure 104 Default appear

Pagina 325 - Memory snapshot

Chapter 9 Customizing the portal and user logon 391Nortel Secure Network Access Switch 4050 User Guide • color3 — the fields, information area, and cl

Pagina 326 - Rule Expression Constructor

392 Chapter 9 Customizing the portal and user logon320818-A For the commands to configure the colors used on the portal, see “Changing the portal colo

Pagina 327

Chapter 9 Customizing the portal and user logon 393Nortel Secure Network Access Switch 4050 User Guide To change the language displayed for tab names,

Pagina 328 - The New SRS window

394 Chapter 9 Customizing the portal and user logon320818-A Linksets and linksYou can add the following types of links to the portal Home tab:• Extern

Pagina 329

Chapter 9 Customizing the portal and user logon 395Nortel Secure Network Access Switch 4050 User Guide Planning the linksetsPlan your configuration so

Pagina 330

396 Chapter 9 Customizing the portal and user logon320818-A Automatic redirection to internal sitesYou can configure the portal to automatically redir

Pagina 331 - Selecting file on disk

Chapter 9 Customizing the portal and user logon 397Nortel Secure Network Access Switch 4050 User Guide Managing the end user experienceNortel recommen

Pagina 332

398 Chapter 9 Customizing the portal and user logon320818-A 2 Download the JRE installer from the Sun Microsystems Java web site (http://www.java.com)

Pagina 333 - Creating logical expressions

Chapter 9 Customizing the portal and user logon 399Nortel Secure Network Access Switch 4050 User Guide /cfg/domain 1/dnscapt/exclude listdel <index

Pagina 334

4320818-A BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nort

Pagina 335

40 Chapter 1 Overview320818-A • fault tolerance — If a Nortel SNAS 4050 device fails, the failure is detected by the other node in the cluster, which

Pagina 336 - The New SRS Rule window

400 Chapter 9 Customizing the portal and user logon320818-A color2 <code>color3 <code>color4 <code>theme default|aqua|apple| jeans|c

Pagina 337

Chapter 9 Customizing the portal and user logon 401Nortel Secure Network Access Switch 4050 User Guide Configuring the captive portal using the CLIBy

Pagina 338 - Registry-based rules

402 Chapter 9 Customizing the portal and user logon320818-A The DNS Exclude menu includes the following options:Changing the portal language using the

Pagina 339 - Supported integer operands

Chapter 9 Customizing the portal and user logon 403Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the CLITo ma

Pagina 340 - Table 67

404 Chapter 9 Customizing the portal and user logon320818-A The Language Support menu includes the following options:/cfg/langfollowed by:import <p

Pagina 341 - Creating a registry entry

Chapter 9 Customizing the portal and user logon 405Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the C

Pagina 342 - Registry-based File/Module

406 Chapter 9 Customizing the portal and user logon320818-A Configuring the portal display using the CLITo modify the look and feel of the portal page

Pagina 343 - Manually creating SRS entries

Chapter 9 Customizing the portal and user logon 407Nortel Secure Network Access Switch 4050 User Guide redirect <URL>Sets the URL to which clien

Pagina 344 - Create new OnDisk SRS Entry

408 Chapter 9 Customizing the portal and user logon320818-A linktext <text>Specifies static text to be displayed above the group links on the po

Pagina 345

Chapter 9 Customizing the portal and user logon 409Nortel Secure Network Access Switch 4050 User Guide Changing the portal colors using the CLITo cust

Pagina 346

Chapter 1 Overview 41Nortel Secure Network Access Switch 4050 User Guide One-armed configurationIn a one-armed configuration, the Nortel SNAS 4050 has

Pagina 347 - File age check

410 Chapter 9 Customizing the portal and user logon320818-A The Portal Colors menu includes the following options:For more information about the porta

Pagina 348 - Adding comments

Chapter 9 Customizing the portal and user logon 411Nortel Secure Network Access Switch 4050 User Guide The Portal Custom Content menu includes the fol

Pagina 349 - The Rule Comment window

412 Chapter 9 Customizing the portal and user logon320818-A Configuring linksets using the CLIA linkset is a set of links that display on the portal H

Pagina 350 - Deleting an expression

Chapter 9 Customizing the portal and user logon 413Nortel Secure Network Access Switch 4050 User Guide The Linkset menu includes the following options

Pagina 351 - Making API calls

414 Chapter 9 Customizing the portal and user logon320818-A Configuring links using the CLITo create and configure the links included in the linkset,

Pagina 352

Chapter 9 Customizing the portal and user logon 415Nortel Secure Network Access Switch 4050 User Guide The Link menu includes the following options:/c

Pagina 353 - Chapter 8

416 Chapter 9 Customizing the portal and user logon320818-A Configuring external link settings using the CLITo launch the wizard to configure settings

Pagina 354

Chapter 9 Customizing the portal and user logon 417Nortel Secure Network Access Switch 4050 User Guide Customizing the portal and logon using the SREM

Pagina 355

418 Chapter 9 Customizing the portal and user logon320818-A Figure 105 DNS Capture screenThe DNS Capture screen includes the following components:2

Pagina 356

Chapter 9 Customizing the portal and user logon 419Nortel Secure Network Access Switch 4050 User Guide Configuring the DNS Exclude List using the SREM

Pagina 357

42 Chapter 1 Overview320818-A Figure 2 illustrates a two-armed configuration.Figure 2 Two-armed configurationNortel SNA configuration and management

Pagina 358

420 Chapter 9 Customizing the portal and user logon320818-A 3 To remove an entry from the Exclude List:a In the DNS Exclude List, select the entry you

Pagina 359

Chapter 9 Customizing the portal and user logon 421Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the SREMTo m

Pagina 360 - CLI configuration examples

422 Chapter 9 Customizing the portal and user logon320818-A Viewing predefined languagesTo view predefined languages, click the Pre-defined Languages

Pagina 361

Chapter 9 Customizing the portal and user logon 423Nortel Secure Network Access Switch 4050 User Guide b Click Apply on the toolbar to send the curren

Pagina 362 - Old: is empty

424 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Language information in the applicable fields. Table 80 describes the Import D

Pagina 363

Chapter 9 Customizing the portal and user logon 425Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the S

Pagina 364 - /cfg/cert)

426 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the language information in the applicable fields. Table 81 describes the Langauge

Pagina 365

Chapter 9 Customizing the portal and user logon 427Nortel Secure Network Access Switch 4050 User Guide Configuring contentTo configure and modify port

Pagina 366 - Changing your own password

428 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Portal Configuration information in the applicable fields. Table 82 describes

Pagina 367

Chapter 9 Customizing the portal and user logon 429Nortel Secure Network Access Switch 4050 User Guide Redirect URL Sets the URL to which clients are

Pagina 368 - 5 Apply the changes

Chapter 1 Overview 43Nortel Secure Network Access Switch 4050 User Guide • Security & Routing Element Manager (SREM)The SREM is a GUI application

Pagina 369 - Deleting a user

430 Chapter 9 Customizing the portal and user logon320818-A Importing bannersTo import a banner to display on the portal Home page, perform the follow

Pagina 370

Chapter 9 Customizing the portal and user logon 431Nortel Secure Network Access Switch 4050 User Guide 2 Enter the banner information in the applicabl

Pagina 371 - User Table

432 Chapter 9 Customizing the portal and user logon320818-A Changing the portal colors using the SREMTo customize the colors used for portal display,

Pagina 372 - Adding new user accounts

Chapter 9 Customizing the portal and user logon 433Nortel Secure Network Access Switch 4050 User Guide 2 Enter the color information in the applicable

Pagina 373 - Add a User fields

434 Chapter 9 Customizing the portal and user logon320818-A Configuring custom content using the SREMTo configure custom content, such as Java applets

Pagina 374 - Figure 98

Chapter 9 Customizing the portal and user logon 435Nortel Secure Network Access Switch 4050 User Guide Viewing basic information about custom contentT

Pagina 375 - Table 70

436 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the basic information in the applicable fields. Table 85 describes the Basics fiel

Pagina 376 - Change Your Password

Chapter 9 Customizing the portal and user logon 437Nortel Secure Network Access Switch 4050 User Guide Importing custom contentTo import custom conten

Pagina 377 - Change Your Password fields

438 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the import information in the applicable fields. Table 86 describes the Import Con

Pagina 378 - Figure 100

Chapter 9 Customizing the portal and user logon 439Nortel Secure Network Access Switch 4050 User Guide Exporting custom contentTo export custom conten

Pagina 379 - Change User Password fields

44 Chapter 1 Overview320818-A For each VLAN:a Create a DHCP scope.b Specify the IP address range and subnet mask for that scope.c Configure the follow

Pagina 380 - Figure 101

440 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the export information in the applicable fields. Table 87 describes the Export Con

Pagina 381

Chapter 9 Customizing the portal and user logon 441Nortel Secure Network Access Switch 4050 User Guide Creating a linksetTo create a linkset, perform

Pagina 382 - Adding a user group

442 Chapter 9 Customizing the portal and user logon320818-A 2 Click Add.The Add a Linkset dialog box appears (see Figure 118).Figure 118 Add a Links

Pagina 383 - Removing a user group

Chapter 9 Customizing the portal and user logon 443Nortel Secure Network Access Switch 4050 User Guide Modifying a linksetTo modify a linkset, perform

Pagina 384

444 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the linkset information in the applicable fields. Table 89 describes the linkset C

Pagina 385 - Chapter 9

Chapter 9 Customizing the portal and user logon 445Nortel Secure Network Access Switch 4050 User Guide Configuring links using the SREMAfter you creat

Pagina 386

446 Chapter 9 Customizing the portal and user logon320818-A Creating an external link using the SREMTo create an external link, perform the following

Pagina 387 - Exclude List

Chapter 9 Customizing the portal and user logon 447Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Portal Link dialog box ap

Pagina 388 - Table 75

448 Chapter 9 Customizing the portal and user logon320818-A 5 Click Apply.The new external link appears in the Links table.6 Click Apply on the toolba

Pagina 389 - Portal display

Chapter 9 Customizing the portal and user logon 449Nortel Secure Network Access Switch 4050 User Guide To create an FTP link, perform the following st

Pagina 390 - Default appearance

Chapter 1 Overview 45Nortel Secure Network Access Switch 4050 User Guide Use the applicable show commands on the router to verify that DHCP relay has

Pagina 391

450 Chapter 9 Customizing the portal and user logon320818-A 4 Enter the link information in the applicable fields. Table 91 describes the Add a Portal

Pagina 392 - Language localization

Chapter 9 Customizing the portal and user logon 451Nortel Secure Network Access Switch 4050 User Guide Modifying external link settings using the SREM

Pagina 393

452 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 92 describes the external lin

Pagina 394 - Autorun linksets

Chapter 9 Customizing the portal and user logon 453Nortel Secure Network Access Switch 4050 User Guide Modifying FTP link settings using the SREMTo mo

Pagina 395 - Planning the linksets

454 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 93 describes the FTP link Con

Pagina 396

Chapter 9 Customizing the portal and user logon 455Nortel Secure Network Access Switch 4050 User Guide The Re Order Links screen appears (see Figure 1

Pagina 397 - Automatic JRE upload

456 Chapter 9 Customizing the portal and user logon320818-A

Pagina 398 - Windows domain logon script

457Nortel Secure Network Access Switch 4050 User Guide Chapter 10 Configuring system settingsThis chapter includes the following topics:Topic PageConf

Pagina 399 - Command Parameter

458 Chapter 10 Configuring system settings320818-A System settings apply to a cluster as a whole.You can log on to either the Management IP address (M

Pagina 400

Chapter 10 Configuring system settings 459Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the CLITo configure the cl

Pagina 401

46 Chapter 1 Overview320818-A Identify switch ports as either uplink or dynamic. When you configure the uplink ports, you associate the NSNA VLANs wit

Pagina 402

460 Chapter 10 Configuring system settings320818-A • disabling SSL traffic trace commands (see “Configuring system settings using the CLI” on page 463

Pagina 403 - /cfg/lang

Chapter 10 Configuring system settings 461Nortel Secure Network Access Switch 4050 User Guide del <index number>add <IPaddr> <mask>

Pagina 404

462 Chapter 10 Configuring system settings320818-A health <interval>hdown <count>hup <count>/cfg/sys/dns/serverslistdel <index nu

Pagina 405

Chapter 10 Configuring system settings 463Nortel Secure Network Access Switch 4050 User Guide show/cfg/sys/adm/sshkeys/knownhostslistdel <index num

Pagina 406 - The Portal menu displays

464 Chapter 10 Configuring system settings320818-A Configuring system settings using the CLITo view and configure cluster-wide system settings, use th

Pagina 407

Chapter 10 Configuring system settings 465Nortel Secure Network Access Switch 4050 User Guide Configuring the Nortel SNAS 4050 host using the CLITo co

Pagina 408

466 Chapter 10 Configuring system settings320818-A The Cluster Host menu includes the following options:/cfg/sys/host <host ID>followed by:ip &l

Pagina 409

Chapter 10 Configuring system settings 467Nortel Secure Network Access Switch 4050 User Guide portAccesses the Host Port menu, in order to configure p

Pagina 410

468 Chapter 10 Configuring system settings320818-A rebootReboots the Nortel SNAS 4050.If the Nortel SNAS 4050 you want to reboot has become isolated f

Pagina 411

Chapter 10 Configuring system settings 469Nortel Secure Network Access Switch 4050 User Guide Viewing host informationTo view the host number and IP a

Pagina 412

Chapter 1 Overview 47Nortel Secure Network Access Switch 4050 User Guide configuration in the SREM (see “Checking configuration using the SREM” on pag

Pagina 413

470 Chapter 10 Configuring system settings320818-A gateway <IPaddr>Sets the default gateway address for the interface. The default gateway is th

Pagina 414

Chapter 10 Configuring system settings 471Nortel Secure Network Access Switch 4050 User Guide Configuring static routes using the CLITo manage static

Pagina 415

472 Chapter 10 Configuring system settings320818-A The system, host, or interface Routes menu displays.When you add a static route to the system, host

Pagina 416

Chapter 10 Configuring system settings 473Nortel Secure Network Access Switch 4050 User Guide The Host Port menu includes the following options:Managi

Pagina 417 - Enabling DNS capture

474 Chapter 10 Configuring system settings320818-A The Interface Ports menu includes the following options:Configuring the Access List using the CLITh

Pagina 418 - DNS Capture fields

Chapter 10 Configuring system settings 475Nortel Secure Network Access Switch 4050 User Guide The Access List menu displays.The Access List menu inclu

Pagina 419 - Add DNS Domain fields

476 Chapter 10 Configuring system settings320818-A The Date and Time menu includes the following options:Managing NTP serversYou can add NTP servers t

Pagina 420

Chapter 10 Configuring system settings 477Nortel Secure Network Access Switch 4050 User Guide The NTP Servers menu includes the following options:Conf

Pagina 421 - Pre-defined Languages

478 Chapter 10 Configuring system settings320818-A retransmit <interval>Sets the interval for retransmitting a DNS query. •interval is a positiv

Pagina 422 - Viewing predefined languages

Chapter 10 Configuring system settings 479Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Pagina 423 - Import/Export Definition

48 Chapter 1 Overview320818-A

Pagina 424

480 Chapter 10 Configuring system settings320818-A Configuring RSA servers using the CLITo configure the symbolic name for the RSA server and import t

Pagina 425 - Figure 110

Chapter 10 Configuring system settings 481Nortel Secure Network Access Switch 4050 User Guide The RSA Servers menu includes the following options:Conf

Pagina 426 - Language fields

482 Chapter 10 Configuring system settings320818-A The Syslog Servers menu includes the following options:/cfg/sys/syslogfollowed by:listLists the IP

Pagina 427 - Configuring content

Chapter 10 Configuring system settings 483Nortel Secure Network Access Switch 4050 User Guide Configuring administrative settings using the CLIAdminis

Pagina 428 - Table 82

484 Chapter 10 Configuring system settings320818-A auditAccesses the Audit menu, in order to configure RADIUS auditing (see “Configuring RADIUS auditi

Pagina 429

Chapter 10 Configuring system settings 485Nortel Secure Network Access Switch 4050 User Guide Enabling TunnelGuard SRS administration using the CLITo

Pagina 430 - Importing banners

486 Chapter 10 Configuring system settings320818-A During initial setup, there is an option to generate the SSH host keys automatically. To generate a

Pagina 431 - Import Banner fields

Chapter 10 Configuring system settings 487Nortel Secure Network Access Switch 4050 User Guide Managing known hosts SSH keys using the CLIYou can paste

Pagina 432 - Figure 113

488 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditing using the CLIYou can configure the Nortel SNAS 4050 cluster to include

Pagina 433 - Color Settings fields

Chapter 10 Configuring system settings 489Nortel Secure Network Access Switch 4050 User Guide The Internet Assigned Numbers Authority (IANA) has desig

Pagina 434

49Nortel Secure Network Access Switch 4050 User Guide Chapter 2 Initial setupThis chapter includes the following topics:Topic PageBefore you begin50Ab

Pagina 435 - Basics screen

490 Chapter 10 Configuring system settings320818-A Managing RADIUS audit servers using the CLITo configure the Nortel SNAS 4050 to use external RADIUS

Pagina 436 - Table 85

Chapter 10 Configuring system settings 491Nortel Secure Network Access Switch 4050 User Guide add <IPaddr> <port> <shared secret>Add

Pagina 437 - Importing custom content

492 Chapter 10 Configuring system settings320818-A Configuring authentication of system users using the CLIYou can configure the Nortel SNAS 4050 clus

Pagina 438 - Table 86

Chapter 10 Configuring system settings 493Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLITo c

Pagina 439 - Exporting custom content

494 Chapter 10 Configuring system settings320818-A The RADIUS Authentication Servers menu includes the following options:/cfg/sys/adm/auth/serversfoll

Pagina 440 - Export Content fields

Chapter 10 Configuring system settings 495Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the SREMTo configure the c

Pagina 441 - Creating a linkset

496 Chapter 10 Configuring system settings320818-A Configuring system settings using the SREMTo view and configure cluster-wide system settings, perfo

Pagina 442 - Add a Linkset

Chapter 10 Configuring system settings 497Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Management IP Address (MIP) information in t

Pagina 443 - Modifying a linkset

498 Chapter 10 Configuring system settings320818-A Viewing host informationTo display a list of available Nortel SNAS 4050 hosts, select the System &g

Pagina 444 - Linkset Configuration fields

Chapter 10 Configuring system settings 499Nortel Secure Network Access Switch 4050 User Guide Viewing and configuring TCP/IP propertiesTo configure ba

Pagina 445

5Nortel Secure Network Access Switch 4050 User Guide ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 446 - Figure 120

50 Chapter 2 Initial setup320818-A Before you beginBefore you can set up the Nortel SNAS 4050, you must complete the following tasks:1 Plan the networ

Pagina 447 - Add a Portal Link fields

500 Chapter 10 Configuring system settings320818-A 2 Enter the host information in the applicable fields. Table 96 describes the Host fields.3 Click A

Pagina 448

Chapter 10 Configuring system settings 501Nortel Secure Network Access Switch 4050 User Guide Additionally, new licenses can be added to a particular

Pagina 449 - Add a Portal Link — FTP

502 Chapter 10 Configuring system settings320818-A Table 97 describes the Global Licenses fields.2 Modify the Auto Refresh and Logging settings, if de

Pagina 450

Chapter 10 Configuring system settings 503Nortel Secure Network Access Switch 4050 User Guide Viewing per domain licenses for all hostsTo view license

Pagina 451 - Figure 123

504 Chapter 10 Configuring system settings320818-A Table 98 describes the Per Domain Licenses fields.2 Modify the Auto Refresh and Logging settings, i

Pagina 452 - Table 92

Chapter 10 Configuring system settings 505Nortel Secure Network Access Switch 4050 User Guide Viewing installed licenses for a particular hostTo view

Pagina 453 - Figure 124

506 Chapter 10 Configuring system settings320818-A Installing a license for a particular hostThe Nortel SNA SSL (portal and Nortel SNAS 4050 domain cl

Pagina 454 - FTP link Configuration fields

Chapter 10 Configuring system settings 507Nortel Secure Network Access Switch 4050 User Guide 3 In the SREM, select the System > Hosts > host &g

Pagina 455 - Re Order Links fields

508 Chapter 10 Configuring system settings320818-A Configuring host interfaces using the SREMThe default IP interface on the Nortel SNAS 4050 host is

Pagina 456

Chapter 10 Configuring system settings 509Nortel Secure Network Access Switch 4050 User Guide • “Removing a host interface” on page 514Adding a host i

Pagina 457 - Configuring system settings

Chapter 2 Initial setup 51Nortel Secure Network Access Switch 4050 User Guide 4 Establish a console connection to the Nortel SNAS 4050 (see “Establish

Pagina 458

510 Chapter 10 Configuring system settings320818-A 4 Click Apply.The new interface appears in the Interfaces table.Gateway Sets the default gateway ad

Pagina 459 - /cfg/sys

Chapter 10 Configuring system settings 511Nortel Secure Network Access Switch 4050 User Guide 5 Click Apply on the toolbar to send the current changes

Pagina 460 - Roadmap of system commands

512 Chapter 10 Configuring system settings320818-A 2 Enter the interface information in the applicable fields. Table 100 describes the Interface confi

Pagina 461

Chapter 10 Configuring system settings 513Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes

Pagina 462

514 Chapter 10 Configuring system settings320818-A Removing a host interfaceTo delete a host interface, perform the following steps:1 Select the Syste

Pagina 463

Chapter 10 Configuring system settings 515Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for a clusterTo configure static r

Pagina 464 - The System menu displays

516 Chapter 10 Configuring system settings320818-A Viewing static routes for a hostTo configure static routes for a host, select the System > Hosts

Pagina 465

Chapter 10 Configuring system settings 517Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for an interfaceTo configure stati

Pagina 466

518 Chapter 10 Configuring system settings320818-A From the selected static route screen, complete the following tasks as necessary:• “Adding a static

Pagina 467

Chapter 10 Configuring system settings 519Nortel Secure Network Access Switch 4050 User Guide 4 Click Add.The new route appears in the table.5 Click A

Pagina 468

52 Chapter 2 Initial setup320818-A Real IP addressThe Real IP address (RIP) is the Nortel SNAS 4050 device host IP address for network connectivity. T

Pagina 469 - Viewing host information

520 Chapter 10 Configuring system settings320818-A Configuring host ports using the SREMTo configure the connection properties for a port, perform the

Pagina 470

Chapter 10 Configuring system settings 521Nortel Secure Network Access Switch 4050 User Guide 2 Select a port to configure from the list.The Port scre

Pagina 471

522 Chapter 10 Configuring system settings320818-A 3 Enter the port information in the applicable fields. Table 102 describes the Port fields.4 Click

Pagina 472

Chapter 10 Configuring system settings 523Nortel Secure Network Access Switch 4050 User Guide Managing interface ports using the SREMTo view and manag

Pagina 473

524 Chapter 10 Configuring system settings320818-A Adding interface portsTo add ports to the selected interface, perform the following steps:1 Select

Pagina 474

Chapter 10 Configuring system settings 525Nortel Secure Network Access Switch 4050 User Guide The port is removed from the Port Table.5 Click Apply on

Pagina 475

526 Chapter 10 Configuring system settings320818-A The Access List Table appears (see Figure 143).Figure 143 Access ListFrom here, you can manage th

Pagina 476 - Managing NTP servers

Chapter 10 Configuring system settings 527Nortel Secure Network Access Switch 4050 User Guide The Add Access Host dialog box appears (see Figure 144).

Pagina 477

528 Chapter 10 Configuring system settings320818-A 4 Click Yes.The entry disappears from the Access List Table.5 Click Apply on the toolbar to send th

Pagina 478

Chapter 10 Configuring system settings 529Nortel Secure Network Access Switch 4050 User Guide You can add NTP servers to the system configuration to e

Pagina 479 - Managing DNS servers

Chapter 2 Initial setup 53Nortel Secure Network Access Switch 4050 User Guide The Setup Menu displays.2 Select the option for a new installation.3 Spe

Pagina 480

530 Chapter 10 Configuring system settings320818-A Adding an NTP serverTo add an additional NTP server, perform the following steps:1 Select the Syste

Pagina 481

Chapter 10 Configuring system settings 531Nortel Secure Network Access Switch 4050 User Guide Removing an NTP serverTo remove an existing NTP server f

Pagina 482

532 Chapter 10 Configuring system settings320818-A Configuring DNS settings using the SREMTo configure DNS client settings, use the following procedur

Pagina 483

Chapter 10 Configuring system settings 533Nortel Secure Network Access Switch 4050 User Guide 2 Enter the DNS Client information in the applicable fie

Pagina 484

534 Chapter 10 Configuring system settings320818-A Configuring servers using the SREMTo configure servers, choose from one of the following tasks:• “M

Pagina 485

Chapter 10 Configuring system settings 535Nortel Secure Network Access Switch 4050 User Guide From this screen, complete the following tasks as necess

Pagina 486

536 Chapter 10 Configuring system settings320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on t

Pagina 487

Chapter 10 Configuring system settings 537Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Pagina 488 - About RADIUS auditing

538 Chapter 10 Configuring system settings320818-A Adding a DNS serverTo manage DNS servers in the system configuration, perform the following steps:1

Pagina 489 - Configuring RADIUS auditing

Chapter 10 Configuring system settings 539Nortel Secure Network Access Switch 4050 User Guide Removing an existing DNS serverTo remove a DNS server fr

Pagina 490

54 Chapter 2 Initial setup320818-A In a two-armed configuration, you are specifying the port you want to use for Nortel SNAS 4050 management traffic.4

Pagina 491

540 Chapter 10 Configuring system settings320818-A Managing RSA serversTo manage RSA servers, select the System > Servers > RSA Server Table tab

Pagina 492

Chapter 10 Configuring system settings 541Nortel Secure Network Access Switch 4050 User Guide • “Removing the RSA node secret” on page 542• “Importing

Pagina 493

542 Chapter 10 Configuring system settings320818-A Removing an existing RSA serverTo remove an existing RSA server, perform the following steps.1 Sele

Pagina 494

Chapter 10 Configuring system settings 543Nortel Secure Network Access Switch 4050 User Guide 3 Select the RSA Server sub-tab.The RSA Server screen ap

Pagina 495

544 Chapter 10 Configuring system settings320818-A 4 Click Remove Secret Node.The RSA node secret is immediately removed.5 Click Apply on the toolbar

Pagina 496 - Figure 126

Chapter 10 Configuring system settings 545Nortel Secure Network Access Switch 4050 User Guide 3 Select the Import sdconf.rec tab.The Import sdconf.rec

Pagina 497 - System Configuration fields

546 Chapter 10 Configuring system settings320818-A 4 Enter the importing information in the applicable fields. Table 112 describes the Import sdconf.r

Pagina 498

Chapter 10 Configuring system settings 547Nortel Secure Network Access Switch 4050 User Guide Configuring SRS control settings using the SREMTo create

Pagina 499 - Figure 128

548 Chapter 10 Configuring system settings320818-A 2 Enter the SRS Control information in the applicable fields. Table 115 describes the SRS Control S

Pagina 500 - Host fields

Chapter 10 Configuring system settings 549Nortel Secure Network Access Switch 4050 User Guide • “Showing SSH keys” on page 549• “Managing Nortel SNAS

Pagina 501 - Global Licenses

Chapter 2 Initial setup 55Nortel Secure Network Access Switch 4050 User Guide 7 Specify whether you are setting up a one-armed or a two-armed configur

Pagina 502 - Table 97

550 Chapter 10 Configuring system settings320818-A • RSA and DSA keys — the SECSH Public Key File Format, as described in Internet Draft draft-ietf-se

Pagina 503 - Figure 130

Chapter 10 Configuring system settings 551Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 and known host SSH keysYou can

Pagina 504 - Table 98

552 Chapter 10 Configuring system settings320818-A 2 To generate the Nortel SNAS 4050 host SSH key:a Enter the host information in applicable fields.

Pagina 505 - Figure 131

Chapter 10 Configuring system settings 553Nortel Secure Network Access Switch 4050 User Guide Adding an SSH key for a known host using the SREMYou can

Pagina 506 - END LICENSE lines

554 Chapter 10 Configuring system settings320818-A 2 Enter the remote host information in the applicable fields. Table 115 describes the Add SSH Key f

Pagina 507 - Install New License

Chapter 10 Configuring system settings 555Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS audit server to the conf

Pagina 508 - Interfaces

556 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditingTo configure the Nortel SNAS 4050 to support RADIUS auditing, choose fro

Pagina 509 - Adding a host interface

Chapter 10 Configuring system settings 557Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS audit settings using the SREMTo confi

Pagina 510

558 Chapter 10 Configuring system settings320818-A describes the Add Audit Configuration fields.3 Click Apply on the toolbar to send the current chang

Pagina 511

Chapter 10 Configuring system settings 559Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS audit servers using the SREMTo manage RA

Pagina 512 - Table 100

56 Chapter 2 Initial setup320818-A used if no other interface is specified. The default gateway IP address on Interface 2 must be within the same subn

Pagina 513 - Interface fields (continued)

560 Chapter 10 Configuring system settings320818-A Adding a new Audit ServerTo add a new RADIUS audit server, perform the following steps:1 Select the

Pagina 514 - Removing a host interface

Chapter 10 Configuring system settings 561Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS audit serverTo remove an exi

Pagina 515 - Figure 136

562 Chapter 10 Configuring system settings320818-A Managing RADIUS authentication of system users using the SREMYou can configure the Nortel SNAS 4050

Pagina 516

Chapter 10 Configuring system settings 563Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS authentication of system users using

Pagina 517 - Managing static routes

564 Chapter 10 Configuring system settings320818-A 2 Enter the RADIUS authentication information in the applicable fields. Table 118 describes the Rad

Pagina 518 - Adding a static route

Chapter 10 Configuring system settings 565Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the SREMTo

Pagina 519 - Removing a static route

566 Chapter 10 Configuring system settings320818-A Adding a RADIUS authentication serverTo add a new RADIUS authentication server, perform the followi

Pagina 520 - Figure 140

Chapter 10 Configuring system settings 567Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS serverTo remove an existing

Pagina 521 - Figure 141

568 Chapter 10 Configuring system settings320818-A

Pagina 522 - Table 102

569Nortel Secure Network Access Switch 4050 User Guide Chapter 11 Managing certificatesThis chapter includes the following topics:Topic PageOverview57

Pagina 523

Chapter 2 Initial setup 57Nortel Secure Network Access Switch 4050 User Guide 12 Configure the time settings.13 Specify the NTP server, if applicable.

Pagina 524 - Removing interface ports

570 Chapter 11 Managing certificates320818-A OverviewTo use the encryption capabilities of the Nortel SNAS 4050, you must add a key and certificate th

Pagina 525

Chapter 11 Managing certificates 571Nortel Secure Network Access Switch 4050 User Guide You can install new certificates or import or renew existing c

Pagina 526 - Adding an access list entry

572 Chapter 11 Managing certificates320818-A Netscape Enterprise ServerYes No Key only (proprietary format). Requires conversion. For information abou

Pagina 527 - Removing an Access List entry

Chapter 11 Managing certificates 573Nortel Secure Network Access Switch 4050 User Guide Creating certificatesThe basic steps to create a new certifica

Pagina 528 - Date & Time

574 Chapter 11 Managing certificates320818-A If you use the certificate index number of an installed certificate when adding a new certificate, the in

Pagina 529 - Date & Time fields

Chapter 11 Managing certificates 575Nortel Secure Network Access Switch 4050 User Guide The recommended steps to update an existing certificate are:1

Pagina 530 - Adding an NTP server

576 Chapter 11 Managing certificates320818-A • import certificates and private keys (see “Importing certificates and keys into the Nortel SNAS 4050 us

Pagina 531 - Removing an NTP server

Chapter 11 Managing certificates 577Nortel Secure Network Access Switch 4050 User Guide Managing and viewing certificates and keys using the CLITo vie

Pagina 532 - Figure 147

578 Chapter 11 Managing certificates320818-A gensigned server|clientGenerates a certificate that is signed using the private key associated with the c

Pagina 533 - Table 107

Chapter 11 Managing certificates 579Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the CLITo prepare a CSR

Pagina 534 - Managing syslog servers

58 Chapter 2 Initial setup320818-A 16 Change the admin user password, if desired.Make sure you remember the password you define for the admin user. Yo

Pagina 535 - Adding a new syslog server

580 Chapter 11 Managing certificates320818-A • to generate a CSR for a new certificate, <cert id> is an unused certificate number• to generate a

Pagina 536

Chapter 11 Managing certificates 581Nortel Secure Network Access Switch 4050 User Guide 3 Generate the CSR.After you have provided the required inform

Pagina 537

582 Chapter 11 Managing certificates320818-A Figure 166 shows sample output for the /cfg/cert #/request command. For more information about the Certif

Pagina 538 - Adding a DNS server

Chapter 11 Managing certificates 583Nortel Secure Network Access Switch 4050 User Guide 5 Save the CSR to a file.a Copy the entire CSR, including the

Pagina 539

584 Chapter 11 Managing certificates320818-A 8 The CA processes the CSR and returns a signed certificate. Create a backup copy of the certificate (see

Pagina 540 - Managing RSA servers

Chapter 11 Managing certificates 585Nortel Secure Network Access Switch 4050 User Guide To verify that the current certificate number is not in use by

Pagina 541 - Adding an RSA server

586 Chapter 11 Managing certificates320818-A Figure 167 shows sample output for the /cfg/cert #/cert command. For more information about the Certifica

Pagina 542 - Removing the RSA node secret

Chapter 11 Managing certificates 587Nortel Secure Network Access Switch 4050 User Guide Adding a private key to the Nortel SNAS 4050 using the CLI1 Ac

Pagina 543 - RSA Server fields

588 Chapter 11 Managing certificates320818-A Figure 168 shows sample output for the /cfg/cert #/key command. For more information about the Certificat

Pagina 544 - Importing sdconf.rec

Chapter 11 Managing certificates 589Nortel Secure Network Access Switch 4050 User Guide To import a certificate and private key into the Nortel SNAS 4

Pagina 545 - Figure 155

Chapter 2 Initial setup 59Nortel Secure Network Access Switch 4050 User Guide For example, if you entered company.com in the DNS search list, users ca

Pagina 546 - Import sdconf.rec fields

590 Chapter 11 Managing certificates320818-A 4 If the private key was not included in the certificate file, repeat step 3 on page 589 to import the ke

Pagina 547 - SRS Control Settings

Chapter 11 Managing certificates 591Nortel Secure Network Access Switch 4050 User Guide Displaying or saving a certificate and key using the CLIYou ca

Pagina 548 - Add SSH Key fields

592 Chapter 11 Managing certificates320818-A 5 Copy the private key, certificate, or both, as required.For the private key, ensure that you include th

Pagina 549 - Showing SSH keys

Chapter 11 Managing certificates 593Nortel Secure Network Access Switch 4050 User Guide Figure 170 shows sample output for the /cfg/cert #/display com

Pagina 550

594 Chapter 11 Managing certificates320818-A Exporting a certificate and key from the Nortel SNAS 4050 using the CLIYou can export certificate files a

Pagina 551 - SSH Keys – Hosts

Chapter 11 Managing certificates 595Nortel Secure Network Access Switch 4050 User Guide Export format The key and certificate format in which you want

Pagina 552 - SSH Keys Hosts field

596 Chapter 11 Managing certificates320818-A Figure 171 shows sample output for the /cfg/cert #/export command. For more information about the Certifi

Pagina 553 - Add SSH Key

Chapter 11 Managing certificates 597Nortel Secure Network Access Switch 4050 User Guide You are prompted to enter the following parameters. The combin

Pagina 554

598 Chapter 11 Managing certificates320818-A Viewing certificates using the SREMTo view basic information about all certificates configured for the No

Pagina 555 - NSNAS-SSL-Audit-Trail)

Chapter 11 Managing certificates 599Nortel Secure Network Access Switch 4050 User Guide 3 Click Yes.The certificate is removed from the Certificates l

Pagina 556

6 Contents320818-A Management IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51Portal Virtual IP addres

Pagina 557 - Figure 160

60 Chapter 2 Initial setup320818-A The action to be performed when the TunnelGuard check fails depends on your selection in step f on page 59.Settings

Pagina 558 - Table 116

600 Chapter 11 Managing certificates320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Pagina 559 - Audit Servers

Chapter 11 Managing certificates 601Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the SREMTo generate a CS

Pagina 560 - Adding a new Audit Server

602 Chapter 11 Managing certificates320818-A 2 Enter the certificate information in the applicable fields.Table 125 describes the CA Request fields.Ta

Pagina 561

Chapter 11 Managing certificates 603Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the information to the No

Pagina 562

604 Chapter 11 Managing certificates320818-A To import a certificate and private key into the Nortel SNAS 4050, perform the following steps.1 Upload t

Pagina 563 - Figure 163

Chapter 11 Managing certificates 605Nortel Secure Network Access Switch 4050 User Guide 3 Enter the import information in the applicable fields. Table

Pagina 564 - Table 118

606 Chapter 11 Managing certificates320818-A To display the current certificate and key or save a copy, perform the following steps:1 Select the Certi

Pagina 565 - Radius Server Table

Chapter 11 Managing certificates 607Nortel Secure Network Access Switch 4050 User Guide 2 If you want to encrypt the key, specify a password in the ap

Pagina 566 - Add Radius Server fields

608 Chapter 11 Managing certificates320818-A To export a certificate and key from the Nortel SNAS 4050, perform the following steps.1 Select the Certi

Pagina 567

Chapter 11 Managing certificates 609Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields. Table

Pagina 568

Chapter 2 Initial setup 61Nortel Secure Network Access Switch 4050 User Guide The profiles determine the VLAN to which the user will be allocated. Tab

Pagina 569 - Managing certificates

610 Chapter 11 Managing certificates320818-A 3 Click Apply on the toolbar to export the certificate.The certificate and private key are immediately ex

Pagina 570

Chapter 11 Managing certificates 611Nortel Secure Network Access Switch 4050 User Guide The Configuration screen appears (see Figure 172).Figure 178

Pagina 571 - Key and certificate formats

612 Chapter 11 Managing certificates320818-A Viewing general informationTo view basic information about a certificate on the Nortel SNAS 4050 cluster,

Pagina 572

Chapter 11 Managing certificates 613Nortel Secure Network Access Switch 4050 User Guide The Info screen appears (see Figure 179).Figure 179 Info scr

Pagina 573 - Creating certificates

614 Chapter 11 Managing certificates320818-A Viewing certificate subject settingsTo view subject settings for a certificate on the Nortel SNAS 4050 cl

Pagina 574 - Updating certificates

Chapter 11 Managing certificates 615Nortel Secure Network Access Switch 4050 User Guide The Subject screen appears (see Figure 180).Figure 180 Subje

Pagina 575

616 Chapter 11 Managing certificates320818-A Organization The registered name of the organization. The organization must own the domain name that appe

Pagina 576

617Nortel Secure Network Access Switch 4050 User Guide Chapter 12 Configuring SNMPThis chapter includes the following topics:Topic PageConfiguring SNM

Pagina 577

618 Chapter 12 Configuring SNMP320818-A Simple Network Management Protocol (SNMP) is a set of protocols for managing complex networks. SNMP works by s

Pagina 578

Chapter 12 Configuring SNMP 619Nortel Secure Network Access Switch 4050 User Guide • SNMP monitors and events (see “Configuring SNMP events using the

Pagina 579

62 Chapter 2 Initial setup320818-A Before you beginLog on to the existing Nortel SNAS 4050 device to check the software version and system settings. U

Pagina 580

620 Chapter 12 Configuring SNMP320818-A Configuring SNMP settings using the CLITo configure SNMP management of the Nortel SNAS 4050 cluster, use the f

Pagina 581

Chapter 12 Configuring SNMP 621Nortel Secure Network Access Switch 4050 User Guide Configuring the SNMP v2 MIB using the CLITo configure parameters in

Pagina 582 - Figure 166

622 Chapter 12 Configuring SNMP320818-A The SNMPv2-MIB menu includes the following options:Configuring the SNMP community using the CLITo configure th

Pagina 583

Chapter 12 Configuring SNMP 623Nortel Secure Network Access Switch 4050 User Guide Configuring SNMPv3 users using the CLIThe Nortel SNAS 4050 manages

Pagina 584

624 Chapter 12 Configuring SNMP320818-A • set — USM user is authorized to perform SNMP set requests (write access to the MIB). Write access automatica

Pagina 585

Chapter 12 Configuring SNMP 625Nortel Secure Network Access Switch 4050 User Guide The SNMP User menu includes the following options:/cfg/sys/adm/snmp

Pagina 586

626 Chapter 12 Configuring SNMP320818-A Configuring SNMP notification targets using the CLISNMP managers function as the notification targets for SNMP

Pagina 587

Chapter 12 Configuring SNMP 627Nortel Secure Network Access Switch 4050 User Guide The Notification Target menu includes the following options:Configu

Pagina 588

628 Chapter 12 Configuring SNMP320818-A The event menu includes the following options:/cfg/sys/adm/snmp/eventfollowed by:addmonitor [<options>]

Pagina 589

Chapter 12 Configuring SNMP 629Nortel Secure Network Access Switch 4050 User Guide addmonitor [<options>] -t <name> <OID> <value

Pagina 590

Chapter 2 Initial setup 63Nortel Secure Network Access Switch 4050 User Guide • To change the version on the existing NSNAS, download the desired soft

Pagina 591

630 Chapter 12 Configuring SNMP320818-A addmonitor [<options>] -x <name> <OID> [present|absent|changed]Adds an existence monitor and

Pagina 592

Chapter 12 Configuring SNMP 631Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP settings using the SREMThis section contains infor

Pagina 593 - Figure 170

632 Chapter 12 Configuring SNMP320818-A Configuring SNMP using the SREMTo configure SNMP, perform the following steps:1 Select the System > Adminis

Pagina 594 - Parameter Description

Chapter 12 Configuring SNMP 633Nortel Secure Network Access Switch 4050 User Guide 2 Enter the SNMP Configuration information in the applicable fields

Pagina 595

634 Chapter 12 Configuring SNMP320818-A Configuring SNMP targets using the SREMSNMP managers function as the notification targets for SNMP monitoring.

Pagina 596

Chapter 12 Configuring SNMP 635Nortel Secure Network Access Switch 4050 User Guide Adding SNMP targetsTo add an SNMP target, perform the following ste

Pagina 597

636 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMP Target dialog box appears (see Figure 183).Figure 183 Add SNMP Target

Pagina 598 - Certificates screen

Chapter 12 Configuring SNMP 637Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMP target information in the applicable fields. Table

Pagina 599 - Add a Certificate Component

638 Chapter 12 Configuring SNMP320818-A Managing SNMP targetsTo manage SNMP targets, perform the following steps:1 Select the System > Administrati

Pagina 600

Chapter 12 Configuring SNMP 639Nortel Secure Network Access Switch 4050 User Guide 2 Modify the SNMP Target information in the applicable fields. Tabl

Pagina 601 - Figure 174

64 Chapter 2 Initial setup320818-A In a one-armed configuration, you are specifying the port you want to use for all network connectivity, since Inter

Pagina 602 - Table 125

640 Chapter 12 Configuring SNMP320818-A A dialog box appears asking for confirmation.4 Click Yes.5 Click Apply on the toolbar to send the current chan

Pagina 603

Chapter 12 Configuring SNMP 641Nortel Secure Network Access Switch 4050 User Guide Adding SNMPv3 usersTo add an SNMPv3 user, perform the following ste

Pagina 604 - Import Certificate screen

642 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMPv3 User dialog box appears (see Figure 186).Figure 186 Add SNMPv3 User

Pagina 605

Chapter 12 Configuring SNMP 643Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMPv3 User information in the applicable fields. Table

Pagina 606 - Figure 176

644 Chapter 12 Configuring SNMP320818-A 4 Click Apply. The new SNMPv3 user appears in the table.5 Click Apply on the toolbar to send the current chang

Pagina 607 - Display Certificates fields

Chapter 12 Configuring SNMP 645Nortel Secure Network Access Switch 4050 User Guide 2 Modify SNMPv3 User information in the applicable fields, as requi

Pagina 608 - Figure 177

646 Chapter 12 Configuring SNMP320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the toolbar

Pagina 609 - Table 128

Chapter 12 Configuring SNMP 647Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP events using the SREMSNMP events can be added to m

Pagina 610 - Viewing configuration details

648 Chapter 12 Configuring SNMP320818-A Adding monitor eventsTo add monitor events, perform the following steps:1 Select the System > Administrativ

Pagina 611 - Table 129

Chapter 12 Configuring SNMP 649Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Monitor dialog box appears. Depending on the

Pagina 612 - Viewing general information

Chapter 2 Initial setup 65Nortel Secure Network Access Switch 4050 User Guide 8 Configure the interface for client portal traffic (Interface 2).a Spec

Pagina 613 - Table 130

650 Chapter 12 Configuring SNMP320818-A Depending on the type of monitor selected, the fields displayed on the Configuration tab will change. For desc

Pagina 614 - Table 130 Info fields

Chapter 12 Configuring SNMP 651Nortel Secure Network Access Switch 4050 User Guide Figure 189 Add a Monitor: BooleanFields used to add and configure

Pagina 615 - Table 131

652 Chapter 12 Configuring SNMP320818-A For details on adding a Boolean monitor, see “Adding monitor events” on page 648.Threshold monitorsThreshold m

Pagina 616 - Table 131 Subject fields

Chapter 12 Configuring SNMP 653Nortel Secure Network Access Switch 4050 User Guide Fields used to add and configure a Threshold monitor are listed in

Pagina 617 - Configuring SNMP

654 Chapter 12 Configuring SNMP320818-A Existence monitorsExistence monitors check the condition of a monitored OID to see determine if it is present,

Pagina 618 - /cfg/sys/adm/snmp

Chapter 12 Configuring SNMP 655Nortel Secure Network Access Switch 4050 User Guide For details on adding a Existence monitor, see “Adding monitor even

Pagina 619 - Roadmap of SNMP commands

656 Chapter 12 Configuring SNMP320818-A Adding notification eventsTo add notification events, perform the following steps:1 Select the System > Adm

Pagina 620

Chapter 12 Configuring SNMP 657Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Notification Event dialog box appears (see F

Pagina 621 - The SNMPv2-MIB menu displays

658 Chapter 12 Configuring SNMP320818-A Removing notification eventsTo delete a notification event, perform the following steps:1 Select the System &g

Pagina 622

659Nortel Secure Network Access Switch 4050 User Guide Chapter 13 Viewing system information and performance statisticsThis chapter includes the follo

Pagina 623

66 Chapter 2 Initial setup320818-A 12 Wait while the Setup utility finishes processing. When processing is complete, you will see Setup successful.The

Pagina 624

660 Chapter 13 Viewing system information and performance statistics320818-A Viewing system information and performance statistics using the CLITo vie

Pagina 625

Chapter 13 Viewing system information and performance statistics 661Nortel Secure Network Access Switch 4050 User Guide Viewing system information usi

Pagina 626

662 Chapter 13 Viewing system information and performance statistics320818-A The Information menu includes the following options:/infofollowed by:cert

Pagina 627

Chapter 13 Viewing system information and performance statistics 663Nortel Secure Network Access Switch 4050 User Guide kick <domain ID> <use

Pagina 628

664 Chapter 13 Viewing system information and performance statistics320818-A mac <MACaddr>Displays session information for a client based on a s

Pagina 629

Chapter 13 Viewing system information and performance statistics 665Nortel Secure Network Access Switch 4050 User Guide localDisplays the current soft

Pagina 630

666 Chapter 13 Viewing system information and performance statistics320818-A Viewing alarm events using the CLITo view active alarms, use the followin

Pagina 631

Chapter 13 Viewing system information and performance statistics 667Nortel Secure Network Access Switch 4050 User Guide Viewing log files using the CL

Pagina 632 - Figure 181

668 Chapter 13 Viewing system information and performance statistics320818-A The CLI reports statistics for all authentication methods configured in t

Pagina 633 - Table 132

Chapter 13 Viewing system information and performance statistics 669Nortel Secure Network Access Switch 4050 User Guide Figure 194 shows sample output

Pagina 634

Chapter 2 Initial setup 67Nortel Secure Network Access Switch 4050 User Guide 3 To finish connecting the Nortel SNAS 4050 to the rest of the network,

Pagina 635 - Adding SNMP targets

670 Chapter 13 Viewing system information and performance statistics320818-A Viewing all statistics using the CLITo view all available statistics for

Pagina 636 - Figure 183

Chapter 13 Viewing system information and performance statistics 671Nortel Secure Network Access Switch 4050 User Guide The Information screen appears

Pagina 637 - SNMP Target fields

672 Chapter 13 Viewing system information and performance statistics320818-A Viewing cluster information using the SREMTo view cluster information, se

Pagina 638 - Managing SNMP targets

Chapter 13 Viewing system information and performance statistics 673Nortel Secure Network Access Switch 4050 User Guide Viewing the controller list us

Pagina 639 - Removing SNMP targets

674 Chapter 13 Viewing system information and performance statistics320818-A Table 143 describes the Controller List fields. Table 143 Controller Li

Pagina 640

Chapter 13 Viewing system information and performance statistics 675Nortel Secure Network Access Switch 4050 User Guide Viewing SONMP topology informa

Pagina 641 - Adding SNMPv3 users

676 Chapter 13 Viewing system information and performance statistics320818-A Table 144 describes the SONMP State fields. Table 144 SONMP State field

Pagina 642 - Figure 186

Chapter 13 Viewing system information and performance statistics 677Nortel Secure Network Access Switch 4050 User Guide Viewing switch distribution us

Pagina 643 - Table 135

678 Chapter 13 Viewing system information and performance statistics320818-A Table 145 describes the Switch Distribution fields. Viewing port informat

Pagina 644 - Managing SNMPv3 users

Chapter 13 Viewing system information and performance statistics 679Nortel Secure Network Access Switch 4050 User Guide To view port information, sele

Pagina 645 - Table 136

68 Chapter 2 Initial setup320818-A Applying and saving the configuration using the CLIIf you have not already done so after each sequence of configura

Pagina 646 - Removing SNMPv3 users

680 Chapter 13 Viewing system information and performance statistics320818-A Viewing license information using the SREMYou can view information about

Pagina 647 - Managing monitor events

Chapter 13 Viewing system information and performance statistics 681Nortel Secure Network Access Switch 4050 User Guide Viewing global license informa

Pagina 648 - Adding monitor events

682 Chapter 13 Viewing system information and performance statistics320818-A Table 147 describes the Global Licenses fields. Table 147 Global Licens

Pagina 649 - Add a Monitor fields

Chapter 13 Viewing system information and performance statistics 683Nortel Secure Network Access Switch 4050 User Guide Viewing license information fo

Pagina 650 - Boolean monitors

684 Chapter 13 Viewing system information and performance statistics320818-A Table 148 describes the Per Domain Licenses fields. Viewing session detai

Pagina 651 - Table 138

Chapter 13 Viewing system information and performance statistics 685Nortel Secure Network Access Switch 4050 User Guide Viewing active sessions using

Pagina 652 - Threshold monitors

686 Chapter 13 Viewing system information and performance statistics320818-A Table 149 describes the Sessions parameters. Table 149 Sessions paramet

Pagina 653 - Table 139

Chapter 13 Viewing system information and performance statistics 687Nortel Secure Network Access Switch 4050 User Guide Viewing details for a particul

Pagina 654 - Existence monitors

688 Chapter 13 Viewing system information and performance statistics320818-A Table 150 describes the Session Properties parameters. Ending active user

Pagina 655 - Managing notification events

Chapter 13 Viewing system information and performance statistics 689Nortel Secure Network Access Switch 4050 User Guide Figure 204 KickOut User scre

Pagina 656 - Adding notification events

Chapter 2 Initial setup 69Nortel Secure Network Access Switch 4050 User Guide Figure 3 on page 69 shows the location of the Apply and Commit buttons.F

Pagina 657 - Add a Notification Event

690 Chapter 13 Viewing system information and performance statistics320818-A Viewing the number of active sessions using the SREMTo view the number of

Pagina 658 - Removing notification events

Chapter 13 Viewing system information and performance statistics 691Nortel Secure Network Access Switch 4050 User Guide Viewing alarms using the SREMY

Pagina 659 - Chapter 13

692 Chapter 13 Viewing system information and performance statistics320818-A Viewing active alarms using the SREMTo view the active alarms for the Nor

Pagina 660

Chapter 13 Viewing system information and performance statistics 693Nortel Secure Network Access Switch 4050 User Guide Table 153 describes the Active

Pagina 661

694 Chapter 13 Viewing system information and performance statistics320818-A Downloading alarms using the SREMTo download an alarm as a logged event,

Pagina 662

Chapter 13 Viewing system information and performance statistics 695Nortel Secure Network Access Switch 4050 User Guide Table 154 describes the Downlo

Pagina 663

696 Chapter 13 Viewing system information and performance statistics320818-A Viewing the log list using the SREMTo view a list of all active logs, sel

Pagina 664

Chapter 13 Viewing system information and performance statistics 697Nortel Secure Network Access Switch 4050 User Guide Downloading log files using th

Pagina 665

698 Chapter 13 Viewing system information and performance statistics320818-A Viewing AAA statistics using the SREMYou can view authentication statisti

Pagina 666 - The Events menu displays

Chapter 13 Viewing system information and performance statistics 699Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for a h

Pagina 667

Contents 7Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 668

70 Chapter 2 Initial setup320818-A

Pagina 669 - Figure 194

700 Chapter 13 Viewing system information and performance statistics320818-A b Expand the Statistics > AAA > Host Statistics > host navigatio

Pagina 670

Chapter 13 Viewing system information and performance statistics 701Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Pagina 671 - Table 142

702 Chapter 13 Viewing system information and performance statistics320818-A Viewing RADIUS statisticsTo view RADIUS statistics, select the Radius tab

Pagina 672

Chapter 13 Viewing system information and performance statistics 703Nortel Secure Network Access Switch 4050 User Guide For a description of the field

Pagina 673 - Figure 196

704 Chapter 13 Viewing system information and performance statistics320818-A Viewing Local database statisticsTo view Local database statistics, selec

Pagina 674 - Table 143

Chapter 13 Viewing system information and performance statistics 705Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Pagina 675 - Figure 197

706 Chapter 13 Viewing system information and performance statistics320818-A For a description of the fields, seeTable 159.Table 159 LDAP statistics

Pagina 676 - Table 144

Chapter 13 Viewing system information and performance statistics 707Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for the

Pagina 677 - Figure 198

708 Chapter 13 Viewing system information and performance statistics320818-A •LDAPSelect one of the following tasks:• Viewing License statistics (see

Pagina 678 - Switch Distribution fields

Chapter 13 Viewing system information and performance statistics 709Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Pagina 679 - Table 146

71Nortel Secure Network Access Switch 4050 User Guide Chapter 3 Managing the network access devicesThis chapter includes the following topics:Topic Pa

Pagina 680

710 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Pagina 681 - Figure 200

Chapter 13 Viewing system information and performance statistics 711Nortel Secure Network Access Switch 4050 User Guide Viewing RADIUS statisticsTo vi

Pagina 682 - Table 147

712 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Pagina 683 - Figure 201

Chapter 13 Viewing system information and performance statistics 713Nortel Secure Network Access Switch 4050 User Guide Viewing Local database statist

Pagina 684 - Per Domain Licenses fields

714 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Pagina 685 - Sessions screen

Chapter 13 Viewing system information and performance statistics 715Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Pagina 686 - Table 149

716 Chapter 13 Viewing system information and performance statistics320818-A Viewing Ethernet statistics using the SREMYou can view statistics for the

Pagina 687 - Figure 203

Chapter 13 Viewing system information and performance statistics 717Nortel Secure Network Access Switch 4050 User Guide To view Ethernet interface sta

Pagina 688 - Ending active user sessions

718 Chapter 13 Viewing system information and performance statistics320818-A Viewing Rx statisticsTo view Rx statistics for an interface, select the R

Pagina 689 - Table 151

Chapter 13 Viewing system information and performance statistics 719Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Pagina 690 - Number of Sessions fields

72 Chapter 3 Managing the network access devices320818-A Before you beginIn Trusted Computing Group (TCG) terminology, the edge switches in a Nortel S

Pagina 691 - Viewing alarms using the SREM

720 Chapter 13 Viewing system information and performance statistics320818-A Viewing Tx statisticsTo view Tx statistics for an interface, select Tx St

Pagina 692 - Figure 206

Chapter 13 Viewing system information and performance statistics 721Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Pagina 693 - Table 153

722 Chapter 13 Viewing system information and performance statistics320818-A

Pagina 694 - Figure 207

723Nortel Secure Network Access Switch 4050 User Guide Chapter 14 Maintaining and managing the systemThis chapter includes the following topics:Topic

Pagina 695 - Table 154

724 Chapter 14 Maintaining and managing the system320818-A You can perform the following activities to manage and maintain the system and individual N

Pagina 696 - Figure 208

Chapter 14 Maintaining and managing the system 725Nortel Secure Network Access Switch 4050 User Guide To manage software versions and Nortel SNAS 4050

Pagina 697 - Table 155

726 Chapter 14 Maintaining and managing the system320818-A Performing maintenance using the CLITo check the applied configuration and to download log

Pagina 698

Chapter 14 Maintaining and managing the system 727Nortel Secure Network Access Switch 4050 User Guide The Maintenance menu includes the following opti

Pagina 699 - The Hosts table

728 Chapter 14 Maintaining and managing the system320818-A dumpstats <protocol> <server> <filename> <all-isds?>Collects curren

Pagina 700

Chapter 14 Maintaining and managing the system 729Nortel Secure Network Access Switch 4050 User Guide starttrace <tags> <domain ID> <ou

Pagina 701 - Viewing License statistics

Chapter 3 Managing the network access devices 73Nortel Secure Network Access Switch 4050 User Guide You require the following information for each net

Pagina 702 - Viewing RADIUS statistics

730 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the CLITo save the system configuration to

Pagina 703 - Table 157

Chapter 14 Maintaining and managing the system 731Nortel Secure Network Access Switch 4050 User Guide Table 166 provides more information about the ba

Pagina 704 - Table 158

732 Chapter 14 Maintaining and managing the system320818-A gtcfg <protocol> <server> <filename> <passphrase>Restores a configu

Pagina 705 - Viewing LDAP statistics

Chapter 14 Maintaining and managing the system 733Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices using the CLIT

Pagina 706 - Table 159

734 Chapter 14 Maintaining and managing the system320818-A Managing software for a Nortel SNAS 4050 device using the CLITo view, download, and activat

Pagina 707 - The Statistics table

Chapter 14 Maintaining and managing the system 735Nortel Secure Network Access Switch 4050 User Guide The Software Management menu includes the follow

Pagina 708

736 Chapter 14 Maintaining and managing the system320818-A Managing and maintaining the system using the SREMPerforming maintenance using the SREMTo p

Pagina 709

Chapter 14 Maintaining and managing the system 737Nortel Secure Network Access Switch 4050 User Guide • “Backing up or restoring the configuration usi

Pagina 710

738 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Dump information in the applicable fields. Table 167 describes the Dump fields.

Pagina 711

Chapter 14 Maintaining and managing the system 739Nortel Secure Network Access Switch 4050 User Guide To start or stop a trace, perform the following

Pagina 712

74 Chapter 3 Managing the network access devices320818-A resetenadisdelete/cfg/domain #/vlan add <name> <VLAN ID>del <index>list/cfg

Pagina 713 - Table 162

740 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Trace information in the applicable fields. Table 168 describes the Start/Stop

Pagina 714

Chapter 14 Maintaining and managing the system 741Nortel Secure Network Access Switch 4050 User Guide Checking configuration using the SREMYou can che

Pagina 715

742 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the SREMYou can save the current configurat

Pagina 716

Chapter 14 Maintaining and managing the system 743Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Backup/Restore information in the ap

Pagina 717 - The Ethernet Interface table

744 Chapter 14 Maintaining and managing the system320818-A • “Rebooting or deleting a Nortel SNAS 4050 device using the SREM” on page 750Managing soft

Pagina 718 - Viewing Rx statistics

Chapter 14 Maintaining and managing the system 745Nortel Secure Network Access Switch 4050 User Guide Table 170 describes the Image List fields.The fo

Pagina 719

746 Chapter 14 Maintaining and managing the system320818-A Viewing details of the active software imageTo view the details of the currently active sof

Pagina 720 - Viewing Tx statistics

Chapter 14 Maintaining and managing the system 747Nortel Secure Network Access Switch 4050 User Guide Activating a software imageTo activate an old or

Pagina 721

748 Chapter 14 Maintaining and managing the system320818-A 4 When prompted, click Yes.The Nortel SNAS 4050 reboots when you confirm the Activate comma

Pagina 722

Chapter 14 Maintaining and managing the system 749Nortel Secure Network Access Switch 4050 User Guide To download an image from a file exchange server

Pagina 723 - Chapter 14

Chapter 3 Managing the network access devices 75Nortel Secure Network Access Switch 4050 User Guide Adding a network access device using the CLIYou ca

Pagina 724

750 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Download Image information in the applicable fields. Table 171 describes the Do

Pagina 725

Chapter 14 Maintaining and managing the system 751Nortel Secure Network Access Switch 4050 User Guide To reboot, shut down, or reset the Nortel SNAS 4

Pagina 726

752 Chapter 14 Maintaining and managing the system320818-A The command resets the device to its factory default configuration. All IP configuration is

Pagina 727

Chapter 14 Maintaining and managing the system 753Nortel Secure Network Access Switch 4050 User Guide The File Download screen appears (see Figure 232

Pagina 728

754 Chapter 14 Maintaining and managing the system320818-A Running Nortel SNAS 4050 diagnostics using the SREMTo run basic diagnostics on the Nortel S

Pagina 729

Chapter 14 Maintaining and managing the system 755Nortel Secure Network Access Switch 4050 User Guide Table 173 describes the Diagnostics fields. Tabl

Pagina 730

756 Chapter 14 Maintaining and managing the system320818-A

Pagina 731 - Table 166

757Nortel Secure Network Access Switch 4050 User Guide Chapter 15 Upgrading or reinstalling the softwareThis chapter includes the following topics:The

Pagina 732

758 Chapter 15 Upgrading or reinstalling the software320818-A Major release upgrade: This kind of release may contain bug fixes as well as feature enh

Pagina 733 - The Boot menu displays

Chapter 15 Upgrading or reinstalling the software 759Nortel Secure Network Access Switch 4050 User Guide The set of installed Nortel SNAS 4050 devices

Pagina 734

76 Chapter 3 Managing the network access devices320818-A 4 Specify the TCP port for communication between the Nortel SNAS 4050 and the network access

Pagina 735

760 Chapter 15 Upgrading or reinstalling the software320818-A If needed, the file name can be prefixed with a search path to the directory on the TFTP

Pagina 736

Chapter 15 Upgrading or reinstalling the software 761Nortel Secure Network Access Switch 4050 User Guide When you have downloaded the software upgrade

Pagina 737

762 Chapter 15 Upgrading or reinstalling the software320818-A 5 At the Software Management# prompt, enter:6 Log in again and verify the new software v

Pagina 738 - Table 167

Chapter 15 Upgrading or reinstalling the software 763Nortel Secure Network Access Switch 4050 User Guide Reinstalling the softwareIf you are adding a

Pagina 739 - Figure 224

764 Chapter 15 Upgrading or reinstalling the software320818-A • authorization to log on as the boot userIf a software CD was shipped with the Nortel S

Pagina 740 - Table 168

Chapter 15 Upgrading or reinstalling the software 765Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from an external fi

Pagina 741 - Check Configuration

766 Chapter 15 Upgrading or reinstalling the software320818-A e Specify the default gateway IP address. 3 Specify the download details:a protocol for

Pagina 742 - Backup & Restore

Chapter 15 Upgrading or reinstalling the software 767Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from a CDTo reinsta

Pagina 743 - Backup & Restore fields

768 Chapter 15 Upgrading or reinstalling the software320818-A

Pagina 744 - Image List

769Nortel Secure Network Access Switch 4050 User Guide Chapter 16 The Command Line InterfaceThis chapter explains how to access the Nortel SNAS 4050 t

Pagina 745

Chapter 3 Managing the network access devices 77Nortel Secure Network Access Switch 4050 User Guide d To continue, go to step 7 on page 77.7 Specify t

Pagina 746

770 Chapter 16 The Command Line Interface320818-A When using a Telnet or SSH client to connect to a cluster of Nortel SNAS 4050 devices, always connec

Pagina 747 - Activating a software image

Chapter 16 The Command Line Interface 771Nortel Secure Network Access Switch 4050 User Guide RequirementsTo establish a console connection with the No

Pagina 748

772 Chapter 16 The Command Line Interface320818-A Establishing a Telnet connectionA Telnet connection offers the convenience of accessing the Nortel S

Pagina 749 - Figure 230

Chapter 16 The Command Line Interface 773Nortel Secure Network Access Switch 4050 User Guide Running TelnetOnce the IP parameters on the Nortel SNAS 4

Pagina 750 - Download Image fields

774 Chapter 16 The Command Line Interface320818-A Running an SSH clientConnecting to the Nortel SNAS 4050 using an SSH client is similar to connecting

Pagina 751 - Reboot/Delete ISD Options

Chapter 16 The Command Line Interface 775Nortel Secure Network Access Switch 4050 User Guide Accessing the Nortel SNAS 4050 clusterTo enable better No

Pagina 752

776 Chapter 16 The Command Line Interface320818-A Access to the Nortel SNAS 4050 CLI and settings is controlled through the use of four predefined use

Pagina 753 - Table 172

Chapter 16 The Command Line Interface 777Nortel Secure Network Access Switch 4050 User Guide CLI Main Menu or SetupOnce the Administrator user passwor

Pagina 754 - Figure 233

778 Chapter 16 The Command Line Interface320818-A If you are automatically disconnected after the specified idle timeout interval, any unapplied confi

Pagina 755 - Table 173

779Nortel Secure Network Access Switch 4050 User Guide Chapter 17 Configuration exampleThis chapter provides an example of a basic Nortel SNA configur

Pagina 756

78 Chapter 3 Managing the network access devices320818-A Manually adding a switchTo add a network access device and configure it manually, use the fol

Pagina 757 - Chapter 15

780 Chapter 17 Configuration example320818-A Figure 235 Basic configurationTable 176 summarizes the devices connected in this environment and their

Pagina 758

Chapter 17 Configuration example 781Nortel Secure Network Access Switch 4050 User Guide Table 177 summarizes the VLANs for the Ethernet Routing Switch

Pagina 759

782 Chapter 17 Configuration example320818-A Steps1 “Configure the network DNS server” on page 7822 “Configure the network DHCP server” on page 7833 “

Pagina 760 - /boot/software/cur command

Chapter 17 Configuration example 783Nortel Secure Network Access Switch 4050 User Guide Configure the network DHCP serverTo configure a DHCP scope usi

Pagina 761

784 Chapter 17 Configuration example320818-A 4 Enter a descriptive name to identify the new scope (see Figure 238).In this example, you are creating a

Pagina 762

Chapter 17 Configuration example 785Nortel Secure Network Access Switch 4050 User Guide 5 Specify the IP address range for the DHCP scope (see Figure

Pagina 763 - Reinstalling the software

786 Chapter 17 Configuration example320818-A 6 Select the Yes, I want to configure these options now option button on the Configure DHCP Options windo

Pagina 764

Chapter 17 Configuration example 787Nortel Secure Network Access Switch 4050 User Guide 7 Enter the IP address of the default gateway (see Figure 241)

Pagina 765

788 Chapter 17 Configuration example320818-A 8 Enter the IP address of the DNS server (see Figure 242).Figure 242 Specifying the DNS server9 Repeat

Pagina 766

Chapter 17 Configuration example 789Nortel Secure Network Access Switch 4050 User Guide Figure 243 shows the DHCP scopes created for use in this examp

Pagina 767

Chapter 3 Managing the network access devices 79Nortel Secure Network Access Switch 4050 User Guide Figure 4 Adding a switch manuallyDeleting a netw

Pagina 768

790 Chapter 17 Configuration example320818-A 2 Assign the VLAN port members.Since the edge switches in this example are operating in Layer 2 mode, ena

Pagina 769 - The Command Line Interface

Chapter 17 Configuration example 791Nortel Secure Network Access Switch 4050 User Guide 7 “Configuring the NSNA ports” on page 7928 “Enabling NSNA glo

Pagina 770

792 Chapter 17 Configuration example320818-A Configuring the NSNA uplink filterPassport-8310:6# config filter acl 100 create ip acl-name "dhcp&qu

Pagina 771 - Procedure

Chapter 17 Configuration example 793Nortel Secure Network Access Switch 4050 User Guide Configure the Ethernet Routing Switch 5510The following config

Pagina 772

794 Chapter 17 Configuration example320818-A Configuring SSHIn this example, the assumption is that the Nortel SNAS 4050 public key has already been u

Pagina 773 - Running Telnet

Chapter 17 Configuration example 795Nortel Secure Network Access Switch 4050 User Guide Configuring the login domain controller filters5510-48T(config

Pagina 774 - Running an SSH client

796 Chapter 17 Configuration example320818-A 3 “Adding the network access devices” on page 7984 “Mapping the VLANs” on page 8005 “Enabling the network

Pagina 775

Chapter 17 Configuration example 797Nortel Secure Network Access Switch 4050 User Guide Enter a password for the "admin" user: Re-enter to c

Pagina 776 - User access levels

798 Chapter 17 Configuration example320818-A Generate and activate the SSH key for communication with the network access devices:>> Main# cfg/do

Pagina 777 - Idle timeout

Chapter 17 Configuration example 799Nortel Secure Network Access Switch 4050 User Guide Adding the Ethernet Routing Switch 8300Add the switch manually

Pagina 778

8 Contents320818-A Configuring domain parameters using the SREM . . . . . . . . . . . . . . . . . . . . . . . . 164Additional domain configuration in

Pagina 779 - Configuration example

80 Chapter 3 Managing the network access devices320818-A The delete command removes the current switch from the control of the Nortel SNAS 4050 cluste

Pagina 780 - Table 176

800 Chapter 17 Configuration example320818-A Adding the Ethernet Routing Switch 5510Use the quick switch wizard:>> Main# cfg/domain 1/quickEnter

Pagina 781

Chapter 17 Configuration example 801Nortel Secure Network Access Switch 4050 User Guide >> Domain Vlan# applyChanges applied successfully.Enabli

Pagina 782

802 Chapter 17 Configuration example320818-A

Pagina 783 - Creating a new DHCP scope

803Nortel Secure Network Access Switch 4050 User Guide Appendix ACLI referenceThe command line interface (CLI) allows you to view system information a

Pagina 784 - Naming the new DHCP scope

804 Appendix A CLI reference320818-A Using the CLICLI commands are grouped into a series of menus and submenus (see “CLI Main Menu” on page 812). Each

Pagina 785 - Figure 239

Appendix A CLI reference 805Nortel Secure Network Access Switch 4050 User Guide pasteRestores a saved configuration that includes private keys. TIP: B

Pagina 786 - Figure 240

806 Appendix A CLI reference320818-A Command line history and editingYou can use the CLI to retrieve and modify commands entered previously. Table 180

Pagina 787 - Figure 241

Appendix A CLI reference 807Nortel Secure Network Access Switch 4050 User Guide CLI shortcutsYou can use the following CLI command shortcuts:• “Comman

Pagina 788 - Specifying the DNS server

808 Appendix A CLI reference320818-A You can also use command stacking to proceed one or more levels in the menu system, and go directly to another su

Pagina 789

Appendix A CLI reference 809Nortel Secure Network Access Switch 4050 User Guide • To display the active menu:— Ensure that the command line is blank.—

Pagina 790

Chapter 3 Managing the network access devices 81Nortel Secure Network Access Switch 4050 User Guide The Switch menu includes the following options:/cf

Pagina 791 - Configuring the VoIP VLANs

810 Appendix A CLI reference320818-A If you use the cur command without the sys submenu argument, information related to the Configuration menu and al

Pagina 792 - Enabling NSNA globally

Appendix A CLI reference 811Nortel Secure Network Access Switch 4050 User Guide • 255.255.255.0 it can also be expressed as 24• 255.255.255.255 it can

Pagina 793 - Setting the switch IP address

812 Appendix A CLI reference320818-A CLI Main MenuThe Main menu appears after a successful connection and login. Figure 244 represents the Main menu a

Pagina 794 - Configuring SSH

Appendix A CLI reference 813Nortel Secure Network Access Switch 4050 User Guide • Maintenance — used for sending technical support information to an e

Pagina 795

814 Appendix A CLI reference320818-A Information menuThe Information menu contains commands used to display current information about the Nortel SNAS

Pagina 796 - Performing initial setup

Appendix A CLI reference 815Nortel Secure Network Access Switch 4050 User Guide Statistics menuThe Statistics menu contains commands used to view stat

Pagina 797 - Completing initial setup

816 Appendix A CLI reference320818-A Configuration menuThe Configuration menu contains commands used to configure the Nortel SNAS 4050. Table 184 list

Pagina 798

Appendix A CLI reference 817Nortel Secure Network Access Switch 4050 User Guide /cfg/domain <domain ID>name <name>pvips <IPaddr>aaas

Pagina 799 - Switch 8300:

818 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/ldapserverssearchbase <DN>groupattr <names>userattr <names>isdbinddn &

Pagina 800 - Mapping the VLANs

Appendix A CLI reference 819Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/auth #/localadd <user name> <password> &

Pagina 801

82 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the CLIThe VLANs are configured on the network access devices. You sp

Pagina 802

820 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/radius/sessiontimvendorid <vendor ID>vendortype <vendor type>enadisConfigure

Pagina 803 - CLI reference

Appendix A CLI reference 821Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/group #/extend #/linksetlistdel <index number>

Pagina 804 - Using the CLI

822 Appendix A CLI reference320818-A /cfg/domain #/aaa/tg quickrecheck <interval>heartbeat <interval>hbretrycnt <count>status-quo on

Pagina 805

Appendix A CLI reference 823Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/linkset <linkset ID>name <name>text <text

Pagina 806

824 Appendix A CLI reference320818-A /cfg/domain #/portal/colorscolor1 <code>color2 <code>color3 <code>color4 <code>theme defa

Pagina 807 - CLI shortcuts

Appendix A CLI reference 825Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/server/adv/traflogsysloghost <IPaddr>udpport <p

Pagina 808 - Tab completion

826 Appendix A CLI reference320818-A /cfg/domain #/switch <switch ID>name <name>type ERS8300|ERS5500ip <IPaddr>port <port>hlth

Pagina 809

Appendix A CLI reference 827Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/vlan add <name> <VLAN ID>del <index>li

Pagina 810 - Network masks

828 Appendix A CLI reference320818-A /cfg/sys/accesslist listdel <index number>add <IPaddr> <mask>Manage the Access List in order to

Pagina 811 - Variables

Appendix A CLI reference 829Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/auth/serverslistdel <index number>add <IPaddr>

Pagina 812 - CLI command reference

Chapter 3 Managing the network access devices 83Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 maintains separate maps for t

Pagina 813 - Appendix A CLI reference 813

830 Appendix A CLI reference320818-A /cfg/sys/adm/snmp/eventaddmonitor [<options>] -b <name> <OID> <op> <value>addmonito

Pagina 814 - Information menu

Appendix A CLI reference 831Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/snmp/users <user ID>name <name>seclevel none|

Pagina 815 - Statistics menu

832 Appendix A CLI reference320818-A /cfg/sys/dns/servers listdel <index number>add <IPaddr> insert <index number> <IPaddr>mov

Pagina 816 - Configuration menu

Appendix A CLI reference 833Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/host <host ID>ip <IPaddr>sysName <name>sysL

Pagina 817

834 Appendix A CLI reference320818-A /cfg/sys/time date <date>time <time>tzonentpConfigure date and time settings for the cluster.page 475

Pagina 818

Appendix A CLI reference 835Nortel Secure Network Access Switch 4050 User Guide Boot menuThe Boot menu contains commands for management of Nortel SNAS

Pagina 819

836 Appendix A CLI reference320818-A Maintenance menuThe Maintenance menu contains commands used to perform maintenance and management activities for

Pagina 820

837Nortel Secure Network Access Switch 4050 User Guide Chapter 18 TroubleshootingThis chapter includes the following topics:Troubleshooting tipsThis c

Pagina 821

838 Chapter 18 Troubleshooting320818-A Cannot connect to the Nortel SNAS 4050 using Telnet or SSHVerify the current configurationConnect with a consol

Pagina 822

Chapter 18 Troubleshooting 839Nortel Secure Network Access Switch 4050 User Guide When Telnet or SSH access is enabled, only those hosts listed in the

Pagina 823

84 Chapter 3 Managing the network access devices320818-A Managing SSH keys using the CLIThe Nortel SNAS 4050 and the network access devices controlled

Pagina 824

840 Chapter 18 Troubleshooting320818-A Ensure that you ping the host IP address (RIP) of the Nortel SNAS 4050, and not the Management IP address (MIP)

Pagina 825

Chapter 18 Troubleshooting 841Nortel Secure Network Access Switch 4050 User Guide Cannot add the Nortel SNAS 4050 to a clusterWhen you try to add a No

Pagina 826

842 Chapter 18 Troubleshooting320818-A The problem may be that there are existing entries in the Access List. When Telnet or SSH access is enabled, on

Pagina 827

Chapter 18 Troubleshooting 843Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 stops respondingTelnet or SSH connection to the

Pagina 828

844 Chapter 18 Troubleshooting320818-A If the operational status of the Nortel SNAS 4050 is still down, reboot the machine. On the device, press the P

Pagina 829

Chapter 18 Troubleshooting 845Nortel Secure Network Access Switch 4050 User Guide Boot user passwordThe default Boot user password cannot be changed,

Pagina 830

846 Chapter 18 Troubleshooting320818-A For more information about the starttrace command, the tags you can specify for the trace, and the available ou

Pagina 831

Chapter 18 Troubleshooting 847Nortel Secure Network Access Switch 4050 User Guide System diagnosticsThe following are useful diagnostic display comman

Pagina 832

848 Chapter 18 Troubleshooting320818-A To check network settings for a specific Nortel SNAS 4050, access the Cluster Host menu by typing the following

Pagina 833

Chapter 18 Troubleshooting 849Nortel Secure Network Access Switch 4050 User Guide To capture and analyze TCP traffic between clients and the virtual S

Pagina 834

Chapter 3 Managing the network access devices 85Nortel Secure Network Access Switch 4050 User Guide If you regenerate the key at any time, you must re

Pagina 835 - Boot menu

850 Chapter 18 Troubleshooting320818-A server you specify. The information can then be used for technical support purposes. The file sent to the TFTP/

Pagina 836 - Maintenance menu

851Nortel Secure Network Access Switch 4050 User Guide Appendix BSyslog messagesThis appendix contains a list of the syslog messages that are sent fro

Pagina 837 - Troubleshooting

852 Appendix B Syslog messages320818-A Operating system (OS) messagesThere are three categories of operating system (OS) system messages:• EMERG (see

Pagina 838 - Check the Access List

Appendix B Syslog messages 853Nortel Secure Network Access Switch 4050 User Guide Table 190 lists the operating system EMERG messages.System Control P

Pagina 839

854 Appendix B Syslog messages320818-A Table 191 lists the System Control Process INFO messages.About alarm messagesAlarms are sent at a syslog level

Pagina 840

Appendix B Syslog messages 855Nortel Secure Network Access Switch 4050 User Guide Table 193 lists the System Control Process ALARM messages. To simpli

Pagina 841 - Cannot contact the MIP

856 Appendix B Syslog messages320818-A About event messagesEvents are sent at the NOTICE syslog level. Event messages are formatted according to the f

Pagina 842

Appendix B Syslog messages 857Nortel Secure Network Access Switch 4050 User Guide Traffic Processing Subsystem messagesThere are four categories of Tr

Pagina 843 - Console connection

858 Appendix B Syslog messages320818-A css error: <reason> ERROR Problem encountered when parsing a style sheet. The problem could be in the Nor

Pagina 844 - A user password is lost

Appendix B Syslog messages 859Nortel Secure Network Access Switch 4050 User Guide Table 197 lists the Traffic Processing WARNING messages.socks error:

Pagina 845 - Trace tools

86 Chapter 3 Managing the network access devices320818-A The NSNAS SSH key menu includes the following options:/cfg/domain #/sshkeyfollowed by:generat

Pagina 846

860 Appendix B Syslog messages320818-A Table 198 lists the Traffic Processing INFO messages.Start-up messagesThe Traffic Processing Subsystem Start-up

Pagina 847 - System diagnostics

Appendix B Syslog messages 861Nortel Secure Network Access Switch 4050 User Guide Table 199 lists the Start-up INFO messages.AAA subsystem messagesThe

Pagina 848

862 Appendix B Syslog messages320818-A Table 201 lists the AAA INFO messages. INFO messages are generated only if the CLI command /cfg/domain #/adv/lo

Pagina 849 - Error log files

Appendix B Syslog messages 863Nortel Secure Network Access Switch 4050 User Guide NSNAS subsystem messagesThere are two categories of NSNAS subsystem

Pagina 850

864 Appendix B Syslog messages320818-A Table 202 lists the NSNAS ERROR messages.Table 203 lists the NSNAS INFO messages.Table 202 NSNAS — ERRORMessa

Pagina 851 - Syslog messages

Appendix B Syslog messages 865Nortel Secure Network Access Switch 4050 User Guide Syslog messages in alphabetical orderTable 204 lists the syslog mess

Pagina 852

866 Appendix B Syslog messages320818-A audit EVENT System Control Sent when a CLI system administrator enters, enters, exits or updates the CLI if aud

Pagina 853

Appendix B Syslog messages 867Nortel Secure Network Access Switch 4050 User Guide copy_software_release_failed ALARM (CRITICAL)System Control A Nortel

Pagina 854 - About alarm messages

868 Appendix B Syslog messages320818-A gzip warning: <reason> INFO Traffic ProcessingProblem encountered when processing compressed content.HC:

Pagina 855 - Table 193

Appendix B Syslog messages 869Nortel Secure Network Access Switch 4050 User Guide isd_down ALARM (CRITICAL)System Control A member of the Nortel SNAS

Pagina 856 - About event messages

Chapter 3 Managing the network access devices 87Nortel Secure Network Access Switch 4050 User Guide Figure 5 shows sample output for the /cfg/domain #

Pagina 857

870 Appendix B Syslog messages320818-A make_software_release_permanent_failedALARM (CRITICAL)System Control Failed to make a new software release perm

Pagina 858

Appendix B Syslog messages 871Nortel Secure Network Access Switch 4050 User Guide NSNAS LoginSucceeded Domain=”<id>” Method=<”ssl”> SrcIp=

Pagina 859

872 Appendix B Syslog messages320818-A Root filesystem repaired - rebootingERROR OS fsck found and fixed errors. Probably OK.Server <id> uses de

Pagina 860 - Start-up messages

Appendix B Syslog messages 873Nortel Secure Network Access Switch 4050 User Guide switch controller:switch [1:<switchID>] – DisconnectedINFO NSN

Pagina 861 - AAA subsystem messages

874 Appendix B Syslog messages320818-A Unable to use the certificate for <server nr>ERROR Traffic ProcessingUnsuitable certificate configured fo

Pagina 862 - Table 201

875Nortel Secure Network Access Switch 4050 User Guide Appendix CSupported MIBsThis appendix describes the Management Information Bases (MIB) and trap

Pagina 863 - NSNAS subsystem messages

876 Appendix C Supported MIBs320818-A • ALTEON-SSL-VPN-MIB• ANAifType-MIB• DISMAN-EVENT-MIB•ENTITY-MIB•IF-MIB• IP-FORWARD-MIB•IP-MIB• NORTEL-SECURE-AC

Pagina 864 - Table 202

Appendix C Supported MIBs 877Nortel Secure Network Access Switch 4050 User Guide ALTEON-ISD-SSL-MIB Contains objects for monitoring the SSL gateways.

Pagina 865 - NSNAS — INFO (Sheet 2 of 2)

878 Appendix C Supported MIBs320818-A NORTEL-SECURE-ACCESS-SWITCH-MIBContains objects for monitoring the Nortel SNAS 4050 devices. The following group

Pagina 866

Appendix C Supported MIBs 879Nortel Secure Network Access Switch 4050 User Guide Supported trapsTable 206 describes the traps supported by the Nortel

Pagina 867

88 Chapter 3 Managing the network access devices320818-A Managing SSH keys for Nortel SNA communication using the CLITo retrieve the public key for th

Pagina 868

880 Appendix C Supported MIBs320818-A

Pagina 869 - /cfg/sys/cur

881Nortel Secure Network Access Switch 4050 User Guide Appendix DSupported ciphersThe Nortel SNAS 4050 supports SSL version 2.0, SSL version 3.0, and

Pagina 870

882 Appendix D Supported ciphers320818-A EDH-RSA-DES-CBC-SHA SSLv3 DH, RSA DES (56) SHA1DES-CBC-SHA SSLv3 RSA, RSA DES (56) SHA1DES-CBC-MD5 SSLv2 RSA,

Pagina 871

883Nortel Secure Network Access Switch 4050 User Guide Appendix EAdding User Preferences attribute to Active DirectoryFor the remote user to be able t

Pagina 872

884 Appendix E Adding User Preferences attribute to Active Directory320818-A Add the Active Directory Schema Snap-in (Windows 2000 Server and Windows

Pagina 873

Appendix E Adding User Preferences attribute to Active Directory 885Nortel Secure Network Access Switch 4050 User Guide The Add/Remove Snap-in window

Pagina 874

886 Appendix E Adding User Preferences attribute to Active Directory320818-A 8 Click OK.The Console window redisplays.9 To save the console (including

Pagina 875 - Supported MIBs

Appendix E Adding User Preferences attribute to Active Directory 887Nortel Secure Network Access Switch 4050 User Guide 3 Select the check box The Sch

Pagina 876 - Supported MIBs (Sheet 1 of 3)

888 Appendix E Adding User Preferences attribute to Active Directory320818-A Create the new classTo create the nortelSSLOffload class, proceed as foll

Pagina 877 - Supported MIBs (Sheet 2 of 3)

Appendix E Adding User Preferences attribute to Active Directory 889Nortel Secure Network Access Switch 4050 User Guide 5 Add the isdUserPrefs attribu

Pagina 878 - Supported MIBs (Sheet 3 of 3)

Chapter 3 Managing the network access devices 89Nortel Secure Network Access Switch 4050 User Guide Reimporting the network access device SSH key usin

Pagina 879 - Supported traps

890 Appendix E Adding User Preferences attribute to Active Directory320818-A 5 Add the nortelSSLOffload class as an auxiliary class as shown below: 6

Pagina 880 - 880 Appendix C Supported MIBs

891Nortel Secure Network Access Switch 4050 User Guide Appendix FConfiguring DHCP to auto-configure IP PhonesThe DHCP server and the IP Phone 2002, IP

Pagina 881 - Supported ciphers

892 Appendix F Configuring DHCP to auto-configure IP Phones320818-A For information on the minimum firmware versions required to support IP Phones in

Pagina 882 - Table 207 Supported ciphers

Appendix F Configuring DHCP to auto-configure IP Phones 893Nortel Secure Network Access Switch 4050 User Guide Figure 245 The DHCP Management Consol

Pagina 883 - Directory

894 Appendix F Configuring DHCP to auto-configure IP Phones320818-A The Predefined Options and Values dialog box opens (see Figure 246).Figure 246 T

Pagina 884

Appendix F Configuring DHCP to auto-configure IP Phones 895Nortel Secure Network Access Switch 4050 User Guide Figure 247 The Option Type dialog box

Pagina 885

896 Appendix F Configuring DHCP to auto-configure IP Phones320818-A b In the Option Type dialog box, enter the required information (see Table 209).c

Pagina 886 - (Windows 2000 Server)

Appendix F Configuring DHCP to auto-configure IP Phones 897Nortel Secure Network Access Switch 4050 User Guide The Scope Options dialog box displays (

Pagina 887 - Create a new attribute

898 Appendix F Configuring DHCP to auto-configure IP Phones320818-A 4 Configure Call Server Information:a Select the check box beside 128 Call Server

Pagina 888 - Create the new class

Appendix F Configuring DHCP to auto-configure IP Phones 899Nortel Secure Network Access Switch 4050 User Guide 5 Configure VLAN Information:a In the S

Pagina 889

Contents 9Nortel Secure Network Access Switch 4050 User Guide Modifying a client filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Pagina 890

90 Chapter 3 Managing the network access devices320818-A The HealthCheck menu includes the following options:Controlling communication with the networ

Pagina 891 - Appendix F

900 Appendix F Configuring DHCP to auto-configure IP Phones320818-A

Pagina 892 - Creating the DHCP options

901Nortel Secure Network Access Switch 4050 User Guide Appendix GUsing a Windows domain logon script to launch the Nortel SNAS 4050 portalThis appendi

Pagina 893 - The DHCP Management Console

902 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 2 On a Windows 2000 domain controller, save the scrip

Pagina 894 - 4 Click Add

Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal 903Nortel Secure Network Access Switch 4050 User Guide 2 Compose

Pagina 895 - The Option Type dialog box

904 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 3 On the Group Policy tab, click Open.4 Double-click

Pagina 896 - Information options

905Nortel Secure Network Access Switch 4050 User Guide Appendix HSoftware licensing informationOpenSSL License issuesThe OpenSSL toolkit stays under a

Pagina 897 - Figure 248

906 Appendix H Software licensing information320818-A conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., c

Pagina 898

Appendix H Software licensing information 907Nortel Secure Network Access Switch 4050 User Guide warranty; keep intact all the notices that refer to t

Pagina 899 - Setting up the IP Phone

908 Appendix H Software licensing information320818-A 4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided

Pagina 900

Appendix H Software licensing information 909Nortel Secure Network Access Switch 4050 User Guide LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY

Pagina 901 - Appendix G

Chapter 3 Managing the network access devices 91Nortel Secure Network Access Switch 4050 User Guide To restart communication between the Nortel SNAS 4

Pagina 902 - Creating a logon script

910 Appendix H Software licensing information320818-A Bouncy Castle licenseCopyright (c) 2000 - 2004 The Legion Of The Bouncy Castle (http://www.bounc

Pagina 903 - Assigning the logon script

Nortel Secure Network Access Switch 4050 User Guide911 IndexSymbols/ (in CLI) 804? (help, in CLI) 804Aaborting commands (CLI) 807accessenable for SSH

Pagina 904 - Assigning a logon script

912 Index320818-A automatic redirection, from portal 396autorun linksets 394Bbackend interfaceconfigure 145backupcertificates and keys 574, 591, 605c

Pagina 905 - Appendix H

Index 913Nortel Secure Network Access Switch 4050 User Guide create 214modify 217clusteradd Nortel SNAS 4050 device 61and Access List 62benefits 39c

Pagina 906 - GNU General Public License

914 Index320818-A RADIUS authentication method 242, 272CSR (Certificate Signing Request)and associated private key 583generate 579, 601information re

Pagina 907

Index 915Nortel Secure Network Access Switch 4050 User Guide create 203, 220map linksets 206, 223, 227modify 222remove linksets 229reorder linksets

Pagina 908

916 Index320818-A IP addresses 51in two-armed configuration 52MIP 51pVIP 51RIP 52subnet requirements 52IP Phones, supported in Nortel SNA 33Jjoin a c

Pagina 909

Index 917Nortel Secure Network Access Switch 4050 User Guide MmacrosLDAP 258, 294used on portal page 395major release upgrade 758manageActive Direct

Pagina 910 - Bouncy Castle license

918 Index320818-A RIP 52role in Nortel SNA solution 33SSH public key, export 84nslookup (CLI global command) 805Oone-armed configuration 40, 41online

Pagina 911

Index 919Nortel Secure Network Access Switch 4050 User Guide create method 242, 272in Nortel SNA 36manage servers 247, 279, 281modify configuration

Pagina 912

92 Chapter 3 Managing the network access devices320818-A The Switches screen appears (see “Switch Configuration screen” on page 116).2 Click Add.The A

Pagina 913

920 Index320818-A existence monitor 627, 654in Nortel SNA 618manage events 655manage monitor events 647manage targets 638monitors 627supported MIBs 8

Pagina 914

Index 921Nortel Secure Network Access Switch 4050 User Guide network diagnostics 847Ttechnical publications 29technical support 29Telnetenable acces

Pagina 915

922 Index320818-A default mapping, domain quick setup wizard 128in Nortel SNA solution 34mapping 82, 96VoIP phones, supported in Nortel SNA 33VoIP VL

Pagina 916

Chapter 3 Managing the network access devices 93Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The network access device appears in

Pagina 917

94 Chapter 3 Managing the network access devices320818-A To reconfigure the VLAN mappings for an existing network access device, you must first disabl

Pagina 918

Chapter 3 Managing the network access devices 95Nortel Secure Network Access Switch 4050 User Guide 2 Enter the network access device information in t

Pagina 919

96 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the SREMThe VLANs are configured on the network access devices. You s

Pagina 920

Chapter 3 Managing the network access devices 97Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domainTo map VLANs in a domain, s

Pagina 921

98 Chapter 3 Managing the network access devices320818-A Adding VLANs to a domainTo add VLANs to a domain, complete the following steps:1 Select the S

Pagina 922

Chapter 3 Managing the network access devices 99Nortel Secure Network Access Switch 4050 User Guide Removing VLANs from a domainTo remove existing VLA

Comentarios a estos manuales

Sin comentarios