Alteon Switched Firewall 3.0.2 Installation And
Total Page:16
File Type:pdf, Size:1020Kb
Installation and User’s Guide Alteon Switched FirewallTM Release 3.0.2 Part Number: 212535-E, April 2003 4655 Great America Parkway Santa Clara, CA 95054 Phone 1-800-4Nortel www.nortelnetworks.com Alteon Switched Firewall Installation and User’s Guide Copyright © 2003 Nortel Networks, Inc., 4655 Great America Parkway, Santa Clara, California, 95054, USA. All rights reserved. Part Number: 212535-E. This document is protected by copyright and distributed under licenses restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Nortel Networks, Inc. Documentation is provided “as is” without warranty of any kind, either express or implied, including any kind of implied or express warranty of non- infringement or the implied warranties of merchantability or fitness for a particular purpose. U.S. Government End Users: This document is provided with a “commercial item” as defined by FAR 2.101 (Oct. 1995) and contains “commercial technical data” and “commercial software documentation” as those terms are used in FAR 12.211-12.212 (Oct. 1995). Government End Users are authorized to use this documentation only in accordance with those rights and restrictions set forth herein, consistent with FAR 12.211- 12.212 (Oct. 1995), DFARS 227.7202 (JUN 1995) and DFARS 252.227-7015 (Nov. 1995). Nortel Networks, Inc. reserves the right to change any products described herein at any time, and without notice. Nortel Networks, Inc. assumes no responsibility or liability arising from the use of products described herein, except as expressly agreed to in writing by Nortel Networks, Inc. The use and purchase of this product does not convey a license under any patent rights, trademark rights, or any other intellectual property rights of Nortel Networks, Inc. Alteon, Alteon WebSystems, Alteon Switched Firewall, ASF 5308, ASF 5408, ASF 5610, ASF 5710, ASF 5722, Firewall OS, Firewall Director, ASF 5008, ASF 5010, Accelerator OS, Firewall Accelerator, ASF 5300, ASF 5400, ASF 5600, and ASF 5700 are trademarks of Nortel Networks, Inc. in the United States and certain other countries. FireWall-1 NG is a registered trademark of Check Point Software Technologies. Any other trademarks appearing in this manual are owned by their respective companies. Portions of this manual are Copyright © 2001 Dell Computer Corporation. All Rights Reserved. Originated in the USA. Export This product, software and related technology is subject to U.S. export control and may be subject to export or import regulations in other countries. Purchaser must strictly comply with all such laws and regulations. A license to export or reexport may be required by the U.S. Department of Commerce. Licensing This product includes software developed by Check Point Software Technologies (http:// www.checkpoint.com). This product also contains software developed by other parties. See Appendix D, “Software Licenses,” for more information. 2 212535-E, April 2003 Alteon Switched Firewall Installation and User’s Guide Regulatory Compliance FCC Class A Notice. The equipment complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: 1) The device may not cause harmful interference, and 2) This equipment must accept any interference received, including interference that may cause undesired operation. The equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. The equipment generates, uses and can radiate radio-frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. Operation of this equipment in a residential area is likely to cause harmful interference. In such a case, the user will be required to correct the interference at his own experience. Do not make mechanical or electrical modifications to the equipment. Industry Canada: This Class A digital apparatus meets all requirements of the Canadian Interference- Causing Equipment Regulations. Cet appareil Numérique de la classe A respecte toutes les exigences du Règlements sur le matériel brouilleur du Canada. VCCI Class A Notice: This is a Class A product based on the standard of the Voluntary Control Council for Interference from Information Technology Equipment (VCCI). If this equipment is used in a domestic environment, radio disturbance may occur. In such a case, the user may be required to take corrective actions. Japanese VCCI Class A Notice Taiwan EMC Notice CE Notice: The CE mark on this equipment indicates that this equipment meets or exceeds the following technical standards: EN55022, EN55024, EN60950, and all supporting document requirements. 3 212535-E, April 2003 Alteon Switched Firewall Installation and User’s Guide Safety Information Caution—Nortel Networks products are designed to work with single-phase power systems having a grounded neutral conductor. To reduce the risk of electric shock, do not plug Nortel Networks products into any other type of power system. Contact your facilities manager or a qualified electrician if you are not sure what type of power is supplied to your building. Caution—Not all power cords have the same ratings. Household extension cords do not have overload protection and are not meant for use with computer systems. Do not use household extension cords with your Nortel Networks product. Caution—Your Nortel Networks product is shipped with a grounding type (three-wire) power cord. To reduce the risk of electric shock, always plug the cord into a grounded power outlet. Lithium Battery Cautions Caution—This product contains a lithium battery. Batteries are not customer replaceable parts. They may explode if mishandled. Do not dispose of the battery in fire. Do not disassemble or recharge. (Norge) ADVARSEL—Litiumbatteri - Eksplosjonsfare. Ved utskifting benyttes kun batteri som anbefalt av apparatfabrikanten. Brukt batteri returneres apparatleverandøren. (Sverige) VARNING—Explosionsfara vid felaktigt batteribyte. Använd samma batterityp eller en ekvivalent typ som rekommenderas av apparattillverkaren. Kassera använt batteri enligt fabrikantens instruktion. (Danmark) ADVARSEL! Litiumbatteri - Eksplosionsfare ved fejlagtig håndtering. Udskiftning må kun ske med batteri af samme fabrikat og type. Levér det brugte batteri tilbage til leverandøren. (Suomi) VAROITUS—Paristo voi räjähtää, jos se on virheellisesti asennettu. Vaihda paristo ainoastaan laitevalmistajan suosittelemaan tyyppiin. Hävitä käytetty paristo valmistajan ohjeiden mukaisesti. Warranty Nortel Networks provides a limited warranty on all its products for a period of one year from the date of shipment. Free technical support and free replacement of hardware is provided for the first 90 days after shipment. You may choose to purchase additional service and support from Nortel Networks. Please contact your local sales representative for more information. 4 212535-E, April 2003 Contents Preface 13 Product Name & Platform Changes 13 Who Should Use This Book 14 How This Book Is Organized 14 How to Get Help 15 Typographic Conventions 16 Chapter 1: The Alteon Switched Firewall 17 Feature Summary 17 Alteon Switched Firewall Basics 18 Network Elements 18 Basic Operation 20 Port Filtering 20 Topology Specifics 21 Security Processing 22 Physical Description 23 The Firewall Director 23 The Alteon Firewall Accelerator 30 Chapter 2: Hardware Installation 33 Required Equipment 34 Model Compatibility 35 Safety Precautions 35 Rack-Mounting the Firewall Accelerator 36 Rack-Mounting the Firewall Director 39 Task Summary 39 Select the Appropriate Rack-Mounting Kit 40 Remove the Rack Doors 42 Mark the Rack 42 Attach the Slide Assemblies to the Rack 44 5 212535-E, April 2003 Alteon Switched Firewall Installation and User’s Guide Attach the System Chassis to the Slide Assemblies 53 Add the Cable-Management Arm 55 Reattach the Cabinet Doors 56 Connecting Network Cables 57 Basic Alteon Switched Firewall Network Topology 57 Network Connector and Cable Specifications 59 Port LED Indicators 62 Automatic Selection of Redundant Connections 63 Using the Firewall Director Cable-Management Arm 64 Connecting Power 65 Connecting AC Power for the Firewall Accelerator 65 Connecting AC Power for the Firewall Director 65 Turning Power On 67 Turning Power Off 67 Connecting a Console Terminal 68 Requirements 68 Console Connector and Cable Specifications 69 Establishing a Connection 70 Chapter 3: Initial Setup 71 Overview of Initial Setup Tasks 72 Collect Basic System Information 72 Example Network 73 Use Setup for Basic Configuration 74 Configure Licenses and Interfaces 78 Install Check Point Management Tools 81 Configuring and Install Firewall Policies 89 Task Overview 89 Log in to the Policy Editor 89 Define the Alteon Switched Firewall Object 90 Establish Secure Internal Communications 92 Using Central Licensing 94 Create and Install Firewall Policies 95 Chapter 4: System Management Basics 97 Management Tools 97 Users and Passwords 98 The Single System Image 99 6 n Contents 212535-E, April 2003 Alteon Switched Firewall Installation and User’s Guide Chapter 5: The Command Line Interface 101 Accessing the Command Line Interface 102 Using the Local Serial Port 102 Defining the Remote