Nortel Networks Nortel Secure Network Access Switch 4050 Instrukcja Użytkownika Strona 1

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Oprogramowanie Nortel Networks Nortel Secure Network Access Switch 4050. Nortel Networks Nortel Secure Network Access Switch 4050 User's Manual Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 0
Part No. 320818-A
December 2005
4655 Great America Parkway
Santa Clara, CA 95054
*320818-A*
Nortel Secure Network Access
Switch 4050 User Guide
Nortel Secure Network Access Switch
Software Release 1.0
Przeglądanie stron 0
1 2 3 4 5 6 ... 921 922

Podsumowanie treści

Strona 1 - Switch 4050 User Guide

Part No. 320818-ADecember 20054655 Great America ParkwaySanta Clara, CA 95054*320818-A*Nortel Secure Network Access Switch 4050 User GuideNortel Secu

Strona 2 - Statement of conditions

10 Contents320818-A Modifying RADIUS configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273Managing additional RADIUS s

Strona 3 - Licensing

100 Chapter 3 Managing the network access devices320818-A Mapping VLANs by switchTo map VLANs by switch, you must first disable the network access dev

Strona 4

Chapter 3 Managing the network access devices 101Nortel Secure Network Access Switch 4050 User Guide • “Removing VLANs from a switch” on page 102Addin

Strona 5 - Contents

102 Chapter 3 Managing the network access devices320818-A Removing VLANs from a switchTo remove existing VLANs from the switch, complete the following

Strona 6

Chapter 3 Managing the network access devices 103Nortel Secure Network Access Switch 4050 User Guide If you created the domain manually, the SSH key w

Strona 7

104 Chapter 3 Managing the network access devices320818-A If the network access device defaults, it generates a new public key. You must reimport the

Strona 8

Chapter 3 Managing the network access devices 105Nortel Secure Network Access Switch 4050 User Guide Generating SSH keys for the domain using the SREM

Strona 9

106 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Strona 10

Chapter 3 Managing the network access devices 107Nortel Secure Network Access Switch 4050 User Guide The Export Key screen appears (see Figure 13).Fig

Strona 11

108 Chapter 3 Managing the network access devices320818-A 2 Enter the export information in the applicable fields. Table 8 describes the fields availa

Strona 12

Chapter 3 Managing the network access devices 109Nortel Secure Network Access Switch 4050 User Guide Managing SSH keys for Nortel SNA communication us

Strona 13

Contents 11Nortel Secure Network Access Switch 4050 User Guide SRS Rule Expression Constructor . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 14

110 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Strona 15

Chapter 3 Managing the network access devices 111Nortel Secure Network Access Switch 4050 User Guide The switch SSH Key screen appears (see Figure 14

Strona 16

112 Chapter 3 Managing the network access devices320818-A The Health Check screen appears (see Figure 15).Figure 15 Health Check screen

Strona 17

Chapter 3 Managing the network access devices 113Nortel Secure Network Access Switch 4050 User Guide 2 Enter the health check information in the appli

Strona 18

114 Chapter 3 Managing the network access devices320818-A The Connected Clients screen appears, displaying information about the connection status and

Strona 19

Chapter 3 Managing the network access devices 115Nortel Secure Network Access Switch 4050 User Guide Controlling communication with the network access

Strona 20

116 Chapter 3 Managing the network access devices320818-A To disable or enable the network access device, perform the following steps:1 Select the Sec

Strona 21

117Nortel Secure Network Access Switch 4050 User Guide Chapter 4 Configuring the domainThis chapter includes the following topics:Topic PageConfigurin

Strona 22

118 Chapter 4 Configuring the domain320818-A A Nortel SNAS 4050 domain encompasses all the switches, authentication servers, and remediation servers a

Strona 23

Chapter 4 Configuring the domain 119Nortel Secure Network Access Switch 4050 User Guide • logging traffic with syslog messages• portal settings (see “

Strona 24 - 24 Contents

12 Contents320818-A Changing a user’s group assignment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365Changing passwords . . . . . .

Strona 25

120 Chapter 4 Configuring the domain320818-A details on|offloglevel fatal|error|warning| info|debug/cfg/domain #/aaa/tg/quick/cfg/domain #/server port

Strona 26

Chapter 4 Configuring the domain 121Nortel Secure Network Access Switch 4050 User Guide Creating a domain using the CLIYou can create a domain in two

Strona 27 - Text conventions

122 Chapter 4 Configuring the domain320818-A When you first create the domain, you are prompted to enter the following parameters:• domain name — a st

Strona 28 - Related information

Chapter 4 Configuring the domain 123Nortel Secure Network Access Switch 4050 User Guide Figure 17 Creating a domainUsing the Nortel SNAS 4050 domain

Strona 29 - How to get help

124 Chapter 4 Configuring the domain320818-A Depending on the options you select in connection with certificates and creating a test user, the two wiz

Strona 30 - 30 Preface

Chapter 4 Configuring the domain 125Nortel Secure Network Access Switch 4050 User Guide c To use an existing certificate, enter the applicable certifi

Strona 31 - Chapter 1

126 Chapter 4 Configuring the domain320818-A c To continue, go to step 8 on page 126.8 Specify whether the SSL server uses chain certificates. 9 If yo

Strona 32 - Supported users

Chapter 4 Configuring the domain 127Nortel Secure Network Access Switch 4050 User Guide 11 To add a network access device, enter the required informat

Strona 33 - Role of the Nortel SNAS 4050

128 Chapter 4 Configuring the domain320818-A The wizard assigns the following default VLAN IDs:• Green VLAN = VLAN ID 110• Yellow VLAN = VLAN ID 120Yo

Strona 34 - Nortel SNA VLANs and filters

Chapter 4 Configuring the domain 129Nortel Secure Network Access Switch 4050 User Guide Deleting a domain using the CLITo delete a domain, use the fol

Strona 35 - Groups and profiles

Contents 13Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the CLI . . . . . . . . . . . . . . . . . . .

Strona 36 - Authentication methods

130 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the CLITo configure the domain, use the following command:/cfg/domain

Strona 37 - Chapter 1 Overview 37

Chapter 4 Configuring the domain 131Nortel Secure Network Access Switch 4050 User Guide portalAccesses the Portal menu, in order to customize the port

Strona 38 - About SSH

132 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the CLIBefore an authenticated client is allowed into the network

Strona 39 - Nortel SNAS 4050 clusters

Chapter 4 Configuring the domain 133Nortel Secure Network Access Switch 4050 User Guide heartbeat <interval>Sets the time interval between check

Strona 40 - 40 Chapter 1 Overview

134 Chapter 4 Configuring the domain320818-A Using the quick TunnelGuard setup wizard in the CLITo configure the settings for the SRS rule check using

Strona 41 - Two-armed configuration

Chapter 4 Configuring the domain 135Nortel Secure Network Access Switch 4050 User Guide The TunnelGuard quick setup wizard creates a default SRS rule

Strona 42 - 42 Chapter 1 Overview

136 Chapter 4 Configuring the domain320818-A The Server 1001 menu includes the following options:Tracing SSL traffic using the CLITo verify connectivi

Strona 43 - Chapter 1 Overview 43

Chapter 4 Configuring the domain 137Nortel Secure Network Access Switch 4050 User Guide The Trace menu displays.The Trace menu includes the following

Strona 44 - 44 Chapter 1 Overview

138 Chapter 4 Configuring the domain320818-A tcpdumpCreates a dump of the TCP traffic flowing between clients and the virtual SSL server. You are prom

Strona 45 - Chapter 1 Overview 45

Chapter 4 Configuring the domain 139Nortel Secure Network Access Switch 4050 User Guide Configuring SSL settings using the CLITo configure SSL-specifi

Strona 46 - 46 Chapter 1 Overview

14 Contents320818-A Chapter 10: Configuring system settings . . . . . . . . . . . . . . . . . . . . . . . . . 457Configuring the cluster using the CLI

Strona 47 - Chapter 1 Overview 47

140 Chapter 4 Configuring the domain320818-A The SSL Settings menu includes the following options:/cfg/domain #/server/sslfollowed by:cert <certifi

Strona 48 - 48 Chapter 1 Overview

Chapter 4 Configuring the domain 141Nortel Secure Network Access Switch 4050 User Guide cachain <certificate index list>Specifies the CA certifi

Strona 49 - Initial setup

142 Chapter 4 Configuring the domain320818-A Configuring traffic log settings using the CLIYou can configure a syslog server to receive User Datagram

Strona 50

Chapter 4 Configuring the domain 143Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Strona 51 - About the IP addresses

144 Chapter 4 Configuring the domain320818-A Configuring HTTP redirect using the CLIYou can configure the Nortel SNAS 4050 domain to automatically red

Strona 52

Chapter 4 Configuring the domain 145Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configure t

Strona 53

146 Chapter 4 Configuring the domain320818-A Configuring RADIUS accounting using the CLIThe Nortel SNAS 4050 can be configured to provide support for

Strona 54

Chapter 4 Configuring the domain 147Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS accounting server to the confi

Strona 55

148 Chapter 4 Configuring the domain320818-A The Radius Accounting Servers menu includes the following options:/cfg/domain #/aaa/radacct/serversfollow

Strona 56

Chapter 4 Configuring the domain 149Nortel Secure Network Access Switch 4050 User Guide Configuring Nortel SNAS 4050-specific attributes using the CLI

Strona 57

Contents 15Nortel Secure Network Access Switch 4050 User Guide Adding a host interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 58

150 Chapter 4 Configuring the domain320818-A The VPN Attribute menu includes the following options:Configuring the domain using the SREMTo configure t

Strona 59

Chapter 4 Configuring the domain 151Nortel Secure Network Access Switch 4050 User Guide • portal settings (see “Customizing the portal and user logon”

Strona 60

152 Chapter 4 Configuring the domain320818-A Manually creating a domain using the SREMTo create and configure a domain manually, perform the following

Strona 61 - Extended profile details

Chapter 4 Configuring the domain 153Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Secure Access Domain dialog box appears

Strona 62

154 Chapter 4 Configuring the domain320818-A Using the SREM Domain Quick WizardThe Nortel SNAS 4050 quick setup wizard is similar to the quick setup w

Strona 63 - Joining a cluster

Chapter 4 Configuring the domain 155Nortel Secure Network Access Switch 4050 User Guide To create a domain using the Nortel SNAS 4050 quick setup wiza

Strona 64

156 Chapter 4 Configuring the domain320818-A 2 Click Domain Quick Wizard.The Domain Quick Wizard — General Settings dialog box appears (see Figure 22)

Strona 65

Chapter 4 Configuring the domain 157Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate dialog box appears (see

Strona 66

158 Chapter 4 Configuring the domain320818-A 6 Click Next.Organization Name Specifies the registered name of the organization. The organization must o

Strona 67 - Chapter 2 Initial setup 67

Chapter 4 Configuring the domain 159Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate Chain dialog box appears

Strona 68

16 Contents320818-A Managing RADIUS audit servers using the SREM . . . . . . . . . . . . . . . . . . . . 559Managing RADIUS authentication of system

Strona 69 - Figure 3

160 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Server dialog box appears (see Figure 25).Figure 25 Domain Quick Wizard – Ser

Strona 70 - 70 Chapter 2 Initial setup

Chapter 4 Configuring the domain 161Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Switch dialog box appears (see Figur

Strona 71 - Chapter 3

162 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Tunnel Guard dialog box appears (see Figure 27).Figure 27 Domain Quick Wizard

Strona 72

Chapter 4 Configuring the domain 163Nortel Secure Network Access Switch 4050 User Guide If there are no problems, then a dialog appears to indicate th

Strona 73

164 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the SREMTo configure a domain, perform the following steps:1 Select t

Strona 74

Chapter 4 Configuring the domain 165Nortel Secure Network Access Switch 4050 User Guide 2 Enter the domain information in the applicable fields. Table

Strona 75

166 Chapter 4 Configuring the domain320818-A Additional domain configuration in the SREMTo configure additional domain settings, there are tabs and tr

Strona 76

Chapter 4 Configuring the domain 167Nortel Secure Network Access Switch 4050 User Guide Table 21 describes the purpose of additional tree components f

Strona 77 - >

168 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the SREMBefore an authenticated client is allowed into the networ

Strona 78 - Manually adding a switch

Chapter 4 Configuring the domain 169Nortel Secure Network Access Switch 4050 User Guide To configure settings for the TunnelGuard host integrity check

Strona 79

Contents 17Nortel Secure Network Access Switch 4050 User Guide Chapter 12: Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 80

170 Chapter 4 Configuring the domain320818-A 2 Enter the TunnelGuard information in the applicable fields. Table 22 describes the TunnelGuard Configur

Strona 81

Chapter 4 Configuring the domain 171Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes to th

Strona 82

172 Chapter 4 Configuring the domain320818-A Using the TunnelGuard Quick Setup in the SREMTo configure settings for the TunnelGuard host integrity che

Strona 83

Chapter 4 Configuring the domain 173Nortel Secure Network Access Switch 4050 User Guide 2 Enter the TunnelGuard information in the applicable fields.

Strona 84

174 Chapter 4 Configuring the domain320818-A Configuring the SSL server using the SREMTo configure settings for the SSL server, perform the following

Strona 85

Chapter 4 Configuring the domain 175Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Strona 86

176 Chapter 4 Configuring the domain320818-A Configuring SSL settings using the SREMTo configure SSL-specific settings for the portal server, perform

Strona 87 - Figure 5

Chapter 4 Configuring the domain 177Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Strona 88 - The SSH Key menu displays

178 Chapter 4 Configuring the domain320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Strona 89

Chapter 4 Configuring the domain 179Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Strona 90

18 Contents320818-A Viewing SONMP topology information using the SREM . . . . . . . . . . . . . . . . 675Viewing switch distribution using the SREM

Strona 91 - /cfg/domain #/switch #/ena

180 Chapter 4 Configuring the domain320818-A 2 Enter the traffic log information in the applicable fields. Table 26 describes the Traffic Log Syslog S

Strona 92 - Add a Switch fields

Chapter 4 Configuring the domain 181Nortel Secure Network Access Switch 4050 User Guide Tracing SSL traffic using the SREMTo verify connectivity and t

Strona 93

182 Chapter 4 Configuring the domain320818-A To configure the domain to automatically redirect HTTP requests to the HTTPS server specified for the dom

Strona 94

Chapter 4 Configuring the domain 183Nortel Secure Network Access Switch 4050 User Guide 2 Enter the redirection information in the applicable fields.

Strona 95 - Table 4

184 Chapter 4 Configuring the domain320818-A • cause of terminationConfigure the RADIUS server in accordance with the recommendations in RFC 2866. Cer

Strona 96

Chapter 4 Configuring the domain 185Nortel Secure Network Access Switch 4050 User Guide Contact your RADIUS system administrator for information about

Strona 97 - Mapping VLANs by domain

186 Chapter 4 Configuring the domain320818-A 2 Enter the RADIUS accounting information in the applicable fields. Table 27 describes the RADIUS account

Strona 98 - Adding VLANs to a domain

Chapter 4 Configuring the domain 187Nortel Secure Network Access Switch 4050 User Guide The Radius Accounting Servers screen appears (see Figure 36).F

Strona 99 - Removing VLANs from a domain

188 Chapter 4 Configuring the domain320818-A 3 Enter the RADIUS accounting server information in the applicable fields. Table 29 describes the Radius

Strona 100 - Mapping VLANs by switch

Chapter 4 Configuring the domain 189Nortel Secure Network Access Switch 4050 User Guide Deleting a RADIUS accounting server using the SREMTo delete a

Strona 101 - Adding VLANs to a switch

Contents 19Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices and software using the SREM . . . . . . . . . 743Mana

Strona 102 - Removing VLANs from a switch

190 Chapter 4 Configuring the domain320818-A

Strona 103

191Nortel Secure Network Access Switch 4050 User Guide Chapter 5 Configuring groups and profilesThis chapter includes the following topics:Topic PageO

Strona 104 - 320818-A

192 Chapter 5 Configuring groups and profiles320818-A OverviewThis section includes the following topics:• “Groups” on page 192• “Linksets” on page 19

Strona 105 - Key Generation screen

Chapter 5 Configuring groups and profiles 193Nortel Secure Network Access Switch 4050 User Guide Each group’s data include the following configurable

Strona 106 - Switch SSH Key fields

194 Chapter 5 Configuring groups and profiles320818-A LinksetsA linkset is a set of links that display on the portal page, so that the user can easily

Strona 107 - Figure 13

Chapter 5 Configuring groups and profiles 195Nortel Secure Network Access Switch 4050 User Guide Extended profilesPassing or failing the SRS rule chec

Strona 108 - Table 8

196 Chapter 5 Configuring groups and profiles320818-A Before you beginBefore you configure groups, client filters, and extended profiles on the Nortel

Strona 109 - Switch SSH Key screen

Chapter 5 Configuring groups and profiles 197Nortel Secure Network Access Switch 4050 User Guide 3 Configure the extended profiles for the group (see

Strona 110

198 Chapter 5 Configuring groups and profiles320818-A Configuring groups using the CLITo create and configure a group, use the following command:/cfg/

Strona 111

Chapter 5 Configuring groups and profiles 199Nortel Secure Network Access Switch 4050 User Guide • number of sessions — the maximum number of simultan

Strona 112 - Figure 15

2320818-A Copyright © Nortel Networks Limited 2005. All rights reserved.The information in this document is subject to change without notice. The stat

Strona 113

20 Contents320818-A Configure the network DNS server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 782Configure the network D

Strona 114 - Table 11

200 Chapter 5 Configuring groups and profiles320818-A Figure 38 shows sample output for the /cfg/domain 1/aaa/group <group ID> command and comma

Strona 115

Chapter 5 Configuring groups and profiles 201Nortel Secure Network Access Switch 4050 User Guide Configuring client filters using the CLITo create and

Strona 116 - Switch Configuration screen

202 Chapter 5 Configuring groups and profiles320818-A The Client Filter menu includes the following options:/cfg/domain 1/aaa/filter <filter ID>

Strona 117 - Configuring the domain

Chapter 5 Configuring groups and profiles 203Nortel Secure Network Access Switch 4050 User Guide Figure 39 shows sample output for the /cfg/domain 1/a

Strona 118 - /cfg/domain

204 Chapter 5 Configuring groups and profiles320818-A When you first create the profile, you are prompted to enter the following parameters:• client f

Strona 119 - Roadmap of domain commands

Chapter 5 Configuring groups and profiles 205Nortel Secure Network Access Switch 4050 User Guide Figure 40 shows sample output for the /cfg/domain 1/a

Strona 120

206 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a group or profile using the CLIYou can tailor the portal page for different

Strona 121

Chapter 5 Configuring groups and profiles 207Nortel Secure Network Access Switch 4050 User Guide Figure 41 shows sample output for the /cfg/domain 1/a

Strona 122 - <domain ID>

208 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the CLITo create a default group, first create a group with exten

Strona 123 - Figure 17 Creating a domain

Chapter 5 Configuring groups and profiles 209Nortel Secure Network Access Switch 4050 User Guide Using the guide for creating groups If you desire add

Strona 124

Contents 21Nortel Secure Network Access Switch 4050 User Guide CLI shortcuts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 125

210 Chapter 5 Configuring groups and profiles320818-A Adding a group To create and configure a group, perform the following steps:1 Select the Secure

Strona 126

Chapter 5 Configuring groups and profiles 211Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Group dialog box appears (see

Strona 127

212 Chapter 5 Configuring groups and profiles320818-A Modifying a groupTo configure a group, perform the following steps:1 Select the Secure Access Do

Strona 128

Chapter 5 Configuring groups and profiles 213Nortel Secure Network Access Switch 4050 User Guide 2 Enter the group information in the applicable field

Strona 129

214 Chapter 5 Configuring groups and profiles320818-A Adding a client filter To create and configure a client filter, perform the following steps:1 Se

Strona 130

Chapter 5 Configuring groups and profiles 215Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Client Filter dialog box appear

Strona 131

216 Chapter 5 Configuring groups and profiles320818-A 4 Click Apply.The new client filter now appears in the Client Filters table.5 Click Apply on the

Strona 132

Chapter 5 Configuring groups and profiles 217Nortel Secure Network Access Switch 4050 User Guide Modifying a client filterTo configure a client filter

Strona 133

218 Chapter 5 Configuring groups and profiles320818-A 2 Enter the Client Filter information in the applicable fields. Table 34 describes the Client Fi

Strona 134

Chapter 5 Configuring groups and profiles 219Nortel Secure Network Access Switch 4050 User Guide Configuring extended profiles using the SREMTo view t

Strona 135

22 Contents320818-A Root user password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 844Boot user password .

Strona 136

220 Chapter 5 Configuring groups and profiles320818-A Adding an extended profile To create an extended profile for a group, perform the following step

Strona 137 - The Trace menu displays

Chapter 5 Configuring groups and profiles 221Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add an Extended Profile dialog box o

Strona 138

222 Chapter 5 Configuring groups and profiles320818-A Modifying an extended profileTo modify an extended profile for a group, perform the following st

Strona 139

Chapter 5 Configuring groups and profiles 223Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Extended Profile information in the appli

Strona 140

224 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a groupTo map a linkset to a group, select the Secure Access Domain > dom

Strona 141

Chapter 5 Configuring groups and profiles 225Nortel Secure Network Access Switch 4050 User Guide Adding linksets to a groupTo add a linkset to a group

Strona 142 - SSL is enabled by default

226 Chapter 5 Configuring groups and profiles320818-A Removing linksets from a groupTo remove a linkset from a group, perform the following steps:1 Se

Strona 143

Chapter 5 Configuring groups and profiles 227Nortel Secure Network Access Switch 4050 User Guide Mapping linksets to a profileTo map a linkset to an e

Strona 144

228 Chapter 5 Configuring groups and profiles320818-A Adding linksets to an extended profileTo add a linkset to an extended profile, perform the follo

Strona 145

Chapter 5 Configuring groups and profiles 229Nortel Secure Network Access Switch 4050 User Guide Removing linksets from an extended profileTo remove a

Strona 146

Contents 23Nortel Secure Network Access Switch 4050 User Guide Create a new attribute(Windows 2000 Server and Windows Server 2003) . . . . . . . . . .

Strona 147

230 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the SREM To create a default group, first create a group with ext

Strona 148

Chapter 5 Configuring groups and profiles 231Nortel Secure Network Access Switch 4050 User Guide 2 Enter the AAA information in the applicable fields.

Strona 149 - NSNAS-Portal-ID)

232 Chapter 5 Configuring groups and profiles320818-A

Strona 150

233Nortel Secure Network Access Switch 4050 User Guide Chapter 6 Configuring authenticationThis chapter includes the following topics:Topic PageOvervi

Strona 151

234 Chapter 6 Configuring authentication320818-A OverviewThe Nortel SNAS 4050 controls authentication of clients when they log on to the network.The N

Strona 152 - Figure 19

Chapter 6 Configuring authentication 235Nortel Secure Network Access Switch 4050 User Guide Before you beginBefore you configure authentication on the

Strona 153 - Add a Secure Access Domain

236 Chapter 6 Configuring authentication320818-A — Vendor-Typeb LDAP servers:— server IP address— port number used for the service— configured account

Strona 154

Chapter 6 Configuring authentication 237Nortel Secure Network Access Switch 4050 User Guide 3 Specify the order in which the authentication methods wi

Strona 155 - Figure 21

238 Chapter 6 Configuring authentication320818-A domainid <domain ID>domaintype <domain type>authproto pap|chapv2timeout <interval>/

Strona 156

Chapter 6 Configuring authentication 239Nortel Secure Network Access Switch 4050 User Guide Configuring authentication methods using the CLITo create

Strona 157

24 Contents320818-A

Strona 158 - 6 Click Next

240 Chapter 6 Configuring authentication320818-A When you first create the method, you are prompted to specify the type. For Nortel Secure Network Acc

Strona 159 - Field Description

Chapter 6 Configuring authentication 241Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configu

Strona 160 - Domain Quick Wizard – Server

242 Chapter 6 Configuring authentication320818-A To configure the current authentication scheme to retrieve user group information from a different au

Strona 161 - Domain Quick Wizard – Switch

Chapter 6 Configuring authentication 243Nortel Secure Network Access Switch 4050 User Guide You can perform the following configuration tasks:• “Addin

Strona 162

244 Chapter 6 Configuring authentication320818-A • vendor type for group — corresponds to the Vendor-Type value used in combination with the Vendor-Id

Strona 163

Chapter 6 Configuring authentication 245Nortel Secure Network Access Switch 4050 User Guide Figure 56 shows sample output for the RADIUS method for th

Strona 164 - Figure 28

246 Chapter 6 Configuring authentication320818-A The RADIUS menu displays.The RADIUS menu includes the following options:/cfg/domain 1/aaa/auth #/radi

Strona 165 - Table 19

Chapter 6 Configuring authentication 247Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLIYou ca

Strona 166 - Table 20

248 Chapter 6 Configuring authentication320818-A The Radius servers menu includes the following options:/cfg/domain 1/aaa/auth #/radius/serversfollowe

Strona 167 - Table 21

Chapter 6 Configuring authentication 249Nortel Secure Network Access Switch 4050 User Guide Configuring session timeout using the CLIYou can configure

Strona 168

25Nortel Secure Network Access Switch 4050 User Guide PrefaceNortel* Secure Network Access (Nortel SNA) is a clientless solution that provides seamles

Strona 169

250 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Strona 170 - Table 22

Chapter 6 Configuring authentication 251Nortel Secure Network Access Switch 4050 User Guide • if user entries are located in several places in the LDA

Strona 171

252 Chapter 6 Configuring authentication320818-A Figure 57 shows sample output for the LDAP method for the /cfg/domain 1/aaa/auth <auth ID> comm

Strona 172

Chapter 6 Configuring authentication 253Nortel Secure Network Access Switch 4050 User Guide The LDAP menu displays.The LDAP menu includes the followin

Strona 173 - Table 23

254 Chapter 6 Configuring authentication320818-A userattr <names>Refers to one of the following:1. the LDAP attribute that contains the user nam

Strona 174 - Figure 31

Chapter 6 Configuring authentication 255Nortel Secure Network Access Switch 4050 User Guide enaldaps true|falseIf true, makes LDAP requests between th

Strona 175 - Table 24

256 Chapter 6 Configuring authentication320818-A Managing LDAP authentication servers using the CLIYou can configure additional LDAP servers for the d

Strona 176 - Figure 32

Chapter 6 Configuring authentication 257Nortel Secure Network Access Switch 4050 User Guide del <index number>Removes the specified LDAP server

Strona 177 - Table 25

258 Chapter 6 Configuring authentication320818-A Managing LDAP macros using the CLIYou can create your own macros (or variables), to allow you to retr

Strona 178

Chapter 6 Configuring authentication 259Nortel Secure Network Access Switch 4050 User Guide add <variable name> <LDAP attribute> [<pref

Strona 179

26 Preface320818-A The document provides instructions for initializing and customizing the features using the Command Line Interface (CLI). To learn t

Strona 180 - Table 26

260 Chapter 6 Configuring authentication320818-A Managing Active Directory passwords using the CLIYou can set up a mechanism for clients to change the

Strona 181

Chapter 6 Configuring authentication 261Nortel Secure Network Access Switch 4050 User Guide Configuring local database authentication using the CLIYou

Strona 182 - Figure 34

262 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Strona 183 - HTTP Redirect fields

Chapter 6 Configuring authentication 263Nortel Secure Network Access Switch 4050 User Guide • group name — the name of the group to which the specifie

Strona 184

264 Chapter 6 Configuring authentication320818-A Managing the local database using the CLIYou can add users to the database in two ways:• manually, us

Strona 185

Chapter 6 Configuring authentication 265Nortel Secure Network Access Switch 4050 User Guide The Local database menu includes the following options:/cf

Strona 186

266 Chapter 6 Configuring authentication320818-A import <protocol> <server> <filename> <key>Imports a database from the specif

Strona 187 - Figure 37

Chapter 6 Configuring authentication 267Nortel Secure Network Access Switch 4050 User Guide Specifying authentication fallback order using the CLIAuth

Strona 188

268 Chapter 6 Configuring authentication320818-A Perform this step even if there is only one method defined on the Nortel SNAS 4050.To specify the aut

Strona 189

Chapter 6 Configuring authentication 269Nortel Secure Network Access Switch 4050 User Guide Configuring authentication using the SREMThe basic steps f

Strona 190

Preface 27Nortel Secure Network Access Switch 4050 User Guide Text conventionsThis guide uses the following text conventions:angle brackets (< >

Strona 191 - Chapter 5

270 Chapter 6 Configuring authentication320818-A Configuring authentication methods using the SREMTo create and configure an authentication method, pe

Strona 192 - Overview

Chapter 6 Configuring authentication 271Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add an Authentication Server dialog box op

Strona 193 - Default group

272 Chapter 6 Configuring authentication320818-A Adding the RADIUS method and serverTo configure the Nortel SNAS 4050 to use an external RADIUS or Ste

Strona 194 - TunnelGuard SRS rule

Chapter 6 Configuring authentication 273Nortel Secure Network Access Switch 4050 User Guide 2 Enter the authentication server information in the appli

Strona 195 - Extended profiles

274 Chapter 6 Configuring authentication320818-A • Modify settings for the specific RADIUS configuration (see “Modifying RADIUS configuration settings

Strona 196 - Before you begin

Chapter 6 Configuring authentication 275Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Strona 197

276 Chapter 6 Configuring authentication320818-A Modifying RADIUS configuration settingsTo modify the RADIUS method configuration, perform the followi

Strona 198

Chapter 6 Configuring authentication 277Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the RADIUS configuration as necessar

Strona 199

278 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Strona 200 - Figure 38

Chapter 6 Configuring authentication 279Nortel Secure Network Access Switch 4050 User Guide Managing additional RADIUS serversAdditional RADIUS server

Strona 201

28 Preface320818-A Related informationThis section lists information sources that relate to this document.PublicationsRefer to the following publicati

Strona 202

280 Chapter 6 Configuring authentication320818-A The RADIUS Server Table allows you to manage additional RADIUS servers by performing any of the follo

Strona 203

Chapter 6 Configuring authentication 281Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new RADIUS server is automatically assig

Strona 204

282 Chapter 6 Configuring authentication320818-A The RADIUS Servers screen appears (see Figure 69 on page 291).2 Select an RADIUS server entry from th

Strona 205 - Figure 40

Chapter 6 Configuring authentication 283Nortel Secure Network Access Switch 4050 User Guide Adding the LDAP method and serverTo configure the Nortel S

Strona 206

284 Chapter 6 Configuring authentication320818-A 3 Click Apply.The LDAP authentication method displays in the Authentication Server Table.4 Click Appl

Strona 207 - Figure 41

Chapter 6 Configuring authentication 285Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP method settingsTo modify settings for an ex

Strona 208

286 Chapter 6 Configuring authentication320818-A 2 Modify settings for the authentication method as necessary.Table 45 describes the Configuration fie

Strona 209

Chapter 6 Configuring authentication 287Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP configuration settingsTo modify the LDAP me

Strona 210 - Adding a group

288 Chapter 6 Configuring authentication320818-A 2 Modify settings for the LDAP configuration as necessary.Table 46 describes the LDAP Configuration f

Strona 211 - Add a Group fields

Chapter 6 Configuring authentication 289Nortel Secure Network Access Switch 4050 User Guide User Attribute Refers to one of the following:1. the LDAP

Strona 212 - Modifying a group

Preface 29Nortel Secure Network Access Switch 4050 User Guide • Release Notes for Nortel Ethernet Routing Switch 5500 Series, Software Release 4.3 (21

Strona 213 - Group Configuration fields

290 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Strona 214 - Adding a client filter

Chapter 6 Configuring authentication 291Nortel Secure Network Access Switch 4050 User Guide Managing additional LDAP serversAdditional LDAP servers ca

Strona 215 - Adding a Client Filter screen

292 Chapter 6 Configuring authentication320818-A The LDAP Server Table allows you to manage additional LDAP servers by performing any of the following

Strona 216 - 4 Click Apply

Chapter 6 Configuring authentication 293Nortel Secure Network Access Switch 4050 User Guide The new LDAP server is automatically assigned a unique ind

Strona 217 - Modifying a client filter

294 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Strona 218 - Table 34

Chapter 6 Configuring authentication 295Nortel Secure Network Access Switch 4050 User Guide To manage LDAP macro variables, select the Secure Access D

Strona 219

296 Chapter 6 Configuring authentication320818-A Adding LDAP macrosTo create an LDAP macro variable, perform the following steps:1 Select the Secure A

Strona 220 - Adding an extended profile

Chapter 6 Configuring authentication 297Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new LDAP macro is automatically assigned

Strona 221

298 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Strona 222 - Modifying an extended profile

Chapter 6 Configuring authentication 299Nortel Secure Network Access Switch 4050 User Guide Adding the Local methodTo configure the Nortel SNAS 4050 t

Strona 223

3Nortel Secure Network Access Switch 4050 User Guide In addition, the program and information contained herein are licensed only pursuant to a license

Strona 224 - Mapping linksets to a group

30 Preface320818-A • To call a Nortel Technical Solutions Center for assistance, click the CALL US link on the left side of the page to find the telep

Strona 225 - Adding linksets to a group

300 Chapter 6 Configuring authentication320818-A 2 Enter the authentication server information in the applicable fields.Table 49 describes the Add an

Strona 226

Chapter 6 Configuring authentication 301Nortel Secure Network Access Switch 4050 User Guide Populating the databaseYou can populate the Local database

Strona 227 - Mapping linksets to a profile

302 Chapter 6 Configuring authentication320818-A 2 Click Add.The Add a Local User dialog box appears (see Figure 75).Figure 75 Add a Local User3 Ent

Strona 228 - Add a Linkset fields

Chapter 6 Configuring authentication 303Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new user entry appears in the list of lo

Strona 229

304 Chapter 6 Configuring authentication320818-A Importing a database To import a database of local users, perform the following steps.1 Select the Se

Strona 230 - AAA Configuration screen

Chapter 6 Configuring authentication 305Nortel Secure Network Access Switch 4050 User Guide 2 Enter the import information in the applicable fields.Ta

Strona 231 - Table 39

306 Chapter 6 Configuring authentication320818-A Modifying Local method settingsTo modify settings for an existing local or LDAP authentication method

Strona 232

Chapter 6 Configuring authentication 307Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Strona 233 - Configuring authentication

308 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Strona 234

Chapter 6 Configuring authentication 309Nortel Secure Network Access Switch 4050 User Guide 3 Modify the local user information in the applicable fiel

Strona 235

31Nortel Secure Network Access Switch 4050 User Guide Chapter 1 OverviewThis chapter includes the following topics:The Nortel SNA solutionNortel Secur

Strona 236

310 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Strona 237

Chapter 6 Configuring authentication 311Nortel Secure Network Access Switch 4050 User Guide 4 Modify the local user information in the applicable fiel

Strona 238

312 Chapter 6 Configuring authentication320818-A Exporting the databaseTo export the database of local users, perform the following steps:1 Select the

Strona 239

Chapter 6 Configuring authentication 313Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields.Ta

Strona 240

314 Chapter 6 Configuring authentication320818-A Specifying authentication fallback order using the SREMAuthentication in the Nortel SNAS 4050 solutio

Strona 241

Chapter 6 Configuring authentication 315Nortel Secure Network Access Switch 4050 User Guide To specify authentication fallback order, perform these st

Strona 242

316 Chapter 6 Configuring authentication320818-A 3 Rearrange the list so that the methods appear in the desired order.a Click on a method to select it

Strona 243

317Nortel Secure Network Access Switch 4050 User Guide Chapter 7 TunnelGuard SRS BuilderThis chapter includes the following topics:Topic PageConfiguri

Strona 244 - 1/aaa/group <group ID>

318 Chapter 7 TunnelGuard SRS Builder320818-A Configuring SRS rulesThe building blocks used to construct the Software Requirement Set (SRS) are files

Strona 245

Chapter 7 TunnelGuard SRS Builder 319Nortel Secure Network Access Switch 4050 User Guide • “Software Definition — Available SRS list” on page 323• “Me

Strona 246 - The RADIUS menu displays

32 Chapter 1 Overview320818-A For Nortel, success is delivering technologies providing secure access to your information using security-compliant syst

Strona 247

320 Chapter 7 TunnelGuard SRS Builder320818-A Software Definition Entry menuTable 58 describes important items from the Software Definition Entry menu

Strona 248

Chapter 7 TunnelGuard SRS Builder 321Nortel Secure Network Access Switch 4050 User Guide TunnelGuard Rule menuTable 59 describes important items from

Strona 249

322 Chapter 7 TunnelGuard SRS Builder320818-A SRS definition toolbarThe buttons on the SRS definition toolbar allow you to create, delete, and manage

Strona 250

Chapter 7 TunnelGuard SRS Builder 323Nortel Secure Network Access Switch 4050 User Guide Software Definition — Available SRS listThe available SRS lis

Strona 251

324 Chapter 7 TunnelGuard SRS Builder320818-A Customizing a componentWhen an SRS component is selected by clicking on it, you can customize it using t

Strona 252

Chapter 7 TunnelGuard SRS Builder 325Nortel Secure Network Access Switch 4050 User Guide Memory snapshotThe memory snapshot section in the lower half

Strona 253 - The LDAP menu displays

326 Chapter 7 TunnelGuard SRS Builder320818-A SRS Rule listThe SRS Rule list shows the existing SRS rules. These rules are retrieved from the Nortel S

Strona 254

Chapter 7 TunnelGuard SRS Builder 327Nortel Secure Network Access Switch 4050 User Guide Once the expression is formed, it is available for rule defin

Strona 255

328 Chapter 7 TunnelGuard SRS Builder320818-A Figure 84 The New SRS window2 Enter a name for the software definition and click OK.For example, to cr

Strona 256

Chapter 7 TunnelGuard SRS Builder 329Nortel Secure Network Access Switch 4050 User Guide Figure 85 The Create New Memory Module SRS window3 In the F

Strona 257

Chapter 1 Overview 33Nortel Secure Network Access Switch 4050 User Guide Java Runtime Environment (JRE) for all browsers:— JRE 1.5.0_04 or later• VoIP

Strona 258

330 Chapter 7 TunnelGuard SRS Builder320818-A If enabled, the client system will be searched for the specified file name, irrespective of path to fold

Strona 259

Chapter 7 TunnelGuard SRS Builder 331Nortel Secure Network Access Switch 4050 User Guide The file/module is added as an entry in the selected software

Strona 260

332 Chapter 7 TunnelGuard SRS Builder320818-A To create a software definition entry for a file not shown in the memory snapshot, perform the following

Strona 261

Chapter 7 TunnelGuard SRS Builder 333Nortel Secure Network Access Switch 4050 User Guide 3 Select the Fetch Module Path from Registry Entry check box,

Strona 262

334 Chapter 7 TunnelGuard SRS Builder320818-A 2 Click the TunnelGuard Rule Definition tab.TunnelGuard rules and expressions with the same names as the

Strona 263

Chapter 7 TunnelGuard SRS Builder 335Nortel Secure Network Access Switch 4050 User Guide 4 Select another expression that you will use to form a new l

Strona 264

336 Chapter 7 TunnelGuard SRS Builder320818-A Figure 88 The Available Expressions screen7 Create a new TunnelGuard Rule.On the TunnelGuard Rule menu

Strona 265

Chapter 7 TunnelGuard SRS Builder 337Nortel Secure Network Access Switch 4050 User Guide The new rule name appears in the TunnelGuard Rule Name column

Strona 266

338 Chapter 7 TunnelGuard SRS Builder320818-A Registry-based rulesTunnelGuard Agent supports checking of on-disk files, running processes, hash checki

Strona 267

Chapter 7 TunnelGuard SRS Builder 339Nortel Secure Network Access Switch 4050 User Guide Table 66 describes supported operands for integer values.The

Strona 268

34 Chapter 1 Overview320818-A Nortel SNAS 4050 functionsThe Nortel SNAS 4050 performs the following functions:• Acts as a web server portal, which is

Strona 269

340 Chapter 7 TunnelGuard SRS Builder320818-A Table 67 describes supported constructs for string-based regular expressions.Table 67 Constructs for s

Strona 270 - Figure 60

Chapter 7 TunnelGuard SRS Builder 341Nortel Secure Network Access Switch 4050 User Guide The following are examples of regular expressions for string-

Strona 271

342 Chapter 7 TunnelGuard SRS Builder320818-A Figure 91 Registry Entry page3 Select the Registry Key Path from the Registry Editor.4 Select the Key

Strona 272

Chapter 7 TunnelGuard SRS Builder 343Nortel Secure Network Access Switch 4050 User Guide Manually creating SRS entriesThe administrator tool applet pr

Strona 273

344 Chapter 7 TunnelGuard SRS Builder320818-A Figure 92 Create new OnDisk SRS Entry3 Click Browse Local System to select the File or Module Path. Th

Strona 274 - Configuration

Chapter 7 TunnelGuard SRS Builder 345Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for either Relative Date/Time Range

Strona 275 - Table 41

346 Chapter 7 TunnelGuard SRS Builder320818-A Figure 93 Create new Memory Module SRS entry3 Click Browse Local System to select the File or Module P

Strona 276 - Figure 63

Chapter 7 TunnelGuard SRS Builder 347Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for Max Version.7 Click an option bu

Strona 277 - Table 42

348 Chapter 7 TunnelGuard SRS Builder320818-A Figure 94 Date/Time RangeAdding comments• “Adding a TunnelGuard rule comment” on page 348• “Adding a s

Strona 278

Chapter 7 TunnelGuard SRS Builder 349Nortel Secure Network Access Switch 4050 User Guide 3 Click the button to display the Rule Comment window (see Fi

Strona 279 - Radius Servers

Chapter 1 Overview 35Nortel Secure Network Access Switch 4050 User Guide • VoIP — automatic access for VoIP traffic. The network access device places

Strona 280 - Adding a RADIUS server

350 Chapter 7 TunnelGuard SRS Builder320818-A Deleting a software definition1 Click the Software Definition tab.2 In the Software Definition column, s

Strona 281 - Removing a RADIUS server

Chapter 7 TunnelGuard SRS Builder 351Nortel Secure Network Access Switch 4050 User Guide 2 In the Available Expressions area, select the desired expre

Strona 282 - Next steps

352 Chapter 7 TunnelGuard SRS Builder320818-A

Strona 283

353Nortel Secure Network Access Switch 4050 User Guide Chapter 8 Managing system users and groupsThis chapter includes the following topics:Topic Page

Strona 284 - Modifying LDAP configuration

354 Chapter 8 Managing system users and groups320818-A User rights and group membershipThere are three groups of system users who routinely access the

Strona 285

Chapter 8 Managing system users and groups 355Nortel Secure Network Access Switch 4050 User Guide Managing system users and groups using the CLITo man

Strona 286 - Table 45

356 Chapter 8 Managing system users and groups320818-A Managing user accounts and passwords using the CLITo change the password for the currently logg

Strona 287 - Figure 68

Chapter 8 Managing system users and groups 357Nortel Secure Network Access Switch 4050 User Guide del <username>Removes the specified user accou

Strona 288 - Table 46

358 Chapter 8 Managing system users and groups320818-A Managing user settings using the CLIYou must have administrator rights in order to change a use

Strona 289

Chapter 8 Managing system users and groups 359Nortel Secure Network Access Switch 4050 User Guide To set or change the login password for a specified

Strona 290

36 Chapter 1 Overview320818-A Authentication methodsYou can configure more than one authentication method within a Nortel SNAS 4050 domain. Nortel Sec

Strona 291 - LDAP Servers

360 Chapter 8 Managing system users and groups320818-A To set or change a user’s group assignment, access the Groups menu by using the following comma

Strona 292 - Adding an LDAP server

Chapter 8 Managing system users and groups 361Nortel Secure Network Access Switch 4050 User Guide In this configuration example, a certificate adminis

Strona 293 - Removing an LDAP server

362 Chapter 8 Managing system users and groups320818-A —oper—admin— certadminBy default, the admin user is a member of all groups above, and can there

Strona 294 - Managing LDAP macros

Chapter 8 Managing system users and groups 363Nortel Secure Network Access Switch 4050 User Guide 7 Apply the changes.8 Let the Certificate Administra

Strona 295 - LDAP Macros

364 Chapter 8 Managing system users and groups320818-A 9 Remove the admin user from the certadmin group.Again, this step is only necessary if you want

Strona 296 - Adding LDAP macros

Chapter 8 Managing system users and groups 365Nortel Secure Network Access Switch 4050 User Guide Changing a user’s group assignmentOnly users who are

Strona 297 - Removing LDAP macros

366 Chapter 8 Managing system users and groups320818-A 4 Verify and apply the changes.Changing passwordsChanging your own passwordAll users can change

Strona 298

Chapter 8 Managing system users and groups 367Nortel Secure Network Access Switch 4050 User Guide 2 Access the User Menu.Type the passwd command to ch

Strona 299 - Adding the Local method

368 Chapter 8 Managing system users and groups320818-A 2 Access the User Menu.3 Specify the user name of the user whose password you want to change.4

Strona 300

Chapter 8 Managing system users and groups 369Nortel Secure Network Access Switch 4050 User Guide Deleting a userTo delete a user from the system, you

Strona 301 - Populating the database

Chapter 1 Overview 37Nortel Secure Network Access Switch 4050 User Guide TunnelGuard host integrity checkThe TunnelGuard application checks client hos

Strona 302 - Add a Local User fields

370 Chapter 8 Managing system users and groups320818-A The imminent removal of the cert_admin user is indicated as a pending configuration change by t

Strona 303

Chapter 8 Managing system users and groups 371Nortel Secure Network Access Switch 4050 User Guide The User Table appears (see Figure 96), displaying a

Strona 304 - Importing a database

372 Chapter 8 Managing system users and groups320818-A Only the admin user can delete users from the system. Of the three built-in users (admin, oper,

Strona 305

Chapter 8 Managing system users and groups 373Nortel Secure Network Access Switch 4050 User Guide 3 Enter the user information in the applicable field

Strona 306

374 Chapter 8 Managing system users and groups320818-A Setting password expiry using the SREMTo set a password expiry date for all passwords in the sy

Strona 307 - Modifying local users

Chapter 8 Managing system users and groups 375Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Password Setting information in the appl

Strona 308 - Figure 78

376 Chapter 8 Managing system users and groups320818-A Changing your password using the SREMOnly the admin user can change the passwords of other user

Strona 309

Chapter 8 Managing system users and groups 377Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Strona 310

378 Chapter 8 Managing system users and groups320818-A To change the password for another user, perform the following steps:1 Select the System > M

Strona 311 - Table 54

Chapter 8 Managing system users and groups 379Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Strona 312 - Exporting the database

38 Chapter 1 Overview320818-A Communication channelsCommunications between the Nortel SNAS 4050 and key elements of the Nortel SNA solution are secure

Strona 313

380 Chapter 8 Managing system users and groups320818-A To set a certificate export pass phrase, perform the following steps:1 Select the System > M

Strona 314

Chapter 8 Managing system users and groups 381Nortel Secure Network Access Switch 4050 User Guide 2 Enter the PassPhrase information in the applicable

Strona 315 - Authentication Server Order

382 Chapter 8 Managing system users and groups320818-A To manage the group to which a user belongs, select the System > Manage Users > user >

Strona 316

Chapter 8 Managing system users and groups 383Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a User Group dialog box appears

Strona 317 - TunnelGuard SRS Builder

384 Chapter 8 Managing system users and groups320818-A The user group is immediately removed from the User Group Table.5 Click Apply on the toolbar to

Strona 318 - Configuring SRS rules

385Nortel Secure Network Access Switch 4050 User Guide Chapter 9 Customizing the portal and user logonThis chapter includes the following topics:Topic

Strona 319 - Menu commands

386 Chapter 9 Customizing the portal and user logon320818-A OverviewThe end user accesses the Nortel SNA network through the Nortel SNAS 4050 portal.

Strona 320

Chapter 9 Customizing the portal and user logon 387Nortel Secure Network Access Switch 4050 User Guide • redirects client requests to an authenticatio

Strona 321 - Tool menu

388 Chapter 9 Customizing the portal and user logon320818-A Table 75 lists the regular expressions and escape sequences you can use in an Exclude List

Strona 322 - SRS definition toolbar

Chapter 9 Customizing the portal and user logon 389Nortel Secure Network Access Switch 4050 User Guide Portal displayYou can modify the following feat

Strona 323 - SRS Components table

Chapter 1 Overview 39Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 supports the use of three different SSH host key types:

Strona 324 - Customizing a component

390 Chapter 9 Customizing the portal and user logon320818-A Default appearanceFigure 104 shows the default portal Home tab.Figure 104 Default appear

Strona 325 - Memory snapshot

Chapter 9 Customizing the portal and user logon 391Nortel Secure Network Access Switch 4050 User Guide • color3 — the fields, information area, and cl

Strona 326 - Rule Expression Constructor

392 Chapter 9 Customizing the portal and user logon320818-A For the commands to configure the colors used on the portal, see “Changing the portal colo

Strona 327

Chapter 9 Customizing the portal and user logon 393Nortel Secure Network Access Switch 4050 User Guide To change the language displayed for tab names,

Strona 328 - The New SRS window

394 Chapter 9 Customizing the portal and user logon320818-A Linksets and linksYou can add the following types of links to the portal Home tab:• Extern

Strona 329

Chapter 9 Customizing the portal and user logon 395Nortel Secure Network Access Switch 4050 User Guide Planning the linksetsPlan your configuration so

Strona 330

396 Chapter 9 Customizing the portal and user logon320818-A Automatic redirection to internal sitesYou can configure the portal to automatically redir

Strona 331 - Selecting file on disk

Chapter 9 Customizing the portal and user logon 397Nortel Secure Network Access Switch 4050 User Guide Managing the end user experienceNortel recommen

Strona 332

398 Chapter 9 Customizing the portal and user logon320818-A 2 Download the JRE installer from the Sun Microsystems Java web site (http://www.java.com)

Strona 333 - Creating logical expressions

Chapter 9 Customizing the portal and user logon 399Nortel Secure Network Access Switch 4050 User Guide /cfg/domain 1/dnscapt/exclude listdel <index

Strona 334

4320818-A BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nort

Strona 335

40 Chapter 1 Overview320818-A • fault tolerance — If a Nortel SNAS 4050 device fails, the failure is detected by the other node in the cluster, which

Strona 336 - The New SRS Rule window

400 Chapter 9 Customizing the portal and user logon320818-A color2 <code>color3 <code>color4 <code>theme default|aqua|apple| jeans|c

Strona 337

Chapter 9 Customizing the portal and user logon 401Nortel Secure Network Access Switch 4050 User Guide Configuring the captive portal using the CLIBy

Strona 338 - Registry-based rules

402 Chapter 9 Customizing the portal and user logon320818-A The DNS Exclude menu includes the following options:Changing the portal language using the

Strona 339 - Supported integer operands

Chapter 9 Customizing the portal and user logon 403Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the CLITo ma

Strona 340 - Table 67

404 Chapter 9 Customizing the portal and user logon320818-A The Language Support menu includes the following options:/cfg/langfollowed by:import <p

Strona 341 - Creating a registry entry

Chapter 9 Customizing the portal and user logon 405Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the C

Strona 342 - Registry-based File/Module

406 Chapter 9 Customizing the portal and user logon320818-A Configuring the portal display using the CLITo modify the look and feel of the portal page

Strona 343 - Manually creating SRS entries

Chapter 9 Customizing the portal and user logon 407Nortel Secure Network Access Switch 4050 User Guide redirect <URL>Sets the URL to which clien

Strona 344 - Create new OnDisk SRS Entry

408 Chapter 9 Customizing the portal and user logon320818-A linktext <text>Specifies static text to be displayed above the group links on the po

Strona 345

Chapter 9 Customizing the portal and user logon 409Nortel Secure Network Access Switch 4050 User Guide Changing the portal colors using the CLITo cust

Strona 346

Chapter 1 Overview 41Nortel Secure Network Access Switch 4050 User Guide One-armed configurationIn a one-armed configuration, the Nortel SNAS 4050 has

Strona 347 - File age check

410 Chapter 9 Customizing the portal and user logon320818-A The Portal Colors menu includes the following options:For more information about the porta

Strona 348 - Adding comments

Chapter 9 Customizing the portal and user logon 411Nortel Secure Network Access Switch 4050 User Guide The Portal Custom Content menu includes the fol

Strona 349 - The Rule Comment window

412 Chapter 9 Customizing the portal and user logon320818-A Configuring linksets using the CLIA linkset is a set of links that display on the portal H

Strona 350 - Deleting an expression

Chapter 9 Customizing the portal and user logon 413Nortel Secure Network Access Switch 4050 User Guide The Linkset menu includes the following options

Strona 351 - Making API calls

414 Chapter 9 Customizing the portal and user logon320818-A Configuring links using the CLITo create and configure the links included in the linkset,

Strona 352

Chapter 9 Customizing the portal and user logon 415Nortel Secure Network Access Switch 4050 User Guide The Link menu includes the following options:/c

Strona 353 - Chapter 8

416 Chapter 9 Customizing the portal and user logon320818-A Configuring external link settings using the CLITo launch the wizard to configure settings

Strona 354

Chapter 9 Customizing the portal and user logon 417Nortel Secure Network Access Switch 4050 User Guide Customizing the portal and logon using the SREM

Strona 355

418 Chapter 9 Customizing the portal and user logon320818-A Figure 105 DNS Capture screenThe DNS Capture screen includes the following components:2

Strona 356

Chapter 9 Customizing the portal and user logon 419Nortel Secure Network Access Switch 4050 User Guide Configuring the DNS Exclude List using the SREM

Strona 357

42 Chapter 1 Overview320818-A Figure 2 illustrates a two-armed configuration.Figure 2 Two-armed configurationNortel SNA configuration and management

Strona 358

420 Chapter 9 Customizing the portal and user logon320818-A 3 To remove an entry from the Exclude List:a In the DNS Exclude List, select the entry you

Strona 359

Chapter 9 Customizing the portal and user logon 421Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the SREMTo m

Strona 360 - CLI configuration examples

422 Chapter 9 Customizing the portal and user logon320818-A Viewing predefined languagesTo view predefined languages, click the Pre-defined Languages

Strona 361

Chapter 9 Customizing the portal and user logon 423Nortel Secure Network Access Switch 4050 User Guide b Click Apply on the toolbar to send the curren

Strona 362 - Old: is empty

424 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Language information in the applicable fields. Table 80 describes the Import D

Strona 363

Chapter 9 Customizing the portal and user logon 425Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the S

Strona 364 - /cfg/cert)

426 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the language information in the applicable fields. Table 81 describes the Langauge

Strona 365

Chapter 9 Customizing the portal and user logon 427Nortel Secure Network Access Switch 4050 User Guide Configuring contentTo configure and modify port

Strona 366 - Changing your own password

428 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Portal Configuration information in the applicable fields. Table 82 describes

Strona 367

Chapter 9 Customizing the portal and user logon 429Nortel Secure Network Access Switch 4050 User Guide Redirect URL Sets the URL to which clients are

Strona 368 - 5 Apply the changes

Chapter 1 Overview 43Nortel Secure Network Access Switch 4050 User Guide • Security & Routing Element Manager (SREM)The SREM is a GUI application

Strona 369 - Deleting a user

430 Chapter 9 Customizing the portal and user logon320818-A Importing bannersTo import a banner to display on the portal Home page, perform the follow

Strona 370

Chapter 9 Customizing the portal and user logon 431Nortel Secure Network Access Switch 4050 User Guide 2 Enter the banner information in the applicabl

Strona 371 - User Table

432 Chapter 9 Customizing the portal and user logon320818-A Changing the portal colors using the SREMTo customize the colors used for portal display,

Strona 372 - Adding new user accounts

Chapter 9 Customizing the portal and user logon 433Nortel Secure Network Access Switch 4050 User Guide 2 Enter the color information in the applicable

Strona 373 - Add a User fields

434 Chapter 9 Customizing the portal and user logon320818-A Configuring custom content using the SREMTo configure custom content, such as Java applets

Strona 374 - Figure 98

Chapter 9 Customizing the portal and user logon 435Nortel Secure Network Access Switch 4050 User Guide Viewing basic information about custom contentT

Strona 375 - Table 70

436 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the basic information in the applicable fields. Table 85 describes the Basics fiel

Strona 376 - Change Your Password

Chapter 9 Customizing the portal and user logon 437Nortel Secure Network Access Switch 4050 User Guide Importing custom contentTo import custom conten

Strona 377 - Change Your Password fields

438 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the import information in the applicable fields. Table 86 describes the Import Con

Strona 378 - Figure 100

Chapter 9 Customizing the portal and user logon 439Nortel Secure Network Access Switch 4050 User Guide Exporting custom contentTo export custom conten

Strona 379 - Change User Password fields

44 Chapter 1 Overview320818-A For each VLAN:a Create a DHCP scope.b Specify the IP address range and subnet mask for that scope.c Configure the follow

Strona 380 - Figure 101

440 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the export information in the applicable fields. Table 87 describes the Export Con

Strona 381

Chapter 9 Customizing the portal and user logon 441Nortel Secure Network Access Switch 4050 User Guide Creating a linksetTo create a linkset, perform

Strona 382 - Adding a user group

442 Chapter 9 Customizing the portal and user logon320818-A 2 Click Add.The Add a Linkset dialog box appears (see Figure 118).Figure 118 Add a Links

Strona 383 - Removing a user group

Chapter 9 Customizing the portal and user logon 443Nortel Secure Network Access Switch 4050 User Guide Modifying a linksetTo modify a linkset, perform

Strona 384

444 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the linkset information in the applicable fields. Table 89 describes the linkset C

Strona 385 - Chapter 9

Chapter 9 Customizing the portal and user logon 445Nortel Secure Network Access Switch 4050 User Guide Configuring links using the SREMAfter you creat

Strona 386

446 Chapter 9 Customizing the portal and user logon320818-A Creating an external link using the SREMTo create an external link, perform the following

Strona 387 - Exclude List

Chapter 9 Customizing the portal and user logon 447Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Portal Link dialog box ap

Strona 388 - Table 75

448 Chapter 9 Customizing the portal and user logon320818-A 5 Click Apply.The new external link appears in the Links table.6 Click Apply on the toolba

Strona 389 - Portal display

Chapter 9 Customizing the portal and user logon 449Nortel Secure Network Access Switch 4050 User Guide To create an FTP link, perform the following st

Strona 390 - Default appearance

Chapter 1 Overview 45Nortel Secure Network Access Switch 4050 User Guide Use the applicable show commands on the router to verify that DHCP relay has

Strona 391

450 Chapter 9 Customizing the portal and user logon320818-A 4 Enter the link information in the applicable fields. Table 91 describes the Add a Portal

Strona 392 - Language localization

Chapter 9 Customizing the portal and user logon 451Nortel Secure Network Access Switch 4050 User Guide Modifying external link settings using the SREM

Strona 393

452 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 92 describes the external lin

Strona 394 - Autorun linksets

Chapter 9 Customizing the portal and user logon 453Nortel Secure Network Access Switch 4050 User Guide Modifying FTP link settings using the SREMTo mo

Strona 395 - Planning the linksets

454 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 93 describes the FTP link Con

Strona 396

Chapter 9 Customizing the portal and user logon 455Nortel Secure Network Access Switch 4050 User Guide The Re Order Links screen appears (see Figure 1

Strona 397 - Automatic JRE upload

456 Chapter 9 Customizing the portal and user logon320818-A

Strona 398 - Windows domain logon script

457Nortel Secure Network Access Switch 4050 User Guide Chapter 10 Configuring system settingsThis chapter includes the following topics:Topic PageConf

Strona 399 - Command Parameter

458 Chapter 10 Configuring system settings320818-A System settings apply to a cluster as a whole.You can log on to either the Management IP address (M

Strona 400

Chapter 10 Configuring system settings 459Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the CLITo configure the cl

Strona 401

46 Chapter 1 Overview320818-A Identify switch ports as either uplink or dynamic. When you configure the uplink ports, you associate the NSNA VLANs wit

Strona 402

460 Chapter 10 Configuring system settings320818-A • disabling SSL traffic trace commands (see “Configuring system settings using the CLI” on page 463

Strona 403 - /cfg/lang

Chapter 10 Configuring system settings 461Nortel Secure Network Access Switch 4050 User Guide del <index number>add <IPaddr> <mask>

Strona 404

462 Chapter 10 Configuring system settings320818-A health <interval>hdown <count>hup <count>/cfg/sys/dns/serverslistdel <index nu

Strona 405

Chapter 10 Configuring system settings 463Nortel Secure Network Access Switch 4050 User Guide show/cfg/sys/adm/sshkeys/knownhostslistdel <index num

Strona 406 - The Portal menu displays

464 Chapter 10 Configuring system settings320818-A Configuring system settings using the CLITo view and configure cluster-wide system settings, use th

Strona 407

Chapter 10 Configuring system settings 465Nortel Secure Network Access Switch 4050 User Guide Configuring the Nortel SNAS 4050 host using the CLITo co

Strona 408

466 Chapter 10 Configuring system settings320818-A The Cluster Host menu includes the following options:/cfg/sys/host <host ID>followed by:ip &l

Strona 409

Chapter 10 Configuring system settings 467Nortel Secure Network Access Switch 4050 User Guide portAccesses the Host Port menu, in order to configure p

Strona 410

468 Chapter 10 Configuring system settings320818-A rebootReboots the Nortel SNAS 4050.If the Nortel SNAS 4050 you want to reboot has become isolated f

Strona 411

Chapter 10 Configuring system settings 469Nortel Secure Network Access Switch 4050 User Guide Viewing host informationTo view the host number and IP a

Strona 412

Chapter 1 Overview 47Nortel Secure Network Access Switch 4050 User Guide configuration in the SREM (see “Checking configuration using the SREM” on pag

Strona 413

470 Chapter 10 Configuring system settings320818-A gateway <IPaddr>Sets the default gateway address for the interface. The default gateway is th

Strona 414

Chapter 10 Configuring system settings 471Nortel Secure Network Access Switch 4050 User Guide Configuring static routes using the CLITo manage static

Strona 415

472 Chapter 10 Configuring system settings320818-A The system, host, or interface Routes menu displays.When you add a static route to the system, host

Strona 416

Chapter 10 Configuring system settings 473Nortel Secure Network Access Switch 4050 User Guide The Host Port menu includes the following options:Managi

Strona 417 - Enabling DNS capture

474 Chapter 10 Configuring system settings320818-A The Interface Ports menu includes the following options:Configuring the Access List using the CLITh

Strona 418 - DNS Capture fields

Chapter 10 Configuring system settings 475Nortel Secure Network Access Switch 4050 User Guide The Access List menu displays.The Access List menu inclu

Strona 419 - Add DNS Domain fields

476 Chapter 10 Configuring system settings320818-A The Date and Time menu includes the following options:Managing NTP serversYou can add NTP servers t

Strona 420

Chapter 10 Configuring system settings 477Nortel Secure Network Access Switch 4050 User Guide The NTP Servers menu includes the following options:Conf

Strona 421 - Pre-defined Languages

478 Chapter 10 Configuring system settings320818-A retransmit <interval>Sets the interval for retransmitting a DNS query. •interval is a positiv

Strona 422 - Viewing predefined languages

Chapter 10 Configuring system settings 479Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Strona 423 - Import/Export Definition

48 Chapter 1 Overview320818-A

Strona 424

480 Chapter 10 Configuring system settings320818-A Configuring RSA servers using the CLITo configure the symbolic name for the RSA server and import t

Strona 425 - Figure 110

Chapter 10 Configuring system settings 481Nortel Secure Network Access Switch 4050 User Guide The RSA Servers menu includes the following options:Conf

Strona 426 - Language fields

482 Chapter 10 Configuring system settings320818-A The Syslog Servers menu includes the following options:/cfg/sys/syslogfollowed by:listLists the IP

Strona 427 - Configuring content

Chapter 10 Configuring system settings 483Nortel Secure Network Access Switch 4050 User Guide Configuring administrative settings using the CLIAdminis

Strona 428 - Table 82

484 Chapter 10 Configuring system settings320818-A auditAccesses the Audit menu, in order to configure RADIUS auditing (see “Configuring RADIUS auditi

Strona 429

Chapter 10 Configuring system settings 485Nortel Secure Network Access Switch 4050 User Guide Enabling TunnelGuard SRS administration using the CLITo

Strona 430 - Importing banners

486 Chapter 10 Configuring system settings320818-A During initial setup, there is an option to generate the SSH host keys automatically. To generate a

Strona 431 - Import Banner fields

Chapter 10 Configuring system settings 487Nortel Secure Network Access Switch 4050 User Guide Managing known hosts SSH keys using the CLIYou can paste

Strona 432 - Figure 113

488 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditing using the CLIYou can configure the Nortel SNAS 4050 cluster to include

Strona 433 - Color Settings fields

Chapter 10 Configuring system settings 489Nortel Secure Network Access Switch 4050 User Guide The Internet Assigned Numbers Authority (IANA) has desig

Strona 434

49Nortel Secure Network Access Switch 4050 User Guide Chapter 2 Initial setupThis chapter includes the following topics:Topic PageBefore you begin50Ab

Strona 435 - Basics screen

490 Chapter 10 Configuring system settings320818-A Managing RADIUS audit servers using the CLITo configure the Nortel SNAS 4050 to use external RADIUS

Strona 436 - Table 85

Chapter 10 Configuring system settings 491Nortel Secure Network Access Switch 4050 User Guide add <IPaddr> <port> <shared secret>Add

Strona 437 - Importing custom content

492 Chapter 10 Configuring system settings320818-A Configuring authentication of system users using the CLIYou can configure the Nortel SNAS 4050 clus

Strona 438 - Table 86

Chapter 10 Configuring system settings 493Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLITo c

Strona 439 - Exporting custom content

494 Chapter 10 Configuring system settings320818-A The RADIUS Authentication Servers menu includes the following options:/cfg/sys/adm/auth/serversfoll

Strona 440 - Export Content fields

Chapter 10 Configuring system settings 495Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the SREMTo configure the c

Strona 441 - Creating a linkset

496 Chapter 10 Configuring system settings320818-A Configuring system settings using the SREMTo view and configure cluster-wide system settings, perfo

Strona 442 - Add a Linkset

Chapter 10 Configuring system settings 497Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Management IP Address (MIP) information in t

Strona 443 - Modifying a linkset

498 Chapter 10 Configuring system settings320818-A Viewing host informationTo display a list of available Nortel SNAS 4050 hosts, select the System &g

Strona 444 - Linkset Configuration fields

Chapter 10 Configuring system settings 499Nortel Secure Network Access Switch 4050 User Guide Viewing and configuring TCP/IP propertiesTo configure ba

Strona 445

5Nortel Secure Network Access Switch 4050 User Guide ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 446 - Figure 120

50 Chapter 2 Initial setup320818-A Before you beginBefore you can set up the Nortel SNAS 4050, you must complete the following tasks:1 Plan the networ

Strona 447 - Add a Portal Link fields

500 Chapter 10 Configuring system settings320818-A 2 Enter the host information in the applicable fields. Table 96 describes the Host fields.3 Click A

Strona 448

Chapter 10 Configuring system settings 501Nortel Secure Network Access Switch 4050 User Guide Additionally, new licenses can be added to a particular

Strona 449 - Add a Portal Link — FTP

502 Chapter 10 Configuring system settings320818-A Table 97 describes the Global Licenses fields.2 Modify the Auto Refresh and Logging settings, if de

Strona 450

Chapter 10 Configuring system settings 503Nortel Secure Network Access Switch 4050 User Guide Viewing per domain licenses for all hostsTo view license

Strona 451 - Figure 123

504 Chapter 10 Configuring system settings320818-A Table 98 describes the Per Domain Licenses fields.2 Modify the Auto Refresh and Logging settings, i

Strona 452 - Table 92

Chapter 10 Configuring system settings 505Nortel Secure Network Access Switch 4050 User Guide Viewing installed licenses for a particular hostTo view

Strona 453 - Figure 124

506 Chapter 10 Configuring system settings320818-A Installing a license for a particular hostThe Nortel SNA SSL (portal and Nortel SNAS 4050 domain cl

Strona 454 - FTP link Configuration fields

Chapter 10 Configuring system settings 507Nortel Secure Network Access Switch 4050 User Guide 3 In the SREM, select the System > Hosts > host &g

Strona 455 - Re Order Links fields

508 Chapter 10 Configuring system settings320818-A Configuring host interfaces using the SREMThe default IP interface on the Nortel SNAS 4050 host is

Strona 456

Chapter 10 Configuring system settings 509Nortel Secure Network Access Switch 4050 User Guide • “Removing a host interface” on page 514Adding a host i

Strona 457 - Configuring system settings

Chapter 2 Initial setup 51Nortel Secure Network Access Switch 4050 User Guide 4 Establish a console connection to the Nortel SNAS 4050 (see “Establish

Strona 458

510 Chapter 10 Configuring system settings320818-A 4 Click Apply.The new interface appears in the Interfaces table.Gateway Sets the default gateway ad

Strona 459 - /cfg/sys

Chapter 10 Configuring system settings 511Nortel Secure Network Access Switch 4050 User Guide 5 Click Apply on the toolbar to send the current changes

Strona 460 - Roadmap of system commands

512 Chapter 10 Configuring system settings320818-A 2 Enter the interface information in the applicable fields. Table 100 describes the Interface confi

Strona 461

Chapter 10 Configuring system settings 513Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes

Strona 462

514 Chapter 10 Configuring system settings320818-A Removing a host interfaceTo delete a host interface, perform the following steps:1 Select the Syste

Strona 463

Chapter 10 Configuring system settings 515Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for a clusterTo configure static r

Strona 464 - The System menu displays

516 Chapter 10 Configuring system settings320818-A Viewing static routes for a hostTo configure static routes for a host, select the System > Hosts

Strona 465

Chapter 10 Configuring system settings 517Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for an interfaceTo configure stati

Strona 466

518 Chapter 10 Configuring system settings320818-A From the selected static route screen, complete the following tasks as necessary:• “Adding a static

Strona 467

Chapter 10 Configuring system settings 519Nortel Secure Network Access Switch 4050 User Guide 4 Click Add.The new route appears in the table.5 Click A

Strona 468

52 Chapter 2 Initial setup320818-A Real IP addressThe Real IP address (RIP) is the Nortel SNAS 4050 device host IP address for network connectivity. T

Strona 469 - Viewing host information

520 Chapter 10 Configuring system settings320818-A Configuring host ports using the SREMTo configure the connection properties for a port, perform the

Strona 470

Chapter 10 Configuring system settings 521Nortel Secure Network Access Switch 4050 User Guide 2 Select a port to configure from the list.The Port scre

Strona 471

522 Chapter 10 Configuring system settings320818-A 3 Enter the port information in the applicable fields. Table 102 describes the Port fields.4 Click

Strona 472

Chapter 10 Configuring system settings 523Nortel Secure Network Access Switch 4050 User Guide Managing interface ports using the SREMTo view and manag

Strona 473

524 Chapter 10 Configuring system settings320818-A Adding interface portsTo add ports to the selected interface, perform the following steps:1 Select

Strona 474

Chapter 10 Configuring system settings 525Nortel Secure Network Access Switch 4050 User Guide The port is removed from the Port Table.5 Click Apply on

Strona 475

526 Chapter 10 Configuring system settings320818-A The Access List Table appears (see Figure 143).Figure 143 Access ListFrom here, you can manage th

Strona 476 - Managing NTP servers

Chapter 10 Configuring system settings 527Nortel Secure Network Access Switch 4050 User Guide The Add Access Host dialog box appears (see Figure 144).

Strona 477

528 Chapter 10 Configuring system settings320818-A 4 Click Yes.The entry disappears from the Access List Table.5 Click Apply on the toolbar to send th

Strona 478

Chapter 10 Configuring system settings 529Nortel Secure Network Access Switch 4050 User Guide You can add NTP servers to the system configuration to e

Strona 479 - Managing DNS servers

Chapter 2 Initial setup 53Nortel Secure Network Access Switch 4050 User Guide The Setup Menu displays.2 Select the option for a new installation.3 Spe

Strona 480

530 Chapter 10 Configuring system settings320818-A Adding an NTP serverTo add an additional NTP server, perform the following steps:1 Select the Syste

Strona 481

Chapter 10 Configuring system settings 531Nortel Secure Network Access Switch 4050 User Guide Removing an NTP serverTo remove an existing NTP server f

Strona 482

532 Chapter 10 Configuring system settings320818-A Configuring DNS settings using the SREMTo configure DNS client settings, use the following procedur

Strona 483

Chapter 10 Configuring system settings 533Nortel Secure Network Access Switch 4050 User Guide 2 Enter the DNS Client information in the applicable fie

Strona 484

534 Chapter 10 Configuring system settings320818-A Configuring servers using the SREMTo configure servers, choose from one of the following tasks:• “M

Strona 485

Chapter 10 Configuring system settings 535Nortel Secure Network Access Switch 4050 User Guide From this screen, complete the following tasks as necess

Strona 486

536 Chapter 10 Configuring system settings320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on t

Strona 487

Chapter 10 Configuring system settings 537Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Strona 488 - About RADIUS auditing

538 Chapter 10 Configuring system settings320818-A Adding a DNS serverTo manage DNS servers in the system configuration, perform the following steps:1

Strona 489 - Configuring RADIUS auditing

Chapter 10 Configuring system settings 539Nortel Secure Network Access Switch 4050 User Guide Removing an existing DNS serverTo remove a DNS server fr

Strona 490

54 Chapter 2 Initial setup320818-A In a two-armed configuration, you are specifying the port you want to use for Nortel SNAS 4050 management traffic.4

Strona 491

540 Chapter 10 Configuring system settings320818-A Managing RSA serversTo manage RSA servers, select the System > Servers > RSA Server Table tab

Strona 492

Chapter 10 Configuring system settings 541Nortel Secure Network Access Switch 4050 User Guide • “Removing the RSA node secret” on page 542• “Importing

Strona 493

542 Chapter 10 Configuring system settings320818-A Removing an existing RSA serverTo remove an existing RSA server, perform the following steps.1 Sele

Strona 494

Chapter 10 Configuring system settings 543Nortel Secure Network Access Switch 4050 User Guide 3 Select the RSA Server sub-tab.The RSA Server screen ap

Strona 495

544 Chapter 10 Configuring system settings320818-A 4 Click Remove Secret Node.The RSA node secret is immediately removed.5 Click Apply on the toolbar

Strona 496 - Figure 126

Chapter 10 Configuring system settings 545Nortel Secure Network Access Switch 4050 User Guide 3 Select the Import sdconf.rec tab.The Import sdconf.rec

Strona 497 - System Configuration fields

546 Chapter 10 Configuring system settings320818-A 4 Enter the importing information in the applicable fields. Table 112 describes the Import sdconf.r

Strona 498

Chapter 10 Configuring system settings 547Nortel Secure Network Access Switch 4050 User Guide Configuring SRS control settings using the SREMTo create

Strona 499 - Figure 128

548 Chapter 10 Configuring system settings320818-A 2 Enter the SRS Control information in the applicable fields. Table 115 describes the SRS Control S

Strona 500 - Host fields

Chapter 10 Configuring system settings 549Nortel Secure Network Access Switch 4050 User Guide • “Showing SSH keys” on page 549• “Managing Nortel SNAS

Strona 501 - Global Licenses

Chapter 2 Initial setup 55Nortel Secure Network Access Switch 4050 User Guide 7 Specify whether you are setting up a one-armed or a two-armed configur

Strona 502 - Table 97

550 Chapter 10 Configuring system settings320818-A • RSA and DSA keys — the SECSH Public Key File Format, as described in Internet Draft draft-ietf-se

Strona 503 - Figure 130

Chapter 10 Configuring system settings 551Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 and known host SSH keysYou can

Strona 504 - Table 98

552 Chapter 10 Configuring system settings320818-A 2 To generate the Nortel SNAS 4050 host SSH key:a Enter the host information in applicable fields.

Strona 505 - Figure 131

Chapter 10 Configuring system settings 553Nortel Secure Network Access Switch 4050 User Guide Adding an SSH key for a known host using the SREMYou can

Strona 506 - END LICENSE lines

554 Chapter 10 Configuring system settings320818-A 2 Enter the remote host information in the applicable fields. Table 115 describes the Add SSH Key f

Strona 507 - Install New License

Chapter 10 Configuring system settings 555Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS audit server to the conf

Strona 508 - Interfaces

556 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditingTo configure the Nortel SNAS 4050 to support RADIUS auditing, choose fro

Strona 509 - Adding a host interface

Chapter 10 Configuring system settings 557Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS audit settings using the SREMTo confi

Strona 510

558 Chapter 10 Configuring system settings320818-A describes the Add Audit Configuration fields.3 Click Apply on the toolbar to send the current chang

Strona 511

Chapter 10 Configuring system settings 559Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS audit servers using the SREMTo manage RA

Strona 512 - Table 100

56 Chapter 2 Initial setup320818-A used if no other interface is specified. The default gateway IP address on Interface 2 must be within the same subn

Strona 513 - Interface fields (continued)

560 Chapter 10 Configuring system settings320818-A Adding a new Audit ServerTo add a new RADIUS audit server, perform the following steps:1 Select the

Strona 514 - Removing a host interface

Chapter 10 Configuring system settings 561Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS audit serverTo remove an exi

Strona 515 - Figure 136

562 Chapter 10 Configuring system settings320818-A Managing RADIUS authentication of system users using the SREMYou can configure the Nortel SNAS 4050

Strona 516

Chapter 10 Configuring system settings 563Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS authentication of system users using

Strona 517 - Managing static routes

564 Chapter 10 Configuring system settings320818-A 2 Enter the RADIUS authentication information in the applicable fields. Table 118 describes the Rad

Strona 518 - Adding a static route

Chapter 10 Configuring system settings 565Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the SREMTo

Strona 519 - Removing a static route

566 Chapter 10 Configuring system settings320818-A Adding a RADIUS authentication serverTo add a new RADIUS authentication server, perform the followi

Strona 520 - Figure 140

Chapter 10 Configuring system settings 567Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS serverTo remove an existing

Strona 521 - Figure 141

568 Chapter 10 Configuring system settings320818-A

Strona 522 - Table 102

569Nortel Secure Network Access Switch 4050 User Guide Chapter 11 Managing certificatesThis chapter includes the following topics:Topic PageOverview57

Strona 523

Chapter 2 Initial setup 57Nortel Secure Network Access Switch 4050 User Guide 12 Configure the time settings.13 Specify the NTP server, if applicable.

Strona 524 - Removing interface ports

570 Chapter 11 Managing certificates320818-A OverviewTo use the encryption capabilities of the Nortel SNAS 4050, you must add a key and certificate th

Strona 525

Chapter 11 Managing certificates 571Nortel Secure Network Access Switch 4050 User Guide You can install new certificates or import or renew existing c

Strona 526 - Adding an access list entry

572 Chapter 11 Managing certificates320818-A Netscape Enterprise ServerYes No Key only (proprietary format). Requires conversion. For information abou

Strona 527 - Removing an Access List entry

Chapter 11 Managing certificates 573Nortel Secure Network Access Switch 4050 User Guide Creating certificatesThe basic steps to create a new certifica

Strona 528 - Date & Time

574 Chapter 11 Managing certificates320818-A If you use the certificate index number of an installed certificate when adding a new certificate, the in

Strona 529 - Date & Time fields

Chapter 11 Managing certificates 575Nortel Secure Network Access Switch 4050 User Guide The recommended steps to update an existing certificate are:1

Strona 530 - Adding an NTP server

576 Chapter 11 Managing certificates320818-A • import certificates and private keys (see “Importing certificates and keys into the Nortel SNAS 4050 us

Strona 531 - Removing an NTP server

Chapter 11 Managing certificates 577Nortel Secure Network Access Switch 4050 User Guide Managing and viewing certificates and keys using the CLITo vie

Strona 532 - Figure 147

578 Chapter 11 Managing certificates320818-A gensigned server|clientGenerates a certificate that is signed using the private key associated with the c

Strona 533 - Table 107

Chapter 11 Managing certificates 579Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the CLITo prepare a CSR

Strona 534 - Managing syslog servers

58 Chapter 2 Initial setup320818-A 16 Change the admin user password, if desired.Make sure you remember the password you define for the admin user. Yo

Strona 535 - Adding a new syslog server

580 Chapter 11 Managing certificates320818-A • to generate a CSR for a new certificate, <cert id> is an unused certificate number• to generate a

Strona 536

Chapter 11 Managing certificates 581Nortel Secure Network Access Switch 4050 User Guide 3 Generate the CSR.After you have provided the required inform

Strona 537

582 Chapter 11 Managing certificates320818-A Figure 166 shows sample output for the /cfg/cert #/request command. For more information about the Certif

Strona 538 - Adding a DNS server

Chapter 11 Managing certificates 583Nortel Secure Network Access Switch 4050 User Guide 5 Save the CSR to a file.a Copy the entire CSR, including the

Strona 539

584 Chapter 11 Managing certificates320818-A 8 The CA processes the CSR and returns a signed certificate. Create a backup copy of the certificate (see

Strona 540 - Managing RSA servers

Chapter 11 Managing certificates 585Nortel Secure Network Access Switch 4050 User Guide To verify that the current certificate number is not in use by

Strona 541 - Adding an RSA server

586 Chapter 11 Managing certificates320818-A Figure 167 shows sample output for the /cfg/cert #/cert command. For more information about the Certifica

Strona 542 - Removing the RSA node secret

Chapter 11 Managing certificates 587Nortel Secure Network Access Switch 4050 User Guide Adding a private key to the Nortel SNAS 4050 using the CLI1 Ac

Strona 543 - RSA Server fields

588 Chapter 11 Managing certificates320818-A Figure 168 shows sample output for the /cfg/cert #/key command. For more information about the Certificat

Strona 544 - Importing sdconf.rec

Chapter 11 Managing certificates 589Nortel Secure Network Access Switch 4050 User Guide To import a certificate and private key into the Nortel SNAS 4

Strona 545 - Figure 155

Chapter 2 Initial setup 59Nortel Secure Network Access Switch 4050 User Guide For example, if you entered company.com in the DNS search list, users ca

Strona 546 - Import sdconf.rec fields

590 Chapter 11 Managing certificates320818-A 4 If the private key was not included in the certificate file, repeat step 3 on page 589 to import the ke

Strona 547 - SRS Control Settings

Chapter 11 Managing certificates 591Nortel Secure Network Access Switch 4050 User Guide Displaying or saving a certificate and key using the CLIYou ca

Strona 548 - Add SSH Key fields

592 Chapter 11 Managing certificates320818-A 5 Copy the private key, certificate, or both, as required.For the private key, ensure that you include th

Strona 549 - Showing SSH keys

Chapter 11 Managing certificates 593Nortel Secure Network Access Switch 4050 User Guide Figure 170 shows sample output for the /cfg/cert #/display com

Strona 550

594 Chapter 11 Managing certificates320818-A Exporting a certificate and key from the Nortel SNAS 4050 using the CLIYou can export certificate files a

Strona 551 - SSH Keys – Hosts

Chapter 11 Managing certificates 595Nortel Secure Network Access Switch 4050 User Guide Export format The key and certificate format in which you want

Strona 552 - SSH Keys Hosts field

596 Chapter 11 Managing certificates320818-A Figure 171 shows sample output for the /cfg/cert #/export command. For more information about the Certifi

Strona 553 - Add SSH Key

Chapter 11 Managing certificates 597Nortel Secure Network Access Switch 4050 User Guide You are prompted to enter the following parameters. The combin

Strona 554

598 Chapter 11 Managing certificates320818-A Viewing certificates using the SREMTo view basic information about all certificates configured for the No

Strona 555 - NSNAS-SSL-Audit-Trail)

Chapter 11 Managing certificates 599Nortel Secure Network Access Switch 4050 User Guide 3 Click Yes.The certificate is removed from the Certificates l

Strona 556

6 Contents320818-A Management IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51Portal Virtual IP addres

Strona 557 - Figure 160

60 Chapter 2 Initial setup320818-A The action to be performed when the TunnelGuard check fails depends on your selection in step f on page 59.Settings

Strona 558 - Table 116

600 Chapter 11 Managing certificates320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Strona 559 - Audit Servers

Chapter 11 Managing certificates 601Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the SREMTo generate a CS

Strona 560 - Adding a new Audit Server

602 Chapter 11 Managing certificates320818-A 2 Enter the certificate information in the applicable fields.Table 125 describes the CA Request fields.Ta

Strona 561

Chapter 11 Managing certificates 603Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the information to the No

Strona 562

604 Chapter 11 Managing certificates320818-A To import a certificate and private key into the Nortel SNAS 4050, perform the following steps.1 Upload t

Strona 563 - Figure 163

Chapter 11 Managing certificates 605Nortel Secure Network Access Switch 4050 User Guide 3 Enter the import information in the applicable fields. Table

Strona 564 - Table 118

606 Chapter 11 Managing certificates320818-A To display the current certificate and key or save a copy, perform the following steps:1 Select the Certi

Strona 565 - Radius Server Table

Chapter 11 Managing certificates 607Nortel Secure Network Access Switch 4050 User Guide 2 If you want to encrypt the key, specify a password in the ap

Strona 566 - Add Radius Server fields

608 Chapter 11 Managing certificates320818-A To export a certificate and key from the Nortel SNAS 4050, perform the following steps.1 Select the Certi

Strona 567

Chapter 11 Managing certificates 609Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields. Table

Strona 568

Chapter 2 Initial setup 61Nortel Secure Network Access Switch 4050 User Guide The profiles determine the VLAN to which the user will be allocated. Tab

Strona 569 - Managing certificates

610 Chapter 11 Managing certificates320818-A 3 Click Apply on the toolbar to export the certificate.The certificate and private key are immediately ex

Strona 570

Chapter 11 Managing certificates 611Nortel Secure Network Access Switch 4050 User Guide The Configuration screen appears (see Figure 172).Figure 178

Strona 571 - Key and certificate formats

612 Chapter 11 Managing certificates320818-A Viewing general informationTo view basic information about a certificate on the Nortel SNAS 4050 cluster,

Strona 572

Chapter 11 Managing certificates 613Nortel Secure Network Access Switch 4050 User Guide The Info screen appears (see Figure 179).Figure 179 Info scr

Strona 573 - Creating certificates

614 Chapter 11 Managing certificates320818-A Viewing certificate subject settingsTo view subject settings for a certificate on the Nortel SNAS 4050 cl

Strona 574 - Updating certificates

Chapter 11 Managing certificates 615Nortel Secure Network Access Switch 4050 User Guide The Subject screen appears (see Figure 180).Figure 180 Subje

Strona 575

616 Chapter 11 Managing certificates320818-A Organization The registered name of the organization. The organization must own the domain name that appe

Strona 576

617Nortel Secure Network Access Switch 4050 User Guide Chapter 12 Configuring SNMPThis chapter includes the following topics:Topic PageConfiguring SNM

Strona 577

618 Chapter 12 Configuring SNMP320818-A Simple Network Management Protocol (SNMP) is a set of protocols for managing complex networks. SNMP works by s

Strona 578

Chapter 12 Configuring SNMP 619Nortel Secure Network Access Switch 4050 User Guide • SNMP monitors and events (see “Configuring SNMP events using the

Strona 579

62 Chapter 2 Initial setup320818-A Before you beginLog on to the existing Nortel SNAS 4050 device to check the software version and system settings. U

Strona 580

620 Chapter 12 Configuring SNMP320818-A Configuring SNMP settings using the CLITo configure SNMP management of the Nortel SNAS 4050 cluster, use the f

Strona 581

Chapter 12 Configuring SNMP 621Nortel Secure Network Access Switch 4050 User Guide Configuring the SNMP v2 MIB using the CLITo configure parameters in

Strona 582 - Figure 166

622 Chapter 12 Configuring SNMP320818-A The SNMPv2-MIB menu includes the following options:Configuring the SNMP community using the CLITo configure th

Strona 583

Chapter 12 Configuring SNMP 623Nortel Secure Network Access Switch 4050 User Guide Configuring SNMPv3 users using the CLIThe Nortel SNAS 4050 manages

Strona 584

624 Chapter 12 Configuring SNMP320818-A • set — USM user is authorized to perform SNMP set requests (write access to the MIB). Write access automatica

Strona 585

Chapter 12 Configuring SNMP 625Nortel Secure Network Access Switch 4050 User Guide The SNMP User menu includes the following options:/cfg/sys/adm/snmp

Strona 586

626 Chapter 12 Configuring SNMP320818-A Configuring SNMP notification targets using the CLISNMP managers function as the notification targets for SNMP

Strona 587

Chapter 12 Configuring SNMP 627Nortel Secure Network Access Switch 4050 User Guide The Notification Target menu includes the following options:Configu

Strona 588

628 Chapter 12 Configuring SNMP320818-A The event menu includes the following options:/cfg/sys/adm/snmp/eventfollowed by:addmonitor [<options>]

Strona 589

Chapter 12 Configuring SNMP 629Nortel Secure Network Access Switch 4050 User Guide addmonitor [<options>] -t <name> <OID> <value

Strona 590

Chapter 2 Initial setup 63Nortel Secure Network Access Switch 4050 User Guide • To change the version on the existing NSNAS, download the desired soft

Strona 591

630 Chapter 12 Configuring SNMP320818-A addmonitor [<options>] -x <name> <OID> [present|absent|changed]Adds an existence monitor and

Strona 592

Chapter 12 Configuring SNMP 631Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP settings using the SREMThis section contains infor

Strona 593 - Figure 170

632 Chapter 12 Configuring SNMP320818-A Configuring SNMP using the SREMTo configure SNMP, perform the following steps:1 Select the System > Adminis

Strona 594 - Parameter Description

Chapter 12 Configuring SNMP 633Nortel Secure Network Access Switch 4050 User Guide 2 Enter the SNMP Configuration information in the applicable fields

Strona 595

634 Chapter 12 Configuring SNMP320818-A Configuring SNMP targets using the SREMSNMP managers function as the notification targets for SNMP monitoring.

Strona 596

Chapter 12 Configuring SNMP 635Nortel Secure Network Access Switch 4050 User Guide Adding SNMP targetsTo add an SNMP target, perform the following ste

Strona 597

636 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMP Target dialog box appears (see Figure 183).Figure 183 Add SNMP Target

Strona 598 - Certificates screen

Chapter 12 Configuring SNMP 637Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMP target information in the applicable fields. Table

Strona 599 - Add a Certificate Component

638 Chapter 12 Configuring SNMP320818-A Managing SNMP targetsTo manage SNMP targets, perform the following steps:1 Select the System > Administrati

Strona 600

Chapter 12 Configuring SNMP 639Nortel Secure Network Access Switch 4050 User Guide 2 Modify the SNMP Target information in the applicable fields. Tabl

Strona 601 - Figure 174

64 Chapter 2 Initial setup320818-A In a one-armed configuration, you are specifying the port you want to use for all network connectivity, since Inter

Strona 602 - Table 125

640 Chapter 12 Configuring SNMP320818-A A dialog box appears asking for confirmation.4 Click Yes.5 Click Apply on the toolbar to send the current chan

Strona 603

Chapter 12 Configuring SNMP 641Nortel Secure Network Access Switch 4050 User Guide Adding SNMPv3 usersTo add an SNMPv3 user, perform the following ste

Strona 604 - Import Certificate screen

642 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMPv3 User dialog box appears (see Figure 186).Figure 186 Add SNMPv3 User

Strona 605

Chapter 12 Configuring SNMP 643Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMPv3 User information in the applicable fields. Table

Strona 606 - Figure 176

644 Chapter 12 Configuring SNMP320818-A 4 Click Apply. The new SNMPv3 user appears in the table.5 Click Apply on the toolbar to send the current chang

Strona 607 - Display Certificates fields

Chapter 12 Configuring SNMP 645Nortel Secure Network Access Switch 4050 User Guide 2 Modify SNMPv3 User information in the applicable fields, as requi

Strona 608 - Figure 177

646 Chapter 12 Configuring SNMP320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the toolbar

Strona 609 - Table 128

Chapter 12 Configuring SNMP 647Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP events using the SREMSNMP events can be added to m

Strona 610 - Viewing configuration details

648 Chapter 12 Configuring SNMP320818-A Adding monitor eventsTo add monitor events, perform the following steps:1 Select the System > Administrativ

Strona 611 - Table 129

Chapter 12 Configuring SNMP 649Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Monitor dialog box appears. Depending on the

Strona 612 - Viewing general information

Chapter 2 Initial setup 65Nortel Secure Network Access Switch 4050 User Guide 8 Configure the interface for client portal traffic (Interface 2).a Spec

Strona 613 - Table 130

650 Chapter 12 Configuring SNMP320818-A Depending on the type of monitor selected, the fields displayed on the Configuration tab will change. For desc

Strona 614 - Table 130 Info fields

Chapter 12 Configuring SNMP 651Nortel Secure Network Access Switch 4050 User Guide Figure 189 Add a Monitor: BooleanFields used to add and configure

Strona 615 - Table 131

652 Chapter 12 Configuring SNMP320818-A For details on adding a Boolean monitor, see “Adding monitor events” on page 648.Threshold monitorsThreshold m

Strona 616 - Table 131 Subject fields

Chapter 12 Configuring SNMP 653Nortel Secure Network Access Switch 4050 User Guide Fields used to add and configure a Threshold monitor are listed in

Strona 617 - Configuring SNMP

654 Chapter 12 Configuring SNMP320818-A Existence monitorsExistence monitors check the condition of a monitored OID to see determine if it is present,

Strona 618 - /cfg/sys/adm/snmp

Chapter 12 Configuring SNMP 655Nortel Secure Network Access Switch 4050 User Guide For details on adding a Existence monitor, see “Adding monitor even

Strona 619 - Roadmap of SNMP commands

656 Chapter 12 Configuring SNMP320818-A Adding notification eventsTo add notification events, perform the following steps:1 Select the System > Adm

Strona 620

Chapter 12 Configuring SNMP 657Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Notification Event dialog box appears (see F

Strona 621 - The SNMPv2-MIB menu displays

658 Chapter 12 Configuring SNMP320818-A Removing notification eventsTo delete a notification event, perform the following steps:1 Select the System &g

Strona 622

659Nortel Secure Network Access Switch 4050 User Guide Chapter 13 Viewing system information and performance statisticsThis chapter includes the follo

Strona 623

66 Chapter 2 Initial setup320818-A 12 Wait while the Setup utility finishes processing. When processing is complete, you will see Setup successful.The

Strona 624

660 Chapter 13 Viewing system information and performance statistics320818-A Viewing system information and performance statistics using the CLITo vie

Strona 625

Chapter 13 Viewing system information and performance statistics 661Nortel Secure Network Access Switch 4050 User Guide Viewing system information usi

Strona 626

662 Chapter 13 Viewing system information and performance statistics320818-A The Information menu includes the following options:/infofollowed by:cert

Strona 627

Chapter 13 Viewing system information and performance statistics 663Nortel Secure Network Access Switch 4050 User Guide kick <domain ID> <use

Strona 628

664 Chapter 13 Viewing system information and performance statistics320818-A mac <MACaddr>Displays session information for a client based on a s

Strona 629

Chapter 13 Viewing system information and performance statistics 665Nortel Secure Network Access Switch 4050 User Guide localDisplays the current soft

Strona 630

666 Chapter 13 Viewing system information and performance statistics320818-A Viewing alarm events using the CLITo view active alarms, use the followin

Strona 631

Chapter 13 Viewing system information and performance statistics 667Nortel Secure Network Access Switch 4050 User Guide Viewing log files using the CL

Strona 632 - Figure 181

668 Chapter 13 Viewing system information and performance statistics320818-A The CLI reports statistics for all authentication methods configured in t

Strona 633 - Table 132

Chapter 13 Viewing system information and performance statistics 669Nortel Secure Network Access Switch 4050 User Guide Figure 194 shows sample output

Strona 634

Chapter 2 Initial setup 67Nortel Secure Network Access Switch 4050 User Guide 3 To finish connecting the Nortel SNAS 4050 to the rest of the network,

Strona 635 - Adding SNMP targets

670 Chapter 13 Viewing system information and performance statistics320818-A Viewing all statistics using the CLITo view all available statistics for

Strona 636 - Figure 183

Chapter 13 Viewing system information and performance statistics 671Nortel Secure Network Access Switch 4050 User Guide The Information screen appears

Strona 637 - SNMP Target fields

672 Chapter 13 Viewing system information and performance statistics320818-A Viewing cluster information using the SREMTo view cluster information, se

Strona 638 - Managing SNMP targets

Chapter 13 Viewing system information and performance statistics 673Nortel Secure Network Access Switch 4050 User Guide Viewing the controller list us

Strona 639 - Removing SNMP targets

674 Chapter 13 Viewing system information and performance statistics320818-A Table 143 describes the Controller List fields. Table 143 Controller Li

Strona 640

Chapter 13 Viewing system information and performance statistics 675Nortel Secure Network Access Switch 4050 User Guide Viewing SONMP topology informa

Strona 641 - Adding SNMPv3 users

676 Chapter 13 Viewing system information and performance statistics320818-A Table 144 describes the SONMP State fields. Table 144 SONMP State field

Strona 642 - Figure 186

Chapter 13 Viewing system information and performance statistics 677Nortel Secure Network Access Switch 4050 User Guide Viewing switch distribution us

Strona 643 - Table 135

678 Chapter 13 Viewing system information and performance statistics320818-A Table 145 describes the Switch Distribution fields. Viewing port informat

Strona 644 - Managing SNMPv3 users

Chapter 13 Viewing system information and performance statistics 679Nortel Secure Network Access Switch 4050 User Guide To view port information, sele

Strona 645 - Table 136

68 Chapter 2 Initial setup320818-A Applying and saving the configuration using the CLIIf you have not already done so after each sequence of configura

Strona 646 - Removing SNMPv3 users

680 Chapter 13 Viewing system information and performance statistics320818-A Viewing license information using the SREMYou can view information about

Strona 647 - Managing monitor events

Chapter 13 Viewing system information and performance statistics 681Nortel Secure Network Access Switch 4050 User Guide Viewing global license informa

Strona 648 - Adding monitor events

682 Chapter 13 Viewing system information and performance statistics320818-A Table 147 describes the Global Licenses fields. Table 147 Global Licens

Strona 649 - Add a Monitor fields

Chapter 13 Viewing system information and performance statistics 683Nortel Secure Network Access Switch 4050 User Guide Viewing license information fo

Strona 650 - Boolean monitors

684 Chapter 13 Viewing system information and performance statistics320818-A Table 148 describes the Per Domain Licenses fields. Viewing session detai

Strona 651 - Table 138

Chapter 13 Viewing system information and performance statistics 685Nortel Secure Network Access Switch 4050 User Guide Viewing active sessions using

Strona 652 - Threshold monitors

686 Chapter 13 Viewing system information and performance statistics320818-A Table 149 describes the Sessions parameters. Table 149 Sessions paramet

Strona 653 - Table 139

Chapter 13 Viewing system information and performance statistics 687Nortel Secure Network Access Switch 4050 User Guide Viewing details for a particul

Strona 654 - Existence monitors

688 Chapter 13 Viewing system information and performance statistics320818-A Table 150 describes the Session Properties parameters. Ending active user

Strona 655 - Managing notification events

Chapter 13 Viewing system information and performance statistics 689Nortel Secure Network Access Switch 4050 User Guide Figure 204 KickOut User scre

Strona 656 - Adding notification events

Chapter 2 Initial setup 69Nortel Secure Network Access Switch 4050 User Guide Figure 3 on page 69 shows the location of the Apply and Commit buttons.F

Strona 657 - Add a Notification Event

690 Chapter 13 Viewing system information and performance statistics320818-A Viewing the number of active sessions using the SREMTo view the number of

Strona 658 - Removing notification events

Chapter 13 Viewing system information and performance statistics 691Nortel Secure Network Access Switch 4050 User Guide Viewing alarms using the SREMY

Strona 659 - Chapter 13

692 Chapter 13 Viewing system information and performance statistics320818-A Viewing active alarms using the SREMTo view the active alarms for the Nor

Strona 660

Chapter 13 Viewing system information and performance statistics 693Nortel Secure Network Access Switch 4050 User Guide Table 153 describes the Active

Strona 661

694 Chapter 13 Viewing system information and performance statistics320818-A Downloading alarms using the SREMTo download an alarm as a logged event,

Strona 662

Chapter 13 Viewing system information and performance statistics 695Nortel Secure Network Access Switch 4050 User Guide Table 154 describes the Downlo

Strona 663

696 Chapter 13 Viewing system information and performance statistics320818-A Viewing the log list using the SREMTo view a list of all active logs, sel

Strona 664

Chapter 13 Viewing system information and performance statistics 697Nortel Secure Network Access Switch 4050 User Guide Downloading log files using th

Strona 665

698 Chapter 13 Viewing system information and performance statistics320818-A Viewing AAA statistics using the SREMYou can view authentication statisti

Strona 666 - The Events menu displays

Chapter 13 Viewing system information and performance statistics 699Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for a h

Strona 667

Contents 7Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 668

70 Chapter 2 Initial setup320818-A

Strona 669 - Figure 194

700 Chapter 13 Viewing system information and performance statistics320818-A b Expand the Statistics > AAA > Host Statistics > host navigatio

Strona 670

Chapter 13 Viewing system information and performance statistics 701Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Strona 671 - Table 142

702 Chapter 13 Viewing system information and performance statistics320818-A Viewing RADIUS statisticsTo view RADIUS statistics, select the Radius tab

Strona 672

Chapter 13 Viewing system information and performance statistics 703Nortel Secure Network Access Switch 4050 User Guide For a description of the field

Strona 673 - Figure 196

704 Chapter 13 Viewing system information and performance statistics320818-A Viewing Local database statisticsTo view Local database statistics, selec

Strona 674 - Table 143

Chapter 13 Viewing system information and performance statistics 705Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Strona 675 - Figure 197

706 Chapter 13 Viewing system information and performance statistics320818-A For a description of the fields, seeTable 159.Table 159 LDAP statistics

Strona 676 - Table 144

Chapter 13 Viewing system information and performance statistics 707Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for the

Strona 677 - Figure 198

708 Chapter 13 Viewing system information and performance statistics320818-A •LDAPSelect one of the following tasks:• Viewing License statistics (see

Strona 678 - Switch Distribution fields

Chapter 13 Viewing system information and performance statistics 709Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Strona 679 - Table 146

71Nortel Secure Network Access Switch 4050 User Guide Chapter 3 Managing the network access devicesThis chapter includes the following topics:Topic Pa

Strona 680

710 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Strona 681 - Figure 200

Chapter 13 Viewing system information and performance statistics 711Nortel Secure Network Access Switch 4050 User Guide Viewing RADIUS statisticsTo vi

Strona 682 - Table 147

712 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Strona 683 - Figure 201

Chapter 13 Viewing system information and performance statistics 713Nortel Secure Network Access Switch 4050 User Guide Viewing Local database statist

Strona 684 - Per Domain Licenses fields

714 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Strona 685 - Sessions screen

Chapter 13 Viewing system information and performance statistics 715Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Strona 686 - Table 149

716 Chapter 13 Viewing system information and performance statistics320818-A Viewing Ethernet statistics using the SREMYou can view statistics for the

Strona 687 - Figure 203

Chapter 13 Viewing system information and performance statistics 717Nortel Secure Network Access Switch 4050 User Guide To view Ethernet interface sta

Strona 688 - Ending active user sessions

718 Chapter 13 Viewing system information and performance statistics320818-A Viewing Rx statisticsTo view Rx statistics for an interface, select the R

Strona 689 - Table 151

Chapter 13 Viewing system information and performance statistics 719Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Strona 690 - Number of Sessions fields

72 Chapter 3 Managing the network access devices320818-A Before you beginIn Trusted Computing Group (TCG) terminology, the edge switches in a Nortel S

Strona 691 - Viewing alarms using the SREM

720 Chapter 13 Viewing system information and performance statistics320818-A Viewing Tx statisticsTo view Tx statistics for an interface, select Tx St

Strona 692 - Figure 206

Chapter 13 Viewing system information and performance statistics 721Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Strona 693 - Table 153

722 Chapter 13 Viewing system information and performance statistics320818-A

Strona 694 - Figure 207

723Nortel Secure Network Access Switch 4050 User Guide Chapter 14 Maintaining and managing the systemThis chapter includes the following topics:Topic

Strona 695 - Table 154

724 Chapter 14 Maintaining and managing the system320818-A You can perform the following activities to manage and maintain the system and individual N

Strona 696 - Figure 208

Chapter 14 Maintaining and managing the system 725Nortel Secure Network Access Switch 4050 User Guide To manage software versions and Nortel SNAS 4050

Strona 697 - Table 155

726 Chapter 14 Maintaining and managing the system320818-A Performing maintenance using the CLITo check the applied configuration and to download log

Strona 698

Chapter 14 Maintaining and managing the system 727Nortel Secure Network Access Switch 4050 User Guide The Maintenance menu includes the following opti

Strona 699 - The Hosts table

728 Chapter 14 Maintaining and managing the system320818-A dumpstats <protocol> <server> <filename> <all-isds?>Collects curren

Strona 700

Chapter 14 Maintaining and managing the system 729Nortel Secure Network Access Switch 4050 User Guide starttrace <tags> <domain ID> <ou

Strona 701 - Viewing License statistics

Chapter 3 Managing the network access devices 73Nortel Secure Network Access Switch 4050 User Guide You require the following information for each net

Strona 702 - Viewing RADIUS statistics

730 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the CLITo save the system configuration to

Strona 703 - Table 157

Chapter 14 Maintaining and managing the system 731Nortel Secure Network Access Switch 4050 User Guide Table 166 provides more information about the ba

Strona 704 - Table 158

732 Chapter 14 Maintaining and managing the system320818-A gtcfg <protocol> <server> <filename> <passphrase>Restores a configu

Strona 705 - Viewing LDAP statistics

Chapter 14 Maintaining and managing the system 733Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices using the CLIT

Strona 706 - Table 159

734 Chapter 14 Maintaining and managing the system320818-A Managing software for a Nortel SNAS 4050 device using the CLITo view, download, and activat

Strona 707 - The Statistics table

Chapter 14 Maintaining and managing the system 735Nortel Secure Network Access Switch 4050 User Guide The Software Management menu includes the follow

Strona 708

736 Chapter 14 Maintaining and managing the system320818-A Managing and maintaining the system using the SREMPerforming maintenance using the SREMTo p

Strona 709

Chapter 14 Maintaining and managing the system 737Nortel Secure Network Access Switch 4050 User Guide • “Backing up or restoring the configuration usi

Strona 710

738 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Dump information in the applicable fields. Table 167 describes the Dump fields.

Strona 711

Chapter 14 Maintaining and managing the system 739Nortel Secure Network Access Switch 4050 User Guide To start or stop a trace, perform the following

Strona 712

74 Chapter 3 Managing the network access devices320818-A resetenadisdelete/cfg/domain #/vlan add <name> <VLAN ID>del <index>list/cfg

Strona 713 - Table 162

740 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Trace information in the applicable fields. Table 168 describes the Start/Stop

Strona 714

Chapter 14 Maintaining and managing the system 741Nortel Secure Network Access Switch 4050 User Guide Checking configuration using the SREMYou can che

Strona 715

742 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the SREMYou can save the current configurat

Strona 716

Chapter 14 Maintaining and managing the system 743Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Backup/Restore information in the ap

Strona 717 - The Ethernet Interface table

744 Chapter 14 Maintaining and managing the system320818-A • “Rebooting or deleting a Nortel SNAS 4050 device using the SREM” on page 750Managing soft

Strona 718 - Viewing Rx statistics

Chapter 14 Maintaining and managing the system 745Nortel Secure Network Access Switch 4050 User Guide Table 170 describes the Image List fields.The fo

Strona 719

746 Chapter 14 Maintaining and managing the system320818-A Viewing details of the active software imageTo view the details of the currently active sof

Strona 720 - Viewing Tx statistics

Chapter 14 Maintaining and managing the system 747Nortel Secure Network Access Switch 4050 User Guide Activating a software imageTo activate an old or

Strona 721

748 Chapter 14 Maintaining and managing the system320818-A 4 When prompted, click Yes.The Nortel SNAS 4050 reboots when you confirm the Activate comma

Strona 722

Chapter 14 Maintaining and managing the system 749Nortel Secure Network Access Switch 4050 User Guide To download an image from a file exchange server

Strona 723 - Chapter 14

Chapter 3 Managing the network access devices 75Nortel Secure Network Access Switch 4050 User Guide Adding a network access device using the CLIYou ca

Strona 724

750 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Download Image information in the applicable fields. Table 171 describes the Do

Strona 725

Chapter 14 Maintaining and managing the system 751Nortel Secure Network Access Switch 4050 User Guide To reboot, shut down, or reset the Nortel SNAS 4

Strona 726

752 Chapter 14 Maintaining and managing the system320818-A The command resets the device to its factory default configuration. All IP configuration is

Strona 727

Chapter 14 Maintaining and managing the system 753Nortel Secure Network Access Switch 4050 User Guide The File Download screen appears (see Figure 232

Strona 728

754 Chapter 14 Maintaining and managing the system320818-A Running Nortel SNAS 4050 diagnostics using the SREMTo run basic diagnostics on the Nortel S

Strona 729

Chapter 14 Maintaining and managing the system 755Nortel Secure Network Access Switch 4050 User Guide Table 173 describes the Diagnostics fields. Tabl

Strona 730

756 Chapter 14 Maintaining and managing the system320818-A

Strona 731 - Table 166

757Nortel Secure Network Access Switch 4050 User Guide Chapter 15 Upgrading or reinstalling the softwareThis chapter includes the following topics:The

Strona 732

758 Chapter 15 Upgrading or reinstalling the software320818-A Major release upgrade: This kind of release may contain bug fixes as well as feature enh

Strona 733 - The Boot menu displays

Chapter 15 Upgrading or reinstalling the software 759Nortel Secure Network Access Switch 4050 User Guide The set of installed Nortel SNAS 4050 devices

Strona 734

76 Chapter 3 Managing the network access devices320818-A 4 Specify the TCP port for communication between the Nortel SNAS 4050 and the network access

Strona 735

760 Chapter 15 Upgrading or reinstalling the software320818-A If needed, the file name can be prefixed with a search path to the directory on the TFTP

Strona 736

Chapter 15 Upgrading or reinstalling the software 761Nortel Secure Network Access Switch 4050 User Guide When you have downloaded the software upgrade

Strona 737

762 Chapter 15 Upgrading or reinstalling the software320818-A 5 At the Software Management# prompt, enter:6 Log in again and verify the new software v

Strona 738 - Table 167

Chapter 15 Upgrading or reinstalling the software 763Nortel Secure Network Access Switch 4050 User Guide Reinstalling the softwareIf you are adding a

Strona 739 - Figure 224

764 Chapter 15 Upgrading or reinstalling the software320818-A • authorization to log on as the boot userIf a software CD was shipped with the Nortel S

Strona 740 - Table 168

Chapter 15 Upgrading or reinstalling the software 765Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from an external fi

Strona 741 - Check Configuration

766 Chapter 15 Upgrading or reinstalling the software320818-A e Specify the default gateway IP address. 3 Specify the download details:a protocol for

Strona 742 - Backup & Restore

Chapter 15 Upgrading or reinstalling the software 767Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from a CDTo reinsta

Strona 743 - Backup & Restore fields

768 Chapter 15 Upgrading or reinstalling the software320818-A

Strona 744 - Image List

769Nortel Secure Network Access Switch 4050 User Guide Chapter 16 The Command Line InterfaceThis chapter explains how to access the Nortel SNAS 4050 t

Strona 745

Chapter 3 Managing the network access devices 77Nortel Secure Network Access Switch 4050 User Guide d To continue, go to step 7 on page 77.7 Specify t

Strona 746

770 Chapter 16 The Command Line Interface320818-A When using a Telnet or SSH client to connect to a cluster of Nortel SNAS 4050 devices, always connec

Strona 747 - Activating a software image

Chapter 16 The Command Line Interface 771Nortel Secure Network Access Switch 4050 User Guide RequirementsTo establish a console connection with the No

Strona 748

772 Chapter 16 The Command Line Interface320818-A Establishing a Telnet connectionA Telnet connection offers the convenience of accessing the Nortel S

Strona 749 - Figure 230

Chapter 16 The Command Line Interface 773Nortel Secure Network Access Switch 4050 User Guide Running TelnetOnce the IP parameters on the Nortel SNAS 4

Strona 750 - Download Image fields

774 Chapter 16 The Command Line Interface320818-A Running an SSH clientConnecting to the Nortel SNAS 4050 using an SSH client is similar to connecting

Strona 751 - Reboot/Delete ISD Options

Chapter 16 The Command Line Interface 775Nortel Secure Network Access Switch 4050 User Guide Accessing the Nortel SNAS 4050 clusterTo enable better No

Strona 752

776 Chapter 16 The Command Line Interface320818-A Access to the Nortel SNAS 4050 CLI and settings is controlled through the use of four predefined use

Strona 753 - Table 172

Chapter 16 The Command Line Interface 777Nortel Secure Network Access Switch 4050 User Guide CLI Main Menu or SetupOnce the Administrator user passwor

Strona 754 - Figure 233

778 Chapter 16 The Command Line Interface320818-A If you are automatically disconnected after the specified idle timeout interval, any unapplied confi

Strona 755 - Table 173

779Nortel Secure Network Access Switch 4050 User Guide Chapter 17 Configuration exampleThis chapter provides an example of a basic Nortel SNA configur

Strona 756

78 Chapter 3 Managing the network access devices320818-A Manually adding a switchTo add a network access device and configure it manually, use the fol

Strona 757 - Chapter 15

780 Chapter 17 Configuration example320818-A Figure 235 Basic configurationTable 176 summarizes the devices connected in this environment and their

Strona 758

Chapter 17 Configuration example 781Nortel Secure Network Access Switch 4050 User Guide Table 177 summarizes the VLANs for the Ethernet Routing Switch

Strona 759

782 Chapter 17 Configuration example320818-A Steps1 “Configure the network DNS server” on page 7822 “Configure the network DHCP server” on page 7833 “

Strona 760 - /boot/software/cur command

Chapter 17 Configuration example 783Nortel Secure Network Access Switch 4050 User Guide Configure the network DHCP serverTo configure a DHCP scope usi

Strona 761

784 Chapter 17 Configuration example320818-A 4 Enter a descriptive name to identify the new scope (see Figure 238).In this example, you are creating a

Strona 762

Chapter 17 Configuration example 785Nortel Secure Network Access Switch 4050 User Guide 5 Specify the IP address range for the DHCP scope (see Figure

Strona 763 - Reinstalling the software

786 Chapter 17 Configuration example320818-A 6 Select the Yes, I want to configure these options now option button on the Configure DHCP Options windo

Strona 764

Chapter 17 Configuration example 787Nortel Secure Network Access Switch 4050 User Guide 7 Enter the IP address of the default gateway (see Figure 241)

Strona 765

788 Chapter 17 Configuration example320818-A 8 Enter the IP address of the DNS server (see Figure 242).Figure 242 Specifying the DNS server9 Repeat

Strona 766

Chapter 17 Configuration example 789Nortel Secure Network Access Switch 4050 User Guide Figure 243 shows the DHCP scopes created for use in this examp

Strona 767

Chapter 3 Managing the network access devices 79Nortel Secure Network Access Switch 4050 User Guide Figure 4 Adding a switch manuallyDeleting a netw

Strona 768

790 Chapter 17 Configuration example320818-A 2 Assign the VLAN port members.Since the edge switches in this example are operating in Layer 2 mode, ena

Strona 769 - The Command Line Interface

Chapter 17 Configuration example 791Nortel Secure Network Access Switch 4050 User Guide 7 “Configuring the NSNA ports” on page 7928 “Enabling NSNA glo

Strona 770

792 Chapter 17 Configuration example320818-A Configuring the NSNA uplink filterPassport-8310:6# config filter acl 100 create ip acl-name "dhcp&qu

Strona 771 - Procedure

Chapter 17 Configuration example 793Nortel Secure Network Access Switch 4050 User Guide Configure the Ethernet Routing Switch 5510The following config

Strona 772

794 Chapter 17 Configuration example320818-A Configuring SSHIn this example, the assumption is that the Nortel SNAS 4050 public key has already been u

Strona 773 - Running Telnet

Chapter 17 Configuration example 795Nortel Secure Network Access Switch 4050 User Guide Configuring the login domain controller filters5510-48T(config

Strona 774 - Running an SSH client

796 Chapter 17 Configuration example320818-A 3 “Adding the network access devices” on page 7984 “Mapping the VLANs” on page 8005 “Enabling the network

Strona 775

Chapter 17 Configuration example 797Nortel Secure Network Access Switch 4050 User Guide Enter a password for the "admin" user: Re-enter to c

Strona 776 - User access levels

798 Chapter 17 Configuration example320818-A Generate and activate the SSH key for communication with the network access devices:>> Main# cfg/do

Strona 777 - Idle timeout

Chapter 17 Configuration example 799Nortel Secure Network Access Switch 4050 User Guide Adding the Ethernet Routing Switch 8300Add the switch manually

Strona 778

8 Contents320818-A Configuring domain parameters using the SREM . . . . . . . . . . . . . . . . . . . . . . . . 164Additional domain configuration in

Strona 779 - Configuration example

80 Chapter 3 Managing the network access devices320818-A The delete command removes the current switch from the control of the Nortel SNAS 4050 cluste

Strona 780 - Table 176

800 Chapter 17 Configuration example320818-A Adding the Ethernet Routing Switch 5510Use the quick switch wizard:>> Main# cfg/domain 1/quickEnter

Strona 781

Chapter 17 Configuration example 801Nortel Secure Network Access Switch 4050 User Guide >> Domain Vlan# applyChanges applied successfully.Enabli

Strona 782

802 Chapter 17 Configuration example320818-A

Strona 783 - Creating a new DHCP scope

803Nortel Secure Network Access Switch 4050 User Guide Appendix ACLI referenceThe command line interface (CLI) allows you to view system information a

Strona 784 - Naming the new DHCP scope

804 Appendix A CLI reference320818-A Using the CLICLI commands are grouped into a series of menus and submenus (see “CLI Main Menu” on page 812). Each

Strona 785 - Figure 239

Appendix A CLI reference 805Nortel Secure Network Access Switch 4050 User Guide pasteRestores a saved configuration that includes private keys. TIP: B

Strona 786 - Figure 240

806 Appendix A CLI reference320818-A Command line history and editingYou can use the CLI to retrieve and modify commands entered previously. Table 180

Strona 787 - Figure 241

Appendix A CLI reference 807Nortel Secure Network Access Switch 4050 User Guide CLI shortcutsYou can use the following CLI command shortcuts:• “Comman

Strona 788 - Specifying the DNS server

808 Appendix A CLI reference320818-A You can also use command stacking to proceed one or more levels in the menu system, and go directly to another su

Strona 789

Appendix A CLI reference 809Nortel Secure Network Access Switch 4050 User Guide • To display the active menu:— Ensure that the command line is blank.—

Strona 790

Chapter 3 Managing the network access devices 81Nortel Secure Network Access Switch 4050 User Guide The Switch menu includes the following options:/cf

Strona 791 - Configuring the VoIP VLANs

810 Appendix A CLI reference320818-A If you use the cur command without the sys submenu argument, information related to the Configuration menu and al

Strona 792 - Enabling NSNA globally

Appendix A CLI reference 811Nortel Secure Network Access Switch 4050 User Guide • 255.255.255.0 it can also be expressed as 24• 255.255.255.255 it can

Strona 793 - Setting the switch IP address

812 Appendix A CLI reference320818-A CLI Main MenuThe Main menu appears after a successful connection and login. Figure 244 represents the Main menu a

Strona 794 - Configuring SSH

Appendix A CLI reference 813Nortel Secure Network Access Switch 4050 User Guide • Maintenance — used for sending technical support information to an e

Strona 795

814 Appendix A CLI reference320818-A Information menuThe Information menu contains commands used to display current information about the Nortel SNAS

Strona 796 - Performing initial setup

Appendix A CLI reference 815Nortel Secure Network Access Switch 4050 User Guide Statistics menuThe Statistics menu contains commands used to view stat

Strona 797 - Completing initial setup

816 Appendix A CLI reference320818-A Configuration menuThe Configuration menu contains commands used to configure the Nortel SNAS 4050. Table 184 list

Strona 798

Appendix A CLI reference 817Nortel Secure Network Access Switch 4050 User Guide /cfg/domain <domain ID>name <name>pvips <IPaddr>aaas

Strona 799 - Switch 8300:

818 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/ldapserverssearchbase <DN>groupattr <names>userattr <names>isdbinddn &

Strona 800 - Mapping the VLANs

Appendix A CLI reference 819Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/auth #/localadd <user name> <password> &

Strona 801

82 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the CLIThe VLANs are configured on the network access devices. You sp

Strona 802

820 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/radius/sessiontimvendorid <vendor ID>vendortype <vendor type>enadisConfigure

Strona 803 - CLI reference

Appendix A CLI reference 821Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/group #/extend #/linksetlistdel <index number>

Strona 804 - Using the CLI

822 Appendix A CLI reference320818-A /cfg/domain #/aaa/tg quickrecheck <interval>heartbeat <interval>hbretrycnt <count>status-quo on

Strona 805

Appendix A CLI reference 823Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/linkset <linkset ID>name <name>text <text

Strona 806

824 Appendix A CLI reference320818-A /cfg/domain #/portal/colorscolor1 <code>color2 <code>color3 <code>color4 <code>theme defa

Strona 807 - CLI shortcuts

Appendix A CLI reference 825Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/server/adv/traflogsysloghost <IPaddr>udpport <p

Strona 808 - Tab completion

826 Appendix A CLI reference320818-A /cfg/domain #/switch <switch ID>name <name>type ERS8300|ERS5500ip <IPaddr>port <port>hlth

Strona 809

Appendix A CLI reference 827Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/vlan add <name> <VLAN ID>del <index>li

Strona 810 - Network masks

828 Appendix A CLI reference320818-A /cfg/sys/accesslist listdel <index number>add <IPaddr> <mask>Manage the Access List in order to

Strona 811 - Variables

Appendix A CLI reference 829Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/auth/serverslistdel <index number>add <IPaddr>

Strona 812 - CLI command reference

Chapter 3 Managing the network access devices 83Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 maintains separate maps for t

Strona 813 - Appendix A CLI reference 813

830 Appendix A CLI reference320818-A /cfg/sys/adm/snmp/eventaddmonitor [<options>] -b <name> <OID> <op> <value>addmonito

Strona 814 - Information menu

Appendix A CLI reference 831Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/snmp/users <user ID>name <name>seclevel none|

Strona 815 - Statistics menu

832 Appendix A CLI reference320818-A /cfg/sys/dns/servers listdel <index number>add <IPaddr> insert <index number> <IPaddr>mov

Strona 816 - Configuration menu

Appendix A CLI reference 833Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/host <host ID>ip <IPaddr>sysName <name>sysL

Strona 817

834 Appendix A CLI reference320818-A /cfg/sys/time date <date>time <time>tzonentpConfigure date and time settings for the cluster.page 475

Strona 818

Appendix A CLI reference 835Nortel Secure Network Access Switch 4050 User Guide Boot menuThe Boot menu contains commands for management of Nortel SNAS

Strona 819

836 Appendix A CLI reference320818-A Maintenance menuThe Maintenance menu contains commands used to perform maintenance and management activities for

Strona 820

837Nortel Secure Network Access Switch 4050 User Guide Chapter 18 TroubleshootingThis chapter includes the following topics:Troubleshooting tipsThis c

Strona 821

838 Chapter 18 Troubleshooting320818-A Cannot connect to the Nortel SNAS 4050 using Telnet or SSHVerify the current configurationConnect with a consol

Strona 822

Chapter 18 Troubleshooting 839Nortel Secure Network Access Switch 4050 User Guide When Telnet or SSH access is enabled, only those hosts listed in the

Strona 823

84 Chapter 3 Managing the network access devices320818-A Managing SSH keys using the CLIThe Nortel SNAS 4050 and the network access devices controlled

Strona 824

840 Chapter 18 Troubleshooting320818-A Ensure that you ping the host IP address (RIP) of the Nortel SNAS 4050, and not the Management IP address (MIP)

Strona 825

Chapter 18 Troubleshooting 841Nortel Secure Network Access Switch 4050 User Guide Cannot add the Nortel SNAS 4050 to a clusterWhen you try to add a No

Strona 826

842 Chapter 18 Troubleshooting320818-A The problem may be that there are existing entries in the Access List. When Telnet or SSH access is enabled, on

Strona 827

Chapter 18 Troubleshooting 843Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 stops respondingTelnet or SSH connection to the

Strona 828

844 Chapter 18 Troubleshooting320818-A If the operational status of the Nortel SNAS 4050 is still down, reboot the machine. On the device, press the P

Strona 829

Chapter 18 Troubleshooting 845Nortel Secure Network Access Switch 4050 User Guide Boot user passwordThe default Boot user password cannot be changed,

Strona 830

846 Chapter 18 Troubleshooting320818-A For more information about the starttrace command, the tags you can specify for the trace, and the available ou

Strona 831

Chapter 18 Troubleshooting 847Nortel Secure Network Access Switch 4050 User Guide System diagnosticsThe following are useful diagnostic display comman

Strona 832

848 Chapter 18 Troubleshooting320818-A To check network settings for a specific Nortel SNAS 4050, access the Cluster Host menu by typing the following

Strona 833

Chapter 18 Troubleshooting 849Nortel Secure Network Access Switch 4050 User Guide To capture and analyze TCP traffic between clients and the virtual S

Strona 834

Chapter 3 Managing the network access devices 85Nortel Secure Network Access Switch 4050 User Guide If you regenerate the key at any time, you must re

Strona 835 - Boot menu

850 Chapter 18 Troubleshooting320818-A server you specify. The information can then be used for technical support purposes. The file sent to the TFTP/

Strona 836 - Maintenance menu

851Nortel Secure Network Access Switch 4050 User Guide Appendix BSyslog messagesThis appendix contains a list of the syslog messages that are sent fro

Strona 837 - Troubleshooting

852 Appendix B Syslog messages320818-A Operating system (OS) messagesThere are three categories of operating system (OS) system messages:• EMERG (see

Strona 838 - Check the Access List

Appendix B Syslog messages 853Nortel Secure Network Access Switch 4050 User Guide Table 190 lists the operating system EMERG messages.System Control P

Strona 839

854 Appendix B Syslog messages320818-A Table 191 lists the System Control Process INFO messages.About alarm messagesAlarms are sent at a syslog level

Strona 840

Appendix B Syslog messages 855Nortel Secure Network Access Switch 4050 User Guide Table 193 lists the System Control Process ALARM messages. To simpli

Strona 841 - Cannot contact the MIP

856 Appendix B Syslog messages320818-A About event messagesEvents are sent at the NOTICE syslog level. Event messages are formatted according to the f

Strona 842

Appendix B Syslog messages 857Nortel Secure Network Access Switch 4050 User Guide Traffic Processing Subsystem messagesThere are four categories of Tr

Strona 843 - Console connection

858 Appendix B Syslog messages320818-A css error: <reason> ERROR Problem encountered when parsing a style sheet. The problem could be in the Nor

Strona 844 - A user password is lost

Appendix B Syslog messages 859Nortel Secure Network Access Switch 4050 User Guide Table 197 lists the Traffic Processing WARNING messages.socks error:

Strona 845 - Trace tools

86 Chapter 3 Managing the network access devices320818-A The NSNAS SSH key menu includes the following options:/cfg/domain #/sshkeyfollowed by:generat

Strona 846

860 Appendix B Syslog messages320818-A Table 198 lists the Traffic Processing INFO messages.Start-up messagesThe Traffic Processing Subsystem Start-up

Strona 847 - System diagnostics

Appendix B Syslog messages 861Nortel Secure Network Access Switch 4050 User Guide Table 199 lists the Start-up INFO messages.AAA subsystem messagesThe

Strona 848

862 Appendix B Syslog messages320818-A Table 201 lists the AAA INFO messages. INFO messages are generated only if the CLI command /cfg/domain #/adv/lo

Strona 849 - Error log files

Appendix B Syslog messages 863Nortel Secure Network Access Switch 4050 User Guide NSNAS subsystem messagesThere are two categories of NSNAS subsystem

Strona 850

864 Appendix B Syslog messages320818-A Table 202 lists the NSNAS ERROR messages.Table 203 lists the NSNAS INFO messages.Table 202 NSNAS — ERRORMessa

Strona 851 - Syslog messages

Appendix B Syslog messages 865Nortel Secure Network Access Switch 4050 User Guide Syslog messages in alphabetical orderTable 204 lists the syslog mess

Strona 852

866 Appendix B Syslog messages320818-A audit EVENT System Control Sent when a CLI system administrator enters, enters, exits or updates the CLI if aud

Strona 853

Appendix B Syslog messages 867Nortel Secure Network Access Switch 4050 User Guide copy_software_release_failed ALARM (CRITICAL)System Control A Nortel

Strona 854 - About alarm messages

868 Appendix B Syslog messages320818-A gzip warning: <reason> INFO Traffic ProcessingProblem encountered when processing compressed content.HC:

Strona 855 - Table 193

Appendix B Syslog messages 869Nortel Secure Network Access Switch 4050 User Guide isd_down ALARM (CRITICAL)System Control A member of the Nortel SNAS

Strona 856 - About event messages

Chapter 3 Managing the network access devices 87Nortel Secure Network Access Switch 4050 User Guide Figure 5 shows sample output for the /cfg/domain #

Strona 857

870 Appendix B Syslog messages320818-A make_software_release_permanent_failedALARM (CRITICAL)System Control Failed to make a new software release perm

Strona 858

Appendix B Syslog messages 871Nortel Secure Network Access Switch 4050 User Guide NSNAS LoginSucceeded Domain=”<id>” Method=<”ssl”> SrcIp=

Strona 859

872 Appendix B Syslog messages320818-A Root filesystem repaired - rebootingERROR OS fsck found and fixed errors. Probably OK.Server <id> uses de

Strona 860 - Start-up messages

Appendix B Syslog messages 873Nortel Secure Network Access Switch 4050 User Guide switch controller:switch [1:<switchID>] – DisconnectedINFO NSN

Strona 861 - AAA subsystem messages

874 Appendix B Syslog messages320818-A Unable to use the certificate for <server nr>ERROR Traffic ProcessingUnsuitable certificate configured fo

Strona 862 - Table 201

875Nortel Secure Network Access Switch 4050 User Guide Appendix CSupported MIBsThis appendix describes the Management Information Bases (MIB) and trap

Strona 863 - NSNAS subsystem messages

876 Appendix C Supported MIBs320818-A • ALTEON-SSL-VPN-MIB• ANAifType-MIB• DISMAN-EVENT-MIB•ENTITY-MIB•IF-MIB• IP-FORWARD-MIB•IP-MIB• NORTEL-SECURE-AC

Strona 864 - Table 202

Appendix C Supported MIBs 877Nortel Secure Network Access Switch 4050 User Guide ALTEON-ISD-SSL-MIB Contains objects for monitoring the SSL gateways.

Strona 865 - NSNAS — INFO (Sheet 2 of 2)

878 Appendix C Supported MIBs320818-A NORTEL-SECURE-ACCESS-SWITCH-MIBContains objects for monitoring the Nortel SNAS 4050 devices. The following group

Strona 866

Appendix C Supported MIBs 879Nortel Secure Network Access Switch 4050 User Guide Supported trapsTable 206 describes the traps supported by the Nortel

Strona 867

88 Chapter 3 Managing the network access devices320818-A Managing SSH keys for Nortel SNA communication using the CLITo retrieve the public key for th

Strona 868

880 Appendix C Supported MIBs320818-A

Strona 869 - /cfg/sys/cur

881Nortel Secure Network Access Switch 4050 User Guide Appendix DSupported ciphersThe Nortel SNAS 4050 supports SSL version 2.0, SSL version 3.0, and

Strona 870

882 Appendix D Supported ciphers320818-A EDH-RSA-DES-CBC-SHA SSLv3 DH, RSA DES (56) SHA1DES-CBC-SHA SSLv3 RSA, RSA DES (56) SHA1DES-CBC-MD5 SSLv2 RSA,

Strona 871

883Nortel Secure Network Access Switch 4050 User Guide Appendix EAdding User Preferences attribute to Active DirectoryFor the remote user to be able t

Strona 872

884 Appendix E Adding User Preferences attribute to Active Directory320818-A Add the Active Directory Schema Snap-in (Windows 2000 Server and Windows

Strona 873

Appendix E Adding User Preferences attribute to Active Directory 885Nortel Secure Network Access Switch 4050 User Guide The Add/Remove Snap-in window

Strona 874

886 Appendix E Adding User Preferences attribute to Active Directory320818-A 8 Click OK.The Console window redisplays.9 To save the console (including

Strona 875 - Supported MIBs

Appendix E Adding User Preferences attribute to Active Directory 887Nortel Secure Network Access Switch 4050 User Guide 3 Select the check box The Sch

Strona 876 - Supported MIBs (Sheet 1 of 3)

888 Appendix E Adding User Preferences attribute to Active Directory320818-A Create the new classTo create the nortelSSLOffload class, proceed as foll

Strona 877 - Supported MIBs (Sheet 2 of 3)

Appendix E Adding User Preferences attribute to Active Directory 889Nortel Secure Network Access Switch 4050 User Guide 5 Add the isdUserPrefs attribu

Strona 878 - Supported MIBs (Sheet 3 of 3)

Chapter 3 Managing the network access devices 89Nortel Secure Network Access Switch 4050 User Guide Reimporting the network access device SSH key usin

Strona 879 - Supported traps

890 Appendix E Adding User Preferences attribute to Active Directory320818-A 5 Add the nortelSSLOffload class as an auxiliary class as shown below: 6

Strona 880 - 880 Appendix C Supported MIBs

891Nortel Secure Network Access Switch 4050 User Guide Appendix FConfiguring DHCP to auto-configure IP PhonesThe DHCP server and the IP Phone 2002, IP

Strona 881 - Supported ciphers

892 Appendix F Configuring DHCP to auto-configure IP Phones320818-A For information on the minimum firmware versions required to support IP Phones in

Strona 882 - Table 207 Supported ciphers

Appendix F Configuring DHCP to auto-configure IP Phones 893Nortel Secure Network Access Switch 4050 User Guide Figure 245 The DHCP Management Consol

Strona 883 - Directory

894 Appendix F Configuring DHCP to auto-configure IP Phones320818-A The Predefined Options and Values dialog box opens (see Figure 246).Figure 246 T

Strona 884

Appendix F Configuring DHCP to auto-configure IP Phones 895Nortel Secure Network Access Switch 4050 User Guide Figure 247 The Option Type dialog box

Strona 885

896 Appendix F Configuring DHCP to auto-configure IP Phones320818-A b In the Option Type dialog box, enter the required information (see Table 209).c

Strona 886 - (Windows 2000 Server)

Appendix F Configuring DHCP to auto-configure IP Phones 897Nortel Secure Network Access Switch 4050 User Guide The Scope Options dialog box displays (

Strona 887 - Create a new attribute

898 Appendix F Configuring DHCP to auto-configure IP Phones320818-A 4 Configure Call Server Information:a Select the check box beside 128 Call Server

Strona 888 - Create the new class

Appendix F Configuring DHCP to auto-configure IP Phones 899Nortel Secure Network Access Switch 4050 User Guide 5 Configure VLAN Information:a In the S

Strona 889

Contents 9Nortel Secure Network Access Switch 4050 User Guide Modifying a client filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 890

90 Chapter 3 Managing the network access devices320818-A The HealthCheck menu includes the following options:Controlling communication with the networ

Strona 891 - Appendix F

900 Appendix F Configuring DHCP to auto-configure IP Phones320818-A

Strona 892 - Creating the DHCP options

901Nortel Secure Network Access Switch 4050 User Guide Appendix GUsing a Windows domain logon script to launch the Nortel SNAS 4050 portalThis appendi

Strona 893 - The DHCP Management Console

902 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 2 On a Windows 2000 domain controller, save the scrip

Strona 894 - 4 Click Add

Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal 903Nortel Secure Network Access Switch 4050 User Guide 2 Compose

Strona 895 - The Option Type dialog box

904 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 3 On the Group Policy tab, click Open.4 Double-click

Strona 896 - Information options

905Nortel Secure Network Access Switch 4050 User Guide Appendix HSoftware licensing informationOpenSSL License issuesThe OpenSSL toolkit stays under a

Strona 897 - Figure 248

906 Appendix H Software licensing information320818-A conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., c

Strona 898

Appendix H Software licensing information 907Nortel Secure Network Access Switch 4050 User Guide warranty; keep intact all the notices that refer to t

Strona 899 - Setting up the IP Phone

908 Appendix H Software licensing information320818-A 4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided

Strona 900

Appendix H Software licensing information 909Nortel Secure Network Access Switch 4050 User Guide LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY

Strona 901 - Appendix G

Chapter 3 Managing the network access devices 91Nortel Secure Network Access Switch 4050 User Guide To restart communication between the Nortel SNAS 4

Strona 902 - Creating a logon script

910 Appendix H Software licensing information320818-A Bouncy Castle licenseCopyright (c) 2000 - 2004 The Legion Of The Bouncy Castle (http://www.bounc

Strona 903 - Assigning the logon script

Nortel Secure Network Access Switch 4050 User Guide911 IndexSymbols/ (in CLI) 804? (help, in CLI) 804Aaborting commands (CLI) 807accessenable for SSH

Strona 904 - Assigning a logon script

912 Index320818-A automatic redirection, from portal 396autorun linksets 394Bbackend interfaceconfigure 145backupcertificates and keys 574, 591, 605c

Strona 905 - Appendix H

Index 913Nortel Secure Network Access Switch 4050 User Guide create 214modify 217clusteradd Nortel SNAS 4050 device 61and Access List 62benefits 39c

Strona 906 - GNU General Public License

914 Index320818-A RADIUS authentication method 242, 272CSR (Certificate Signing Request)and associated private key 583generate 579, 601information re

Strona 907

Index 915Nortel Secure Network Access Switch 4050 User Guide create 203, 220map linksets 206, 223, 227modify 222remove linksets 229reorder linksets

Strona 908

916 Index320818-A IP addresses 51in two-armed configuration 52MIP 51pVIP 51RIP 52subnet requirements 52IP Phones, supported in Nortel SNA 33Jjoin a c

Strona 909

Index 917Nortel Secure Network Access Switch 4050 User Guide MmacrosLDAP 258, 294used on portal page 395major release upgrade 758manageActive Direct

Strona 910 - Bouncy Castle license

918 Index320818-A RIP 52role in Nortel SNA solution 33SSH public key, export 84nslookup (CLI global command) 805Oone-armed configuration 40, 41online

Strona 911

Index 919Nortel Secure Network Access Switch 4050 User Guide create method 242, 272in Nortel SNA 36manage servers 247, 279, 281modify configuration

Strona 912

92 Chapter 3 Managing the network access devices320818-A The Switches screen appears (see “Switch Configuration screen” on page 116).2 Click Add.The A

Strona 913

920 Index320818-A existence monitor 627, 654in Nortel SNA 618manage events 655manage monitor events 647manage targets 638monitors 627supported MIBs 8

Strona 914

Index 921Nortel Secure Network Access Switch 4050 User Guide network diagnostics 847Ttechnical publications 29technical support 29Telnetenable acces

Strona 915

922 Index320818-A default mapping, domain quick setup wizard 128in Nortel SNA solution 34mapping 82, 96VoIP phones, supported in Nortel SNA 33VoIP VL

Strona 916

Chapter 3 Managing the network access devices 93Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The network access device appears in

Strona 917

94 Chapter 3 Managing the network access devices320818-A To reconfigure the VLAN mappings for an existing network access device, you must first disabl

Strona 918

Chapter 3 Managing the network access devices 95Nortel Secure Network Access Switch 4050 User Guide 2 Enter the network access device information in t

Strona 919

96 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the SREMThe VLANs are configured on the network access devices. You s

Strona 920

Chapter 3 Managing the network access devices 97Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domainTo map VLANs in a domain, s

Strona 921

98 Chapter 3 Managing the network access devices320818-A Adding VLANs to a domainTo add VLANs to a domain, complete the following steps:1 Select the S

Strona 922

Chapter 3 Managing the network access devices 99Nortel Secure Network Access Switch 4050 User Guide Removing VLANs from a domainTo remove existing VLA

Komentarze do niniejszej Instrukcji

Brak uwag