Nortel Networks Nortel Secure Network Access Switch 4050 Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Software Nortel Networks Nortel Secure Network Access Switch 4050. Nortel Networks Nortel Secure Network Access Switch 4050 User's Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 0
Part No. 320818-A
December 2005
4655 Great America Parkway
Santa Clara, CA 95054
*320818-A*
Nortel Secure Network Access
Switch 4050 User Guide
Nortel Secure Network Access Switch
Software Release 1.0
Vista de página 0
1 2 3 4 5 6 ... 921 922

Resumo do Conteúdo

Página 1 - Switch 4050 User Guide

Part No. 320818-ADecember 20054655 Great America ParkwaySanta Clara, CA 95054*320818-A*Nortel Secure Network Access Switch 4050 User GuideNortel Secu

Página 2 - Statement of conditions

10 Contents320818-A Modifying RADIUS configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273Managing additional RADIUS s

Página 3 - Licensing

100 Chapter 3 Managing the network access devices320818-A Mapping VLANs by switchTo map VLANs by switch, you must first disable the network access dev

Página 4

Chapter 3 Managing the network access devices 101Nortel Secure Network Access Switch 4050 User Guide • “Removing VLANs from a switch” on page 102Addin

Página 5 - Contents

102 Chapter 3 Managing the network access devices320818-A Removing VLANs from a switchTo remove existing VLANs from the switch, complete the following

Página 6

Chapter 3 Managing the network access devices 103Nortel Secure Network Access Switch 4050 User Guide If you created the domain manually, the SSH key w

Página 7

104 Chapter 3 Managing the network access devices320818-A If the network access device defaults, it generates a new public key. You must reimport the

Página 8

Chapter 3 Managing the network access devices 105Nortel Secure Network Access Switch 4050 User Guide Generating SSH keys for the domain using the SREM

Página 9

106 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Página 10

Chapter 3 Managing the network access devices 107Nortel Secure Network Access Switch 4050 User Guide The Export Key screen appears (see Figure 13).Fig

Página 11

108 Chapter 3 Managing the network access devices320818-A 2 Enter the export information in the applicable fields. Table 8 describes the fields availa

Página 12

Chapter 3 Managing the network access devices 109Nortel Secure Network Access Switch 4050 User Guide Managing SSH keys for Nortel SNA communication us

Página 13

Contents 11Nortel Secure Network Access Switch 4050 User Guide SRS Rule Expression Constructor . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 14

110 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Página 15

Chapter 3 Managing the network access devices 111Nortel Secure Network Access Switch 4050 User Guide The switch SSH Key screen appears (see Figure 14

Página 16

112 Chapter 3 Managing the network access devices320818-A The Health Check screen appears (see Figure 15).Figure 15 Health Check screen

Página 17

Chapter 3 Managing the network access devices 113Nortel Secure Network Access Switch 4050 User Guide 2 Enter the health check information in the appli

Página 18

114 Chapter 3 Managing the network access devices320818-A The Connected Clients screen appears, displaying information about the connection status and

Página 19

Chapter 3 Managing the network access devices 115Nortel Secure Network Access Switch 4050 User Guide Controlling communication with the network access

Página 20

116 Chapter 3 Managing the network access devices320818-A To disable or enable the network access device, perform the following steps:1 Select the Sec

Página 21

117Nortel Secure Network Access Switch 4050 User Guide Chapter 4 Configuring the domainThis chapter includes the following topics:Topic PageConfigurin

Página 22

118 Chapter 4 Configuring the domain320818-A A Nortel SNAS 4050 domain encompasses all the switches, authentication servers, and remediation servers a

Página 23

Chapter 4 Configuring the domain 119Nortel Secure Network Access Switch 4050 User Guide • logging traffic with syslog messages• portal settings (see “

Página 24 - 24 Contents

12 Contents320818-A Changing a user’s group assignment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365Changing passwords . . . . . .

Página 25

120 Chapter 4 Configuring the domain320818-A details on|offloglevel fatal|error|warning| info|debug/cfg/domain #/aaa/tg/quick/cfg/domain #/server port

Página 26

Chapter 4 Configuring the domain 121Nortel Secure Network Access Switch 4050 User Guide Creating a domain using the CLIYou can create a domain in two

Página 27 - Text conventions

122 Chapter 4 Configuring the domain320818-A When you first create the domain, you are prompted to enter the following parameters:• domain name — a st

Página 28 - Related information

Chapter 4 Configuring the domain 123Nortel Secure Network Access Switch 4050 User Guide Figure 17 Creating a domainUsing the Nortel SNAS 4050 domain

Página 29 - How to get help

124 Chapter 4 Configuring the domain320818-A Depending on the options you select in connection with certificates and creating a test user, the two wiz

Página 30 - 30 Preface

Chapter 4 Configuring the domain 125Nortel Secure Network Access Switch 4050 User Guide c To use an existing certificate, enter the applicable certifi

Página 31 - Chapter 1

126 Chapter 4 Configuring the domain320818-A c To continue, go to step 8 on page 126.8 Specify whether the SSL server uses chain certificates. 9 If yo

Página 32 - Supported users

Chapter 4 Configuring the domain 127Nortel Secure Network Access Switch 4050 User Guide 11 To add a network access device, enter the required informat

Página 33 - Role of the Nortel SNAS 4050

128 Chapter 4 Configuring the domain320818-A The wizard assigns the following default VLAN IDs:• Green VLAN = VLAN ID 110• Yellow VLAN = VLAN ID 120Yo

Página 34 - Nortel SNA VLANs and filters

Chapter 4 Configuring the domain 129Nortel Secure Network Access Switch 4050 User Guide Deleting a domain using the CLITo delete a domain, use the fol

Página 35 - Groups and profiles

Contents 13Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the CLI . . . . . . . . . . . . . . . . . . .

Página 36 - Authentication methods

130 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the CLITo configure the domain, use the following command:/cfg/domain

Página 37 - Chapter 1 Overview 37

Chapter 4 Configuring the domain 131Nortel Secure Network Access Switch 4050 User Guide portalAccesses the Portal menu, in order to customize the port

Página 38 - About SSH

132 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the CLIBefore an authenticated client is allowed into the network

Página 39 - Nortel SNAS 4050 clusters

Chapter 4 Configuring the domain 133Nortel Secure Network Access Switch 4050 User Guide heartbeat <interval>Sets the time interval between check

Página 40 - 40 Chapter 1 Overview

134 Chapter 4 Configuring the domain320818-A Using the quick TunnelGuard setup wizard in the CLITo configure the settings for the SRS rule check using

Página 41 - Two-armed configuration

Chapter 4 Configuring the domain 135Nortel Secure Network Access Switch 4050 User Guide The TunnelGuard quick setup wizard creates a default SRS rule

Página 42 - 42 Chapter 1 Overview

136 Chapter 4 Configuring the domain320818-A The Server 1001 menu includes the following options:Tracing SSL traffic using the CLITo verify connectivi

Página 43 - Chapter 1 Overview 43

Chapter 4 Configuring the domain 137Nortel Secure Network Access Switch 4050 User Guide The Trace menu displays.The Trace menu includes the following

Página 44 - 44 Chapter 1 Overview

138 Chapter 4 Configuring the domain320818-A tcpdumpCreates a dump of the TCP traffic flowing between clients and the virtual SSL server. You are prom

Página 45 - Chapter 1 Overview 45

Chapter 4 Configuring the domain 139Nortel Secure Network Access Switch 4050 User Guide Configuring SSL settings using the CLITo configure SSL-specifi

Página 46 - 46 Chapter 1 Overview

14 Contents320818-A Chapter 10: Configuring system settings . . . . . . . . . . . . . . . . . . . . . . . . . 457Configuring the cluster using the CLI

Página 47 - Chapter 1 Overview 47

140 Chapter 4 Configuring the domain320818-A The SSL Settings menu includes the following options:/cfg/domain #/server/sslfollowed by:cert <certifi

Página 48 - 48 Chapter 1 Overview

Chapter 4 Configuring the domain 141Nortel Secure Network Access Switch 4050 User Guide cachain <certificate index list>Specifies the CA certifi

Página 49 - Initial setup

142 Chapter 4 Configuring the domain320818-A Configuring traffic log settings using the CLIYou can configure a syslog server to receive User Datagram

Página 50

Chapter 4 Configuring the domain 143Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Página 51 - About the IP addresses

144 Chapter 4 Configuring the domain320818-A Configuring HTTP redirect using the CLIYou can configure the Nortel SNAS 4050 domain to automatically red

Página 52

Chapter 4 Configuring the domain 145Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configure t

Página 53

146 Chapter 4 Configuring the domain320818-A Configuring RADIUS accounting using the CLIThe Nortel SNAS 4050 can be configured to provide support for

Página 54

Chapter 4 Configuring the domain 147Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS accounting server to the confi

Página 55

148 Chapter 4 Configuring the domain320818-A The Radius Accounting Servers menu includes the following options:/cfg/domain #/aaa/radacct/serversfollow

Página 56

Chapter 4 Configuring the domain 149Nortel Secure Network Access Switch 4050 User Guide Configuring Nortel SNAS 4050-specific attributes using the CLI

Página 57

Contents 15Nortel Secure Network Access Switch 4050 User Guide Adding a host interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 58

150 Chapter 4 Configuring the domain320818-A The VPN Attribute menu includes the following options:Configuring the domain using the SREMTo configure t

Página 59

Chapter 4 Configuring the domain 151Nortel Secure Network Access Switch 4050 User Guide • portal settings (see “Customizing the portal and user logon”

Página 60

152 Chapter 4 Configuring the domain320818-A Manually creating a domain using the SREMTo create and configure a domain manually, perform the following

Página 61 - Extended profile details

Chapter 4 Configuring the domain 153Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Secure Access Domain dialog box appears

Página 62

154 Chapter 4 Configuring the domain320818-A Using the SREM Domain Quick WizardThe Nortel SNAS 4050 quick setup wizard is similar to the quick setup w

Página 63 - Joining a cluster

Chapter 4 Configuring the domain 155Nortel Secure Network Access Switch 4050 User Guide To create a domain using the Nortel SNAS 4050 quick setup wiza

Página 64

156 Chapter 4 Configuring the domain320818-A 2 Click Domain Quick Wizard.The Domain Quick Wizard — General Settings dialog box appears (see Figure 22)

Página 65

Chapter 4 Configuring the domain 157Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate dialog box appears (see

Página 66

158 Chapter 4 Configuring the domain320818-A 6 Click Next.Organization Name Specifies the registered name of the organization. The organization must o

Página 67 - Chapter 2 Initial setup 67

Chapter 4 Configuring the domain 159Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate Chain dialog box appears

Página 68

16 Contents320818-A Managing RADIUS audit servers using the SREM . . . . . . . . . . . . . . . . . . . . 559Managing RADIUS authentication of system

Página 69 - Figure 3

160 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Server dialog box appears (see Figure 25).Figure 25 Domain Quick Wizard – Ser

Página 70 - 70 Chapter 2 Initial setup

Chapter 4 Configuring the domain 161Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Switch dialog box appears (see Figur

Página 71 - Chapter 3

162 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Tunnel Guard dialog box appears (see Figure 27).Figure 27 Domain Quick Wizard

Página 72

Chapter 4 Configuring the domain 163Nortel Secure Network Access Switch 4050 User Guide If there are no problems, then a dialog appears to indicate th

Página 73

164 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the SREMTo configure a domain, perform the following steps:1 Select t

Página 74

Chapter 4 Configuring the domain 165Nortel Secure Network Access Switch 4050 User Guide 2 Enter the domain information in the applicable fields. Table

Página 75

166 Chapter 4 Configuring the domain320818-A Additional domain configuration in the SREMTo configure additional domain settings, there are tabs and tr

Página 76

Chapter 4 Configuring the domain 167Nortel Secure Network Access Switch 4050 User Guide Table 21 describes the purpose of additional tree components f

Página 77 - >

168 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the SREMBefore an authenticated client is allowed into the networ

Página 78 - Manually adding a switch

Chapter 4 Configuring the domain 169Nortel Secure Network Access Switch 4050 User Guide To configure settings for the TunnelGuard host integrity check

Página 79

Contents 17Nortel Secure Network Access Switch 4050 User Guide Chapter 12: Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 80

170 Chapter 4 Configuring the domain320818-A 2 Enter the TunnelGuard information in the applicable fields. Table 22 describes the TunnelGuard Configur

Página 81

Chapter 4 Configuring the domain 171Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes to th

Página 82

172 Chapter 4 Configuring the domain320818-A Using the TunnelGuard Quick Setup in the SREMTo configure settings for the TunnelGuard host integrity che

Página 83

Chapter 4 Configuring the domain 173Nortel Secure Network Access Switch 4050 User Guide 2 Enter the TunnelGuard information in the applicable fields.

Página 84

174 Chapter 4 Configuring the domain320818-A Configuring the SSL server using the SREMTo configure settings for the SSL server, perform the following

Página 85

Chapter 4 Configuring the domain 175Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Página 86

176 Chapter 4 Configuring the domain320818-A Configuring SSL settings using the SREMTo configure SSL-specific settings for the portal server, perform

Página 87 - Figure 5

Chapter 4 Configuring the domain 177Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Página 88 - The SSH Key menu displays

178 Chapter 4 Configuring the domain320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Página 89

Chapter 4 Configuring the domain 179Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Página 90

18 Contents320818-A Viewing SONMP topology information using the SREM . . . . . . . . . . . . . . . . 675Viewing switch distribution using the SREM

Página 91 - /cfg/domain #/switch #/ena

180 Chapter 4 Configuring the domain320818-A 2 Enter the traffic log information in the applicable fields. Table 26 describes the Traffic Log Syslog S

Página 92 - Add a Switch fields

Chapter 4 Configuring the domain 181Nortel Secure Network Access Switch 4050 User Guide Tracing SSL traffic using the SREMTo verify connectivity and t

Página 93

182 Chapter 4 Configuring the domain320818-A To configure the domain to automatically redirect HTTP requests to the HTTPS server specified for the dom

Página 94

Chapter 4 Configuring the domain 183Nortel Secure Network Access Switch 4050 User Guide 2 Enter the redirection information in the applicable fields.

Página 95 - Table 4

184 Chapter 4 Configuring the domain320818-A • cause of terminationConfigure the RADIUS server in accordance with the recommendations in RFC 2866. Cer

Página 96

Chapter 4 Configuring the domain 185Nortel Secure Network Access Switch 4050 User Guide Contact your RADIUS system administrator for information about

Página 97 - Mapping VLANs by domain

186 Chapter 4 Configuring the domain320818-A 2 Enter the RADIUS accounting information in the applicable fields. Table 27 describes the RADIUS account

Página 98 - Adding VLANs to a domain

Chapter 4 Configuring the domain 187Nortel Secure Network Access Switch 4050 User Guide The Radius Accounting Servers screen appears (see Figure 36).F

Página 99 - Removing VLANs from a domain

188 Chapter 4 Configuring the domain320818-A 3 Enter the RADIUS accounting server information in the applicable fields. Table 29 describes the Radius

Página 100 - Mapping VLANs by switch

Chapter 4 Configuring the domain 189Nortel Secure Network Access Switch 4050 User Guide Deleting a RADIUS accounting server using the SREMTo delete a

Página 101 - Adding VLANs to a switch

Contents 19Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices and software using the SREM . . . . . . . . . 743Mana

Página 102 - Removing VLANs from a switch

190 Chapter 4 Configuring the domain320818-A

Página 103

191Nortel Secure Network Access Switch 4050 User Guide Chapter 5 Configuring groups and profilesThis chapter includes the following topics:Topic PageO

Página 104 - 320818-A

192 Chapter 5 Configuring groups and profiles320818-A OverviewThis section includes the following topics:• “Groups” on page 192• “Linksets” on page 19

Página 105 - Key Generation screen

Chapter 5 Configuring groups and profiles 193Nortel Secure Network Access Switch 4050 User Guide Each group’s data include the following configurable

Página 106 - Switch SSH Key fields

194 Chapter 5 Configuring groups and profiles320818-A LinksetsA linkset is a set of links that display on the portal page, so that the user can easily

Página 107 - Figure 13

Chapter 5 Configuring groups and profiles 195Nortel Secure Network Access Switch 4050 User Guide Extended profilesPassing or failing the SRS rule chec

Página 108 - Table 8

196 Chapter 5 Configuring groups and profiles320818-A Before you beginBefore you configure groups, client filters, and extended profiles on the Nortel

Página 109 - Switch SSH Key screen

Chapter 5 Configuring groups and profiles 197Nortel Secure Network Access Switch 4050 User Guide 3 Configure the extended profiles for the group (see

Página 110

198 Chapter 5 Configuring groups and profiles320818-A Configuring groups using the CLITo create and configure a group, use the following command:/cfg/

Página 111

Chapter 5 Configuring groups and profiles 199Nortel Secure Network Access Switch 4050 User Guide • number of sessions — the maximum number of simultan

Página 112 - Figure 15

2320818-A Copyright © Nortel Networks Limited 2005. All rights reserved.The information in this document is subject to change without notice. The stat

Página 113

20 Contents320818-A Configure the network DNS server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 782Configure the network D

Página 114 - Table 11

200 Chapter 5 Configuring groups and profiles320818-A Figure 38 shows sample output for the /cfg/domain 1/aaa/group <group ID> command and comma

Página 115

Chapter 5 Configuring groups and profiles 201Nortel Secure Network Access Switch 4050 User Guide Configuring client filters using the CLITo create and

Página 116 - Switch Configuration screen

202 Chapter 5 Configuring groups and profiles320818-A The Client Filter menu includes the following options:/cfg/domain 1/aaa/filter <filter ID>

Página 117 - Configuring the domain

Chapter 5 Configuring groups and profiles 203Nortel Secure Network Access Switch 4050 User Guide Figure 39 shows sample output for the /cfg/domain 1/a

Página 118 - /cfg/domain

204 Chapter 5 Configuring groups and profiles320818-A When you first create the profile, you are prompted to enter the following parameters:• client f

Página 119 - Roadmap of domain commands

Chapter 5 Configuring groups and profiles 205Nortel Secure Network Access Switch 4050 User Guide Figure 40 shows sample output for the /cfg/domain 1/a

Página 120

206 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a group or profile using the CLIYou can tailor the portal page for different

Página 121

Chapter 5 Configuring groups and profiles 207Nortel Secure Network Access Switch 4050 User Guide Figure 41 shows sample output for the /cfg/domain 1/a

Página 122 - <domain ID>

208 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the CLITo create a default group, first create a group with exten

Página 123 - Figure 17 Creating a domain

Chapter 5 Configuring groups and profiles 209Nortel Secure Network Access Switch 4050 User Guide Using the guide for creating groups If you desire add

Página 124

Contents 21Nortel Secure Network Access Switch 4050 User Guide CLI shortcuts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 125

210 Chapter 5 Configuring groups and profiles320818-A Adding a group To create and configure a group, perform the following steps:1 Select the Secure

Página 126

Chapter 5 Configuring groups and profiles 211Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Group dialog box appears (see

Página 127

212 Chapter 5 Configuring groups and profiles320818-A Modifying a groupTo configure a group, perform the following steps:1 Select the Secure Access Do

Página 128

Chapter 5 Configuring groups and profiles 213Nortel Secure Network Access Switch 4050 User Guide 2 Enter the group information in the applicable field

Página 129

214 Chapter 5 Configuring groups and profiles320818-A Adding a client filter To create and configure a client filter, perform the following steps:1 Se

Página 130

Chapter 5 Configuring groups and profiles 215Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Client Filter dialog box appear

Página 131

216 Chapter 5 Configuring groups and profiles320818-A 4 Click Apply.The new client filter now appears in the Client Filters table.5 Click Apply on the

Página 132

Chapter 5 Configuring groups and profiles 217Nortel Secure Network Access Switch 4050 User Guide Modifying a client filterTo configure a client filter

Página 133

218 Chapter 5 Configuring groups and profiles320818-A 2 Enter the Client Filter information in the applicable fields. Table 34 describes the Client Fi

Página 134

Chapter 5 Configuring groups and profiles 219Nortel Secure Network Access Switch 4050 User Guide Configuring extended profiles using the SREMTo view t

Página 135

22 Contents320818-A Root user password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 844Boot user password .

Página 136

220 Chapter 5 Configuring groups and profiles320818-A Adding an extended profile To create an extended profile for a group, perform the following step

Página 137 - The Trace menu displays

Chapter 5 Configuring groups and profiles 221Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add an Extended Profile dialog box o

Página 138

222 Chapter 5 Configuring groups and profiles320818-A Modifying an extended profileTo modify an extended profile for a group, perform the following st

Página 139

Chapter 5 Configuring groups and profiles 223Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Extended Profile information in the appli

Página 140

224 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a groupTo map a linkset to a group, select the Secure Access Domain > dom

Página 141

Chapter 5 Configuring groups and profiles 225Nortel Secure Network Access Switch 4050 User Guide Adding linksets to a groupTo add a linkset to a group

Página 142 - SSL is enabled by default

226 Chapter 5 Configuring groups and profiles320818-A Removing linksets from a groupTo remove a linkset from a group, perform the following steps:1 Se

Página 143

Chapter 5 Configuring groups and profiles 227Nortel Secure Network Access Switch 4050 User Guide Mapping linksets to a profileTo map a linkset to an e

Página 144

228 Chapter 5 Configuring groups and profiles320818-A Adding linksets to an extended profileTo add a linkset to an extended profile, perform the follo

Página 145

Chapter 5 Configuring groups and profiles 229Nortel Secure Network Access Switch 4050 User Guide Removing linksets from an extended profileTo remove a

Página 146

Contents 23Nortel Secure Network Access Switch 4050 User Guide Create a new attribute(Windows 2000 Server and Windows Server 2003) . . . . . . . . . .

Página 147

230 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the SREM To create a default group, first create a group with ext

Página 148

Chapter 5 Configuring groups and profiles 231Nortel Secure Network Access Switch 4050 User Guide 2 Enter the AAA information in the applicable fields.

Página 149 - NSNAS-Portal-ID)

232 Chapter 5 Configuring groups and profiles320818-A

Página 150

233Nortel Secure Network Access Switch 4050 User Guide Chapter 6 Configuring authenticationThis chapter includes the following topics:Topic PageOvervi

Página 151

234 Chapter 6 Configuring authentication320818-A OverviewThe Nortel SNAS 4050 controls authentication of clients when they log on to the network.The N

Página 152 - Figure 19

Chapter 6 Configuring authentication 235Nortel Secure Network Access Switch 4050 User Guide Before you beginBefore you configure authentication on the

Página 153 - Add a Secure Access Domain

236 Chapter 6 Configuring authentication320818-A — Vendor-Typeb LDAP servers:— server IP address— port number used for the service— configured account

Página 154

Chapter 6 Configuring authentication 237Nortel Secure Network Access Switch 4050 User Guide 3 Specify the order in which the authentication methods wi

Página 155 - Figure 21

238 Chapter 6 Configuring authentication320818-A domainid <domain ID>domaintype <domain type>authproto pap|chapv2timeout <interval>/

Página 156

Chapter 6 Configuring authentication 239Nortel Secure Network Access Switch 4050 User Guide Configuring authentication methods using the CLITo create

Página 157

24 Contents320818-A

Página 158 - 6 Click Next

240 Chapter 6 Configuring authentication320818-A When you first create the method, you are prompted to specify the type. For Nortel Secure Network Acc

Página 159 - Field Description

Chapter 6 Configuring authentication 241Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configu

Página 160 - Domain Quick Wizard – Server

242 Chapter 6 Configuring authentication320818-A To configure the current authentication scheme to retrieve user group information from a different au

Página 161 - Domain Quick Wizard – Switch

Chapter 6 Configuring authentication 243Nortel Secure Network Access Switch 4050 User Guide You can perform the following configuration tasks:• “Addin

Página 162

244 Chapter 6 Configuring authentication320818-A • vendor type for group — corresponds to the Vendor-Type value used in combination with the Vendor-Id

Página 163

Chapter 6 Configuring authentication 245Nortel Secure Network Access Switch 4050 User Guide Figure 56 shows sample output for the RADIUS method for th

Página 164 - Figure 28

246 Chapter 6 Configuring authentication320818-A The RADIUS menu displays.The RADIUS menu includes the following options:/cfg/domain 1/aaa/auth #/radi

Página 165 - Table 19

Chapter 6 Configuring authentication 247Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLIYou ca

Página 166 - Table 20

248 Chapter 6 Configuring authentication320818-A The Radius servers menu includes the following options:/cfg/domain 1/aaa/auth #/radius/serversfollowe

Página 167 - Table 21

Chapter 6 Configuring authentication 249Nortel Secure Network Access Switch 4050 User Guide Configuring session timeout using the CLIYou can configure

Página 168

25Nortel Secure Network Access Switch 4050 User Guide PrefaceNortel* Secure Network Access (Nortel SNA) is a clientless solution that provides seamles

Página 169

250 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Página 170 - Table 22

Chapter 6 Configuring authentication 251Nortel Secure Network Access Switch 4050 User Guide • if user entries are located in several places in the LDA

Página 171

252 Chapter 6 Configuring authentication320818-A Figure 57 shows sample output for the LDAP method for the /cfg/domain 1/aaa/auth <auth ID> comm

Página 172

Chapter 6 Configuring authentication 253Nortel Secure Network Access Switch 4050 User Guide The LDAP menu displays.The LDAP menu includes the followin

Página 173 - Table 23

254 Chapter 6 Configuring authentication320818-A userattr <names>Refers to one of the following:1. the LDAP attribute that contains the user nam

Página 174 - Figure 31

Chapter 6 Configuring authentication 255Nortel Secure Network Access Switch 4050 User Guide enaldaps true|falseIf true, makes LDAP requests between th

Página 175 - Table 24

256 Chapter 6 Configuring authentication320818-A Managing LDAP authentication servers using the CLIYou can configure additional LDAP servers for the d

Página 176 - Figure 32

Chapter 6 Configuring authentication 257Nortel Secure Network Access Switch 4050 User Guide del <index number>Removes the specified LDAP server

Página 177 - Table 25

258 Chapter 6 Configuring authentication320818-A Managing LDAP macros using the CLIYou can create your own macros (or variables), to allow you to retr

Página 178

Chapter 6 Configuring authentication 259Nortel Secure Network Access Switch 4050 User Guide add <variable name> <LDAP attribute> [<pref

Página 179

26 Preface320818-A The document provides instructions for initializing and customizing the features using the Command Line Interface (CLI). To learn t

Página 180 - Table 26

260 Chapter 6 Configuring authentication320818-A Managing Active Directory passwords using the CLIYou can set up a mechanism for clients to change the

Página 181

Chapter 6 Configuring authentication 261Nortel Secure Network Access Switch 4050 User Guide Configuring local database authentication using the CLIYou

Página 182 - Figure 34

262 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Página 183 - HTTP Redirect fields

Chapter 6 Configuring authentication 263Nortel Secure Network Access Switch 4050 User Guide • group name — the name of the group to which the specifie

Página 184

264 Chapter 6 Configuring authentication320818-A Managing the local database using the CLIYou can add users to the database in two ways:• manually, us

Página 185

Chapter 6 Configuring authentication 265Nortel Secure Network Access Switch 4050 User Guide The Local database menu includes the following options:/cf

Página 186

266 Chapter 6 Configuring authentication320818-A import <protocol> <server> <filename> <key>Imports a database from the specif

Página 187 - Figure 37

Chapter 6 Configuring authentication 267Nortel Secure Network Access Switch 4050 User Guide Specifying authentication fallback order using the CLIAuth

Página 188

268 Chapter 6 Configuring authentication320818-A Perform this step even if there is only one method defined on the Nortel SNAS 4050.To specify the aut

Página 189

Chapter 6 Configuring authentication 269Nortel Secure Network Access Switch 4050 User Guide Configuring authentication using the SREMThe basic steps f

Página 190

Preface 27Nortel Secure Network Access Switch 4050 User Guide Text conventionsThis guide uses the following text conventions:angle brackets (< >

Página 191 - Chapter 5

270 Chapter 6 Configuring authentication320818-A Configuring authentication methods using the SREMTo create and configure an authentication method, pe

Página 192 - Overview

Chapter 6 Configuring authentication 271Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add an Authentication Server dialog box op

Página 193 - Default group

272 Chapter 6 Configuring authentication320818-A Adding the RADIUS method and serverTo configure the Nortel SNAS 4050 to use an external RADIUS or Ste

Página 194 - TunnelGuard SRS rule

Chapter 6 Configuring authentication 273Nortel Secure Network Access Switch 4050 User Guide 2 Enter the authentication server information in the appli

Página 195 - Extended profiles

274 Chapter 6 Configuring authentication320818-A • Modify settings for the specific RADIUS configuration (see “Modifying RADIUS configuration settings

Página 196 - Before you begin

Chapter 6 Configuring authentication 275Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Página 197

276 Chapter 6 Configuring authentication320818-A Modifying RADIUS configuration settingsTo modify the RADIUS method configuration, perform the followi

Página 198

Chapter 6 Configuring authentication 277Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the RADIUS configuration as necessar

Página 199

278 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Página 200 - Figure 38

Chapter 6 Configuring authentication 279Nortel Secure Network Access Switch 4050 User Guide Managing additional RADIUS serversAdditional RADIUS server

Página 201

28 Preface320818-A Related informationThis section lists information sources that relate to this document.PublicationsRefer to the following publicati

Página 202

280 Chapter 6 Configuring authentication320818-A The RADIUS Server Table allows you to manage additional RADIUS servers by performing any of the follo

Página 203

Chapter 6 Configuring authentication 281Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new RADIUS server is automatically assig

Página 204

282 Chapter 6 Configuring authentication320818-A The RADIUS Servers screen appears (see Figure 69 on page 291).2 Select an RADIUS server entry from th

Página 205 - Figure 40

Chapter 6 Configuring authentication 283Nortel Secure Network Access Switch 4050 User Guide Adding the LDAP method and serverTo configure the Nortel S

Página 206

284 Chapter 6 Configuring authentication320818-A 3 Click Apply.The LDAP authentication method displays in the Authentication Server Table.4 Click Appl

Página 207 - Figure 41

Chapter 6 Configuring authentication 285Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP method settingsTo modify settings for an ex

Página 208

286 Chapter 6 Configuring authentication320818-A 2 Modify settings for the authentication method as necessary.Table 45 describes the Configuration fie

Página 209

Chapter 6 Configuring authentication 287Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP configuration settingsTo modify the LDAP me

Página 210 - Adding a group

288 Chapter 6 Configuring authentication320818-A 2 Modify settings for the LDAP configuration as necessary.Table 46 describes the LDAP Configuration f

Página 211 - Add a Group fields

Chapter 6 Configuring authentication 289Nortel Secure Network Access Switch 4050 User Guide User Attribute Refers to one of the following:1. the LDAP

Página 212 - Modifying a group

Preface 29Nortel Secure Network Access Switch 4050 User Guide • Release Notes for Nortel Ethernet Routing Switch 5500 Series, Software Release 4.3 (21

Página 213 - Group Configuration fields

290 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Página 214 - Adding a client filter

Chapter 6 Configuring authentication 291Nortel Secure Network Access Switch 4050 User Guide Managing additional LDAP serversAdditional LDAP servers ca

Página 215 - Adding a Client Filter screen

292 Chapter 6 Configuring authentication320818-A The LDAP Server Table allows you to manage additional LDAP servers by performing any of the following

Página 216 - 4 Click Apply

Chapter 6 Configuring authentication 293Nortel Secure Network Access Switch 4050 User Guide The new LDAP server is automatically assigned a unique ind

Página 217 - Modifying a client filter

294 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Página 218 - Table 34

Chapter 6 Configuring authentication 295Nortel Secure Network Access Switch 4050 User Guide To manage LDAP macro variables, select the Secure Access D

Página 219

296 Chapter 6 Configuring authentication320818-A Adding LDAP macrosTo create an LDAP macro variable, perform the following steps:1 Select the Secure A

Página 220 - Adding an extended profile

Chapter 6 Configuring authentication 297Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new LDAP macro is automatically assigned

Página 221

298 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Página 222 - Modifying an extended profile

Chapter 6 Configuring authentication 299Nortel Secure Network Access Switch 4050 User Guide Adding the Local methodTo configure the Nortel SNAS 4050 t

Página 223

3Nortel Secure Network Access Switch 4050 User Guide In addition, the program and information contained herein are licensed only pursuant to a license

Página 224 - Mapping linksets to a group

30 Preface320818-A • To call a Nortel Technical Solutions Center for assistance, click the CALL US link on the left side of the page to find the telep

Página 225 - Adding linksets to a group

300 Chapter 6 Configuring authentication320818-A 2 Enter the authentication server information in the applicable fields.Table 49 describes the Add an

Página 226

Chapter 6 Configuring authentication 301Nortel Secure Network Access Switch 4050 User Guide Populating the databaseYou can populate the Local database

Página 227 - Mapping linksets to a profile

302 Chapter 6 Configuring authentication320818-A 2 Click Add.The Add a Local User dialog box appears (see Figure 75).Figure 75 Add a Local User3 Ent

Página 228 - Add a Linkset fields

Chapter 6 Configuring authentication 303Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new user entry appears in the list of lo

Página 229

304 Chapter 6 Configuring authentication320818-A Importing a database To import a database of local users, perform the following steps.1 Select the Se

Página 230 - AAA Configuration screen

Chapter 6 Configuring authentication 305Nortel Secure Network Access Switch 4050 User Guide 2 Enter the import information in the applicable fields.Ta

Página 231 - Table 39

306 Chapter 6 Configuring authentication320818-A Modifying Local method settingsTo modify settings for an existing local or LDAP authentication method

Página 232

Chapter 6 Configuring authentication 307Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Página 233 - Configuring authentication

308 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Página 234

Chapter 6 Configuring authentication 309Nortel Secure Network Access Switch 4050 User Guide 3 Modify the local user information in the applicable fiel

Página 235

31Nortel Secure Network Access Switch 4050 User Guide Chapter 1 OverviewThis chapter includes the following topics:The Nortel SNA solutionNortel Secur

Página 236

310 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Página 237

Chapter 6 Configuring authentication 311Nortel Secure Network Access Switch 4050 User Guide 4 Modify the local user information in the applicable fiel

Página 238

312 Chapter 6 Configuring authentication320818-A Exporting the databaseTo export the database of local users, perform the following steps:1 Select the

Página 239

Chapter 6 Configuring authentication 313Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields.Ta

Página 240

314 Chapter 6 Configuring authentication320818-A Specifying authentication fallback order using the SREMAuthentication in the Nortel SNAS 4050 solutio

Página 241

Chapter 6 Configuring authentication 315Nortel Secure Network Access Switch 4050 User Guide To specify authentication fallback order, perform these st

Página 242

316 Chapter 6 Configuring authentication320818-A 3 Rearrange the list so that the methods appear in the desired order.a Click on a method to select it

Página 243

317Nortel Secure Network Access Switch 4050 User Guide Chapter 7 TunnelGuard SRS BuilderThis chapter includes the following topics:Topic PageConfiguri

Página 244 - 1/aaa/group <group ID>

318 Chapter 7 TunnelGuard SRS Builder320818-A Configuring SRS rulesThe building blocks used to construct the Software Requirement Set (SRS) are files

Página 245

Chapter 7 TunnelGuard SRS Builder 319Nortel Secure Network Access Switch 4050 User Guide • “Software Definition — Available SRS list” on page 323• “Me

Página 246 - The RADIUS menu displays

32 Chapter 1 Overview320818-A For Nortel, success is delivering technologies providing secure access to your information using security-compliant syst

Página 247

320 Chapter 7 TunnelGuard SRS Builder320818-A Software Definition Entry menuTable 58 describes important items from the Software Definition Entry menu

Página 248

Chapter 7 TunnelGuard SRS Builder 321Nortel Secure Network Access Switch 4050 User Guide TunnelGuard Rule menuTable 59 describes important items from

Página 249

322 Chapter 7 TunnelGuard SRS Builder320818-A SRS definition toolbarThe buttons on the SRS definition toolbar allow you to create, delete, and manage

Página 250

Chapter 7 TunnelGuard SRS Builder 323Nortel Secure Network Access Switch 4050 User Guide Software Definition — Available SRS listThe available SRS lis

Página 251

324 Chapter 7 TunnelGuard SRS Builder320818-A Customizing a componentWhen an SRS component is selected by clicking on it, you can customize it using t

Página 252

Chapter 7 TunnelGuard SRS Builder 325Nortel Secure Network Access Switch 4050 User Guide Memory snapshotThe memory snapshot section in the lower half

Página 253 - The LDAP menu displays

326 Chapter 7 TunnelGuard SRS Builder320818-A SRS Rule listThe SRS Rule list shows the existing SRS rules. These rules are retrieved from the Nortel S

Página 254

Chapter 7 TunnelGuard SRS Builder 327Nortel Secure Network Access Switch 4050 User Guide Once the expression is formed, it is available for rule defin

Página 255

328 Chapter 7 TunnelGuard SRS Builder320818-A Figure 84 The New SRS window2 Enter a name for the software definition and click OK.For example, to cr

Página 256

Chapter 7 TunnelGuard SRS Builder 329Nortel Secure Network Access Switch 4050 User Guide Figure 85 The Create New Memory Module SRS window3 In the F

Página 257

Chapter 1 Overview 33Nortel Secure Network Access Switch 4050 User Guide Java Runtime Environment (JRE) for all browsers:— JRE 1.5.0_04 or later• VoIP

Página 258

330 Chapter 7 TunnelGuard SRS Builder320818-A If enabled, the client system will be searched for the specified file name, irrespective of path to fold

Página 259

Chapter 7 TunnelGuard SRS Builder 331Nortel Secure Network Access Switch 4050 User Guide The file/module is added as an entry in the selected software

Página 260

332 Chapter 7 TunnelGuard SRS Builder320818-A To create a software definition entry for a file not shown in the memory snapshot, perform the following

Página 261

Chapter 7 TunnelGuard SRS Builder 333Nortel Secure Network Access Switch 4050 User Guide 3 Select the Fetch Module Path from Registry Entry check box,

Página 262

334 Chapter 7 TunnelGuard SRS Builder320818-A 2 Click the TunnelGuard Rule Definition tab.TunnelGuard rules and expressions with the same names as the

Página 263

Chapter 7 TunnelGuard SRS Builder 335Nortel Secure Network Access Switch 4050 User Guide 4 Select another expression that you will use to form a new l

Página 264

336 Chapter 7 TunnelGuard SRS Builder320818-A Figure 88 The Available Expressions screen7 Create a new TunnelGuard Rule.On the TunnelGuard Rule menu

Página 265

Chapter 7 TunnelGuard SRS Builder 337Nortel Secure Network Access Switch 4050 User Guide The new rule name appears in the TunnelGuard Rule Name column

Página 266

338 Chapter 7 TunnelGuard SRS Builder320818-A Registry-based rulesTunnelGuard Agent supports checking of on-disk files, running processes, hash checki

Página 267

Chapter 7 TunnelGuard SRS Builder 339Nortel Secure Network Access Switch 4050 User Guide Table 66 describes supported operands for integer values.The

Página 268

34 Chapter 1 Overview320818-A Nortel SNAS 4050 functionsThe Nortel SNAS 4050 performs the following functions:• Acts as a web server portal, which is

Página 269

340 Chapter 7 TunnelGuard SRS Builder320818-A Table 67 describes supported constructs for string-based regular expressions.Table 67 Constructs for s

Página 270 - Figure 60

Chapter 7 TunnelGuard SRS Builder 341Nortel Secure Network Access Switch 4050 User Guide The following are examples of regular expressions for string-

Página 271

342 Chapter 7 TunnelGuard SRS Builder320818-A Figure 91 Registry Entry page3 Select the Registry Key Path from the Registry Editor.4 Select the Key

Página 272

Chapter 7 TunnelGuard SRS Builder 343Nortel Secure Network Access Switch 4050 User Guide Manually creating SRS entriesThe administrator tool applet pr

Página 273

344 Chapter 7 TunnelGuard SRS Builder320818-A Figure 92 Create new OnDisk SRS Entry3 Click Browse Local System to select the File or Module Path. Th

Página 274 - Configuration

Chapter 7 TunnelGuard SRS Builder 345Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for either Relative Date/Time Range

Página 275 - Table 41

346 Chapter 7 TunnelGuard SRS Builder320818-A Figure 93 Create new Memory Module SRS entry3 Click Browse Local System to select the File or Module P

Página 276 - Figure 63

Chapter 7 TunnelGuard SRS Builder 347Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for Max Version.7 Click an option bu

Página 277 - Table 42

348 Chapter 7 TunnelGuard SRS Builder320818-A Figure 94 Date/Time RangeAdding comments• “Adding a TunnelGuard rule comment” on page 348• “Adding a s

Página 278

Chapter 7 TunnelGuard SRS Builder 349Nortel Secure Network Access Switch 4050 User Guide 3 Click the button to display the Rule Comment window (see Fi

Página 279 - Radius Servers

Chapter 1 Overview 35Nortel Secure Network Access Switch 4050 User Guide • VoIP — automatic access for VoIP traffic. The network access device places

Página 280 - Adding a RADIUS server

350 Chapter 7 TunnelGuard SRS Builder320818-A Deleting a software definition1 Click the Software Definition tab.2 In the Software Definition column, s

Página 281 - Removing a RADIUS server

Chapter 7 TunnelGuard SRS Builder 351Nortel Secure Network Access Switch 4050 User Guide 2 In the Available Expressions area, select the desired expre

Página 282 - Next steps

352 Chapter 7 TunnelGuard SRS Builder320818-A

Página 283

353Nortel Secure Network Access Switch 4050 User Guide Chapter 8 Managing system users and groupsThis chapter includes the following topics:Topic Page

Página 284 - Modifying LDAP configuration

354 Chapter 8 Managing system users and groups320818-A User rights and group membershipThere are three groups of system users who routinely access the

Página 285

Chapter 8 Managing system users and groups 355Nortel Secure Network Access Switch 4050 User Guide Managing system users and groups using the CLITo man

Página 286 - Table 45

356 Chapter 8 Managing system users and groups320818-A Managing user accounts and passwords using the CLITo change the password for the currently logg

Página 287 - Figure 68

Chapter 8 Managing system users and groups 357Nortel Secure Network Access Switch 4050 User Guide del <username>Removes the specified user accou

Página 288 - Table 46

358 Chapter 8 Managing system users and groups320818-A Managing user settings using the CLIYou must have administrator rights in order to change a use

Página 289

Chapter 8 Managing system users and groups 359Nortel Secure Network Access Switch 4050 User Guide To set or change the login password for a specified

Página 290

36 Chapter 1 Overview320818-A Authentication methodsYou can configure more than one authentication method within a Nortel SNAS 4050 domain. Nortel Sec

Página 291 - LDAP Servers

360 Chapter 8 Managing system users and groups320818-A To set or change a user’s group assignment, access the Groups menu by using the following comma

Página 292 - Adding an LDAP server

Chapter 8 Managing system users and groups 361Nortel Secure Network Access Switch 4050 User Guide In this configuration example, a certificate adminis

Página 293 - Removing an LDAP server

362 Chapter 8 Managing system users and groups320818-A —oper—admin— certadminBy default, the admin user is a member of all groups above, and can there

Página 294 - Managing LDAP macros

Chapter 8 Managing system users and groups 363Nortel Secure Network Access Switch 4050 User Guide 7 Apply the changes.8 Let the Certificate Administra

Página 295 - LDAP Macros

364 Chapter 8 Managing system users and groups320818-A 9 Remove the admin user from the certadmin group.Again, this step is only necessary if you want

Página 296 - Adding LDAP macros

Chapter 8 Managing system users and groups 365Nortel Secure Network Access Switch 4050 User Guide Changing a user’s group assignmentOnly users who are

Página 297 - Removing LDAP macros

366 Chapter 8 Managing system users and groups320818-A 4 Verify and apply the changes.Changing passwordsChanging your own passwordAll users can change

Página 298

Chapter 8 Managing system users and groups 367Nortel Secure Network Access Switch 4050 User Guide 2 Access the User Menu.Type the passwd command to ch

Página 299 - Adding the Local method

368 Chapter 8 Managing system users and groups320818-A 2 Access the User Menu.3 Specify the user name of the user whose password you want to change.4

Página 300

Chapter 8 Managing system users and groups 369Nortel Secure Network Access Switch 4050 User Guide Deleting a userTo delete a user from the system, you

Página 301 - Populating the database

Chapter 1 Overview 37Nortel Secure Network Access Switch 4050 User Guide TunnelGuard host integrity checkThe TunnelGuard application checks client hos

Página 302 - Add a Local User fields

370 Chapter 8 Managing system users and groups320818-A The imminent removal of the cert_admin user is indicated as a pending configuration change by t

Página 303

Chapter 8 Managing system users and groups 371Nortel Secure Network Access Switch 4050 User Guide The User Table appears (see Figure 96), displaying a

Página 304 - Importing a database

372 Chapter 8 Managing system users and groups320818-A Only the admin user can delete users from the system. Of the three built-in users (admin, oper,

Página 305

Chapter 8 Managing system users and groups 373Nortel Secure Network Access Switch 4050 User Guide 3 Enter the user information in the applicable field

Página 306

374 Chapter 8 Managing system users and groups320818-A Setting password expiry using the SREMTo set a password expiry date for all passwords in the sy

Página 307 - Modifying local users

Chapter 8 Managing system users and groups 375Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Password Setting information in the appl

Página 308 - Figure 78

376 Chapter 8 Managing system users and groups320818-A Changing your password using the SREMOnly the admin user can change the passwords of other user

Página 309

Chapter 8 Managing system users and groups 377Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Página 310

378 Chapter 8 Managing system users and groups320818-A To change the password for another user, perform the following steps:1 Select the System > M

Página 311 - Table 54

Chapter 8 Managing system users and groups 379Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Página 312 - Exporting the database

38 Chapter 1 Overview320818-A Communication channelsCommunications between the Nortel SNAS 4050 and key elements of the Nortel SNA solution are secure

Página 313

380 Chapter 8 Managing system users and groups320818-A To set a certificate export pass phrase, perform the following steps:1 Select the System > M

Página 314

Chapter 8 Managing system users and groups 381Nortel Secure Network Access Switch 4050 User Guide 2 Enter the PassPhrase information in the applicable

Página 315 - Authentication Server Order

382 Chapter 8 Managing system users and groups320818-A To manage the group to which a user belongs, select the System > Manage Users > user >

Página 316

Chapter 8 Managing system users and groups 383Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a User Group dialog box appears

Página 317 - TunnelGuard SRS Builder

384 Chapter 8 Managing system users and groups320818-A The user group is immediately removed from the User Group Table.5 Click Apply on the toolbar to

Página 318 - Configuring SRS rules

385Nortel Secure Network Access Switch 4050 User Guide Chapter 9 Customizing the portal and user logonThis chapter includes the following topics:Topic

Página 319 - Menu commands

386 Chapter 9 Customizing the portal and user logon320818-A OverviewThe end user accesses the Nortel SNA network through the Nortel SNAS 4050 portal.

Página 320

Chapter 9 Customizing the portal and user logon 387Nortel Secure Network Access Switch 4050 User Guide • redirects client requests to an authenticatio

Página 321 - Tool menu

388 Chapter 9 Customizing the portal and user logon320818-A Table 75 lists the regular expressions and escape sequences you can use in an Exclude List

Página 322 - SRS definition toolbar

Chapter 9 Customizing the portal and user logon 389Nortel Secure Network Access Switch 4050 User Guide Portal displayYou can modify the following feat

Página 323 - SRS Components table

Chapter 1 Overview 39Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 supports the use of three different SSH host key types:

Página 324 - Customizing a component

390 Chapter 9 Customizing the portal and user logon320818-A Default appearanceFigure 104 shows the default portal Home tab.Figure 104 Default appear

Página 325 - Memory snapshot

Chapter 9 Customizing the portal and user logon 391Nortel Secure Network Access Switch 4050 User Guide • color3 — the fields, information area, and cl

Página 326 - Rule Expression Constructor

392 Chapter 9 Customizing the portal and user logon320818-A For the commands to configure the colors used on the portal, see “Changing the portal colo

Página 327

Chapter 9 Customizing the portal and user logon 393Nortel Secure Network Access Switch 4050 User Guide To change the language displayed for tab names,

Página 328 - The New SRS window

394 Chapter 9 Customizing the portal and user logon320818-A Linksets and linksYou can add the following types of links to the portal Home tab:• Extern

Página 329

Chapter 9 Customizing the portal and user logon 395Nortel Secure Network Access Switch 4050 User Guide Planning the linksetsPlan your configuration so

Página 330

396 Chapter 9 Customizing the portal and user logon320818-A Automatic redirection to internal sitesYou can configure the portal to automatically redir

Página 331 - Selecting file on disk

Chapter 9 Customizing the portal and user logon 397Nortel Secure Network Access Switch 4050 User Guide Managing the end user experienceNortel recommen

Página 332

398 Chapter 9 Customizing the portal and user logon320818-A 2 Download the JRE installer from the Sun Microsystems Java web site (http://www.java.com)

Página 333 - Creating logical expressions

Chapter 9 Customizing the portal and user logon 399Nortel Secure Network Access Switch 4050 User Guide /cfg/domain 1/dnscapt/exclude listdel <index

Página 334

4320818-A BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nort

Página 335

40 Chapter 1 Overview320818-A • fault tolerance — If a Nortel SNAS 4050 device fails, the failure is detected by the other node in the cluster, which

Página 336 - The New SRS Rule window

400 Chapter 9 Customizing the portal and user logon320818-A color2 <code>color3 <code>color4 <code>theme default|aqua|apple| jeans|c

Página 337

Chapter 9 Customizing the portal and user logon 401Nortel Secure Network Access Switch 4050 User Guide Configuring the captive portal using the CLIBy

Página 338 - Registry-based rules

402 Chapter 9 Customizing the portal and user logon320818-A The DNS Exclude menu includes the following options:Changing the portal language using the

Página 339 - Supported integer operands

Chapter 9 Customizing the portal and user logon 403Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the CLITo ma

Página 340 - Table 67

404 Chapter 9 Customizing the portal and user logon320818-A The Language Support menu includes the following options:/cfg/langfollowed by:import <p

Página 341 - Creating a registry entry

Chapter 9 Customizing the portal and user logon 405Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the C

Página 342 - Registry-based File/Module

406 Chapter 9 Customizing the portal and user logon320818-A Configuring the portal display using the CLITo modify the look and feel of the portal page

Página 343 - Manually creating SRS entries

Chapter 9 Customizing the portal and user logon 407Nortel Secure Network Access Switch 4050 User Guide redirect <URL>Sets the URL to which clien

Página 344 - Create new OnDisk SRS Entry

408 Chapter 9 Customizing the portal and user logon320818-A linktext <text>Specifies static text to be displayed above the group links on the po

Página 345

Chapter 9 Customizing the portal and user logon 409Nortel Secure Network Access Switch 4050 User Guide Changing the portal colors using the CLITo cust

Página 346

Chapter 1 Overview 41Nortel Secure Network Access Switch 4050 User Guide One-armed configurationIn a one-armed configuration, the Nortel SNAS 4050 has

Página 347 - File age check

410 Chapter 9 Customizing the portal and user logon320818-A The Portal Colors menu includes the following options:For more information about the porta

Página 348 - Adding comments

Chapter 9 Customizing the portal and user logon 411Nortel Secure Network Access Switch 4050 User Guide The Portal Custom Content menu includes the fol

Página 349 - The Rule Comment window

412 Chapter 9 Customizing the portal and user logon320818-A Configuring linksets using the CLIA linkset is a set of links that display on the portal H

Página 350 - Deleting an expression

Chapter 9 Customizing the portal and user logon 413Nortel Secure Network Access Switch 4050 User Guide The Linkset menu includes the following options

Página 351 - Making API calls

414 Chapter 9 Customizing the portal and user logon320818-A Configuring links using the CLITo create and configure the links included in the linkset,

Página 352

Chapter 9 Customizing the portal and user logon 415Nortel Secure Network Access Switch 4050 User Guide The Link menu includes the following options:/c

Página 353 - Chapter 8

416 Chapter 9 Customizing the portal and user logon320818-A Configuring external link settings using the CLITo launch the wizard to configure settings

Página 354

Chapter 9 Customizing the portal and user logon 417Nortel Secure Network Access Switch 4050 User Guide Customizing the portal and logon using the SREM

Página 355

418 Chapter 9 Customizing the portal and user logon320818-A Figure 105 DNS Capture screenThe DNS Capture screen includes the following components:2

Página 356

Chapter 9 Customizing the portal and user logon 419Nortel Secure Network Access Switch 4050 User Guide Configuring the DNS Exclude List using the SREM

Página 357

42 Chapter 1 Overview320818-A Figure 2 illustrates a two-armed configuration.Figure 2 Two-armed configurationNortel SNA configuration and management

Página 358

420 Chapter 9 Customizing the portal and user logon320818-A 3 To remove an entry from the Exclude List:a In the DNS Exclude List, select the entry you

Página 359

Chapter 9 Customizing the portal and user logon 421Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the SREMTo m

Página 360 - CLI configuration examples

422 Chapter 9 Customizing the portal and user logon320818-A Viewing predefined languagesTo view predefined languages, click the Pre-defined Languages

Página 361

Chapter 9 Customizing the portal and user logon 423Nortel Secure Network Access Switch 4050 User Guide b Click Apply on the toolbar to send the curren

Página 362 - Old: is empty

424 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Language information in the applicable fields. Table 80 describes the Import D

Página 363

Chapter 9 Customizing the portal and user logon 425Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the S

Página 364 - /cfg/cert)

426 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the language information in the applicable fields. Table 81 describes the Langauge

Página 365

Chapter 9 Customizing the portal and user logon 427Nortel Secure Network Access Switch 4050 User Guide Configuring contentTo configure and modify port

Página 366 - Changing your own password

428 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Portal Configuration information in the applicable fields. Table 82 describes

Página 367

Chapter 9 Customizing the portal and user logon 429Nortel Secure Network Access Switch 4050 User Guide Redirect URL Sets the URL to which clients are

Página 368 - 5 Apply the changes

Chapter 1 Overview 43Nortel Secure Network Access Switch 4050 User Guide • Security & Routing Element Manager (SREM)The SREM is a GUI application

Página 369 - Deleting a user

430 Chapter 9 Customizing the portal and user logon320818-A Importing bannersTo import a banner to display on the portal Home page, perform the follow

Página 370

Chapter 9 Customizing the portal and user logon 431Nortel Secure Network Access Switch 4050 User Guide 2 Enter the banner information in the applicabl

Página 371 - User Table

432 Chapter 9 Customizing the portal and user logon320818-A Changing the portal colors using the SREMTo customize the colors used for portal display,

Página 372 - Adding new user accounts

Chapter 9 Customizing the portal and user logon 433Nortel Secure Network Access Switch 4050 User Guide 2 Enter the color information in the applicable

Página 373 - Add a User fields

434 Chapter 9 Customizing the portal and user logon320818-A Configuring custom content using the SREMTo configure custom content, such as Java applets

Página 374 - Figure 98

Chapter 9 Customizing the portal and user logon 435Nortel Secure Network Access Switch 4050 User Guide Viewing basic information about custom contentT

Página 375 - Table 70

436 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the basic information in the applicable fields. Table 85 describes the Basics fiel

Página 376 - Change Your Password

Chapter 9 Customizing the portal and user logon 437Nortel Secure Network Access Switch 4050 User Guide Importing custom contentTo import custom conten

Página 377 - Change Your Password fields

438 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the import information in the applicable fields. Table 86 describes the Import Con

Página 378 - Figure 100

Chapter 9 Customizing the portal and user logon 439Nortel Secure Network Access Switch 4050 User Guide Exporting custom contentTo export custom conten

Página 379 - Change User Password fields

44 Chapter 1 Overview320818-A For each VLAN:a Create a DHCP scope.b Specify the IP address range and subnet mask for that scope.c Configure the follow

Página 380 - Figure 101

440 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the export information in the applicable fields. Table 87 describes the Export Con

Página 381

Chapter 9 Customizing the portal and user logon 441Nortel Secure Network Access Switch 4050 User Guide Creating a linksetTo create a linkset, perform

Página 382 - Adding a user group

442 Chapter 9 Customizing the portal and user logon320818-A 2 Click Add.The Add a Linkset dialog box appears (see Figure 118).Figure 118 Add a Links

Página 383 - Removing a user group

Chapter 9 Customizing the portal and user logon 443Nortel Secure Network Access Switch 4050 User Guide Modifying a linksetTo modify a linkset, perform

Página 384

444 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the linkset information in the applicable fields. Table 89 describes the linkset C

Página 385 - Chapter 9

Chapter 9 Customizing the portal and user logon 445Nortel Secure Network Access Switch 4050 User Guide Configuring links using the SREMAfter you creat

Página 386

446 Chapter 9 Customizing the portal and user logon320818-A Creating an external link using the SREMTo create an external link, perform the following

Página 387 - Exclude List

Chapter 9 Customizing the portal and user logon 447Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Portal Link dialog box ap

Página 388 - Table 75

448 Chapter 9 Customizing the portal and user logon320818-A 5 Click Apply.The new external link appears in the Links table.6 Click Apply on the toolba

Página 389 - Portal display

Chapter 9 Customizing the portal and user logon 449Nortel Secure Network Access Switch 4050 User Guide To create an FTP link, perform the following st

Página 390 - Default appearance

Chapter 1 Overview 45Nortel Secure Network Access Switch 4050 User Guide Use the applicable show commands on the router to verify that DHCP relay has

Página 391

450 Chapter 9 Customizing the portal and user logon320818-A 4 Enter the link information in the applicable fields. Table 91 describes the Add a Portal

Página 392 - Language localization

Chapter 9 Customizing the portal and user logon 451Nortel Secure Network Access Switch 4050 User Guide Modifying external link settings using the SREM

Página 393

452 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 92 describes the external lin

Página 394 - Autorun linksets

Chapter 9 Customizing the portal and user logon 453Nortel Secure Network Access Switch 4050 User Guide Modifying FTP link settings using the SREMTo mo

Página 395 - Planning the linksets

454 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 93 describes the FTP link Con

Página 396

Chapter 9 Customizing the portal and user logon 455Nortel Secure Network Access Switch 4050 User Guide The Re Order Links screen appears (see Figure 1

Página 397 - Automatic JRE upload

456 Chapter 9 Customizing the portal and user logon320818-A

Página 398 - Windows domain logon script

457Nortel Secure Network Access Switch 4050 User Guide Chapter 10 Configuring system settingsThis chapter includes the following topics:Topic PageConf

Página 399 - Command Parameter

458 Chapter 10 Configuring system settings320818-A System settings apply to a cluster as a whole.You can log on to either the Management IP address (M

Página 400

Chapter 10 Configuring system settings 459Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the CLITo configure the cl

Página 401

46 Chapter 1 Overview320818-A Identify switch ports as either uplink or dynamic. When you configure the uplink ports, you associate the NSNA VLANs wit

Página 402

460 Chapter 10 Configuring system settings320818-A • disabling SSL traffic trace commands (see “Configuring system settings using the CLI” on page 463

Página 403 - /cfg/lang

Chapter 10 Configuring system settings 461Nortel Secure Network Access Switch 4050 User Guide del <index number>add <IPaddr> <mask>

Página 404

462 Chapter 10 Configuring system settings320818-A health <interval>hdown <count>hup <count>/cfg/sys/dns/serverslistdel <index nu

Página 405

Chapter 10 Configuring system settings 463Nortel Secure Network Access Switch 4050 User Guide show/cfg/sys/adm/sshkeys/knownhostslistdel <index num

Página 406 - The Portal menu displays

464 Chapter 10 Configuring system settings320818-A Configuring system settings using the CLITo view and configure cluster-wide system settings, use th

Página 407

Chapter 10 Configuring system settings 465Nortel Secure Network Access Switch 4050 User Guide Configuring the Nortel SNAS 4050 host using the CLITo co

Página 408

466 Chapter 10 Configuring system settings320818-A The Cluster Host menu includes the following options:/cfg/sys/host <host ID>followed by:ip &l

Página 409

Chapter 10 Configuring system settings 467Nortel Secure Network Access Switch 4050 User Guide portAccesses the Host Port menu, in order to configure p

Página 410

468 Chapter 10 Configuring system settings320818-A rebootReboots the Nortel SNAS 4050.If the Nortel SNAS 4050 you want to reboot has become isolated f

Página 411

Chapter 10 Configuring system settings 469Nortel Secure Network Access Switch 4050 User Guide Viewing host informationTo view the host number and IP a

Página 412

Chapter 1 Overview 47Nortel Secure Network Access Switch 4050 User Guide configuration in the SREM (see “Checking configuration using the SREM” on pag

Página 413

470 Chapter 10 Configuring system settings320818-A gateway <IPaddr>Sets the default gateway address for the interface. The default gateway is th

Página 414

Chapter 10 Configuring system settings 471Nortel Secure Network Access Switch 4050 User Guide Configuring static routes using the CLITo manage static

Página 415

472 Chapter 10 Configuring system settings320818-A The system, host, or interface Routes menu displays.When you add a static route to the system, host

Página 416

Chapter 10 Configuring system settings 473Nortel Secure Network Access Switch 4050 User Guide The Host Port menu includes the following options:Managi

Página 417 - Enabling DNS capture

474 Chapter 10 Configuring system settings320818-A The Interface Ports menu includes the following options:Configuring the Access List using the CLITh

Página 418 - DNS Capture fields

Chapter 10 Configuring system settings 475Nortel Secure Network Access Switch 4050 User Guide The Access List menu displays.The Access List menu inclu

Página 419 - Add DNS Domain fields

476 Chapter 10 Configuring system settings320818-A The Date and Time menu includes the following options:Managing NTP serversYou can add NTP servers t

Página 420

Chapter 10 Configuring system settings 477Nortel Secure Network Access Switch 4050 User Guide The NTP Servers menu includes the following options:Conf

Página 421 - Pre-defined Languages

478 Chapter 10 Configuring system settings320818-A retransmit <interval>Sets the interval for retransmitting a DNS query. •interval is a positiv

Página 422 - Viewing predefined languages

Chapter 10 Configuring system settings 479Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Página 423 - Import/Export Definition

48 Chapter 1 Overview320818-A

Página 424

480 Chapter 10 Configuring system settings320818-A Configuring RSA servers using the CLITo configure the symbolic name for the RSA server and import t

Página 425 - Figure 110

Chapter 10 Configuring system settings 481Nortel Secure Network Access Switch 4050 User Guide The RSA Servers menu includes the following options:Conf

Página 426 - Language fields

482 Chapter 10 Configuring system settings320818-A The Syslog Servers menu includes the following options:/cfg/sys/syslogfollowed by:listLists the IP

Página 427 - Configuring content

Chapter 10 Configuring system settings 483Nortel Secure Network Access Switch 4050 User Guide Configuring administrative settings using the CLIAdminis

Página 428 - Table 82

484 Chapter 10 Configuring system settings320818-A auditAccesses the Audit menu, in order to configure RADIUS auditing (see “Configuring RADIUS auditi

Página 429

Chapter 10 Configuring system settings 485Nortel Secure Network Access Switch 4050 User Guide Enabling TunnelGuard SRS administration using the CLITo

Página 430 - Importing banners

486 Chapter 10 Configuring system settings320818-A During initial setup, there is an option to generate the SSH host keys automatically. To generate a

Página 431 - Import Banner fields

Chapter 10 Configuring system settings 487Nortel Secure Network Access Switch 4050 User Guide Managing known hosts SSH keys using the CLIYou can paste

Página 432 - Figure 113

488 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditing using the CLIYou can configure the Nortel SNAS 4050 cluster to include

Página 433 - Color Settings fields

Chapter 10 Configuring system settings 489Nortel Secure Network Access Switch 4050 User Guide The Internet Assigned Numbers Authority (IANA) has desig

Página 434

49Nortel Secure Network Access Switch 4050 User Guide Chapter 2 Initial setupThis chapter includes the following topics:Topic PageBefore you begin50Ab

Página 435 - Basics screen

490 Chapter 10 Configuring system settings320818-A Managing RADIUS audit servers using the CLITo configure the Nortel SNAS 4050 to use external RADIUS

Página 436 - Table 85

Chapter 10 Configuring system settings 491Nortel Secure Network Access Switch 4050 User Guide add <IPaddr> <port> <shared secret>Add

Página 437 - Importing custom content

492 Chapter 10 Configuring system settings320818-A Configuring authentication of system users using the CLIYou can configure the Nortel SNAS 4050 clus

Página 438 - Table 86

Chapter 10 Configuring system settings 493Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLITo c

Página 439 - Exporting custom content

494 Chapter 10 Configuring system settings320818-A The RADIUS Authentication Servers menu includes the following options:/cfg/sys/adm/auth/serversfoll

Página 440 - Export Content fields

Chapter 10 Configuring system settings 495Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the SREMTo configure the c

Página 441 - Creating a linkset

496 Chapter 10 Configuring system settings320818-A Configuring system settings using the SREMTo view and configure cluster-wide system settings, perfo

Página 442 - Add a Linkset

Chapter 10 Configuring system settings 497Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Management IP Address (MIP) information in t

Página 443 - Modifying a linkset

498 Chapter 10 Configuring system settings320818-A Viewing host informationTo display a list of available Nortel SNAS 4050 hosts, select the System &g

Página 444 - Linkset Configuration fields

Chapter 10 Configuring system settings 499Nortel Secure Network Access Switch 4050 User Guide Viewing and configuring TCP/IP propertiesTo configure ba

Página 445

5Nortel Secure Network Access Switch 4050 User Guide ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 446 - Figure 120

50 Chapter 2 Initial setup320818-A Before you beginBefore you can set up the Nortel SNAS 4050, you must complete the following tasks:1 Plan the networ

Página 447 - Add a Portal Link fields

500 Chapter 10 Configuring system settings320818-A 2 Enter the host information in the applicable fields. Table 96 describes the Host fields.3 Click A

Página 448

Chapter 10 Configuring system settings 501Nortel Secure Network Access Switch 4050 User Guide Additionally, new licenses can be added to a particular

Página 449 - Add a Portal Link — FTP

502 Chapter 10 Configuring system settings320818-A Table 97 describes the Global Licenses fields.2 Modify the Auto Refresh and Logging settings, if de

Página 450

Chapter 10 Configuring system settings 503Nortel Secure Network Access Switch 4050 User Guide Viewing per domain licenses for all hostsTo view license

Página 451 - Figure 123

504 Chapter 10 Configuring system settings320818-A Table 98 describes the Per Domain Licenses fields.2 Modify the Auto Refresh and Logging settings, i

Página 452 - Table 92

Chapter 10 Configuring system settings 505Nortel Secure Network Access Switch 4050 User Guide Viewing installed licenses for a particular hostTo view

Página 453 - Figure 124

506 Chapter 10 Configuring system settings320818-A Installing a license for a particular hostThe Nortel SNA SSL (portal and Nortel SNAS 4050 domain cl

Página 454 - FTP link Configuration fields

Chapter 10 Configuring system settings 507Nortel Secure Network Access Switch 4050 User Guide 3 In the SREM, select the System > Hosts > host &g

Página 455 - Re Order Links fields

508 Chapter 10 Configuring system settings320818-A Configuring host interfaces using the SREMThe default IP interface on the Nortel SNAS 4050 host is

Página 456

Chapter 10 Configuring system settings 509Nortel Secure Network Access Switch 4050 User Guide • “Removing a host interface” on page 514Adding a host i

Página 457 - Configuring system settings

Chapter 2 Initial setup 51Nortel Secure Network Access Switch 4050 User Guide 4 Establish a console connection to the Nortel SNAS 4050 (see “Establish

Página 458

510 Chapter 10 Configuring system settings320818-A 4 Click Apply.The new interface appears in the Interfaces table.Gateway Sets the default gateway ad

Página 459 - /cfg/sys

Chapter 10 Configuring system settings 511Nortel Secure Network Access Switch 4050 User Guide 5 Click Apply on the toolbar to send the current changes

Página 460 - Roadmap of system commands

512 Chapter 10 Configuring system settings320818-A 2 Enter the interface information in the applicable fields. Table 100 describes the Interface confi

Página 461

Chapter 10 Configuring system settings 513Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes

Página 462

514 Chapter 10 Configuring system settings320818-A Removing a host interfaceTo delete a host interface, perform the following steps:1 Select the Syste

Página 463

Chapter 10 Configuring system settings 515Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for a clusterTo configure static r

Página 464 - The System menu displays

516 Chapter 10 Configuring system settings320818-A Viewing static routes for a hostTo configure static routes for a host, select the System > Hosts

Página 465

Chapter 10 Configuring system settings 517Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for an interfaceTo configure stati

Página 466

518 Chapter 10 Configuring system settings320818-A From the selected static route screen, complete the following tasks as necessary:• “Adding a static

Página 467

Chapter 10 Configuring system settings 519Nortel Secure Network Access Switch 4050 User Guide 4 Click Add.The new route appears in the table.5 Click A

Página 468

52 Chapter 2 Initial setup320818-A Real IP addressThe Real IP address (RIP) is the Nortel SNAS 4050 device host IP address for network connectivity. T

Página 469 - Viewing host information

520 Chapter 10 Configuring system settings320818-A Configuring host ports using the SREMTo configure the connection properties for a port, perform the

Página 470

Chapter 10 Configuring system settings 521Nortel Secure Network Access Switch 4050 User Guide 2 Select a port to configure from the list.The Port scre

Página 471

522 Chapter 10 Configuring system settings320818-A 3 Enter the port information in the applicable fields. Table 102 describes the Port fields.4 Click

Página 472

Chapter 10 Configuring system settings 523Nortel Secure Network Access Switch 4050 User Guide Managing interface ports using the SREMTo view and manag

Página 473

524 Chapter 10 Configuring system settings320818-A Adding interface portsTo add ports to the selected interface, perform the following steps:1 Select

Página 474

Chapter 10 Configuring system settings 525Nortel Secure Network Access Switch 4050 User Guide The port is removed from the Port Table.5 Click Apply on

Página 475

526 Chapter 10 Configuring system settings320818-A The Access List Table appears (see Figure 143).Figure 143 Access ListFrom here, you can manage th

Página 476 - Managing NTP servers

Chapter 10 Configuring system settings 527Nortel Secure Network Access Switch 4050 User Guide The Add Access Host dialog box appears (see Figure 144).

Página 477

528 Chapter 10 Configuring system settings320818-A 4 Click Yes.The entry disappears from the Access List Table.5 Click Apply on the toolbar to send th

Página 478

Chapter 10 Configuring system settings 529Nortel Secure Network Access Switch 4050 User Guide You can add NTP servers to the system configuration to e

Página 479 - Managing DNS servers

Chapter 2 Initial setup 53Nortel Secure Network Access Switch 4050 User Guide The Setup Menu displays.2 Select the option for a new installation.3 Spe

Página 480

530 Chapter 10 Configuring system settings320818-A Adding an NTP serverTo add an additional NTP server, perform the following steps:1 Select the Syste

Página 481

Chapter 10 Configuring system settings 531Nortel Secure Network Access Switch 4050 User Guide Removing an NTP serverTo remove an existing NTP server f

Página 482

532 Chapter 10 Configuring system settings320818-A Configuring DNS settings using the SREMTo configure DNS client settings, use the following procedur

Página 483

Chapter 10 Configuring system settings 533Nortel Secure Network Access Switch 4050 User Guide 2 Enter the DNS Client information in the applicable fie

Página 484

534 Chapter 10 Configuring system settings320818-A Configuring servers using the SREMTo configure servers, choose from one of the following tasks:• “M

Página 485

Chapter 10 Configuring system settings 535Nortel Secure Network Access Switch 4050 User Guide From this screen, complete the following tasks as necess

Página 486

536 Chapter 10 Configuring system settings320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on t

Página 487

Chapter 10 Configuring system settings 537Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Página 488 - About RADIUS auditing

538 Chapter 10 Configuring system settings320818-A Adding a DNS serverTo manage DNS servers in the system configuration, perform the following steps:1

Página 489 - Configuring RADIUS auditing

Chapter 10 Configuring system settings 539Nortel Secure Network Access Switch 4050 User Guide Removing an existing DNS serverTo remove a DNS server fr

Página 490

54 Chapter 2 Initial setup320818-A In a two-armed configuration, you are specifying the port you want to use for Nortel SNAS 4050 management traffic.4

Página 491

540 Chapter 10 Configuring system settings320818-A Managing RSA serversTo manage RSA servers, select the System > Servers > RSA Server Table tab

Página 492

Chapter 10 Configuring system settings 541Nortel Secure Network Access Switch 4050 User Guide • “Removing the RSA node secret” on page 542• “Importing

Página 493

542 Chapter 10 Configuring system settings320818-A Removing an existing RSA serverTo remove an existing RSA server, perform the following steps.1 Sele

Página 494

Chapter 10 Configuring system settings 543Nortel Secure Network Access Switch 4050 User Guide 3 Select the RSA Server sub-tab.The RSA Server screen ap

Página 495

544 Chapter 10 Configuring system settings320818-A 4 Click Remove Secret Node.The RSA node secret is immediately removed.5 Click Apply on the toolbar

Página 496 - Figure 126

Chapter 10 Configuring system settings 545Nortel Secure Network Access Switch 4050 User Guide 3 Select the Import sdconf.rec tab.The Import sdconf.rec

Página 497 - System Configuration fields

546 Chapter 10 Configuring system settings320818-A 4 Enter the importing information in the applicable fields. Table 112 describes the Import sdconf.r

Página 498

Chapter 10 Configuring system settings 547Nortel Secure Network Access Switch 4050 User Guide Configuring SRS control settings using the SREMTo create

Página 499 - Figure 128

548 Chapter 10 Configuring system settings320818-A 2 Enter the SRS Control information in the applicable fields. Table 115 describes the SRS Control S

Página 500 - Host fields

Chapter 10 Configuring system settings 549Nortel Secure Network Access Switch 4050 User Guide • “Showing SSH keys” on page 549• “Managing Nortel SNAS

Página 501 - Global Licenses

Chapter 2 Initial setup 55Nortel Secure Network Access Switch 4050 User Guide 7 Specify whether you are setting up a one-armed or a two-armed configur

Página 502 - Table 97

550 Chapter 10 Configuring system settings320818-A • RSA and DSA keys — the SECSH Public Key File Format, as described in Internet Draft draft-ietf-se

Página 503 - Figure 130

Chapter 10 Configuring system settings 551Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 and known host SSH keysYou can

Página 504 - Table 98

552 Chapter 10 Configuring system settings320818-A 2 To generate the Nortel SNAS 4050 host SSH key:a Enter the host information in applicable fields.

Página 505 - Figure 131

Chapter 10 Configuring system settings 553Nortel Secure Network Access Switch 4050 User Guide Adding an SSH key for a known host using the SREMYou can

Página 506 - END LICENSE lines

554 Chapter 10 Configuring system settings320818-A 2 Enter the remote host information in the applicable fields. Table 115 describes the Add SSH Key f

Página 507 - Install New License

Chapter 10 Configuring system settings 555Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS audit server to the conf

Página 508 - Interfaces

556 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditingTo configure the Nortel SNAS 4050 to support RADIUS auditing, choose fro

Página 509 - Adding a host interface

Chapter 10 Configuring system settings 557Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS audit settings using the SREMTo confi

Página 510

558 Chapter 10 Configuring system settings320818-A describes the Add Audit Configuration fields.3 Click Apply on the toolbar to send the current chang

Página 511

Chapter 10 Configuring system settings 559Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS audit servers using the SREMTo manage RA

Página 512 - Table 100

56 Chapter 2 Initial setup320818-A used if no other interface is specified. The default gateway IP address on Interface 2 must be within the same subn

Página 513 - Interface fields (continued)

560 Chapter 10 Configuring system settings320818-A Adding a new Audit ServerTo add a new RADIUS audit server, perform the following steps:1 Select the

Página 514 - Removing a host interface

Chapter 10 Configuring system settings 561Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS audit serverTo remove an exi

Página 515 - Figure 136

562 Chapter 10 Configuring system settings320818-A Managing RADIUS authentication of system users using the SREMYou can configure the Nortel SNAS 4050

Página 516

Chapter 10 Configuring system settings 563Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS authentication of system users using

Página 517 - Managing static routes

564 Chapter 10 Configuring system settings320818-A 2 Enter the RADIUS authentication information in the applicable fields. Table 118 describes the Rad

Página 518 - Adding a static route

Chapter 10 Configuring system settings 565Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the SREMTo

Página 519 - Removing a static route

566 Chapter 10 Configuring system settings320818-A Adding a RADIUS authentication serverTo add a new RADIUS authentication server, perform the followi

Página 520 - Figure 140

Chapter 10 Configuring system settings 567Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS serverTo remove an existing

Página 521 - Figure 141

568 Chapter 10 Configuring system settings320818-A

Página 522 - Table 102

569Nortel Secure Network Access Switch 4050 User Guide Chapter 11 Managing certificatesThis chapter includes the following topics:Topic PageOverview57

Página 523

Chapter 2 Initial setup 57Nortel Secure Network Access Switch 4050 User Guide 12 Configure the time settings.13 Specify the NTP server, if applicable.

Página 524 - Removing interface ports

570 Chapter 11 Managing certificates320818-A OverviewTo use the encryption capabilities of the Nortel SNAS 4050, you must add a key and certificate th

Página 525

Chapter 11 Managing certificates 571Nortel Secure Network Access Switch 4050 User Guide You can install new certificates or import or renew existing c

Página 526 - Adding an access list entry

572 Chapter 11 Managing certificates320818-A Netscape Enterprise ServerYes No Key only (proprietary format). Requires conversion. For information abou

Página 527 - Removing an Access List entry

Chapter 11 Managing certificates 573Nortel Secure Network Access Switch 4050 User Guide Creating certificatesThe basic steps to create a new certifica

Página 528 - Date & Time

574 Chapter 11 Managing certificates320818-A If you use the certificate index number of an installed certificate when adding a new certificate, the in

Página 529 - Date & Time fields

Chapter 11 Managing certificates 575Nortel Secure Network Access Switch 4050 User Guide The recommended steps to update an existing certificate are:1

Página 530 - Adding an NTP server

576 Chapter 11 Managing certificates320818-A • import certificates and private keys (see “Importing certificates and keys into the Nortel SNAS 4050 us

Página 531 - Removing an NTP server

Chapter 11 Managing certificates 577Nortel Secure Network Access Switch 4050 User Guide Managing and viewing certificates and keys using the CLITo vie

Página 532 - Figure 147

578 Chapter 11 Managing certificates320818-A gensigned server|clientGenerates a certificate that is signed using the private key associated with the c

Página 533 - Table 107

Chapter 11 Managing certificates 579Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the CLITo prepare a CSR

Página 534 - Managing syslog servers

58 Chapter 2 Initial setup320818-A 16 Change the admin user password, if desired.Make sure you remember the password you define for the admin user. Yo

Página 535 - Adding a new syslog server

580 Chapter 11 Managing certificates320818-A • to generate a CSR for a new certificate, <cert id> is an unused certificate number• to generate a

Página 536

Chapter 11 Managing certificates 581Nortel Secure Network Access Switch 4050 User Guide 3 Generate the CSR.After you have provided the required inform

Página 537

582 Chapter 11 Managing certificates320818-A Figure 166 shows sample output for the /cfg/cert #/request command. For more information about the Certif

Página 538 - Adding a DNS server

Chapter 11 Managing certificates 583Nortel Secure Network Access Switch 4050 User Guide 5 Save the CSR to a file.a Copy the entire CSR, including the

Página 539

584 Chapter 11 Managing certificates320818-A 8 The CA processes the CSR and returns a signed certificate. Create a backup copy of the certificate (see

Página 540 - Managing RSA servers

Chapter 11 Managing certificates 585Nortel Secure Network Access Switch 4050 User Guide To verify that the current certificate number is not in use by

Página 541 - Adding an RSA server

586 Chapter 11 Managing certificates320818-A Figure 167 shows sample output for the /cfg/cert #/cert command. For more information about the Certifica

Página 542 - Removing the RSA node secret

Chapter 11 Managing certificates 587Nortel Secure Network Access Switch 4050 User Guide Adding a private key to the Nortel SNAS 4050 using the CLI1 Ac

Página 543 - RSA Server fields

588 Chapter 11 Managing certificates320818-A Figure 168 shows sample output for the /cfg/cert #/key command. For more information about the Certificat

Página 544 - Importing sdconf.rec

Chapter 11 Managing certificates 589Nortel Secure Network Access Switch 4050 User Guide To import a certificate and private key into the Nortel SNAS 4

Página 545 - Figure 155

Chapter 2 Initial setup 59Nortel Secure Network Access Switch 4050 User Guide For example, if you entered company.com in the DNS search list, users ca

Página 546 - Import sdconf.rec fields

590 Chapter 11 Managing certificates320818-A 4 If the private key was not included in the certificate file, repeat step 3 on page 589 to import the ke

Página 547 - SRS Control Settings

Chapter 11 Managing certificates 591Nortel Secure Network Access Switch 4050 User Guide Displaying or saving a certificate and key using the CLIYou ca

Página 548 - Add SSH Key fields

592 Chapter 11 Managing certificates320818-A 5 Copy the private key, certificate, or both, as required.For the private key, ensure that you include th

Página 549 - Showing SSH keys

Chapter 11 Managing certificates 593Nortel Secure Network Access Switch 4050 User Guide Figure 170 shows sample output for the /cfg/cert #/display com

Página 550

594 Chapter 11 Managing certificates320818-A Exporting a certificate and key from the Nortel SNAS 4050 using the CLIYou can export certificate files a

Página 551 - SSH Keys – Hosts

Chapter 11 Managing certificates 595Nortel Secure Network Access Switch 4050 User Guide Export format The key and certificate format in which you want

Página 552 - SSH Keys Hosts field

596 Chapter 11 Managing certificates320818-A Figure 171 shows sample output for the /cfg/cert #/export command. For more information about the Certifi

Página 553 - Add SSH Key

Chapter 11 Managing certificates 597Nortel Secure Network Access Switch 4050 User Guide You are prompted to enter the following parameters. The combin

Página 554

598 Chapter 11 Managing certificates320818-A Viewing certificates using the SREMTo view basic information about all certificates configured for the No

Página 555 - NSNAS-SSL-Audit-Trail)

Chapter 11 Managing certificates 599Nortel Secure Network Access Switch 4050 User Guide 3 Click Yes.The certificate is removed from the Certificates l

Página 556

6 Contents320818-A Management IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51Portal Virtual IP addres

Página 557 - Figure 160

60 Chapter 2 Initial setup320818-A The action to be performed when the TunnelGuard check fails depends on your selection in step f on page 59.Settings

Página 558 - Table 116

600 Chapter 11 Managing certificates320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Página 559 - Audit Servers

Chapter 11 Managing certificates 601Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the SREMTo generate a CS

Página 560 - Adding a new Audit Server

602 Chapter 11 Managing certificates320818-A 2 Enter the certificate information in the applicable fields.Table 125 describes the CA Request fields.Ta

Página 561

Chapter 11 Managing certificates 603Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the information to the No

Página 562

604 Chapter 11 Managing certificates320818-A To import a certificate and private key into the Nortel SNAS 4050, perform the following steps.1 Upload t

Página 563 - Figure 163

Chapter 11 Managing certificates 605Nortel Secure Network Access Switch 4050 User Guide 3 Enter the import information in the applicable fields. Table

Página 564 - Table 118

606 Chapter 11 Managing certificates320818-A To display the current certificate and key or save a copy, perform the following steps:1 Select the Certi

Página 565 - Radius Server Table

Chapter 11 Managing certificates 607Nortel Secure Network Access Switch 4050 User Guide 2 If you want to encrypt the key, specify a password in the ap

Página 566 - Add Radius Server fields

608 Chapter 11 Managing certificates320818-A To export a certificate and key from the Nortel SNAS 4050, perform the following steps.1 Select the Certi

Página 567

Chapter 11 Managing certificates 609Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields. Table

Página 568

Chapter 2 Initial setup 61Nortel Secure Network Access Switch 4050 User Guide The profiles determine the VLAN to which the user will be allocated. Tab

Página 569 - Managing certificates

610 Chapter 11 Managing certificates320818-A 3 Click Apply on the toolbar to export the certificate.The certificate and private key are immediately ex

Página 570

Chapter 11 Managing certificates 611Nortel Secure Network Access Switch 4050 User Guide The Configuration screen appears (see Figure 172).Figure 178

Página 571 - Key and certificate formats

612 Chapter 11 Managing certificates320818-A Viewing general informationTo view basic information about a certificate on the Nortel SNAS 4050 cluster,

Página 572

Chapter 11 Managing certificates 613Nortel Secure Network Access Switch 4050 User Guide The Info screen appears (see Figure 179).Figure 179 Info scr

Página 573 - Creating certificates

614 Chapter 11 Managing certificates320818-A Viewing certificate subject settingsTo view subject settings for a certificate on the Nortel SNAS 4050 cl

Página 574 - Updating certificates

Chapter 11 Managing certificates 615Nortel Secure Network Access Switch 4050 User Guide The Subject screen appears (see Figure 180).Figure 180 Subje

Página 575

616 Chapter 11 Managing certificates320818-A Organization The registered name of the organization. The organization must own the domain name that appe

Página 576

617Nortel Secure Network Access Switch 4050 User Guide Chapter 12 Configuring SNMPThis chapter includes the following topics:Topic PageConfiguring SNM

Página 577

618 Chapter 12 Configuring SNMP320818-A Simple Network Management Protocol (SNMP) is a set of protocols for managing complex networks. SNMP works by s

Página 578

Chapter 12 Configuring SNMP 619Nortel Secure Network Access Switch 4050 User Guide • SNMP monitors and events (see “Configuring SNMP events using the

Página 579

62 Chapter 2 Initial setup320818-A Before you beginLog on to the existing Nortel SNAS 4050 device to check the software version and system settings. U

Página 580

620 Chapter 12 Configuring SNMP320818-A Configuring SNMP settings using the CLITo configure SNMP management of the Nortel SNAS 4050 cluster, use the f

Página 581

Chapter 12 Configuring SNMP 621Nortel Secure Network Access Switch 4050 User Guide Configuring the SNMP v2 MIB using the CLITo configure parameters in

Página 582 - Figure 166

622 Chapter 12 Configuring SNMP320818-A The SNMPv2-MIB menu includes the following options:Configuring the SNMP community using the CLITo configure th

Página 583

Chapter 12 Configuring SNMP 623Nortel Secure Network Access Switch 4050 User Guide Configuring SNMPv3 users using the CLIThe Nortel SNAS 4050 manages

Página 584

624 Chapter 12 Configuring SNMP320818-A • set — USM user is authorized to perform SNMP set requests (write access to the MIB). Write access automatica

Página 585

Chapter 12 Configuring SNMP 625Nortel Secure Network Access Switch 4050 User Guide The SNMP User menu includes the following options:/cfg/sys/adm/snmp

Página 586

626 Chapter 12 Configuring SNMP320818-A Configuring SNMP notification targets using the CLISNMP managers function as the notification targets for SNMP

Página 587

Chapter 12 Configuring SNMP 627Nortel Secure Network Access Switch 4050 User Guide The Notification Target menu includes the following options:Configu

Página 588

628 Chapter 12 Configuring SNMP320818-A The event menu includes the following options:/cfg/sys/adm/snmp/eventfollowed by:addmonitor [<options>]

Página 589

Chapter 12 Configuring SNMP 629Nortel Secure Network Access Switch 4050 User Guide addmonitor [<options>] -t <name> <OID> <value

Página 590

Chapter 2 Initial setup 63Nortel Secure Network Access Switch 4050 User Guide • To change the version on the existing NSNAS, download the desired soft

Página 591

630 Chapter 12 Configuring SNMP320818-A addmonitor [<options>] -x <name> <OID> [present|absent|changed]Adds an existence monitor and

Página 592

Chapter 12 Configuring SNMP 631Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP settings using the SREMThis section contains infor

Página 593 - Figure 170

632 Chapter 12 Configuring SNMP320818-A Configuring SNMP using the SREMTo configure SNMP, perform the following steps:1 Select the System > Adminis

Página 594 - Parameter Description

Chapter 12 Configuring SNMP 633Nortel Secure Network Access Switch 4050 User Guide 2 Enter the SNMP Configuration information in the applicable fields

Página 595

634 Chapter 12 Configuring SNMP320818-A Configuring SNMP targets using the SREMSNMP managers function as the notification targets for SNMP monitoring.

Página 596

Chapter 12 Configuring SNMP 635Nortel Secure Network Access Switch 4050 User Guide Adding SNMP targetsTo add an SNMP target, perform the following ste

Página 597

636 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMP Target dialog box appears (see Figure 183).Figure 183 Add SNMP Target

Página 598 - Certificates screen

Chapter 12 Configuring SNMP 637Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMP target information in the applicable fields. Table

Página 599 - Add a Certificate Component

638 Chapter 12 Configuring SNMP320818-A Managing SNMP targetsTo manage SNMP targets, perform the following steps:1 Select the System > Administrati

Página 600

Chapter 12 Configuring SNMP 639Nortel Secure Network Access Switch 4050 User Guide 2 Modify the SNMP Target information in the applicable fields. Tabl

Página 601 - Figure 174

64 Chapter 2 Initial setup320818-A In a one-armed configuration, you are specifying the port you want to use for all network connectivity, since Inter

Página 602 - Table 125

640 Chapter 12 Configuring SNMP320818-A A dialog box appears asking for confirmation.4 Click Yes.5 Click Apply on the toolbar to send the current chan

Página 603

Chapter 12 Configuring SNMP 641Nortel Secure Network Access Switch 4050 User Guide Adding SNMPv3 usersTo add an SNMPv3 user, perform the following ste

Página 604 - Import Certificate screen

642 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMPv3 User dialog box appears (see Figure 186).Figure 186 Add SNMPv3 User

Página 605

Chapter 12 Configuring SNMP 643Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMPv3 User information in the applicable fields. Table

Página 606 - Figure 176

644 Chapter 12 Configuring SNMP320818-A 4 Click Apply. The new SNMPv3 user appears in the table.5 Click Apply on the toolbar to send the current chang

Página 607 - Display Certificates fields

Chapter 12 Configuring SNMP 645Nortel Secure Network Access Switch 4050 User Guide 2 Modify SNMPv3 User information in the applicable fields, as requi

Página 608 - Figure 177

646 Chapter 12 Configuring SNMP320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the toolbar

Página 609 - Table 128

Chapter 12 Configuring SNMP 647Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP events using the SREMSNMP events can be added to m

Página 610 - Viewing configuration details

648 Chapter 12 Configuring SNMP320818-A Adding monitor eventsTo add monitor events, perform the following steps:1 Select the System > Administrativ

Página 611 - Table 129

Chapter 12 Configuring SNMP 649Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Monitor dialog box appears. Depending on the

Página 612 - Viewing general information

Chapter 2 Initial setup 65Nortel Secure Network Access Switch 4050 User Guide 8 Configure the interface for client portal traffic (Interface 2).a Spec

Página 613 - Table 130

650 Chapter 12 Configuring SNMP320818-A Depending on the type of monitor selected, the fields displayed on the Configuration tab will change. For desc

Página 614 - Table 130 Info fields

Chapter 12 Configuring SNMP 651Nortel Secure Network Access Switch 4050 User Guide Figure 189 Add a Monitor: BooleanFields used to add and configure

Página 615 - Table 131

652 Chapter 12 Configuring SNMP320818-A For details on adding a Boolean monitor, see “Adding monitor events” on page 648.Threshold monitorsThreshold m

Página 616 - Table 131 Subject fields

Chapter 12 Configuring SNMP 653Nortel Secure Network Access Switch 4050 User Guide Fields used to add and configure a Threshold monitor are listed in

Página 617 - Configuring SNMP

654 Chapter 12 Configuring SNMP320818-A Existence monitorsExistence monitors check the condition of a monitored OID to see determine if it is present,

Página 618 - /cfg/sys/adm/snmp

Chapter 12 Configuring SNMP 655Nortel Secure Network Access Switch 4050 User Guide For details on adding a Existence monitor, see “Adding monitor even

Página 619 - Roadmap of SNMP commands

656 Chapter 12 Configuring SNMP320818-A Adding notification eventsTo add notification events, perform the following steps:1 Select the System > Adm

Página 620

Chapter 12 Configuring SNMP 657Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Notification Event dialog box appears (see F

Página 621 - The SNMPv2-MIB menu displays

658 Chapter 12 Configuring SNMP320818-A Removing notification eventsTo delete a notification event, perform the following steps:1 Select the System &g

Página 622

659Nortel Secure Network Access Switch 4050 User Guide Chapter 13 Viewing system information and performance statisticsThis chapter includes the follo

Página 623

66 Chapter 2 Initial setup320818-A 12 Wait while the Setup utility finishes processing. When processing is complete, you will see Setup successful.The

Página 624

660 Chapter 13 Viewing system information and performance statistics320818-A Viewing system information and performance statistics using the CLITo vie

Página 625

Chapter 13 Viewing system information and performance statistics 661Nortel Secure Network Access Switch 4050 User Guide Viewing system information usi

Página 626

662 Chapter 13 Viewing system information and performance statistics320818-A The Information menu includes the following options:/infofollowed by:cert

Página 627

Chapter 13 Viewing system information and performance statistics 663Nortel Secure Network Access Switch 4050 User Guide kick <domain ID> <use

Página 628

664 Chapter 13 Viewing system information and performance statistics320818-A mac <MACaddr>Displays session information for a client based on a s

Página 629

Chapter 13 Viewing system information and performance statistics 665Nortel Secure Network Access Switch 4050 User Guide localDisplays the current soft

Página 630

666 Chapter 13 Viewing system information and performance statistics320818-A Viewing alarm events using the CLITo view active alarms, use the followin

Página 631

Chapter 13 Viewing system information and performance statistics 667Nortel Secure Network Access Switch 4050 User Guide Viewing log files using the CL

Página 632 - Figure 181

668 Chapter 13 Viewing system information and performance statistics320818-A The CLI reports statistics for all authentication methods configured in t

Página 633 - Table 132

Chapter 13 Viewing system information and performance statistics 669Nortel Secure Network Access Switch 4050 User Guide Figure 194 shows sample output

Página 634

Chapter 2 Initial setup 67Nortel Secure Network Access Switch 4050 User Guide 3 To finish connecting the Nortel SNAS 4050 to the rest of the network,

Página 635 - Adding SNMP targets

670 Chapter 13 Viewing system information and performance statistics320818-A Viewing all statistics using the CLITo view all available statistics for

Página 636 - Figure 183

Chapter 13 Viewing system information and performance statistics 671Nortel Secure Network Access Switch 4050 User Guide The Information screen appears

Página 637 - SNMP Target fields

672 Chapter 13 Viewing system information and performance statistics320818-A Viewing cluster information using the SREMTo view cluster information, se

Página 638 - Managing SNMP targets

Chapter 13 Viewing system information and performance statistics 673Nortel Secure Network Access Switch 4050 User Guide Viewing the controller list us

Página 639 - Removing SNMP targets

674 Chapter 13 Viewing system information and performance statistics320818-A Table 143 describes the Controller List fields. Table 143 Controller Li

Página 640

Chapter 13 Viewing system information and performance statistics 675Nortel Secure Network Access Switch 4050 User Guide Viewing SONMP topology informa

Página 641 - Adding SNMPv3 users

676 Chapter 13 Viewing system information and performance statistics320818-A Table 144 describes the SONMP State fields. Table 144 SONMP State field

Página 642 - Figure 186

Chapter 13 Viewing system information and performance statistics 677Nortel Secure Network Access Switch 4050 User Guide Viewing switch distribution us

Página 643 - Table 135

678 Chapter 13 Viewing system information and performance statistics320818-A Table 145 describes the Switch Distribution fields. Viewing port informat

Página 644 - Managing SNMPv3 users

Chapter 13 Viewing system information and performance statistics 679Nortel Secure Network Access Switch 4050 User Guide To view port information, sele

Página 645 - Table 136

68 Chapter 2 Initial setup320818-A Applying and saving the configuration using the CLIIf you have not already done so after each sequence of configura

Página 646 - Removing SNMPv3 users

680 Chapter 13 Viewing system information and performance statistics320818-A Viewing license information using the SREMYou can view information about

Página 647 - Managing monitor events

Chapter 13 Viewing system information and performance statistics 681Nortel Secure Network Access Switch 4050 User Guide Viewing global license informa

Página 648 - Adding monitor events

682 Chapter 13 Viewing system information and performance statistics320818-A Table 147 describes the Global Licenses fields. Table 147 Global Licens

Página 649 - Add a Monitor fields

Chapter 13 Viewing system information and performance statistics 683Nortel Secure Network Access Switch 4050 User Guide Viewing license information fo

Página 650 - Boolean monitors

684 Chapter 13 Viewing system information and performance statistics320818-A Table 148 describes the Per Domain Licenses fields. Viewing session detai

Página 651 - Table 138

Chapter 13 Viewing system information and performance statistics 685Nortel Secure Network Access Switch 4050 User Guide Viewing active sessions using

Página 652 - Threshold monitors

686 Chapter 13 Viewing system information and performance statistics320818-A Table 149 describes the Sessions parameters. Table 149 Sessions paramet

Página 653 - Table 139

Chapter 13 Viewing system information and performance statistics 687Nortel Secure Network Access Switch 4050 User Guide Viewing details for a particul

Página 654 - Existence monitors

688 Chapter 13 Viewing system information and performance statistics320818-A Table 150 describes the Session Properties parameters. Ending active user

Página 655 - Managing notification events

Chapter 13 Viewing system information and performance statistics 689Nortel Secure Network Access Switch 4050 User Guide Figure 204 KickOut User scre

Página 656 - Adding notification events

Chapter 2 Initial setup 69Nortel Secure Network Access Switch 4050 User Guide Figure 3 on page 69 shows the location of the Apply and Commit buttons.F

Página 657 - Add a Notification Event

690 Chapter 13 Viewing system information and performance statistics320818-A Viewing the number of active sessions using the SREMTo view the number of

Página 658 - Removing notification events

Chapter 13 Viewing system information and performance statistics 691Nortel Secure Network Access Switch 4050 User Guide Viewing alarms using the SREMY

Página 659 - Chapter 13

692 Chapter 13 Viewing system information and performance statistics320818-A Viewing active alarms using the SREMTo view the active alarms for the Nor

Página 660

Chapter 13 Viewing system information and performance statistics 693Nortel Secure Network Access Switch 4050 User Guide Table 153 describes the Active

Página 661

694 Chapter 13 Viewing system information and performance statistics320818-A Downloading alarms using the SREMTo download an alarm as a logged event,

Página 662

Chapter 13 Viewing system information and performance statistics 695Nortel Secure Network Access Switch 4050 User Guide Table 154 describes the Downlo

Página 663

696 Chapter 13 Viewing system information and performance statistics320818-A Viewing the log list using the SREMTo view a list of all active logs, sel

Página 664

Chapter 13 Viewing system information and performance statistics 697Nortel Secure Network Access Switch 4050 User Guide Downloading log files using th

Página 665

698 Chapter 13 Viewing system information and performance statistics320818-A Viewing AAA statistics using the SREMYou can view authentication statisti

Página 666 - The Events menu displays

Chapter 13 Viewing system information and performance statistics 699Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for a h

Página 667

Contents 7Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 668

70 Chapter 2 Initial setup320818-A

Página 669 - Figure 194

700 Chapter 13 Viewing system information and performance statistics320818-A b Expand the Statistics > AAA > Host Statistics > host navigatio

Página 670

Chapter 13 Viewing system information and performance statistics 701Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Página 671 - Table 142

702 Chapter 13 Viewing system information and performance statistics320818-A Viewing RADIUS statisticsTo view RADIUS statistics, select the Radius tab

Página 672

Chapter 13 Viewing system information and performance statistics 703Nortel Secure Network Access Switch 4050 User Guide For a description of the field

Página 673 - Figure 196

704 Chapter 13 Viewing system information and performance statistics320818-A Viewing Local database statisticsTo view Local database statistics, selec

Página 674 - Table 143

Chapter 13 Viewing system information and performance statistics 705Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Página 675 - Figure 197

706 Chapter 13 Viewing system information and performance statistics320818-A For a description of the fields, seeTable 159.Table 159 LDAP statistics

Página 676 - Table 144

Chapter 13 Viewing system information and performance statistics 707Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for the

Página 677 - Figure 198

708 Chapter 13 Viewing system information and performance statistics320818-A •LDAPSelect one of the following tasks:• Viewing License statistics (see

Página 678 - Switch Distribution fields

Chapter 13 Viewing system information and performance statistics 709Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Página 679 - Table 146

71Nortel Secure Network Access Switch 4050 User Guide Chapter 3 Managing the network access devicesThis chapter includes the following topics:Topic Pa

Página 680

710 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Página 681 - Figure 200

Chapter 13 Viewing system information and performance statistics 711Nortel Secure Network Access Switch 4050 User Guide Viewing RADIUS statisticsTo vi

Página 682 - Table 147

712 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Página 683 - Figure 201

Chapter 13 Viewing system information and performance statistics 713Nortel Secure Network Access Switch 4050 User Guide Viewing Local database statist

Página 684 - Per Domain Licenses fields

714 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Página 685 - Sessions screen

Chapter 13 Viewing system information and performance statistics 715Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Página 686 - Table 149

716 Chapter 13 Viewing system information and performance statistics320818-A Viewing Ethernet statistics using the SREMYou can view statistics for the

Página 687 - Figure 203

Chapter 13 Viewing system information and performance statistics 717Nortel Secure Network Access Switch 4050 User Guide To view Ethernet interface sta

Página 688 - Ending active user sessions

718 Chapter 13 Viewing system information and performance statistics320818-A Viewing Rx statisticsTo view Rx statistics for an interface, select the R

Página 689 - Table 151

Chapter 13 Viewing system information and performance statistics 719Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Página 690 - Number of Sessions fields

72 Chapter 3 Managing the network access devices320818-A Before you beginIn Trusted Computing Group (TCG) terminology, the edge switches in a Nortel S

Página 691 - Viewing alarms using the SREM

720 Chapter 13 Viewing system information and performance statistics320818-A Viewing Tx statisticsTo view Tx statistics for an interface, select Tx St

Página 692 - Figure 206

Chapter 13 Viewing system information and performance statistics 721Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Página 693 - Table 153

722 Chapter 13 Viewing system information and performance statistics320818-A

Página 694 - Figure 207

723Nortel Secure Network Access Switch 4050 User Guide Chapter 14 Maintaining and managing the systemThis chapter includes the following topics:Topic

Página 695 - Table 154

724 Chapter 14 Maintaining and managing the system320818-A You can perform the following activities to manage and maintain the system and individual N

Página 696 - Figure 208

Chapter 14 Maintaining and managing the system 725Nortel Secure Network Access Switch 4050 User Guide To manage software versions and Nortel SNAS 4050

Página 697 - Table 155

726 Chapter 14 Maintaining and managing the system320818-A Performing maintenance using the CLITo check the applied configuration and to download log

Página 698

Chapter 14 Maintaining and managing the system 727Nortel Secure Network Access Switch 4050 User Guide The Maintenance menu includes the following opti

Página 699 - The Hosts table

728 Chapter 14 Maintaining and managing the system320818-A dumpstats <protocol> <server> <filename> <all-isds?>Collects curren

Página 700

Chapter 14 Maintaining and managing the system 729Nortel Secure Network Access Switch 4050 User Guide starttrace <tags> <domain ID> <ou

Página 701 - Viewing License statistics

Chapter 3 Managing the network access devices 73Nortel Secure Network Access Switch 4050 User Guide You require the following information for each net

Página 702 - Viewing RADIUS statistics

730 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the CLITo save the system configuration to

Página 703 - Table 157

Chapter 14 Maintaining and managing the system 731Nortel Secure Network Access Switch 4050 User Guide Table 166 provides more information about the ba

Página 704 - Table 158

732 Chapter 14 Maintaining and managing the system320818-A gtcfg <protocol> <server> <filename> <passphrase>Restores a configu

Página 705 - Viewing LDAP statistics

Chapter 14 Maintaining and managing the system 733Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices using the CLIT

Página 706 - Table 159

734 Chapter 14 Maintaining and managing the system320818-A Managing software for a Nortel SNAS 4050 device using the CLITo view, download, and activat

Página 707 - The Statistics table

Chapter 14 Maintaining and managing the system 735Nortel Secure Network Access Switch 4050 User Guide The Software Management menu includes the follow

Página 708

736 Chapter 14 Maintaining and managing the system320818-A Managing and maintaining the system using the SREMPerforming maintenance using the SREMTo p

Página 709

Chapter 14 Maintaining and managing the system 737Nortel Secure Network Access Switch 4050 User Guide • “Backing up or restoring the configuration usi

Página 710

738 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Dump information in the applicable fields. Table 167 describes the Dump fields.

Página 711

Chapter 14 Maintaining and managing the system 739Nortel Secure Network Access Switch 4050 User Guide To start or stop a trace, perform the following

Página 712

74 Chapter 3 Managing the network access devices320818-A resetenadisdelete/cfg/domain #/vlan add <name> <VLAN ID>del <index>list/cfg

Página 713 - Table 162

740 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Trace information in the applicable fields. Table 168 describes the Start/Stop

Página 714

Chapter 14 Maintaining and managing the system 741Nortel Secure Network Access Switch 4050 User Guide Checking configuration using the SREMYou can che

Página 715

742 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the SREMYou can save the current configurat

Página 716

Chapter 14 Maintaining and managing the system 743Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Backup/Restore information in the ap

Página 717 - The Ethernet Interface table

744 Chapter 14 Maintaining and managing the system320818-A • “Rebooting or deleting a Nortel SNAS 4050 device using the SREM” on page 750Managing soft

Página 718 - Viewing Rx statistics

Chapter 14 Maintaining and managing the system 745Nortel Secure Network Access Switch 4050 User Guide Table 170 describes the Image List fields.The fo

Página 719

746 Chapter 14 Maintaining and managing the system320818-A Viewing details of the active software imageTo view the details of the currently active sof

Página 720 - Viewing Tx statistics

Chapter 14 Maintaining and managing the system 747Nortel Secure Network Access Switch 4050 User Guide Activating a software imageTo activate an old or

Página 721

748 Chapter 14 Maintaining and managing the system320818-A 4 When prompted, click Yes.The Nortel SNAS 4050 reboots when you confirm the Activate comma

Página 722

Chapter 14 Maintaining and managing the system 749Nortel Secure Network Access Switch 4050 User Guide To download an image from a file exchange server

Página 723 - Chapter 14

Chapter 3 Managing the network access devices 75Nortel Secure Network Access Switch 4050 User Guide Adding a network access device using the CLIYou ca

Página 724

750 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Download Image information in the applicable fields. Table 171 describes the Do

Página 725

Chapter 14 Maintaining and managing the system 751Nortel Secure Network Access Switch 4050 User Guide To reboot, shut down, or reset the Nortel SNAS 4

Página 726

752 Chapter 14 Maintaining and managing the system320818-A The command resets the device to its factory default configuration. All IP configuration is

Página 727

Chapter 14 Maintaining and managing the system 753Nortel Secure Network Access Switch 4050 User Guide The File Download screen appears (see Figure 232

Página 728

754 Chapter 14 Maintaining and managing the system320818-A Running Nortel SNAS 4050 diagnostics using the SREMTo run basic diagnostics on the Nortel S

Página 729

Chapter 14 Maintaining and managing the system 755Nortel Secure Network Access Switch 4050 User Guide Table 173 describes the Diagnostics fields. Tabl

Página 730

756 Chapter 14 Maintaining and managing the system320818-A

Página 731 - Table 166

757Nortel Secure Network Access Switch 4050 User Guide Chapter 15 Upgrading or reinstalling the softwareThis chapter includes the following topics:The

Página 732

758 Chapter 15 Upgrading or reinstalling the software320818-A Major release upgrade: This kind of release may contain bug fixes as well as feature enh

Página 733 - The Boot menu displays

Chapter 15 Upgrading or reinstalling the software 759Nortel Secure Network Access Switch 4050 User Guide The set of installed Nortel SNAS 4050 devices

Página 734

76 Chapter 3 Managing the network access devices320818-A 4 Specify the TCP port for communication between the Nortel SNAS 4050 and the network access

Página 735

760 Chapter 15 Upgrading or reinstalling the software320818-A If needed, the file name can be prefixed with a search path to the directory on the TFTP

Página 736

Chapter 15 Upgrading or reinstalling the software 761Nortel Secure Network Access Switch 4050 User Guide When you have downloaded the software upgrade

Página 737

762 Chapter 15 Upgrading or reinstalling the software320818-A 5 At the Software Management# prompt, enter:6 Log in again and verify the new software v

Página 738 - Table 167

Chapter 15 Upgrading or reinstalling the software 763Nortel Secure Network Access Switch 4050 User Guide Reinstalling the softwareIf you are adding a

Página 739 - Figure 224

764 Chapter 15 Upgrading or reinstalling the software320818-A • authorization to log on as the boot userIf a software CD was shipped with the Nortel S

Página 740 - Table 168

Chapter 15 Upgrading or reinstalling the software 765Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from an external fi

Página 741 - Check Configuration

766 Chapter 15 Upgrading or reinstalling the software320818-A e Specify the default gateway IP address. 3 Specify the download details:a protocol for

Página 742 - Backup & Restore

Chapter 15 Upgrading or reinstalling the software 767Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from a CDTo reinsta

Página 743 - Backup & Restore fields

768 Chapter 15 Upgrading or reinstalling the software320818-A

Página 744 - Image List

769Nortel Secure Network Access Switch 4050 User Guide Chapter 16 The Command Line InterfaceThis chapter explains how to access the Nortel SNAS 4050 t

Página 745

Chapter 3 Managing the network access devices 77Nortel Secure Network Access Switch 4050 User Guide d To continue, go to step 7 on page 77.7 Specify t

Página 746

770 Chapter 16 The Command Line Interface320818-A When using a Telnet or SSH client to connect to a cluster of Nortel SNAS 4050 devices, always connec

Página 747 - Activating a software image

Chapter 16 The Command Line Interface 771Nortel Secure Network Access Switch 4050 User Guide RequirementsTo establish a console connection with the No

Página 748

772 Chapter 16 The Command Line Interface320818-A Establishing a Telnet connectionA Telnet connection offers the convenience of accessing the Nortel S

Página 749 - Figure 230

Chapter 16 The Command Line Interface 773Nortel Secure Network Access Switch 4050 User Guide Running TelnetOnce the IP parameters on the Nortel SNAS 4

Página 750 - Download Image fields

774 Chapter 16 The Command Line Interface320818-A Running an SSH clientConnecting to the Nortel SNAS 4050 using an SSH client is similar to connecting

Página 751 - Reboot/Delete ISD Options

Chapter 16 The Command Line Interface 775Nortel Secure Network Access Switch 4050 User Guide Accessing the Nortel SNAS 4050 clusterTo enable better No

Página 752

776 Chapter 16 The Command Line Interface320818-A Access to the Nortel SNAS 4050 CLI and settings is controlled through the use of four predefined use

Página 753 - Table 172

Chapter 16 The Command Line Interface 777Nortel Secure Network Access Switch 4050 User Guide CLI Main Menu or SetupOnce the Administrator user passwor

Página 754 - Figure 233

778 Chapter 16 The Command Line Interface320818-A If you are automatically disconnected after the specified idle timeout interval, any unapplied confi

Página 755 - Table 173

779Nortel Secure Network Access Switch 4050 User Guide Chapter 17 Configuration exampleThis chapter provides an example of a basic Nortel SNA configur

Página 756

78 Chapter 3 Managing the network access devices320818-A Manually adding a switchTo add a network access device and configure it manually, use the fol

Página 757 - Chapter 15

780 Chapter 17 Configuration example320818-A Figure 235 Basic configurationTable 176 summarizes the devices connected in this environment and their

Página 758

Chapter 17 Configuration example 781Nortel Secure Network Access Switch 4050 User Guide Table 177 summarizes the VLANs for the Ethernet Routing Switch

Página 759

782 Chapter 17 Configuration example320818-A Steps1 “Configure the network DNS server” on page 7822 “Configure the network DHCP server” on page 7833 “

Página 760 - /boot/software/cur command

Chapter 17 Configuration example 783Nortel Secure Network Access Switch 4050 User Guide Configure the network DHCP serverTo configure a DHCP scope usi

Página 761

784 Chapter 17 Configuration example320818-A 4 Enter a descriptive name to identify the new scope (see Figure 238).In this example, you are creating a

Página 762

Chapter 17 Configuration example 785Nortel Secure Network Access Switch 4050 User Guide 5 Specify the IP address range for the DHCP scope (see Figure

Página 763 - Reinstalling the software

786 Chapter 17 Configuration example320818-A 6 Select the Yes, I want to configure these options now option button on the Configure DHCP Options windo

Página 764

Chapter 17 Configuration example 787Nortel Secure Network Access Switch 4050 User Guide 7 Enter the IP address of the default gateway (see Figure 241)

Página 765

788 Chapter 17 Configuration example320818-A 8 Enter the IP address of the DNS server (see Figure 242).Figure 242 Specifying the DNS server9 Repeat

Página 766

Chapter 17 Configuration example 789Nortel Secure Network Access Switch 4050 User Guide Figure 243 shows the DHCP scopes created for use in this examp

Página 767

Chapter 3 Managing the network access devices 79Nortel Secure Network Access Switch 4050 User Guide Figure 4 Adding a switch manuallyDeleting a netw

Página 768

790 Chapter 17 Configuration example320818-A 2 Assign the VLAN port members.Since the edge switches in this example are operating in Layer 2 mode, ena

Página 769 - The Command Line Interface

Chapter 17 Configuration example 791Nortel Secure Network Access Switch 4050 User Guide 7 “Configuring the NSNA ports” on page 7928 “Enabling NSNA glo

Página 770

792 Chapter 17 Configuration example320818-A Configuring the NSNA uplink filterPassport-8310:6# config filter acl 100 create ip acl-name "dhcp&qu

Página 771 - Procedure

Chapter 17 Configuration example 793Nortel Secure Network Access Switch 4050 User Guide Configure the Ethernet Routing Switch 5510The following config

Página 772

794 Chapter 17 Configuration example320818-A Configuring SSHIn this example, the assumption is that the Nortel SNAS 4050 public key has already been u

Página 773 - Running Telnet

Chapter 17 Configuration example 795Nortel Secure Network Access Switch 4050 User Guide Configuring the login domain controller filters5510-48T(config

Página 774 - Running an SSH client

796 Chapter 17 Configuration example320818-A 3 “Adding the network access devices” on page 7984 “Mapping the VLANs” on page 8005 “Enabling the network

Página 775

Chapter 17 Configuration example 797Nortel Secure Network Access Switch 4050 User Guide Enter a password for the "admin" user: Re-enter to c

Página 776 - User access levels

798 Chapter 17 Configuration example320818-A Generate and activate the SSH key for communication with the network access devices:>> Main# cfg/do

Página 777 - Idle timeout

Chapter 17 Configuration example 799Nortel Secure Network Access Switch 4050 User Guide Adding the Ethernet Routing Switch 8300Add the switch manually

Página 778

8 Contents320818-A Configuring domain parameters using the SREM . . . . . . . . . . . . . . . . . . . . . . . . 164Additional domain configuration in

Página 779 - Configuration example

80 Chapter 3 Managing the network access devices320818-A The delete command removes the current switch from the control of the Nortel SNAS 4050 cluste

Página 780 - Table 176

800 Chapter 17 Configuration example320818-A Adding the Ethernet Routing Switch 5510Use the quick switch wizard:>> Main# cfg/domain 1/quickEnter

Página 781

Chapter 17 Configuration example 801Nortel Secure Network Access Switch 4050 User Guide >> Domain Vlan# applyChanges applied successfully.Enabli

Página 782

802 Chapter 17 Configuration example320818-A

Página 783 - Creating a new DHCP scope

803Nortel Secure Network Access Switch 4050 User Guide Appendix ACLI referenceThe command line interface (CLI) allows you to view system information a

Página 784 - Naming the new DHCP scope

804 Appendix A CLI reference320818-A Using the CLICLI commands are grouped into a series of menus and submenus (see “CLI Main Menu” on page 812). Each

Página 785 - Figure 239

Appendix A CLI reference 805Nortel Secure Network Access Switch 4050 User Guide pasteRestores a saved configuration that includes private keys. TIP: B

Página 786 - Figure 240

806 Appendix A CLI reference320818-A Command line history and editingYou can use the CLI to retrieve and modify commands entered previously. Table 180

Página 787 - Figure 241

Appendix A CLI reference 807Nortel Secure Network Access Switch 4050 User Guide CLI shortcutsYou can use the following CLI command shortcuts:• “Comman

Página 788 - Specifying the DNS server

808 Appendix A CLI reference320818-A You can also use command stacking to proceed one or more levels in the menu system, and go directly to another su

Página 789

Appendix A CLI reference 809Nortel Secure Network Access Switch 4050 User Guide • To display the active menu:— Ensure that the command line is blank.—

Página 790

Chapter 3 Managing the network access devices 81Nortel Secure Network Access Switch 4050 User Guide The Switch menu includes the following options:/cf

Página 791 - Configuring the VoIP VLANs

810 Appendix A CLI reference320818-A If you use the cur command without the sys submenu argument, information related to the Configuration menu and al

Página 792 - Enabling NSNA globally

Appendix A CLI reference 811Nortel Secure Network Access Switch 4050 User Guide • 255.255.255.0 it can also be expressed as 24• 255.255.255.255 it can

Página 793 - Setting the switch IP address

812 Appendix A CLI reference320818-A CLI Main MenuThe Main menu appears after a successful connection and login. Figure 244 represents the Main menu a

Página 794 - Configuring SSH

Appendix A CLI reference 813Nortel Secure Network Access Switch 4050 User Guide • Maintenance — used for sending technical support information to an e

Página 795

814 Appendix A CLI reference320818-A Information menuThe Information menu contains commands used to display current information about the Nortel SNAS

Página 796 - Performing initial setup

Appendix A CLI reference 815Nortel Secure Network Access Switch 4050 User Guide Statistics menuThe Statistics menu contains commands used to view stat

Página 797 - Completing initial setup

816 Appendix A CLI reference320818-A Configuration menuThe Configuration menu contains commands used to configure the Nortel SNAS 4050. Table 184 list

Página 798

Appendix A CLI reference 817Nortel Secure Network Access Switch 4050 User Guide /cfg/domain <domain ID>name <name>pvips <IPaddr>aaas

Página 799 - Switch 8300:

818 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/ldapserverssearchbase <DN>groupattr <names>userattr <names>isdbinddn &

Página 800 - Mapping the VLANs

Appendix A CLI reference 819Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/auth #/localadd <user name> <password> &

Página 801

82 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the CLIThe VLANs are configured on the network access devices. You sp

Página 802

820 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/radius/sessiontimvendorid <vendor ID>vendortype <vendor type>enadisConfigure

Página 803 - CLI reference

Appendix A CLI reference 821Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/group #/extend #/linksetlistdel <index number>

Página 804 - Using the CLI

822 Appendix A CLI reference320818-A /cfg/domain #/aaa/tg quickrecheck <interval>heartbeat <interval>hbretrycnt <count>status-quo on

Página 805

Appendix A CLI reference 823Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/linkset <linkset ID>name <name>text <text

Página 806

824 Appendix A CLI reference320818-A /cfg/domain #/portal/colorscolor1 <code>color2 <code>color3 <code>color4 <code>theme defa

Página 807 - CLI shortcuts

Appendix A CLI reference 825Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/server/adv/traflogsysloghost <IPaddr>udpport <p

Página 808 - Tab completion

826 Appendix A CLI reference320818-A /cfg/domain #/switch <switch ID>name <name>type ERS8300|ERS5500ip <IPaddr>port <port>hlth

Página 809

Appendix A CLI reference 827Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/vlan add <name> <VLAN ID>del <index>li

Página 810 - Network masks

828 Appendix A CLI reference320818-A /cfg/sys/accesslist listdel <index number>add <IPaddr> <mask>Manage the Access List in order to

Página 811 - Variables

Appendix A CLI reference 829Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/auth/serverslistdel <index number>add <IPaddr>

Página 812 - CLI command reference

Chapter 3 Managing the network access devices 83Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 maintains separate maps for t

Página 813 - Appendix A CLI reference 813

830 Appendix A CLI reference320818-A /cfg/sys/adm/snmp/eventaddmonitor [<options>] -b <name> <OID> <op> <value>addmonito

Página 814 - Information menu

Appendix A CLI reference 831Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/snmp/users <user ID>name <name>seclevel none|

Página 815 - Statistics menu

832 Appendix A CLI reference320818-A /cfg/sys/dns/servers listdel <index number>add <IPaddr> insert <index number> <IPaddr>mov

Página 816 - Configuration menu

Appendix A CLI reference 833Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/host <host ID>ip <IPaddr>sysName <name>sysL

Página 817

834 Appendix A CLI reference320818-A /cfg/sys/time date <date>time <time>tzonentpConfigure date and time settings for the cluster.page 475

Página 818

Appendix A CLI reference 835Nortel Secure Network Access Switch 4050 User Guide Boot menuThe Boot menu contains commands for management of Nortel SNAS

Página 819

836 Appendix A CLI reference320818-A Maintenance menuThe Maintenance menu contains commands used to perform maintenance and management activities for

Página 820

837Nortel Secure Network Access Switch 4050 User Guide Chapter 18 TroubleshootingThis chapter includes the following topics:Troubleshooting tipsThis c

Página 821

838 Chapter 18 Troubleshooting320818-A Cannot connect to the Nortel SNAS 4050 using Telnet or SSHVerify the current configurationConnect with a consol

Página 822

Chapter 18 Troubleshooting 839Nortel Secure Network Access Switch 4050 User Guide When Telnet or SSH access is enabled, only those hosts listed in the

Página 823

84 Chapter 3 Managing the network access devices320818-A Managing SSH keys using the CLIThe Nortel SNAS 4050 and the network access devices controlled

Página 824

840 Chapter 18 Troubleshooting320818-A Ensure that you ping the host IP address (RIP) of the Nortel SNAS 4050, and not the Management IP address (MIP)

Página 825

Chapter 18 Troubleshooting 841Nortel Secure Network Access Switch 4050 User Guide Cannot add the Nortel SNAS 4050 to a clusterWhen you try to add a No

Página 826

842 Chapter 18 Troubleshooting320818-A The problem may be that there are existing entries in the Access List. When Telnet or SSH access is enabled, on

Página 827

Chapter 18 Troubleshooting 843Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 stops respondingTelnet or SSH connection to the

Página 828

844 Chapter 18 Troubleshooting320818-A If the operational status of the Nortel SNAS 4050 is still down, reboot the machine. On the device, press the P

Página 829

Chapter 18 Troubleshooting 845Nortel Secure Network Access Switch 4050 User Guide Boot user passwordThe default Boot user password cannot be changed,

Página 830

846 Chapter 18 Troubleshooting320818-A For more information about the starttrace command, the tags you can specify for the trace, and the available ou

Página 831

Chapter 18 Troubleshooting 847Nortel Secure Network Access Switch 4050 User Guide System diagnosticsThe following are useful diagnostic display comman

Página 832

848 Chapter 18 Troubleshooting320818-A To check network settings for a specific Nortel SNAS 4050, access the Cluster Host menu by typing the following

Página 833

Chapter 18 Troubleshooting 849Nortel Secure Network Access Switch 4050 User Guide To capture and analyze TCP traffic between clients and the virtual S

Página 834

Chapter 3 Managing the network access devices 85Nortel Secure Network Access Switch 4050 User Guide If you regenerate the key at any time, you must re

Página 835 - Boot menu

850 Chapter 18 Troubleshooting320818-A server you specify. The information can then be used for technical support purposes. The file sent to the TFTP/

Página 836 - Maintenance menu

851Nortel Secure Network Access Switch 4050 User Guide Appendix BSyslog messagesThis appendix contains a list of the syslog messages that are sent fro

Página 837 - Troubleshooting

852 Appendix B Syslog messages320818-A Operating system (OS) messagesThere are three categories of operating system (OS) system messages:• EMERG (see

Página 838 - Check the Access List

Appendix B Syslog messages 853Nortel Secure Network Access Switch 4050 User Guide Table 190 lists the operating system EMERG messages.System Control P

Página 839

854 Appendix B Syslog messages320818-A Table 191 lists the System Control Process INFO messages.About alarm messagesAlarms are sent at a syslog level

Página 840

Appendix B Syslog messages 855Nortel Secure Network Access Switch 4050 User Guide Table 193 lists the System Control Process ALARM messages. To simpli

Página 841 - Cannot contact the MIP

856 Appendix B Syslog messages320818-A About event messagesEvents are sent at the NOTICE syslog level. Event messages are formatted according to the f

Página 842

Appendix B Syslog messages 857Nortel Secure Network Access Switch 4050 User Guide Traffic Processing Subsystem messagesThere are four categories of Tr

Página 843 - Console connection

858 Appendix B Syslog messages320818-A css error: <reason> ERROR Problem encountered when parsing a style sheet. The problem could be in the Nor

Página 844 - A user password is lost

Appendix B Syslog messages 859Nortel Secure Network Access Switch 4050 User Guide Table 197 lists the Traffic Processing WARNING messages.socks error:

Página 845 - Trace tools

86 Chapter 3 Managing the network access devices320818-A The NSNAS SSH key menu includes the following options:/cfg/domain #/sshkeyfollowed by:generat

Página 846

860 Appendix B Syslog messages320818-A Table 198 lists the Traffic Processing INFO messages.Start-up messagesThe Traffic Processing Subsystem Start-up

Página 847 - System diagnostics

Appendix B Syslog messages 861Nortel Secure Network Access Switch 4050 User Guide Table 199 lists the Start-up INFO messages.AAA subsystem messagesThe

Página 848

862 Appendix B Syslog messages320818-A Table 201 lists the AAA INFO messages. INFO messages are generated only if the CLI command /cfg/domain #/adv/lo

Página 849 - Error log files

Appendix B Syslog messages 863Nortel Secure Network Access Switch 4050 User Guide NSNAS subsystem messagesThere are two categories of NSNAS subsystem

Página 850

864 Appendix B Syslog messages320818-A Table 202 lists the NSNAS ERROR messages.Table 203 lists the NSNAS INFO messages.Table 202 NSNAS — ERRORMessa

Página 851 - Syslog messages

Appendix B Syslog messages 865Nortel Secure Network Access Switch 4050 User Guide Syslog messages in alphabetical orderTable 204 lists the syslog mess

Página 852

866 Appendix B Syslog messages320818-A audit EVENT System Control Sent when a CLI system administrator enters, enters, exits or updates the CLI if aud

Página 853

Appendix B Syslog messages 867Nortel Secure Network Access Switch 4050 User Guide copy_software_release_failed ALARM (CRITICAL)System Control A Nortel

Página 854 - About alarm messages

868 Appendix B Syslog messages320818-A gzip warning: <reason> INFO Traffic ProcessingProblem encountered when processing compressed content.HC:

Página 855 - Table 193

Appendix B Syslog messages 869Nortel Secure Network Access Switch 4050 User Guide isd_down ALARM (CRITICAL)System Control A member of the Nortel SNAS

Página 856 - About event messages

Chapter 3 Managing the network access devices 87Nortel Secure Network Access Switch 4050 User Guide Figure 5 shows sample output for the /cfg/domain #

Página 857

870 Appendix B Syslog messages320818-A make_software_release_permanent_failedALARM (CRITICAL)System Control Failed to make a new software release perm

Página 858

Appendix B Syslog messages 871Nortel Secure Network Access Switch 4050 User Guide NSNAS LoginSucceeded Domain=”<id>” Method=<”ssl”> SrcIp=

Página 859

872 Appendix B Syslog messages320818-A Root filesystem repaired - rebootingERROR OS fsck found and fixed errors. Probably OK.Server <id> uses de

Página 860 - Start-up messages

Appendix B Syslog messages 873Nortel Secure Network Access Switch 4050 User Guide switch controller:switch [1:<switchID>] – DisconnectedINFO NSN

Página 861 - AAA subsystem messages

874 Appendix B Syslog messages320818-A Unable to use the certificate for <server nr>ERROR Traffic ProcessingUnsuitable certificate configured fo

Página 862 - Table 201

875Nortel Secure Network Access Switch 4050 User Guide Appendix CSupported MIBsThis appendix describes the Management Information Bases (MIB) and trap

Página 863 - NSNAS subsystem messages

876 Appendix C Supported MIBs320818-A • ALTEON-SSL-VPN-MIB• ANAifType-MIB• DISMAN-EVENT-MIB•ENTITY-MIB•IF-MIB• IP-FORWARD-MIB•IP-MIB• NORTEL-SECURE-AC

Página 864 - Table 202

Appendix C Supported MIBs 877Nortel Secure Network Access Switch 4050 User Guide ALTEON-ISD-SSL-MIB Contains objects for monitoring the SSL gateways.

Página 865 - NSNAS — INFO (Sheet 2 of 2)

878 Appendix C Supported MIBs320818-A NORTEL-SECURE-ACCESS-SWITCH-MIBContains objects for monitoring the Nortel SNAS 4050 devices. The following group

Página 866

Appendix C Supported MIBs 879Nortel Secure Network Access Switch 4050 User Guide Supported trapsTable 206 describes the traps supported by the Nortel

Página 867

88 Chapter 3 Managing the network access devices320818-A Managing SSH keys for Nortel SNA communication using the CLITo retrieve the public key for th

Página 868

880 Appendix C Supported MIBs320818-A

Página 869 - /cfg/sys/cur

881Nortel Secure Network Access Switch 4050 User Guide Appendix DSupported ciphersThe Nortel SNAS 4050 supports SSL version 2.0, SSL version 3.0, and

Página 870

882 Appendix D Supported ciphers320818-A EDH-RSA-DES-CBC-SHA SSLv3 DH, RSA DES (56) SHA1DES-CBC-SHA SSLv3 RSA, RSA DES (56) SHA1DES-CBC-MD5 SSLv2 RSA,

Página 871

883Nortel Secure Network Access Switch 4050 User Guide Appendix EAdding User Preferences attribute to Active DirectoryFor the remote user to be able t

Página 872

884 Appendix E Adding User Preferences attribute to Active Directory320818-A Add the Active Directory Schema Snap-in (Windows 2000 Server and Windows

Página 873

Appendix E Adding User Preferences attribute to Active Directory 885Nortel Secure Network Access Switch 4050 User Guide The Add/Remove Snap-in window

Página 874

886 Appendix E Adding User Preferences attribute to Active Directory320818-A 8 Click OK.The Console window redisplays.9 To save the console (including

Página 875 - Supported MIBs

Appendix E Adding User Preferences attribute to Active Directory 887Nortel Secure Network Access Switch 4050 User Guide 3 Select the check box The Sch

Página 876 - Supported MIBs (Sheet 1 of 3)

888 Appendix E Adding User Preferences attribute to Active Directory320818-A Create the new classTo create the nortelSSLOffload class, proceed as foll

Página 877 - Supported MIBs (Sheet 2 of 3)

Appendix E Adding User Preferences attribute to Active Directory 889Nortel Secure Network Access Switch 4050 User Guide 5 Add the isdUserPrefs attribu

Página 878 - Supported MIBs (Sheet 3 of 3)

Chapter 3 Managing the network access devices 89Nortel Secure Network Access Switch 4050 User Guide Reimporting the network access device SSH key usin

Página 879 - Supported traps

890 Appendix E Adding User Preferences attribute to Active Directory320818-A 5 Add the nortelSSLOffload class as an auxiliary class as shown below: 6

Página 880 - 880 Appendix C Supported MIBs

891Nortel Secure Network Access Switch 4050 User Guide Appendix FConfiguring DHCP to auto-configure IP PhonesThe DHCP server and the IP Phone 2002, IP

Página 881 - Supported ciphers

892 Appendix F Configuring DHCP to auto-configure IP Phones320818-A For information on the minimum firmware versions required to support IP Phones in

Página 882 - Table 207 Supported ciphers

Appendix F Configuring DHCP to auto-configure IP Phones 893Nortel Secure Network Access Switch 4050 User Guide Figure 245 The DHCP Management Consol

Página 883 - Directory

894 Appendix F Configuring DHCP to auto-configure IP Phones320818-A The Predefined Options and Values dialog box opens (see Figure 246).Figure 246 T

Página 884

Appendix F Configuring DHCP to auto-configure IP Phones 895Nortel Secure Network Access Switch 4050 User Guide Figure 247 The Option Type dialog box

Página 885

896 Appendix F Configuring DHCP to auto-configure IP Phones320818-A b In the Option Type dialog box, enter the required information (see Table 209).c

Página 886 - (Windows 2000 Server)

Appendix F Configuring DHCP to auto-configure IP Phones 897Nortel Secure Network Access Switch 4050 User Guide The Scope Options dialog box displays (

Página 887 - Create a new attribute

898 Appendix F Configuring DHCP to auto-configure IP Phones320818-A 4 Configure Call Server Information:a Select the check box beside 128 Call Server

Página 888 - Create the new class

Appendix F Configuring DHCP to auto-configure IP Phones 899Nortel Secure Network Access Switch 4050 User Guide 5 Configure VLAN Information:a In the S

Página 889

Contents 9Nortel Secure Network Access Switch 4050 User Guide Modifying a client filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Página 890

90 Chapter 3 Managing the network access devices320818-A The HealthCheck menu includes the following options:Controlling communication with the networ

Página 891 - Appendix F

900 Appendix F Configuring DHCP to auto-configure IP Phones320818-A

Página 892 - Creating the DHCP options

901Nortel Secure Network Access Switch 4050 User Guide Appendix GUsing a Windows domain logon script to launch the Nortel SNAS 4050 portalThis appendi

Página 893 - The DHCP Management Console

902 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 2 On a Windows 2000 domain controller, save the scrip

Página 894 - 4 Click Add

Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal 903Nortel Secure Network Access Switch 4050 User Guide 2 Compose

Página 895 - The Option Type dialog box

904 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 3 On the Group Policy tab, click Open.4 Double-click

Página 896 - Information options

905Nortel Secure Network Access Switch 4050 User Guide Appendix HSoftware licensing informationOpenSSL License issuesThe OpenSSL toolkit stays under a

Página 897 - Figure 248

906 Appendix H Software licensing information320818-A conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., c

Página 898

Appendix H Software licensing information 907Nortel Secure Network Access Switch 4050 User Guide warranty; keep intact all the notices that refer to t

Página 899 - Setting up the IP Phone

908 Appendix H Software licensing information320818-A 4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided

Página 900

Appendix H Software licensing information 909Nortel Secure Network Access Switch 4050 User Guide LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY

Página 901 - Appendix G

Chapter 3 Managing the network access devices 91Nortel Secure Network Access Switch 4050 User Guide To restart communication between the Nortel SNAS 4

Página 902 - Creating a logon script

910 Appendix H Software licensing information320818-A Bouncy Castle licenseCopyright (c) 2000 - 2004 The Legion Of The Bouncy Castle (http://www.bounc

Página 903 - Assigning the logon script

Nortel Secure Network Access Switch 4050 User Guide911 IndexSymbols/ (in CLI) 804? (help, in CLI) 804Aaborting commands (CLI) 807accessenable for SSH

Página 904 - Assigning a logon script

912 Index320818-A automatic redirection, from portal 396autorun linksets 394Bbackend interfaceconfigure 145backupcertificates and keys 574, 591, 605c

Página 905 - Appendix H

Index 913Nortel Secure Network Access Switch 4050 User Guide create 214modify 217clusteradd Nortel SNAS 4050 device 61and Access List 62benefits 39c

Página 906 - GNU General Public License

914 Index320818-A RADIUS authentication method 242, 272CSR (Certificate Signing Request)and associated private key 583generate 579, 601information re

Página 907

Index 915Nortel Secure Network Access Switch 4050 User Guide create 203, 220map linksets 206, 223, 227modify 222remove linksets 229reorder linksets

Página 908

916 Index320818-A IP addresses 51in two-armed configuration 52MIP 51pVIP 51RIP 52subnet requirements 52IP Phones, supported in Nortel SNA 33Jjoin a c

Página 909

Index 917Nortel Secure Network Access Switch 4050 User Guide MmacrosLDAP 258, 294used on portal page 395major release upgrade 758manageActive Direct

Página 910 - Bouncy Castle license

918 Index320818-A RIP 52role in Nortel SNA solution 33SSH public key, export 84nslookup (CLI global command) 805Oone-armed configuration 40, 41online

Página 911

Index 919Nortel Secure Network Access Switch 4050 User Guide create method 242, 272in Nortel SNA 36manage servers 247, 279, 281modify configuration

Página 912

92 Chapter 3 Managing the network access devices320818-A The Switches screen appears (see “Switch Configuration screen” on page 116).2 Click Add.The A

Página 913

920 Index320818-A existence monitor 627, 654in Nortel SNA 618manage events 655manage monitor events 647manage targets 638monitors 627supported MIBs 8

Página 914

Index 921Nortel Secure Network Access Switch 4050 User Guide network diagnostics 847Ttechnical publications 29technical support 29Telnetenable acces

Página 915

922 Index320818-A default mapping, domain quick setup wizard 128in Nortel SNA solution 34mapping 82, 96VoIP phones, supported in Nortel SNA 33VoIP VL

Página 916

Chapter 3 Managing the network access devices 93Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The network access device appears in

Página 917

94 Chapter 3 Managing the network access devices320818-A To reconfigure the VLAN mappings for an existing network access device, you must first disabl

Página 918

Chapter 3 Managing the network access devices 95Nortel Secure Network Access Switch 4050 User Guide 2 Enter the network access device information in t

Página 919

96 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the SREMThe VLANs are configured on the network access devices. You s

Página 920

Chapter 3 Managing the network access devices 97Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domainTo map VLANs in a domain, s

Página 921

98 Chapter 3 Managing the network access devices320818-A Adding VLANs to a domainTo add VLANs to a domain, complete the following steps:1 Select the S

Página 922

Chapter 3 Managing the network access devices 99Nortel Secure Network Access Switch 4050 User Guide Removing VLANs from a domainTo remove existing VLA

Comentários a estes Manuais

Sem comentários