Alteon SSL Accelerator 4.1.2 User's Guide and Command Reference
Total Page:16
File Type:pdf, Size:1020Kb
User’s Guide and Command Reference Alteon SSL AcceleratorTM 4.1.2 Secure Sockets Layer Offload Device Part Number: 212939-F, November 2003 4655 Great America Parkway Santa Clara, CA 95054 Phone 1-800-4Nortel www.nortelnetworks.com Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Copyright 2003 Nortel Networks, Inc., 4655 Great America Parkway, Santa Clara, California 95054, USA. All rights reserved. Part Number: 212939-F. This document is protected by copyright and distributed under licenses restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Nortel Networks, Inc. Documentation is provided “as is” without warranty of any kind, either express or implied, including any kind of implied or express warranty of non- infringement or the implied warranties of merchantability or fitness for a particular purpose. U.S. Government End Users: This document is provided with a “commercial item” as defined by FAR 2.101 (Oct 1995) and contains “commercial technical data” and “commercial software documentation” as those terms are used in FAR 12.211-12.212 (Oct 1995). Government End Users are authorized to use this documentation only in accordance with those rights and restrictions set forth herein, consistent with FAR 12.211- 12.212 (Oct 1995), DFARS 227.7202 (JUN 1995) and DFARS 252.227-7015 (Nov 1995). Nortel Networks, Inc. reserves the right to change any products described herein at any time, and without notice. Nortel Networks, Inc. assumes no responsibility or liability arising from the use of products described herein, except as expressly agreed to in writing by Nortel Networks, Inc. The use and purchase of this product does not convey a license under any patent rights, trademark rights, or any other intellectual property rights of Nortel Networks, Inc. CryptoSwift® HSM is a registered trademark of Rainbow Technologies, Inc. Portions of this manual are Copyright 2001 Rainbow Technologies, Inc. All rights reserved. Export This product, software and related technology is subject to U.S. export control and may be subject to export or import regulations in other countries. Purchaser must strictly comply with all such laws and regulations. A license to export or reexport may be required by the U.S. Department of Commerce. Licensing This product includes software developed by the OpenSSL Project for use in the OpenSSL Toolkit (http://www.openssl.org/). This product includes cryptographic software written by Eric Young ([email protected]). This product includes software written by Tim Hudson ([email protected]). This product includes software developed by the Apache Software Foundation (http://www.apache.org/). See Appendix D, “License Information,” for more information. 2 212939-F, November 2003 Contents Preface 13 Who Should Use This Book 13 Related Documentation 13 How This Book Is Organized 14 New Product Names 15 Typographic Conventions 16 How to Get Help 17 Part 1: User’s Guide Chapter 1: Introducing the ASA 21 Features 22 Performance 22 Scalability and Redundancy 22 Certificate and Key Management 22 Advanced Processing 23 Load Balancing of Secure SSL Sessions 23 Networking 23 Statistics Viewing 24 Logging Capabilities 24 Management 24 Supported Standards 24 Compatibility 24 SSL VPN 25 New Software Features 26 SSL Acceleration 26 SSL VPN 26 3 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Chapter 2: Introducing the ASA 310-FIPS 27 HSM Overview 27 Extended Mode vs. FIPS Mode 28 FIPS 140-1 Level 3 Security 29 The Concept of iKey Authentication 29 Types of iKeys 29 Wrap Keys for ASA 310-FIPS Clusters 30 Available Operations and iKeys Required 31 Additional HSM Information 32 Chapter 3: Initial Setup 33 Clusters 33 Ports and Interfaces within a Cluster 34 Configuration at Boot Up 35 Installing and Adding ASAs 36 Installing an ASA in a New Cluster 36 Adding an ASA to an Existing Cluster 39 Installing and Adding an ASA 310-FIPS 42 Installing an ASA 310-FIPS in a New Cluster 43 Adding an ASA 310-FIPS to an Existing Cluster 49 Reinstalling the Software 56 Chapter 4: Upgrading the ASA Software 59 Performing Minor/Major Release Upgrades 60 Activating the Software Upgrade Package 61 Upgrading a Mixed ASA Cluster 63 Chapter 5: Managing Users and Groups 65 User Rights and Group Membership 65 Adding a New User 66 Changing a User’s Group Assignment 70 Changing a User’s Password 71 Changing Your Own Password 71 Changing Another User’s Password 72 Deleting a User 73 4 Contents 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Chapter 6: Managing Certificates and Client Authentication 75 Generating and Submitting a CSR Using the CLI 76 Adding Certificates to the ASA 81 Using a Copy-and-Paste Operation to Add Certificates 82 Using a Copy-and-Paste Operation to Add a Private Key 84 Using TFTP or FTP to Add Certificates and Keys 86 Update Existing Certificate 88 Create a New Certificate 88 Configuring a Virtual SSL Server for Client Authentication 89 Generating Client Certificates on the ASA 91 Managing Revocation of Client Certificates 95 Revoking Client Certificates Issued by an External CA 96 Revoking Client Certificates Issued within your Own Organization 97 Creating Your Own Certificate Revocation List 98 Chapter 7: Using the Quick Server Setup Wizard 101 Create an HTTP Server 101 Create a Socks server 106 Create a Portal Server 108 Chapter 8: The Command Line Interface 111 Connecting to the ASA 112 Establishing a Console Connection 112 Establishing a Telnet Connection 113 Establishing a Connection Using SSH (Secure Shell) 114 Accessing the ASA 116 CLI vs. Setup 117 Command Line History and Editing 118 Idle Timeout 118 Contents 5 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Chapter 9: Troubleshooting the ASA 119 Cannot Connect to ASA via Telnet or SSH 120 Verify the Current Configuration 120 Enable Telnet or SSH Access 120 Check the Access List 120 Check the IP Address Configuration 121 Cannot Add an ASA to a Cluster 122 Cannot Contact the MIP 123 Check the Access List 123 Add Interface 1 IP Addresses and MIP to Access List 123 The ASA Stops Responding 124 Telnet or SSH Connection to the Management IP Address 124 Console Connection 124 A User Password is Lost 125 Administrator User Password 125 Operator User Password 125 Boot User Password 125 An ASA HSM Stops Processing Traffic 126 Resetting HSM Cards on the ASA 310-FIPS 128 An ASA 310-FIPS Cluster Must be Reconstructed onto New Devices 131 System Diagnostics 135 Installed Certificates and Virtual SSL Servers 135 Network Diagnostics 135 Active Alarms and the Events Log File 137 Error Log Files 137 Part 2: Command Reference 6 Contents 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Chapter 10: ASA Command Reference 141 Menu Basics 141 Global Commands 142 Command Line History and Editing 144 Command Line Interface Shortcuts 146 Command Stacking 146 Command Abbreviation 146 Tab Completion 146 Using Submenu Name as Command Argument 147 Using Slashes (/) and Spaces in Commands 148 The Main Menu 149 Menu Summary 149 Information Menu 150 Events Menu 154 HSM Command 155 iSD List Command 155 Information Local Command 155 Information Ethernet Command 155 Statistics Menu 156 Cluster Wide SSL Statistics Server Menu 158 Local Statistics Menu 161 Single iSD Statistics Menu 163 Single ISD Statistics for Virtual SSL Server Menu 165 Single iSD Host SSL Server Healthcheck Command 170 Single iSD Host SSL Server Poolstatus Command 170 AAA Statistics Menu 171 Configuration Menu 172 Viewing, Applying and Removing Changes 174 Contents 7 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference SSL Configuration Menu 175 DNS Client Settings Configuration 177 Certificate Management Configuration 179 Certificate Revocation Configuration 185 Automatic CRL Menu 187 SSL Server Management Configuration 190 Network Traffic Dump Commands 194 SSL Settings Configuration 196 SSL Server TCP Settings Configuration 199 SSL Server HTTP Settings Configuration 201 SSL Server HTTP Rewrite Configuration 207 SSL Server WWW Authentication Settings Configuration 208 SSL Server DNS Settings Configuration 210 Socks Settings Configuration 211 HTTP Proxy Settings Configuration 214 Portal Settings Configuration 217 Advanced Settings Menu 220 Load Balancing Strings Configuration 222 Connection Pooling Configuration 225 Traffic Syslog Configuration 226 Standalone Menu 228 IP List Menu 230 Load Balancing Settings 232 Cookie Settings Configuration 236 Health Check Script Configuration 240 Remote SSL Connect Configuration 243 Remote SSL Connect Verify Configuration 245 Backend Server Configuration 246 SSL Connect Configuration 249 SSL Connect Verify Configuration 251 8 Contents 212939-F, November 2003 Alteon SSL Accelerator 4.1.2 User’s Guide and Command Reference Xnet Menu 252 Xnet Domain Configuration 253 SSL VPN Portal Configuration 256 Portal Colors Configuration 258 Authentication Configuration 259 RADIUS Configuration 261 Radius Servers Menu 263 LDAP Configuration 264 LDAP Servers Menu 266 NTLM Configuration 268 NTLM Servers Menu 269 Local Database Configuration 270 Advanced Settings Configuration 273 Network Access Configuration 274 Subnet Access Configuration 275 Service Access Configuration 276 Application Specific Menu 278 Client Filter Configuration 280 Group Configuration 282 Access Rule Configuration 285 Link Configuration