ASF 2.0.3 Installation and User's Guide
Total Page:16
File Type:pdf, Size:1020Kb
Installation and User’s Guide Alteon Switched FirewallTM Release 2.0.3 Part Number: 212535-C, October 2002 4655 Great America Parkway Santa Clara, CA 95054 Phone 1-800-4Nortel www.nortelnetworks.com Alteon Switched Firewall Installation and User’s Guide Copyright © 2002 Nortel Networks, Inc., 4655 Great America Parkway, Santa Clara, California, 95054, USA. All rights reserved. Part Number: 212535-C. This document is protected by copyright and distributed under licenses restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Nortel Networks, Inc. Documentation is provided “as is” without warranty of any kind, either express or implied, including any kind of implied or express warranty of non- infringement or the implied warranties of merchantability or fitness for a particular purpose. U.S. Government End Users: This document is provided with a “commercial item” as defined by FAR 2.101 (Oct. 1995) and contains “commercial technical data” and “commercial software documentation” as those terms are used in FAR 12.211-12.212 (Oct. 1995). Government End Users are authorized to use this documentation only in accordance with those rights and restrictions set forth herein, consistent with FAR 12.211- 12.212 (Oct. 1995), DFARS 227.7202 (JUN 1995) and DFARS 252.227-7015 (Nov. 1995). Nortel Networks, Inc. reserves the right to change any products described herein at any time, and without notice. Nortel Networks, Inc. assumes no responsibility or liability arising from the use of products described herein, except as expressly agreed to in writing by Nortel Networks, Inc. The use and purchase of this product does not convey a license under any patent rights, trademark rights, or any other intellectual property rights of Nortel Networks, Inc. Alteon, Alteon WebSystems, Alteon Switched Firewall, ASF 5308, ASF 5408, ASF 5610, ASF 5710, ASF 5722, Firewall OS, Firewall Director, ASF 5008, ASF 5010, ASF 5022, Accelerator OS, Firewall Accelerator, ASF 5300, ASF 5400, ASF 5600, and ASF 5700 are trademarks of Nortel Networks, Inc. in the United States and certain other countries. FireWall-1 NG is a registered trademark of Check Point Software Technologies. Any other trademarks appearing in this manual are owned by their respective companies. Portions of this manual are Copyright © 2001 Dell Computer Corporation. All Rights Reserved. Originated in the USA. Export This product, software and related technology is subject to U.S. export control and may be subject to export or import regulations in other countries. Purchaser must strictly comply with all such laws and regulations. A license to export or reexport may be required by the U.S. Department of Commerce. Licensing This product includes software developed by Check Point Software Technologies (http:// www.checkpoint.com). This product also contains software developed by other parties. See Appendix D, “Software Licenses,” for more information. 2 212535-C, October 2002 Alteon Switched Firewall Installation and User’s Guide Regulatory Compliance FCC Class A Notice. The equipment complies with Part 15 of the FCC Rules. Operation is subject to the following two conditions: 1) The device may not cause harmful interference, and 2) This equipment must accept any interference received, including interference that may cause undesired operation. The equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference in a residential installation. The equipment generates, uses and can radiate radio-frequency energy and, if not installed and used in accordance with the instructions, may cause harmful interference to radio communications. However, there is no guarantee that interference will not occur in a particular installation. Operation of this equipment in a residential area is likely to cause harmful interference. In such a case, the user will be required to correct the interference at his own experience. Do not make mechanical or electrical modifications to the equipment. Industry Canada: This Class A digital apparatus meets all requirements of the Canadian Interference- Causing Equipment Regulations. Cet appareil Numérique de la classe A respecte toutes les exigences du Règlements sur le matériel brouilleur du Canada. VCCI Class A Notice: This is a Class A product based on the standard of the Voluntary Control Council for Interference from Information Technology Equipment (VCCI). If this equipment is used in a domestic environment, radio disturbance may occur. In such a case, the user may be required to take corrective actions. Japanese VCCI Class A Notice Taiwan EMC Notice CE Notice: The CE mark on this equipment indicates that this equipment meets or exceeds the following technical standards: EN55022, EN55024, EN60950, and all supporting document requirements. 3 212535-C, October 2002 Alteon Switched Firewall Installation and User’s Guide Safety Information Caution—Nortel Networks products are designed to work with single-phase power systems having a grounded neutral conductor. To reduce the risk of electric shock, do not plug Nortel Networks products into any other type of power system. Contact your facilities manager or a qualified electrician if you are not sure what type of power is supplied to your building. Caution—Not all power cords have the same ratings. Household extension cords do not have overload protection and are not meant for use with computer systems. Do not use household extension cords with your Nortel Networks product. Caution—Your Nortel Networks product is shipped with a grounding type (three-wire) power cord. To reduce the risk of electric shock, always plug the cord into a grounded power outlet. Lithium Battery Cautions Caution—This product contains a lithium battery. Batteries are not customer replaceable parts. They may explode if mishandled. Do not dispose of the battery in fire. Do not disassemble or recharge. (Norge) ADVARSEL—Litiumbatteri - Eksplosjonsfare. Ved utskifting benyttes kun batteri som anbefalt av apparatfabrikanten. Brukt batteri returneres apparatleverandøren. (Sverige) VARNING—Explosionsfara vid felaktigt batteribyte. Använd samma batterityp eller en ekvivalent typ som rekommenderas av apparattillverkaren. Kassera använt batteri enligt fabrikantens instruktion. (Danmark) ADVARSEL! Litiumbatteri - Eksplosionsfare ved fejlagtig håndtering. Udskiftning må kun ske med batteri af samme fabrikat og type. Levér det brugte batteri tilbage til leverandøren. (Suomi) VAROITUS—Paristo voi räjähtää, jos se on virheellisesti asennettu. Vaihda paristo ainoastaan laitevalmistajan suosittelemaan tyyppiin. Hävitä käytetty paristo valmistajan ohjeiden mukaisesti. Warranty Nortel Networks provides a limited warranty on all its products for a period of one year from the date of shipment. Free technical support and free replacement of hardware is provided for the first 90 days after shipment. You may choose to purchase additional service and support from Nortel Networks. Please contact your local sales representative for more information. 4 212535-C, October 2002 Contents Preface 15 Product Name & Platform Changes 15 Who Should Use This Book 16 How This Book Is Organized 16 How to Get Help 17 Typographic Conventions 18 Chapter 1: The Alteon Switched Firewall 19 Feature Summary 19 Alteon Switched Firewall Basics 20 Network Elements 20 Basic Operation 22 Port Filtering 22 Topology Specifics 23 Security Processing 24 Physical Description 25 The Firewall Director 25 The Alteon Firewall Accelerator 32 5 212535-C, October 2002 Alteon Switched Firewall Installation and User’s Guide Chapter 2: Hardware Installation 35 Required Equipment 36 Model Compatibility 37 Safety Precautions 38 Rack-Mounting the Firewall Accelerator 39 Rack-Mounting the Firewall Director 41 Task Summary 41 Select the Appropriate Rack-Mounting Kit 42 Remove the Rack Doors 44 Mark the Rack 44 Attach the Slide Assemblies to the Rack 46 Attach the System Chassis to the Slide Assemblies 55 Add the Cable-Management Arm 57 Reattach the Cabinet Doors 58 Connecting Network Cables 59 Basic Alteon Switched Firewall Network Topology 59 Network Connector and Cable Specifications 61 Port LED Indicators 64 Automatic Selection of Redundant Connections 65 Using the Firewall Director Cable-Management Arm 66 Connecting Power 67 Connecting AC Power for the Firewall Accelerator 67 Connecting AC Power for the Firewall Director 67 Turning Power On 69 Turning Power Off 69 Connecting a Console Terminal 70 Requirements 70 Console Connector and Cable Specifications 71 Establishing a Connection 72 6 Contents 212535-C, October 2002 Alteon Switched Firewall Installation and User’s Guide Chapter 3: Initial Setup 73 Overview of Initial Setup Tasks 73 Collect Basic System Information 74 Example Network 75 Use Setup for Basic Configuration 76 Configure Licenses and Interfaces 80 Install Check Point Management Tools 83 Configuring and Install Firewall Policies 91 Task Overview 91 Log in to the Policy Editor 91 Define the Alteon Switched Firewall Object 92 Establish Secure Internal Communications 94 Using Central Licensing 96 Create and Install Firewall Policies 97 Chapter 4: System Management Basics 99 Management Tools 99 Users and Passwords 100 The Single System Image 101 Chapter 5: The Command Line Interface 103 Accessing the Command Line Interface 104 Using the Local Serial Port