Nortel Networks Nortel Secure Network Access Switch 4050 Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Logiciel Nortel Networks Nortel Secure Network Access Switch 4050. Nortel Networks Nortel Secure Network Access Switch 4050 User's Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 922
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
Part No. 320818-A
December 2005
4655 Great America Parkway
Santa Clara, CA 95054
*320818-A*
Nortel Secure Network Access
Switch 4050 User Guide
Nortel Secure Network Access Switch
Software Release 1.0
Vue de la page 0
1 2 3 4 5 6 ... 921 922

Résumé du contenu

Page 1 - Switch 4050 User Guide

Part No. 320818-ADecember 20054655 Great America ParkwaySanta Clara, CA 95054*320818-A*Nortel Secure Network Access Switch 4050 User GuideNortel Secu

Page 2 - Statement of conditions

10 Contents320818-A Modifying RADIUS configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 273Managing additional RADIUS s

Page 3 - Licensing

100 Chapter 3 Managing the network access devices320818-A Mapping VLANs by switchTo map VLANs by switch, you must first disable the network access dev

Page 4

Chapter 3 Managing the network access devices 101Nortel Secure Network Access Switch 4050 User Guide • “Removing VLANs from a switch” on page 102Addin

Page 5 - Contents

102 Chapter 3 Managing the network access devices320818-A Removing VLANs from a switchTo remove existing VLANs from the switch, complete the following

Page 6

Chapter 3 Managing the network access devices 103Nortel Secure Network Access Switch 4050 User Guide If you created the domain manually, the SSH key w

Page 7

104 Chapter 3 Managing the network access devices320818-A If the network access device defaults, it generates a new public key. You must reimport the

Page 8

Chapter 3 Managing the network access devices 105Nortel Secure Network Access Switch 4050 User Guide Generating SSH keys for the domain using the SREM

Page 9

106 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Page 10

Chapter 3 Managing the network access devices 107Nortel Secure Network Access Switch 4050 User Guide The Export Key screen appears (see Figure 13).Fig

Page 11

108 Chapter 3 Managing the network access devices320818-A 2 Enter the export information in the applicable fields. Table 8 describes the fields availa

Page 12

Chapter 3 Managing the network access devices 109Nortel Secure Network Access Switch 4050 User Guide Managing SSH keys for Nortel SNA communication us

Page 13

Contents 11Nortel Secure Network Access Switch 4050 User Guide SRS Rule Expression Constructor . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 14

110 Chapter 3 Managing the network access devices320818-A Table 9 describes the fields and controls available from the switch SSH Key screen.2 Click A

Page 15

Chapter 3 Managing the network access devices 111Nortel Secure Network Access Switch 4050 User Guide The switch SSH Key screen appears (see Figure 14

Page 16

112 Chapter 3 Managing the network access devices320818-A The Health Check screen appears (see Figure 15).Figure 15 Health Check screen

Page 17

Chapter 3 Managing the network access devices 113Nortel Secure Network Access Switch 4050 User Guide 2 Enter the health check information in the appli

Page 18

114 Chapter 3 Managing the network access devices320818-A The Connected Clients screen appears, displaying information about the connection status and

Page 19

Chapter 3 Managing the network access devices 115Nortel Secure Network Access Switch 4050 User Guide Controlling communication with the network access

Page 20

116 Chapter 3 Managing the network access devices320818-A To disable or enable the network access device, perform the following steps:1 Select the Sec

Page 21

117Nortel Secure Network Access Switch 4050 User Guide Chapter 4 Configuring the domainThis chapter includes the following topics:Topic PageConfigurin

Page 22

118 Chapter 4 Configuring the domain320818-A A Nortel SNAS 4050 domain encompasses all the switches, authentication servers, and remediation servers a

Page 23

Chapter 4 Configuring the domain 119Nortel Secure Network Access Switch 4050 User Guide • logging traffic with syslog messages• portal settings (see “

Page 24 - 24 Contents

12 Contents320818-A Changing a user’s group assignment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365Changing passwords . . . . . .

Page 25

120 Chapter 4 Configuring the domain320818-A details on|offloglevel fatal|error|warning| info|debug/cfg/domain #/aaa/tg/quick/cfg/domain #/server port

Page 26

Chapter 4 Configuring the domain 121Nortel Secure Network Access Switch 4050 User Guide Creating a domain using the CLIYou can create a domain in two

Page 27 - Text conventions

122 Chapter 4 Configuring the domain320818-A When you first create the domain, you are prompted to enter the following parameters:• domain name — a st

Page 28 - Related information

Chapter 4 Configuring the domain 123Nortel Secure Network Access Switch 4050 User Guide Figure 17 Creating a domainUsing the Nortel SNAS 4050 domain

Page 29 - How to get help

124 Chapter 4 Configuring the domain320818-A Depending on the options you select in connection with certificates and creating a test user, the two wiz

Page 30 - 30 Preface

Chapter 4 Configuring the domain 125Nortel Secure Network Access Switch 4050 User Guide c To use an existing certificate, enter the applicable certifi

Page 31 - Chapter 1

126 Chapter 4 Configuring the domain320818-A c To continue, go to step 8 on page 126.8 Specify whether the SSL server uses chain certificates. 9 If yo

Page 32 - Supported users

Chapter 4 Configuring the domain 127Nortel Secure Network Access Switch 4050 User Guide 11 To add a network access device, enter the required informat

Page 33 - Role of the Nortel SNAS 4050

128 Chapter 4 Configuring the domain320818-A The wizard assigns the following default VLAN IDs:• Green VLAN = VLAN ID 110• Yellow VLAN = VLAN ID 120Yo

Page 34 - Nortel SNA VLANs and filters

Chapter 4 Configuring the domain 129Nortel Secure Network Access Switch 4050 User Guide Deleting a domain using the CLITo delete a domain, use the fol

Page 35 - Groups and profiles

Contents 13Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the CLI . . . . . . . . . . . . . . . . . . .

Page 36 - Authentication methods

130 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the CLITo configure the domain, use the following command:/cfg/domain

Page 37 - Chapter 1 Overview 37

Chapter 4 Configuring the domain 131Nortel Secure Network Access Switch 4050 User Guide portalAccesses the Portal menu, in order to customize the port

Page 38 - About SSH

132 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the CLIBefore an authenticated client is allowed into the network

Page 39 - Nortel SNAS 4050 clusters

Chapter 4 Configuring the domain 133Nortel Secure Network Access Switch 4050 User Guide heartbeat <interval>Sets the time interval between check

Page 40 - 40 Chapter 1 Overview

134 Chapter 4 Configuring the domain320818-A Using the quick TunnelGuard setup wizard in the CLITo configure the settings for the SRS rule check using

Page 41 - Two-armed configuration

Chapter 4 Configuring the domain 135Nortel Secure Network Access Switch 4050 User Guide The TunnelGuard quick setup wizard creates a default SRS rule

Page 42 - 42 Chapter 1 Overview

136 Chapter 4 Configuring the domain320818-A The Server 1001 menu includes the following options:Tracing SSL traffic using the CLITo verify connectivi

Page 43 - Chapter 1 Overview 43

Chapter 4 Configuring the domain 137Nortel Secure Network Access Switch 4050 User Guide The Trace menu displays.The Trace menu includes the following

Page 44 - 44 Chapter 1 Overview

138 Chapter 4 Configuring the domain320818-A tcpdumpCreates a dump of the TCP traffic flowing between clients and the virtual SSL server. You are prom

Page 45 - Chapter 1 Overview 45

Chapter 4 Configuring the domain 139Nortel Secure Network Access Switch 4050 User Guide Configuring SSL settings using the CLITo configure SSL-specifi

Page 46 - 46 Chapter 1 Overview

14 Contents320818-A Chapter 10: Configuring system settings . . . . . . . . . . . . . . . . . . . . . . . . . 457Configuring the cluster using the CLI

Page 47 - Chapter 1 Overview 47

140 Chapter 4 Configuring the domain320818-A The SSL Settings menu includes the following options:/cfg/domain #/server/sslfollowed by:cert <certifi

Page 48 - 48 Chapter 1 Overview

Chapter 4 Configuring the domain 141Nortel Secure Network Access Switch 4050 User Guide cachain <certificate index list>Specifies the CA certifi

Page 49 - Initial setup

142 Chapter 4 Configuring the domain320818-A Configuring traffic log settings using the CLIYou can configure a syslog server to receive User Datagram

Page 50

Chapter 4 Configuring the domain 143Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Page 51 - About the IP addresses

144 Chapter 4 Configuring the domain320818-A Configuring HTTP redirect using the CLIYou can configure the Nortel SNAS 4050 domain to automatically red

Page 52

Chapter 4 Configuring the domain 145Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configure t

Page 53

146 Chapter 4 Configuring the domain320818-A Configuring RADIUS accounting using the CLIThe Nortel SNAS 4050 can be configured to provide support for

Page 54

Chapter 4 Configuring the domain 147Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS accounting server to the confi

Page 55

148 Chapter 4 Configuring the domain320818-A The Radius Accounting Servers menu includes the following options:/cfg/domain #/aaa/radacct/serversfollow

Page 56

Chapter 4 Configuring the domain 149Nortel Secure Network Access Switch 4050 User Guide Configuring Nortel SNAS 4050-specific attributes using the CLI

Page 57

Contents 15Nortel Secure Network Access Switch 4050 User Guide Adding a host interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 58

150 Chapter 4 Configuring the domain320818-A The VPN Attribute menu includes the following options:Configuring the domain using the SREMTo configure t

Page 59

Chapter 4 Configuring the domain 151Nortel Secure Network Access Switch 4050 User Guide • portal settings (see “Customizing the portal and user logon”

Page 60

152 Chapter 4 Configuring the domain320818-A Manually creating a domain using the SREMTo create and configure a domain manually, perform the following

Page 61 - Extended profile details

Chapter 4 Configuring the domain 153Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Secure Access Domain dialog box appears

Page 62

154 Chapter 4 Configuring the domain320818-A Using the SREM Domain Quick WizardThe Nortel SNAS 4050 quick setup wizard is similar to the quick setup w

Page 63 - Joining a cluster

Chapter 4 Configuring the domain 155Nortel Secure Network Access Switch 4050 User Guide To create a domain using the Nortel SNAS 4050 quick setup wiza

Page 64

156 Chapter 4 Configuring the domain320818-A 2 Click Domain Quick Wizard.The Domain Quick Wizard — General Settings dialog box appears (see Figure 22)

Page 65

Chapter 4 Configuring the domain 157Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate dialog box appears (see

Page 66

158 Chapter 4 Configuring the domain320818-A 6 Click Next.Organization Name Specifies the registered name of the organization. The organization must o

Page 67 - Chapter 2 Initial setup 67

Chapter 4 Configuring the domain 159Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Certificate Chain dialog box appears

Page 68

16 Contents320818-A Managing RADIUS audit servers using the SREM . . . . . . . . . . . . . . . . . . . . 559Managing RADIUS authentication of system

Page 69 - Figure 3

160 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Server dialog box appears (see Figure 25).Figure 25 Domain Quick Wizard – Ser

Page 70 - 70 Chapter 2 Initial setup

Chapter 4 Configuring the domain 161Nortel Secure Network Access Switch 4050 User Guide The Domain Quick Wizard — Switch dialog box appears (see Figur

Page 71 - Chapter 3

162 Chapter 4 Configuring the domain320818-A The Domain Quick Wizard — Tunnel Guard dialog box appears (see Figure 27).Figure 27 Domain Quick Wizard

Page 72

Chapter 4 Configuring the domain 163Nortel Secure Network Access Switch 4050 User Guide If there are no problems, then a dialog appears to indicate th

Page 73

164 Chapter 4 Configuring the domain320818-A Configuring domain parameters using the SREMTo configure a domain, perform the following steps:1 Select t

Page 74

Chapter 4 Configuring the domain 165Nortel Secure Network Access Switch 4050 User Guide 2 Enter the domain information in the applicable fields. Table

Page 75

166 Chapter 4 Configuring the domain320818-A Additional domain configuration in the SREMTo configure additional domain settings, there are tabs and tr

Page 76

Chapter 4 Configuring the domain 167Nortel Secure Network Access Switch 4050 User Guide Table 21 describes the purpose of additional tree components f

Page 77 - >

168 Chapter 4 Configuring the domain320818-A Configuring the TunnelGuard check using the SREMBefore an authenticated client is allowed into the networ

Page 78 - Manually adding a switch

Chapter 4 Configuring the domain 169Nortel Secure Network Access Switch 4050 User Guide To configure settings for the TunnelGuard host integrity check

Page 79

Contents 17Nortel Secure Network Access Switch 4050 User Guide Chapter 12: Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 80

170 Chapter 4 Configuring the domain320818-A 2 Enter the TunnelGuard information in the applicable fields. Table 22 describes the TunnelGuard Configur

Page 81

Chapter 4 Configuring the domain 171Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes to th

Page 82

172 Chapter 4 Configuring the domain320818-A Using the TunnelGuard Quick Setup in the SREMTo configure settings for the TunnelGuard host integrity che

Page 83

Chapter 4 Configuring the domain 173Nortel Secure Network Access Switch 4050 User Guide 2 Enter the TunnelGuard information in the applicable fields.

Page 84

174 Chapter 4 Configuring the domain320818-A Configuring the SSL server using the SREMTo configure settings for the SSL server, perform the following

Page 85

Chapter 4 Configuring the domain 175Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Page 86

176 Chapter 4 Configuring the domain320818-A Configuring SSL settings using the SREMTo configure SSL-specific settings for the portal server, perform

Page 87 - Figure 5

Chapter 4 Configuring the domain 177Nortel Secure Network Access Switch 4050 User Guide 2 Enter the server information in the applicable fields. Table

Page 88 - The SSH Key menu displays

178 Chapter 4 Configuring the domain320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Page 89

Chapter 4 Configuring the domain 179Nortel Secure Network Access Switch 4050 User Guide To set up a syslog server to receive UDP syslog messages for a

Page 90

18 Contents320818-A Viewing SONMP topology information using the SREM . . . . . . . . . . . . . . . . 675Viewing switch distribution using the SREM

Page 91 - /cfg/domain #/switch #/ena

180 Chapter 4 Configuring the domain320818-A 2 Enter the traffic log information in the applicable fields. Table 26 describes the Traffic Log Syslog S

Page 92 - Add a Switch fields

Chapter 4 Configuring the domain 181Nortel Secure Network Access Switch 4050 User Guide Tracing SSL traffic using the SREMTo verify connectivity and t

Page 93

182 Chapter 4 Configuring the domain320818-A To configure the domain to automatically redirect HTTP requests to the HTTPS server specified for the dom

Page 94

Chapter 4 Configuring the domain 183Nortel Secure Network Access Switch 4050 User Guide 2 Enter the redirection information in the applicable fields.

Page 95 - Table 4

184 Chapter 4 Configuring the domain320818-A • cause of terminationConfigure the RADIUS server in accordance with the recommendations in RFC 2866. Cer

Page 96

Chapter 4 Configuring the domain 185Nortel Secure Network Access Switch 4050 User Guide Contact your RADIUS system administrator for information about

Page 97 - Mapping VLANs by domain

186 Chapter 4 Configuring the domain320818-A 2 Enter the RADIUS accounting information in the applicable fields. Table 27 describes the RADIUS account

Page 98 - Adding VLANs to a domain

Chapter 4 Configuring the domain 187Nortel Secure Network Access Switch 4050 User Guide The Radius Accounting Servers screen appears (see Figure 36).F

Page 99 - Removing VLANs from a domain

188 Chapter 4 Configuring the domain320818-A 3 Enter the RADIUS accounting server information in the applicable fields. Table 29 describes the Radius

Page 100 - Mapping VLANs by switch

Chapter 4 Configuring the domain 189Nortel Secure Network Access Switch 4050 User Guide Deleting a RADIUS accounting server using the SREMTo delete a

Page 101 - Adding VLANs to a switch

Contents 19Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices and software using the SREM . . . . . . . . . 743Mana

Page 102 - Removing VLANs from a switch

190 Chapter 4 Configuring the domain320818-A

Page 103

191Nortel Secure Network Access Switch 4050 User Guide Chapter 5 Configuring groups and profilesThis chapter includes the following topics:Topic PageO

Page 104 - 320818-A

192 Chapter 5 Configuring groups and profiles320818-A OverviewThis section includes the following topics:• “Groups” on page 192• “Linksets” on page 19

Page 105 - Key Generation screen

Chapter 5 Configuring groups and profiles 193Nortel Secure Network Access Switch 4050 User Guide Each group’s data include the following configurable

Page 106 - Switch SSH Key fields

194 Chapter 5 Configuring groups and profiles320818-A LinksetsA linkset is a set of links that display on the portal page, so that the user can easily

Page 107 - Figure 13

Chapter 5 Configuring groups and profiles 195Nortel Secure Network Access Switch 4050 User Guide Extended profilesPassing or failing the SRS rule chec

Page 108 - Table 8

196 Chapter 5 Configuring groups and profiles320818-A Before you beginBefore you configure groups, client filters, and extended profiles on the Nortel

Page 109 - Switch SSH Key screen

Chapter 5 Configuring groups and profiles 197Nortel Secure Network Access Switch 4050 User Guide 3 Configure the extended profiles for the group (see

Page 110

198 Chapter 5 Configuring groups and profiles320818-A Configuring groups using the CLITo create and configure a group, use the following command:/cfg/

Page 111

Chapter 5 Configuring groups and profiles 199Nortel Secure Network Access Switch 4050 User Guide • number of sessions — the maximum number of simultan

Page 112 - Figure 15

2320818-A Copyright © Nortel Networks Limited 2005. All rights reserved.The information in this document is subject to change without notice. The stat

Page 113

20 Contents320818-A Configure the network DNS server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 782Configure the network D

Page 114 - Table 11

200 Chapter 5 Configuring groups and profiles320818-A Figure 38 shows sample output for the /cfg/domain 1/aaa/group <group ID> command and comma

Page 115

Chapter 5 Configuring groups and profiles 201Nortel Secure Network Access Switch 4050 User Guide Configuring client filters using the CLITo create and

Page 116 - Switch Configuration screen

202 Chapter 5 Configuring groups and profiles320818-A The Client Filter menu includes the following options:/cfg/domain 1/aaa/filter <filter ID>

Page 117 - Configuring the domain

Chapter 5 Configuring groups and profiles 203Nortel Secure Network Access Switch 4050 User Guide Figure 39 shows sample output for the /cfg/domain 1/a

Page 118 - /cfg/domain

204 Chapter 5 Configuring groups and profiles320818-A When you first create the profile, you are prompted to enter the following parameters:• client f

Page 119 - Roadmap of domain commands

Chapter 5 Configuring groups and profiles 205Nortel Secure Network Access Switch 4050 User Guide Figure 40 shows sample output for the /cfg/domain 1/a

Page 120

206 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a group or profile using the CLIYou can tailor the portal page for different

Page 121

Chapter 5 Configuring groups and profiles 207Nortel Secure Network Access Switch 4050 User Guide Figure 41 shows sample output for the /cfg/domain 1/a

Page 122 - <domain ID>

208 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the CLITo create a default group, first create a group with exten

Page 123 - Figure 17 Creating a domain

Chapter 5 Configuring groups and profiles 209Nortel Secure Network Access Switch 4050 User Guide Using the guide for creating groups If you desire add

Page 124

Contents 21Nortel Secure Network Access Switch 4050 User Guide CLI shortcuts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 125

210 Chapter 5 Configuring groups and profiles320818-A Adding a group To create and configure a group, perform the following steps:1 Select the Secure

Page 126

Chapter 5 Configuring groups and profiles 211Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Group dialog box appears (see

Page 127

212 Chapter 5 Configuring groups and profiles320818-A Modifying a groupTo configure a group, perform the following steps:1 Select the Secure Access Do

Page 128

Chapter 5 Configuring groups and profiles 213Nortel Secure Network Access Switch 4050 User Guide 2 Enter the group information in the applicable field

Page 129

214 Chapter 5 Configuring groups and profiles320818-A Adding a client filter To create and configure a client filter, perform the following steps:1 Se

Page 130

Chapter 5 Configuring groups and profiles 215Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Client Filter dialog box appear

Page 131

216 Chapter 5 Configuring groups and profiles320818-A 4 Click Apply.The new client filter now appears in the Client Filters table.5 Click Apply on the

Page 132

Chapter 5 Configuring groups and profiles 217Nortel Secure Network Access Switch 4050 User Guide Modifying a client filterTo configure a client filter

Page 133

218 Chapter 5 Configuring groups and profiles320818-A 2 Enter the Client Filter information in the applicable fields. Table 34 describes the Client Fi

Page 134

Chapter 5 Configuring groups and profiles 219Nortel Secure Network Access Switch 4050 User Guide Configuring extended profiles using the SREMTo view t

Page 135

22 Contents320818-A Root user password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 844Boot user password .

Page 136

220 Chapter 5 Configuring groups and profiles320818-A Adding an extended profile To create an extended profile for a group, perform the following step

Page 137 - The Trace menu displays

Chapter 5 Configuring groups and profiles 221Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add an Extended Profile dialog box o

Page 138

222 Chapter 5 Configuring groups and profiles320818-A Modifying an extended profileTo modify an extended profile for a group, perform the following st

Page 139

Chapter 5 Configuring groups and profiles 223Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Extended Profile information in the appli

Page 140

224 Chapter 5 Configuring groups and profiles320818-A Mapping linksets to a groupTo map a linkset to a group, select the Secure Access Domain > dom

Page 141

Chapter 5 Configuring groups and profiles 225Nortel Secure Network Access Switch 4050 User Guide Adding linksets to a groupTo add a linkset to a group

Page 142 - SSL is enabled by default

226 Chapter 5 Configuring groups and profiles320818-A Removing linksets from a groupTo remove a linkset from a group, perform the following steps:1 Se

Page 143

Chapter 5 Configuring groups and profiles 227Nortel Secure Network Access Switch 4050 User Guide Mapping linksets to a profileTo map a linkset to an e

Page 144

228 Chapter 5 Configuring groups and profiles320818-A Adding linksets to an extended profileTo add a linkset to an extended profile, perform the follo

Page 145

Chapter 5 Configuring groups and profiles 229Nortel Secure Network Access Switch 4050 User Guide Removing linksets from an extended profileTo remove a

Page 146

Contents 23Nortel Secure Network Access Switch 4050 User Guide Create a new attribute(Windows 2000 Server and Windows Server 2003) . . . . . . . . . .

Page 147

230 Chapter 5 Configuring groups and profiles320818-A Creating a default group using the SREM To create a default group, first create a group with ext

Page 148

Chapter 5 Configuring groups and profiles 231Nortel Secure Network Access Switch 4050 User Guide 2 Enter the AAA information in the applicable fields.

Page 149 - NSNAS-Portal-ID)

232 Chapter 5 Configuring groups and profiles320818-A

Page 150

233Nortel Secure Network Access Switch 4050 User Guide Chapter 6 Configuring authenticationThis chapter includes the following topics:Topic PageOvervi

Page 151

234 Chapter 6 Configuring authentication320818-A OverviewThe Nortel SNAS 4050 controls authentication of clients when they log on to the network.The N

Page 152 - Figure 19

Chapter 6 Configuring authentication 235Nortel Secure Network Access Switch 4050 User Guide Before you beginBefore you configure authentication on the

Page 153 - Add a Secure Access Domain

236 Chapter 6 Configuring authentication320818-A — Vendor-Typeb LDAP servers:— server IP address— port number used for the service— configured account

Page 154

Chapter 6 Configuring authentication 237Nortel Secure Network Access Switch 4050 User Guide 3 Specify the order in which the authentication methods wi

Page 155 - Figure 21

238 Chapter 6 Configuring authentication320818-A domainid <domain ID>domaintype <domain type>authproto pap|chapv2timeout <interval>/

Page 156

Chapter 6 Configuring authentication 239Nortel Secure Network Access Switch 4050 User Guide Configuring authentication methods using the CLITo create

Page 157

24 Contents320818-A

Page 158 - 6 Click Next

240 Chapter 6 Configuring authentication320818-A When you first create the method, you are prompted to specify the type. For Nortel Secure Network Acc

Page 159 - Field Description

Chapter 6 Configuring authentication 241Nortel Secure Network Access Switch 4050 User Guide Configuring advanced settings using the CLIYou can configu

Page 160 - Domain Quick Wizard – Server

242 Chapter 6 Configuring authentication320818-A To configure the current authentication scheme to retrieve user group information from a different au

Page 161 - Domain Quick Wizard – Switch

Chapter 6 Configuring authentication 243Nortel Secure Network Access Switch 4050 User Guide You can perform the following configuration tasks:• “Addin

Page 162

244 Chapter 6 Configuring authentication320818-A • vendor type for group — corresponds to the Vendor-Type value used in combination with the Vendor-Id

Page 163

Chapter 6 Configuring authentication 245Nortel Secure Network Access Switch 4050 User Guide Figure 56 shows sample output for the RADIUS method for th

Page 164 - Figure 28

246 Chapter 6 Configuring authentication320818-A The RADIUS menu displays.The RADIUS menu includes the following options:/cfg/domain 1/aaa/auth #/radi

Page 165 - Table 19

Chapter 6 Configuring authentication 247Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLIYou ca

Page 166 - Table 20

248 Chapter 6 Configuring authentication320818-A The Radius servers menu includes the following options:/cfg/domain 1/aaa/auth #/radius/serversfollowe

Page 167 - Table 21

Chapter 6 Configuring authentication 249Nortel Secure Network Access Switch 4050 User Guide Configuring session timeout using the CLIYou can configure

Page 168

25Nortel Secure Network Access Switch 4050 User Guide PrefaceNortel* Secure Network Access (Nortel SNA) is a clientless solution that provides seamles

Page 169

250 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Page 170 - Table 22

Chapter 6 Configuring authentication 251Nortel Secure Network Access Switch 4050 User Guide • if user entries are located in several places in the LDA

Page 171

252 Chapter 6 Configuring authentication320818-A Figure 57 shows sample output for the LDAP method for the /cfg/domain 1/aaa/auth <auth ID> comm

Page 172

Chapter 6 Configuring authentication 253Nortel Secure Network Access Switch 4050 User Guide The LDAP menu displays.The LDAP menu includes the followin

Page 173 - Table 23

254 Chapter 6 Configuring authentication320818-A userattr <names>Refers to one of the following:1. the LDAP attribute that contains the user nam

Page 174 - Figure 31

Chapter 6 Configuring authentication 255Nortel Secure Network Access Switch 4050 User Guide enaldaps true|falseIf true, makes LDAP requests between th

Page 175 - Table 24

256 Chapter 6 Configuring authentication320818-A Managing LDAP authentication servers using the CLIYou can configure additional LDAP servers for the d

Page 176 - Figure 32

Chapter 6 Configuring authentication 257Nortel Secure Network Access Switch 4050 User Guide del <index number>Removes the specified LDAP server

Page 177 - Table 25

258 Chapter 6 Configuring authentication320818-A Managing LDAP macros using the CLIYou can create your own macros (or variables), to allow you to retr

Page 178

Chapter 6 Configuring authentication 259Nortel Secure Network Access Switch 4050 User Guide add <variable name> <LDAP attribute> [<pref

Page 179

26 Preface320818-A The document provides instructions for initializing and customizing the features using the Command Line Interface (CLI). To learn t

Page 180 - Table 26

260 Chapter 6 Configuring authentication320818-A Managing Active Directory passwords using the CLIYou can set up a mechanism for clients to change the

Page 181

Chapter 6 Configuring authentication 261Nortel Secure Network Access Switch 4050 User Guide Configuring local database authentication using the CLIYou

Page 182 - Figure 34

262 Chapter 6 Configuring authentication320818-A where auth ID is an integer in the range 1 to 63 that uniquely identifies the authentication method i

Page 183 - HTTP Redirect fields

Chapter 6 Configuring authentication 263Nortel Secure Network Access Switch 4050 User Guide • group name — the name of the group to which the specifie

Page 184

264 Chapter 6 Configuring authentication320818-A Managing the local database using the CLIYou can add users to the database in two ways:• manually, us

Page 185

Chapter 6 Configuring authentication 265Nortel Secure Network Access Switch 4050 User Guide The Local database menu includes the following options:/cf

Page 186

266 Chapter 6 Configuring authentication320818-A import <protocol> <server> <filename> <key>Imports a database from the specif

Page 187 - Figure 37

Chapter 6 Configuring authentication 267Nortel Secure Network Access Switch 4050 User Guide Specifying authentication fallback order using the CLIAuth

Page 188

268 Chapter 6 Configuring authentication320818-A Perform this step even if there is only one method defined on the Nortel SNAS 4050.To specify the aut

Page 189

Chapter 6 Configuring authentication 269Nortel Secure Network Access Switch 4050 User Guide Configuring authentication using the SREMThe basic steps f

Page 190

Preface 27Nortel Secure Network Access Switch 4050 User Guide Text conventionsThis guide uses the following text conventions:angle brackets (< >

Page 191 - Chapter 5

270 Chapter 6 Configuring authentication320818-A Configuring authentication methods using the SREMTo create and configure an authentication method, pe

Page 192 - Overview

Chapter 6 Configuring authentication 271Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add an Authentication Server dialog box op

Page 193 - Default group

272 Chapter 6 Configuring authentication320818-A Adding the RADIUS method and serverTo configure the Nortel SNAS 4050 to use an external RADIUS or Ste

Page 194 - TunnelGuard SRS rule

Chapter 6 Configuring authentication 273Nortel Secure Network Access Switch 4050 User Guide 2 Enter the authentication server information in the appli

Page 195 - Extended profiles

274 Chapter 6 Configuring authentication320818-A • Modify settings for the specific RADIUS configuration (see “Modifying RADIUS configuration settings

Page 196 - Before you begin

Chapter 6 Configuring authentication 275Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Page 197

276 Chapter 6 Configuring authentication320818-A Modifying RADIUS configuration settingsTo modify the RADIUS method configuration, perform the followi

Page 198

Chapter 6 Configuring authentication 277Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the RADIUS configuration as necessar

Page 199

278 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Page 200 - Figure 38

Chapter 6 Configuring authentication 279Nortel Secure Network Access Switch 4050 User Guide Managing additional RADIUS serversAdditional RADIUS server

Page 201

28 Preface320818-A Related informationThis section lists information sources that relate to this document.PublicationsRefer to the following publicati

Page 202

280 Chapter 6 Configuring authentication320818-A The RADIUS Server Table allows you to manage additional RADIUS servers by performing any of the follo

Page 203

Chapter 6 Configuring authentication 281Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new RADIUS server is automatically assig

Page 204

282 Chapter 6 Configuring authentication320818-A The RADIUS Servers screen appears (see Figure 69 on page 291).2 Select an RADIUS server entry from th

Page 205 - Figure 40

Chapter 6 Configuring authentication 283Nortel Secure Network Access Switch 4050 User Guide Adding the LDAP method and serverTo configure the Nortel S

Page 206

284 Chapter 6 Configuring authentication320818-A 3 Click Apply.The LDAP authentication method displays in the Authentication Server Table.4 Click Appl

Page 207 - Figure 41

Chapter 6 Configuring authentication 285Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP method settingsTo modify settings for an ex

Page 208

286 Chapter 6 Configuring authentication320818-A 2 Modify settings for the authentication method as necessary.Table 45 describes the Configuration fie

Page 209

Chapter 6 Configuring authentication 287Nortel Secure Network Access Switch 4050 User Guide Modifying LDAP configuration settingsTo modify the LDAP me

Page 210 - Adding a group

288 Chapter 6 Configuring authentication320818-A 2 Modify settings for the LDAP configuration as necessary.Table 46 describes the LDAP Configuration f

Page 211 - Add a Group fields

Chapter 6 Configuring authentication 289Nortel Secure Network Access Switch 4050 User Guide User Attribute Refers to one of the following:1. the LDAP

Page 212 - Modifying a group

Preface 29Nortel Secure Network Access Switch 4050 User Guide • Release Notes for Nortel Ethernet Routing Switch 5500 Series, Software Release 4.3 (21

Page 213 - Group Configuration fields

290 Chapter 6 Configuring authentication320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Page 214 - Adding a client filter

Chapter 6 Configuring authentication 291Nortel Secure Network Access Switch 4050 User Guide Managing additional LDAP serversAdditional LDAP servers ca

Page 215 - Adding a Client Filter screen

292 Chapter 6 Configuring authentication320818-A The LDAP Server Table allows you to manage additional LDAP servers by performing any of the following

Page 216 - 4 Click Apply

Chapter 6 Configuring authentication 293Nortel Secure Network Access Switch 4050 User Guide The new LDAP server is automatically assigned a unique ind

Page 217 - Modifying a client filter

294 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Page 218 - Table 34

Chapter 6 Configuring authentication 295Nortel Secure Network Access Switch 4050 User Guide To manage LDAP macro variables, select the Secure Access D

Page 219

296 Chapter 6 Configuring authentication320818-A Adding LDAP macrosTo create an LDAP macro variable, perform the following steps:1 Select the Secure A

Page 220 - Adding an extended profile

Chapter 6 Configuring authentication 297Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new LDAP macro is automatically assigned

Page 221

298 Chapter 6 Configuring authentication320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the

Page 222 - Modifying an extended profile

Chapter 6 Configuring authentication 299Nortel Secure Network Access Switch 4050 User Guide Adding the Local methodTo configure the Nortel SNAS 4050 t

Page 223

3Nortel Secure Network Access Switch 4050 User Guide In addition, the program and information contained herein are licensed only pursuant to a license

Page 224 - Mapping linksets to a group

30 Preface320818-A • To call a Nortel Technical Solutions Center for assistance, click the CALL US link on the left side of the page to find the telep

Page 225 - Adding linksets to a group

300 Chapter 6 Configuring authentication320818-A 2 Enter the authentication server information in the applicable fields.Table 49 describes the Add an

Page 226

Chapter 6 Configuring authentication 301Nortel Secure Network Access Switch 4050 User Guide Populating the databaseYou can populate the Local database

Page 227 - Mapping linksets to a profile

302 Chapter 6 Configuring authentication320818-A 2 Click Add.The Add a Local User dialog box appears (see Figure 75).Figure 75 Add a Local User3 Ent

Page 228 - Add a Linkset fields

Chapter 6 Configuring authentication 303Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The new user entry appears in the list of lo

Page 229

304 Chapter 6 Configuring authentication320818-A Importing a database To import a database of local users, perform the following steps.1 Select the Se

Page 230 - AAA Configuration screen

Chapter 6 Configuring authentication 305Nortel Secure Network Access Switch 4050 User Guide 2 Enter the import information in the applicable fields.Ta

Page 231 - Table 39

306 Chapter 6 Configuring authentication320818-A Modifying Local method settingsTo modify settings for an existing local or LDAP authentication method

Page 232

Chapter 6 Configuring authentication 307Nortel Secure Network Access Switch 4050 User Guide 2 Modify settings for the authentication method as necessa

Page 233 - Configuring authentication

308 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Page 234

Chapter 6 Configuring authentication 309Nortel Secure Network Access Switch 4050 User Guide 3 Modify the local user information in the applicable fiel

Page 235

31Nortel Secure Network Access Switch 4050 User Guide Chapter 1 OverviewThis chapter includes the following topics:The Nortel SNA solutionNortel Secur

Page 236

310 Chapter 6 Configuring authentication320818-A 2 In the User Name list, select the user you want to edit. The Local Users screen refreshes to displa

Page 237

Chapter 6 Configuring authentication 311Nortel Secure Network Access Switch 4050 User Guide 4 Modify the local user information in the applicable fiel

Page 238

312 Chapter 6 Configuring authentication320818-A Exporting the databaseTo export the database of local users, perform the following steps:1 Select the

Page 239

Chapter 6 Configuring authentication 313Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields.Ta

Page 240

314 Chapter 6 Configuring authentication320818-A Specifying authentication fallback order using the SREMAuthentication in the Nortel SNAS 4050 solutio

Page 241

Chapter 6 Configuring authentication 315Nortel Secure Network Access Switch 4050 User Guide To specify authentication fallback order, perform these st

Page 242

316 Chapter 6 Configuring authentication320818-A 3 Rearrange the list so that the methods appear in the desired order.a Click on a method to select it

Page 243

317Nortel Secure Network Access Switch 4050 User Guide Chapter 7 TunnelGuard SRS BuilderThis chapter includes the following topics:Topic PageConfiguri

Page 244 - 1/aaa/group <group ID>

318 Chapter 7 TunnelGuard SRS Builder320818-A Configuring SRS rulesThe building blocks used to construct the Software Requirement Set (SRS) are files

Page 245

Chapter 7 TunnelGuard SRS Builder 319Nortel Secure Network Access Switch 4050 User Guide • “Software Definition — Available SRS list” on page 323• “Me

Page 246 - The RADIUS menu displays

32 Chapter 1 Overview320818-A For Nortel, success is delivering technologies providing secure access to your information using security-compliant syst

Page 247

320 Chapter 7 TunnelGuard SRS Builder320818-A Software Definition Entry menuTable 58 describes important items from the Software Definition Entry menu

Page 248

Chapter 7 TunnelGuard SRS Builder 321Nortel Secure Network Access Switch 4050 User Guide TunnelGuard Rule menuTable 59 describes important items from

Page 249

322 Chapter 7 TunnelGuard SRS Builder320818-A SRS definition toolbarThe buttons on the SRS definition toolbar allow you to create, delete, and manage

Page 250

Chapter 7 TunnelGuard SRS Builder 323Nortel Secure Network Access Switch 4050 User Guide Software Definition — Available SRS listThe available SRS lis

Page 251

324 Chapter 7 TunnelGuard SRS Builder320818-A Customizing a componentWhen an SRS component is selected by clicking on it, you can customize it using t

Page 252

Chapter 7 TunnelGuard SRS Builder 325Nortel Secure Network Access Switch 4050 User Guide Memory snapshotThe memory snapshot section in the lower half

Page 253 - The LDAP menu displays

326 Chapter 7 TunnelGuard SRS Builder320818-A SRS Rule listThe SRS Rule list shows the existing SRS rules. These rules are retrieved from the Nortel S

Page 254

Chapter 7 TunnelGuard SRS Builder 327Nortel Secure Network Access Switch 4050 User Guide Once the expression is formed, it is available for rule defin

Page 255

328 Chapter 7 TunnelGuard SRS Builder320818-A Figure 84 The New SRS window2 Enter a name for the software definition and click OK.For example, to cr

Page 256

Chapter 7 TunnelGuard SRS Builder 329Nortel Secure Network Access Switch 4050 User Guide Figure 85 The Create New Memory Module SRS window3 In the F

Page 257

Chapter 1 Overview 33Nortel Secure Network Access Switch 4050 User Guide Java Runtime Environment (JRE) for all browsers:— JRE 1.5.0_04 or later• VoIP

Page 258

330 Chapter 7 TunnelGuard SRS Builder320818-A If enabled, the client system will be searched for the specified file name, irrespective of path to fold

Page 259

Chapter 7 TunnelGuard SRS Builder 331Nortel Secure Network Access Switch 4050 User Guide The file/module is added as an entry in the selected software

Page 260

332 Chapter 7 TunnelGuard SRS Builder320818-A To create a software definition entry for a file not shown in the memory snapshot, perform the following

Page 261

Chapter 7 TunnelGuard SRS Builder 333Nortel Secure Network Access Switch 4050 User Guide 3 Select the Fetch Module Path from Registry Entry check box,

Page 262

334 Chapter 7 TunnelGuard SRS Builder320818-A 2 Click the TunnelGuard Rule Definition tab.TunnelGuard rules and expressions with the same names as the

Page 263

Chapter 7 TunnelGuard SRS Builder 335Nortel Secure Network Access Switch 4050 User Guide 4 Select another expression that you will use to form a new l

Page 264

336 Chapter 7 TunnelGuard SRS Builder320818-A Figure 88 The Available Expressions screen7 Create a new TunnelGuard Rule.On the TunnelGuard Rule menu

Page 265

Chapter 7 TunnelGuard SRS Builder 337Nortel Secure Network Access Switch 4050 User Guide The new rule name appears in the TunnelGuard Rule Name column

Page 266

338 Chapter 7 TunnelGuard SRS Builder320818-A Registry-based rulesTunnelGuard Agent supports checking of on-disk files, running processes, hash checki

Page 267

Chapter 7 TunnelGuard SRS Builder 339Nortel Secure Network Access Switch 4050 User Guide Table 66 describes supported operands for integer values.The

Page 268

34 Chapter 1 Overview320818-A Nortel SNAS 4050 functionsThe Nortel SNAS 4050 performs the following functions:• Acts as a web server portal, which is

Page 269

340 Chapter 7 TunnelGuard SRS Builder320818-A Table 67 describes supported constructs for string-based regular expressions.Table 67 Constructs for s

Page 270 - Figure 60

Chapter 7 TunnelGuard SRS Builder 341Nortel Secure Network Access Switch 4050 User Guide The following are examples of regular expressions for string-

Page 271

342 Chapter 7 TunnelGuard SRS Builder320818-A Figure 91 Registry Entry page3 Select the Registry Key Path from the Registry Editor.4 Select the Key

Page 272

Chapter 7 TunnelGuard SRS Builder 343Nortel Secure Network Access Switch 4050 User Guide Manually creating SRS entriesThe administrator tool applet pr

Page 273

344 Chapter 7 TunnelGuard SRS Builder320818-A Figure 92 Create new OnDisk SRS Entry3 Click Browse Local System to select the File or Module Path. Th

Page 274 - Configuration

Chapter 7 TunnelGuard SRS Builder 345Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for either Relative Date/Time Range

Page 275 - Table 41

346 Chapter 7 TunnelGuard SRS Builder320818-A Figure 93 Create new Memory Module SRS entry3 Click Browse Local System to select the File or Module P

Page 276 - Figure 63

Chapter 7 TunnelGuard SRS Builder 347Nortel Secure Network Access Switch 4050 User Guide 6 Click an option button for Max Version.7 Click an option bu

Page 277 - Table 42

348 Chapter 7 TunnelGuard SRS Builder320818-A Figure 94 Date/Time RangeAdding comments• “Adding a TunnelGuard rule comment” on page 348• “Adding a s

Page 278

Chapter 7 TunnelGuard SRS Builder 349Nortel Secure Network Access Switch 4050 User Guide 3 Click the button to display the Rule Comment window (see Fi

Page 279 - Radius Servers

Chapter 1 Overview 35Nortel Secure Network Access Switch 4050 User Guide • VoIP — automatic access for VoIP traffic. The network access device places

Page 280 - Adding a RADIUS server

350 Chapter 7 TunnelGuard SRS Builder320818-A Deleting a software definition1 Click the Software Definition tab.2 In the Software Definition column, s

Page 281 - Removing a RADIUS server

Chapter 7 TunnelGuard SRS Builder 351Nortel Secure Network Access Switch 4050 User Guide 2 In the Available Expressions area, select the desired expre

Page 282 - Next steps

352 Chapter 7 TunnelGuard SRS Builder320818-A

Page 283

353Nortel Secure Network Access Switch 4050 User Guide Chapter 8 Managing system users and groupsThis chapter includes the following topics:Topic Page

Page 284 - Modifying LDAP configuration

354 Chapter 8 Managing system users and groups320818-A User rights and group membershipThere are three groups of system users who routinely access the

Page 285

Chapter 8 Managing system users and groups 355Nortel Secure Network Access Switch 4050 User Guide Managing system users and groups using the CLITo man

Page 286 - Table 45

356 Chapter 8 Managing system users and groups320818-A Managing user accounts and passwords using the CLITo change the password for the currently logg

Page 287 - Figure 68

Chapter 8 Managing system users and groups 357Nortel Secure Network Access Switch 4050 User Guide del <username>Removes the specified user accou

Page 288 - Table 46

358 Chapter 8 Managing system users and groups320818-A Managing user settings using the CLIYou must have administrator rights in order to change a use

Page 289

Chapter 8 Managing system users and groups 359Nortel Secure Network Access Switch 4050 User Guide To set or change the login password for a specified

Page 290

36 Chapter 1 Overview320818-A Authentication methodsYou can configure more than one authentication method within a Nortel SNAS 4050 domain. Nortel Sec

Page 291 - LDAP Servers

360 Chapter 8 Managing system users and groups320818-A To set or change a user’s group assignment, access the Groups menu by using the following comma

Page 292 - Adding an LDAP server

Chapter 8 Managing system users and groups 361Nortel Secure Network Access Switch 4050 User Guide In this configuration example, a certificate adminis

Page 293 - Removing an LDAP server

362 Chapter 8 Managing system users and groups320818-A —oper—admin— certadminBy default, the admin user is a member of all groups above, and can there

Page 294 - Managing LDAP macros

Chapter 8 Managing system users and groups 363Nortel Secure Network Access Switch 4050 User Guide 7 Apply the changes.8 Let the Certificate Administra

Page 295 - LDAP Macros

364 Chapter 8 Managing system users and groups320818-A 9 Remove the admin user from the certadmin group.Again, this step is only necessary if you want

Page 296 - Adding LDAP macros

Chapter 8 Managing system users and groups 365Nortel Secure Network Access Switch 4050 User Guide Changing a user’s group assignmentOnly users who are

Page 297 - Removing LDAP macros

366 Chapter 8 Managing system users and groups320818-A 4 Verify and apply the changes.Changing passwordsChanging your own passwordAll users can change

Page 298

Chapter 8 Managing system users and groups 367Nortel Secure Network Access Switch 4050 User Guide 2 Access the User Menu.Type the passwd command to ch

Page 299 - Adding the Local method

368 Chapter 8 Managing system users and groups320818-A 2 Access the User Menu.3 Specify the user name of the user whose password you want to change.4

Page 300

Chapter 8 Managing system users and groups 369Nortel Secure Network Access Switch 4050 User Guide Deleting a userTo delete a user from the system, you

Page 301 - Populating the database

Chapter 1 Overview 37Nortel Secure Network Access Switch 4050 User Guide TunnelGuard host integrity checkThe TunnelGuard application checks client hos

Page 302 - Add a Local User fields

370 Chapter 8 Managing system users and groups320818-A The imminent removal of the cert_admin user is indicated as a pending configuration change by t

Page 303

Chapter 8 Managing system users and groups 371Nortel Secure Network Access Switch 4050 User Guide The User Table appears (see Figure 96), displaying a

Page 304 - Importing a database

372 Chapter 8 Managing system users and groups320818-A Only the admin user can delete users from the system. Of the three built-in users (admin, oper,

Page 305

Chapter 8 Managing system users and groups 373Nortel Secure Network Access Switch 4050 User Guide 3 Enter the user information in the applicable field

Page 306

374 Chapter 8 Managing system users and groups320818-A Setting password expiry using the SREMTo set a password expiry date for all passwords in the sy

Page 307 - Modifying local users

Chapter 8 Managing system users and groups 375Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Password Setting information in the appl

Page 308 - Figure 78

376 Chapter 8 Managing system users and groups320818-A Changing your password using the SREMOnly the admin user can change the passwords of other user

Page 309

Chapter 8 Managing system users and groups 377Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Page 310

378 Chapter 8 Managing system users and groups320818-A To change the password for another user, perform the following steps:1 Select the System > M

Page 311 - Table 54

Chapter 8 Managing system users and groups 379Nortel Secure Network Access Switch 4050 User Guide 2 Enter the password information in the applicable f

Page 312 - Exporting the database

38 Chapter 1 Overview320818-A Communication channelsCommunications between the Nortel SNAS 4050 and key elements of the Nortel SNA solution are secure

Page 313

380 Chapter 8 Managing system users and groups320818-A To set a certificate export pass phrase, perform the following steps:1 Select the System > M

Page 314

Chapter 8 Managing system users and groups 381Nortel Secure Network Access Switch 4050 User Guide 2 Enter the PassPhrase information in the applicable

Page 315 - Authentication Server Order

382 Chapter 8 Managing system users and groups320818-A To manage the group to which a user belongs, select the System > Manage Users > user >

Page 316

Chapter 8 Managing system users and groups 383Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a User Group dialog box appears

Page 317 - TunnelGuard SRS Builder

384 Chapter 8 Managing system users and groups320818-A The user group is immediately removed from the User Group Table.5 Click Apply on the toolbar to

Page 318 - Configuring SRS rules

385Nortel Secure Network Access Switch 4050 User Guide Chapter 9 Customizing the portal and user logonThis chapter includes the following topics:Topic

Page 319 - Menu commands

386 Chapter 9 Customizing the portal and user logon320818-A OverviewThe end user accesses the Nortel SNA network through the Nortel SNAS 4050 portal.

Page 320

Chapter 9 Customizing the portal and user logon 387Nortel Secure Network Access Switch 4050 User Guide • redirects client requests to an authenticatio

Page 321 - Tool menu

388 Chapter 9 Customizing the portal and user logon320818-A Table 75 lists the regular expressions and escape sequences you can use in an Exclude List

Page 322 - SRS definition toolbar

Chapter 9 Customizing the portal and user logon 389Nortel Secure Network Access Switch 4050 User Guide Portal displayYou can modify the following feat

Page 323 - SRS Components table

Chapter 1 Overview 39Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 supports the use of three different SSH host key types:

Page 324 - Customizing a component

390 Chapter 9 Customizing the portal and user logon320818-A Default appearanceFigure 104 shows the default portal Home tab.Figure 104 Default appear

Page 325 - Memory snapshot

Chapter 9 Customizing the portal and user logon 391Nortel Secure Network Access Switch 4050 User Guide • color3 — the fields, information area, and cl

Page 326 - Rule Expression Constructor

392 Chapter 9 Customizing the portal and user logon320818-A For the commands to configure the colors used on the portal, see “Changing the portal colo

Page 327

Chapter 9 Customizing the portal and user logon 393Nortel Secure Network Access Switch 4050 User Guide To change the language displayed for tab names,

Page 328 - The New SRS window

394 Chapter 9 Customizing the portal and user logon320818-A Linksets and linksYou can add the following types of links to the portal Home tab:• Extern

Page 329

Chapter 9 Customizing the portal and user logon 395Nortel Secure Network Access Switch 4050 User Guide Planning the linksetsPlan your configuration so

Page 330

396 Chapter 9 Customizing the portal and user logon320818-A Automatic redirection to internal sitesYou can configure the portal to automatically redir

Page 331 - Selecting file on disk

Chapter 9 Customizing the portal and user logon 397Nortel Secure Network Access Switch 4050 User Guide Managing the end user experienceNortel recommen

Page 332

398 Chapter 9 Customizing the portal and user logon320818-A 2 Download the JRE installer from the Sun Microsystems Java web site (http://www.java.com)

Page 333 - Creating logical expressions

Chapter 9 Customizing the portal and user logon 399Nortel Secure Network Access Switch 4050 User Guide /cfg/domain 1/dnscapt/exclude listdel <index

Page 334

4320818-A BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nort

Page 335

40 Chapter 1 Overview320818-A • fault tolerance — If a Nortel SNAS 4050 device fails, the failure is detected by the other node in the cluster, which

Page 336 - The New SRS Rule window

400 Chapter 9 Customizing the portal and user logon320818-A color2 <code>color3 <code>color4 <code>theme default|aqua|apple| jeans|c

Page 337

Chapter 9 Customizing the portal and user logon 401Nortel Secure Network Access Switch 4050 User Guide Configuring the captive portal using the CLIBy

Page 338 - Registry-based rules

402 Chapter 9 Customizing the portal and user logon320818-A The DNS Exclude menu includes the following options:Changing the portal language using the

Page 339 - Supported integer operands

Chapter 9 Customizing the portal and user logon 403Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the CLITo ma

Page 340 - Table 67

404 Chapter 9 Customizing the portal and user logon320818-A The Language Support menu includes the following options:/cfg/langfollowed by:import <p

Page 341 - Creating a registry entry

Chapter 9 Customizing the portal and user logon 405Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the C

Page 342 - Registry-based File/Module

406 Chapter 9 Customizing the portal and user logon320818-A Configuring the portal display using the CLITo modify the look and feel of the portal page

Page 343 - Manually creating SRS entries

Chapter 9 Customizing the portal and user logon 407Nortel Secure Network Access Switch 4050 User Guide redirect <URL>Sets the URL to which clien

Page 344 - Create new OnDisk SRS Entry

408 Chapter 9 Customizing the portal and user logon320818-A linktext <text>Specifies static text to be displayed above the group links on the po

Page 345

Chapter 9 Customizing the portal and user logon 409Nortel Secure Network Access Switch 4050 User Guide Changing the portal colors using the CLITo cust

Page 346

Chapter 1 Overview 41Nortel Secure Network Access Switch 4050 User Guide One-armed configurationIn a one-armed configuration, the Nortel SNAS 4050 has

Page 347 - File age check

410 Chapter 9 Customizing the portal and user logon320818-A The Portal Colors menu includes the following options:For more information about the porta

Page 348 - Adding comments

Chapter 9 Customizing the portal and user logon 411Nortel Secure Network Access Switch 4050 User Guide The Portal Custom Content menu includes the fol

Page 349 - The Rule Comment window

412 Chapter 9 Customizing the portal and user logon320818-A Configuring linksets using the CLIA linkset is a set of links that display on the portal H

Page 350 - Deleting an expression

Chapter 9 Customizing the portal and user logon 413Nortel Secure Network Access Switch 4050 User Guide The Linkset menu includes the following options

Page 351 - Making API calls

414 Chapter 9 Customizing the portal and user logon320818-A Configuring links using the CLITo create and configure the links included in the linkset,

Page 352

Chapter 9 Customizing the portal and user logon 415Nortel Secure Network Access Switch 4050 User Guide The Link menu includes the following options:/c

Page 353 - Chapter 8

416 Chapter 9 Customizing the portal and user logon320818-A Configuring external link settings using the CLITo launch the wizard to configure settings

Page 354

Chapter 9 Customizing the portal and user logon 417Nortel Secure Network Access Switch 4050 User Guide Customizing the portal and logon using the SREM

Page 355

418 Chapter 9 Customizing the portal and user logon320818-A Figure 105 DNS Capture screenThe DNS Capture screen includes the following components:2

Page 356

Chapter 9 Customizing the portal and user logon 419Nortel Secure Network Access Switch 4050 User Guide Configuring the DNS Exclude List using the SREM

Page 357

42 Chapter 1 Overview320818-A Figure 2 illustrates a two-armed configuration.Figure 2 Two-armed configurationNortel SNA configuration and management

Page 358

420 Chapter 9 Customizing the portal and user logon320818-A 3 To remove an entry from the Exclude List:a In the DNS Exclude List, select the entry you

Page 359

Chapter 9 Customizing the portal and user logon 421Nortel Secure Network Access Switch 4050 User Guide Configuring language support using the SREMTo m

Page 360 - CLI configuration examples

422 Chapter 9 Customizing the portal and user logon320818-A Viewing predefined languagesTo view predefined languages, click the Pre-defined Languages

Page 361

Chapter 9 Customizing the portal and user logon 423Nortel Secure Network Access Switch 4050 User Guide b Click Apply on the toolbar to send the curren

Page 362 - Old: is empty

424 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Language information in the applicable fields. Table 80 describes the Import D

Page 363

Chapter 9 Customizing the portal and user logon 425Nortel Secure Network Access Switch 4050 User Guide Setting the portal display language using the S

Page 364 - /cfg/cert)

426 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the language information in the applicable fields. Table 81 describes the Langauge

Page 365

Chapter 9 Customizing the portal and user logon 427Nortel Secure Network Access Switch 4050 User Guide Configuring contentTo configure and modify port

Page 366 - Changing your own password

428 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the Portal Configuration information in the applicable fields. Table 82 describes

Page 367

Chapter 9 Customizing the portal and user logon 429Nortel Secure Network Access Switch 4050 User Guide Redirect URL Sets the URL to which clients are

Page 368 - 5 Apply the changes

Chapter 1 Overview 43Nortel Secure Network Access Switch 4050 User Guide • Security & Routing Element Manager (SREM)The SREM is a GUI application

Page 369 - Deleting a user

430 Chapter 9 Customizing the portal and user logon320818-A Importing bannersTo import a banner to display on the portal Home page, perform the follow

Page 370

Chapter 9 Customizing the portal and user logon 431Nortel Secure Network Access Switch 4050 User Guide 2 Enter the banner information in the applicabl

Page 371 - User Table

432 Chapter 9 Customizing the portal and user logon320818-A Changing the portal colors using the SREMTo customize the colors used for portal display,

Page 372 - Adding new user accounts

Chapter 9 Customizing the portal and user logon 433Nortel Secure Network Access Switch 4050 User Guide 2 Enter the color information in the applicable

Page 373 - Add a User fields

434 Chapter 9 Customizing the portal and user logon320818-A Configuring custom content using the SREMTo configure custom content, such as Java applets

Page 374 - Figure 98

Chapter 9 Customizing the portal and user logon 435Nortel Secure Network Access Switch 4050 User Guide Viewing basic information about custom contentT

Page 375 - Table 70

436 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the basic information in the applicable fields. Table 85 describes the Basics fiel

Page 376 - Change Your Password

Chapter 9 Customizing the portal and user logon 437Nortel Secure Network Access Switch 4050 User Guide Importing custom contentTo import custom conten

Page 377 - Change Your Password fields

438 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the import information in the applicable fields. Table 86 describes the Import Con

Page 378 - Figure 100

Chapter 9 Customizing the portal and user logon 439Nortel Secure Network Access Switch 4050 User Guide Exporting custom contentTo export custom conten

Page 379 - Change User Password fields

44 Chapter 1 Overview320818-A For each VLAN:a Create a DHCP scope.b Specify the IP address range and subnet mask for that scope.c Configure the follow

Page 380 - Figure 101

440 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the export information in the applicable fields. Table 87 describes the Export Con

Page 381

Chapter 9 Customizing the portal and user logon 441Nortel Secure Network Access Switch 4050 User Guide Creating a linksetTo create a linkset, perform

Page 382 - Adding a user group

442 Chapter 9 Customizing the portal and user logon320818-A 2 Click Add.The Add a Linkset dialog box appears (see Figure 118).Figure 118 Add a Links

Page 383 - Removing a user group

Chapter 9 Customizing the portal and user logon 443Nortel Secure Network Access Switch 4050 User Guide Modifying a linksetTo modify a linkset, perform

Page 384

444 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the linkset information in the applicable fields. Table 89 describes the linkset C

Page 385 - Chapter 9

Chapter 9 Customizing the portal and user logon 445Nortel Secure Network Access Switch 4050 User Guide Configuring links using the SREMAfter you creat

Page 386

446 Chapter 9 Customizing the portal and user logon320818-A Creating an external link using the SREMTo create an external link, perform the following

Page 387 - Exclude List

Chapter 9 Customizing the portal and user logon 447Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Portal Link dialog box ap

Page 388 - Table 75

448 Chapter 9 Customizing the portal and user logon320818-A 5 Click Apply.The new external link appears in the Links table.6 Click Apply on the toolba

Page 389 - Portal display

Chapter 9 Customizing the portal and user logon 449Nortel Secure Network Access Switch 4050 User Guide To create an FTP link, perform the following st

Page 390 - Default appearance

Chapter 1 Overview 45Nortel Secure Network Access Switch 4050 User Guide Use the applicable show commands on the router to verify that DHCP relay has

Page 391

450 Chapter 9 Customizing the portal and user logon320818-A 4 Enter the link information in the applicable fields. Table 91 describes the Add a Portal

Page 392 - Language localization

Chapter 9 Customizing the portal and user logon 451Nortel Secure Network Access Switch 4050 User Guide Modifying external link settings using the SREM

Page 393

452 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 92 describes the external lin

Page 394 - Autorun linksets

Chapter 9 Customizing the portal and user logon 453Nortel Secure Network Access Switch 4050 User Guide Modifying FTP link settings using the SREMTo mo

Page 395 - Planning the linksets

454 Chapter 9 Customizing the portal and user logon320818-A 2 Enter the link information in the applicable fields. Table 93 describes the FTP link Con

Page 396

Chapter 9 Customizing the portal and user logon 455Nortel Secure Network Access Switch 4050 User Guide The Re Order Links screen appears (see Figure 1

Page 397 - Automatic JRE upload

456 Chapter 9 Customizing the portal and user logon320818-A

Page 398 - Windows domain logon script

457Nortel Secure Network Access Switch 4050 User Guide Chapter 10 Configuring system settingsThis chapter includes the following topics:Topic PageConf

Page 399 - Command Parameter

458 Chapter 10 Configuring system settings320818-A System settings apply to a cluster as a whole.You can log on to either the Management IP address (M

Page 400

Chapter 10 Configuring system settings 459Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the CLITo configure the cl

Page 401

46 Chapter 1 Overview320818-A Identify switch ports as either uplink or dynamic. When you configure the uplink ports, you associate the NSNA VLANs wit

Page 402

460 Chapter 10 Configuring system settings320818-A • disabling SSL traffic trace commands (see “Configuring system settings using the CLI” on page 463

Page 403 - /cfg/lang

Chapter 10 Configuring system settings 461Nortel Secure Network Access Switch 4050 User Guide del <index number>add <IPaddr> <mask>

Page 404

462 Chapter 10 Configuring system settings320818-A health <interval>hdown <count>hup <count>/cfg/sys/dns/serverslistdel <index nu

Page 405

Chapter 10 Configuring system settings 463Nortel Secure Network Access Switch 4050 User Guide show/cfg/sys/adm/sshkeys/knownhostslistdel <index num

Page 406 - The Portal menu displays

464 Chapter 10 Configuring system settings320818-A Configuring system settings using the CLITo view and configure cluster-wide system settings, use th

Page 407

Chapter 10 Configuring system settings 465Nortel Secure Network Access Switch 4050 User Guide Configuring the Nortel SNAS 4050 host using the CLITo co

Page 408

466 Chapter 10 Configuring system settings320818-A The Cluster Host menu includes the following options:/cfg/sys/host <host ID>followed by:ip &l

Page 409

Chapter 10 Configuring system settings 467Nortel Secure Network Access Switch 4050 User Guide portAccesses the Host Port menu, in order to configure p

Page 410

468 Chapter 10 Configuring system settings320818-A rebootReboots the Nortel SNAS 4050.If the Nortel SNAS 4050 you want to reboot has become isolated f

Page 411

Chapter 10 Configuring system settings 469Nortel Secure Network Access Switch 4050 User Guide Viewing host informationTo view the host number and IP a

Page 412

Chapter 1 Overview 47Nortel Secure Network Access Switch 4050 User Guide configuration in the SREM (see “Checking configuration using the SREM” on pag

Page 413

470 Chapter 10 Configuring system settings320818-A gateway <IPaddr>Sets the default gateway address for the interface. The default gateway is th

Page 414

Chapter 10 Configuring system settings 471Nortel Secure Network Access Switch 4050 User Guide Configuring static routes using the CLITo manage static

Page 415

472 Chapter 10 Configuring system settings320818-A The system, host, or interface Routes menu displays.When you add a static route to the system, host

Page 416

Chapter 10 Configuring system settings 473Nortel Secure Network Access Switch 4050 User Guide The Host Port menu includes the following options:Managi

Page 417 - Enabling DNS capture

474 Chapter 10 Configuring system settings320818-A The Interface Ports menu includes the following options:Configuring the Access List using the CLITh

Page 418 - DNS Capture fields

Chapter 10 Configuring system settings 475Nortel Secure Network Access Switch 4050 User Guide The Access List menu displays.The Access List menu inclu

Page 419 - Add DNS Domain fields

476 Chapter 10 Configuring system settings320818-A The Date and Time menu includes the following options:Managing NTP serversYou can add NTP servers t

Page 420

Chapter 10 Configuring system settings 477Nortel Secure Network Access Switch 4050 User Guide The NTP Servers menu includes the following options:Conf

Page 421 - Pre-defined Languages

478 Chapter 10 Configuring system settings320818-A retransmit <interval>Sets the interval for retransmitting a DNS query. •interval is a positiv

Page 422 - Viewing predefined languages

Chapter 10 Configuring system settings 479Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Page 423 - Import/Export Definition

48 Chapter 1 Overview320818-A

Page 424

480 Chapter 10 Configuring system settings320818-A Configuring RSA servers using the CLITo configure the symbolic name for the RSA server and import t

Page 425 - Figure 110

Chapter 10 Configuring system settings 481Nortel Secure Network Access Switch 4050 User Guide The RSA Servers menu includes the following options:Conf

Page 426 - Language fields

482 Chapter 10 Configuring system settings320818-A The Syslog Servers menu includes the following options:/cfg/sys/syslogfollowed by:listLists the IP

Page 427 - Configuring content

Chapter 10 Configuring system settings 483Nortel Secure Network Access Switch 4050 User Guide Configuring administrative settings using the CLIAdminis

Page 428 - Table 82

484 Chapter 10 Configuring system settings320818-A auditAccesses the Audit menu, in order to configure RADIUS auditing (see “Configuring RADIUS auditi

Page 429

Chapter 10 Configuring system settings 485Nortel Secure Network Access Switch 4050 User Guide Enabling TunnelGuard SRS administration using the CLITo

Page 430 - Importing banners

486 Chapter 10 Configuring system settings320818-A During initial setup, there is an option to generate the SSH host keys automatically. To generate a

Page 431 - Import Banner fields

Chapter 10 Configuring system settings 487Nortel Secure Network Access Switch 4050 User Guide Managing known hosts SSH keys using the CLIYou can paste

Page 432 - Figure 113

488 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditing using the CLIYou can configure the Nortel SNAS 4050 cluster to include

Page 433 - Color Settings fields

Chapter 10 Configuring system settings 489Nortel Secure Network Access Switch 4050 User Guide The Internet Assigned Numbers Authority (IANA) has desig

Page 434

49Nortel Secure Network Access Switch 4050 User Guide Chapter 2 Initial setupThis chapter includes the following topics:Topic PageBefore you begin50Ab

Page 435 - Basics screen

490 Chapter 10 Configuring system settings320818-A Managing RADIUS audit servers using the CLITo configure the Nortel SNAS 4050 to use external RADIUS

Page 436 - Table 85

Chapter 10 Configuring system settings 491Nortel Secure Network Access Switch 4050 User Guide add <IPaddr> <port> <shared secret>Add

Page 437 - Importing custom content

492 Chapter 10 Configuring system settings320818-A Configuring authentication of system users using the CLIYou can configure the Nortel SNAS 4050 clus

Page 438 - Table 86

Chapter 10 Configuring system settings 493Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the CLITo c

Page 439 - Exporting custom content

494 Chapter 10 Configuring system settings320818-A The RADIUS Authentication Servers menu includes the following options:/cfg/sys/adm/auth/serversfoll

Page 440 - Export Content fields

Chapter 10 Configuring system settings 495Nortel Secure Network Access Switch 4050 User Guide Configuring the cluster using the SREMTo configure the c

Page 441 - Creating a linkset

496 Chapter 10 Configuring system settings320818-A Configuring system settings using the SREMTo view and configure cluster-wide system settings, perfo

Page 442 - Add a Linkset

Chapter 10 Configuring system settings 497Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Management IP Address (MIP) information in t

Page 443 - Modifying a linkset

498 Chapter 10 Configuring system settings320818-A Viewing host informationTo display a list of available Nortel SNAS 4050 hosts, select the System &g

Page 444 - Linkset Configuration fields

Chapter 10 Configuring system settings 499Nortel Secure Network Access Switch 4050 User Guide Viewing and configuring TCP/IP propertiesTo configure ba

Page 445

5Nortel Secure Network Access Switch 4050 User Guide ContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 446 - Figure 120

50 Chapter 2 Initial setup320818-A Before you beginBefore you can set up the Nortel SNAS 4050, you must complete the following tasks:1 Plan the networ

Page 447 - Add a Portal Link fields

500 Chapter 10 Configuring system settings320818-A 2 Enter the host information in the applicable fields. Table 96 describes the Host fields.3 Click A

Page 448

Chapter 10 Configuring system settings 501Nortel Secure Network Access Switch 4050 User Guide Additionally, new licenses can be added to a particular

Page 449 - Add a Portal Link — FTP

502 Chapter 10 Configuring system settings320818-A Table 97 describes the Global Licenses fields.2 Modify the Auto Refresh and Logging settings, if de

Page 450

Chapter 10 Configuring system settings 503Nortel Secure Network Access Switch 4050 User Guide Viewing per domain licenses for all hostsTo view license

Page 451 - Figure 123

504 Chapter 10 Configuring system settings320818-A Table 98 describes the Per Domain Licenses fields.2 Modify the Auto Refresh and Logging settings, i

Page 452 - Table 92

Chapter 10 Configuring system settings 505Nortel Secure Network Access Switch 4050 User Guide Viewing installed licenses for a particular hostTo view

Page 453 - Figure 124

506 Chapter 10 Configuring system settings320818-A Installing a license for a particular hostThe Nortel SNA SSL (portal and Nortel SNAS 4050 domain cl

Page 454 - FTP link Configuration fields

Chapter 10 Configuring system settings 507Nortel Secure Network Access Switch 4050 User Guide 3 In the SREM, select the System > Hosts > host &g

Page 455 - Re Order Links fields

508 Chapter 10 Configuring system settings320818-A Configuring host interfaces using the SREMThe default IP interface on the Nortel SNAS 4050 host is

Page 456

Chapter 10 Configuring system settings 509Nortel Secure Network Access Switch 4050 User Guide • “Removing a host interface” on page 514Adding a host i

Page 457 - Configuring system settings

Chapter 2 Initial setup 51Nortel Secure Network Access Switch 4050 User Guide 4 Establish a console connection to the Nortel SNAS 4050 (see “Establish

Page 458

510 Chapter 10 Configuring system settings320818-A 4 Click Apply.The new interface appears in the Interfaces table.Gateway Sets the default gateway ad

Page 459 - /cfg/sys

Chapter 10 Configuring system settings 511Nortel Secure Network Access Switch 4050 User Guide 5 Click Apply on the toolbar to send the current changes

Page 460 - Roadmap of system commands

512 Chapter 10 Configuring system settings320818-A 2 Enter the interface information in the applicable fields. Table 100 describes the Interface confi

Page 461

Chapter 10 Configuring system settings 513Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the current changes

Page 462

514 Chapter 10 Configuring system settings320818-A Removing a host interfaceTo delete a host interface, perform the following steps:1 Select the Syste

Page 463

Chapter 10 Configuring system settings 515Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for a clusterTo configure static r

Page 464 - The System menu displays

516 Chapter 10 Configuring system settings320818-A Viewing static routes for a hostTo configure static routes for a host, select the System > Hosts

Page 465

Chapter 10 Configuring system settings 517Nortel Secure Network Access Switch 4050 User Guide Viewing static routes for an interfaceTo configure stati

Page 466

518 Chapter 10 Configuring system settings320818-A From the selected static route screen, complete the following tasks as necessary:• “Adding a static

Page 467

Chapter 10 Configuring system settings 519Nortel Secure Network Access Switch 4050 User Guide 4 Click Add.The new route appears in the table.5 Click A

Page 468

52 Chapter 2 Initial setup320818-A Real IP addressThe Real IP address (RIP) is the Nortel SNAS 4050 device host IP address for network connectivity. T

Page 469 - Viewing host information

520 Chapter 10 Configuring system settings320818-A Configuring host ports using the SREMTo configure the connection properties for a port, perform the

Page 470

Chapter 10 Configuring system settings 521Nortel Secure Network Access Switch 4050 User Guide 2 Select a port to configure from the list.The Port scre

Page 471

522 Chapter 10 Configuring system settings320818-A 3 Enter the port information in the applicable fields. Table 102 describes the Port fields.4 Click

Page 472

Chapter 10 Configuring system settings 523Nortel Secure Network Access Switch 4050 User Guide Managing interface ports using the SREMTo view and manag

Page 473

524 Chapter 10 Configuring system settings320818-A Adding interface portsTo add ports to the selected interface, perform the following steps:1 Select

Page 474

Chapter 10 Configuring system settings 525Nortel Secure Network Access Switch 4050 User Guide The port is removed from the Port Table.5 Click Apply on

Page 475

526 Chapter 10 Configuring system settings320818-A The Access List Table appears (see Figure 143).Figure 143 Access ListFrom here, you can manage th

Page 476 - Managing NTP servers

Chapter 10 Configuring system settings 527Nortel Secure Network Access Switch 4050 User Guide The Add Access Host dialog box appears (see Figure 144).

Page 477

528 Chapter 10 Configuring system settings320818-A 4 Click Yes.The entry disappears from the Access List Table.5 Click Apply on the toolbar to send th

Page 478

Chapter 10 Configuring system settings 529Nortel Secure Network Access Switch 4050 User Guide You can add NTP servers to the system configuration to e

Page 479 - Managing DNS servers

Chapter 2 Initial setup 53Nortel Secure Network Access Switch 4050 User Guide The Setup Menu displays.2 Select the option for a new installation.3 Spe

Page 480

530 Chapter 10 Configuring system settings320818-A Adding an NTP serverTo add an additional NTP server, perform the following steps:1 Select the Syste

Page 481

Chapter 10 Configuring system settings 531Nortel Secure Network Access Switch 4050 User Guide Removing an NTP serverTo remove an existing NTP server f

Page 482

532 Chapter 10 Configuring system settings320818-A Configuring DNS settings using the SREMTo configure DNS client settings, use the following procedur

Page 483

Chapter 10 Configuring system settings 533Nortel Secure Network Access Switch 4050 User Guide 2 Enter the DNS Client information in the applicable fie

Page 484

534 Chapter 10 Configuring system settings320818-A Configuring servers using the SREMTo configure servers, choose from one of the following tasks:• “M

Page 485

Chapter 10 Configuring system settings 535Nortel Secure Network Access Switch 4050 User Guide From this screen, complete the following tasks as necess

Page 486

536 Chapter 10 Configuring system settings320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on t

Page 487

Chapter 10 Configuring system settings 537Nortel Secure Network Access Switch 4050 User Guide Managing DNS serversYou can add up to three DNS servers

Page 488 - About RADIUS auditing

538 Chapter 10 Configuring system settings320818-A Adding a DNS serverTo manage DNS servers in the system configuration, perform the following steps:1

Page 489 - Configuring RADIUS auditing

Chapter 10 Configuring system settings 539Nortel Secure Network Access Switch 4050 User Guide Removing an existing DNS serverTo remove a DNS server fr

Page 490

54 Chapter 2 Initial setup320818-A In a two-armed configuration, you are specifying the port you want to use for Nortel SNAS 4050 management traffic.4

Page 491

540 Chapter 10 Configuring system settings320818-A Managing RSA serversTo manage RSA servers, select the System > Servers > RSA Server Table tab

Page 492

Chapter 10 Configuring system settings 541Nortel Secure Network Access Switch 4050 User Guide • “Removing the RSA node secret” on page 542• “Importing

Page 493

542 Chapter 10 Configuring system settings320818-A Removing an existing RSA serverTo remove an existing RSA server, perform the following steps.1 Sele

Page 494

Chapter 10 Configuring system settings 543Nortel Secure Network Access Switch 4050 User Guide 3 Select the RSA Server sub-tab.The RSA Server screen ap

Page 495

544 Chapter 10 Configuring system settings320818-A 4 Click Remove Secret Node.The RSA node secret is immediately removed.5 Click Apply on the toolbar

Page 496 - Figure 126

Chapter 10 Configuring system settings 545Nortel Secure Network Access Switch 4050 User Guide 3 Select the Import sdconf.rec tab.The Import sdconf.rec

Page 497 - System Configuration fields

546 Chapter 10 Configuring system settings320818-A 4 Enter the importing information in the applicable fields. Table 112 describes the Import sdconf.r

Page 498

Chapter 10 Configuring system settings 547Nortel Secure Network Access Switch 4050 User Guide Configuring SRS control settings using the SREMTo create

Page 499 - Figure 128

548 Chapter 10 Configuring system settings320818-A 2 Enter the SRS Control information in the applicable fields. Table 115 describes the SRS Control S

Page 500 - Host fields

Chapter 10 Configuring system settings 549Nortel Secure Network Access Switch 4050 User Guide • “Showing SSH keys” on page 549• “Managing Nortel SNAS

Page 501 - Global Licenses

Chapter 2 Initial setup 55Nortel Secure Network Access Switch 4050 User Guide 7 Specify whether you are setting up a one-armed or a two-armed configur

Page 502 - Table 97

550 Chapter 10 Configuring system settings320818-A • RSA and DSA keys — the SECSH Public Key File Format, as described in Internet Draft draft-ietf-se

Page 503 - Figure 130

Chapter 10 Configuring system settings 551Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 and known host SSH keysYou can

Page 504 - Table 98

552 Chapter 10 Configuring system settings320818-A 2 To generate the Nortel SNAS 4050 host SSH key:a Enter the host information in applicable fields.

Page 505 - Figure 131

Chapter 10 Configuring system settings 553Nortel Secure Network Access Switch 4050 User Guide Adding an SSH key for a known host using the SREMYou can

Page 506 - END LICENSE lines

554 Chapter 10 Configuring system settings320818-A 2 Enter the remote host information in the applicable fields. Table 115 describes the Add SSH Key f

Page 507 - Install New License

Chapter 10 Configuring system settings 555Nortel Secure Network Access Switch 4050 User Guide When you add an external RADIUS audit server to the conf

Page 508 - Interfaces

556 Chapter 10 Configuring system settings320818-A Configuring RADIUS auditingTo configure the Nortel SNAS 4050 to support RADIUS auditing, choose fro

Page 509 - Adding a host interface

Chapter 10 Configuring system settings 557Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS audit settings using the SREMTo confi

Page 510

558 Chapter 10 Configuring system settings320818-A describes the Add Audit Configuration fields.3 Click Apply on the toolbar to send the current chang

Page 511

Chapter 10 Configuring system settings 559Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS audit servers using the SREMTo manage RA

Page 512 - Table 100

56 Chapter 2 Initial setup320818-A used if no other interface is specified. The default gateway IP address on Interface 2 must be within the same subn

Page 513 - Interface fields (continued)

560 Chapter 10 Configuring system settings320818-A Adding a new Audit ServerTo add a new RADIUS audit server, perform the following steps:1 Select the

Page 514 - Removing a host interface

Chapter 10 Configuring system settings 561Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS audit serverTo remove an exi

Page 515 - Figure 136

562 Chapter 10 Configuring system settings320818-A Managing RADIUS authentication of system users using the SREMYou can configure the Nortel SNAS 4050

Page 516

Chapter 10 Configuring system settings 563Nortel Secure Network Access Switch 4050 User Guide Configuring RADIUS authentication of system users using

Page 517 - Managing static routes

564 Chapter 10 Configuring system settings320818-A 2 Enter the RADIUS authentication information in the applicable fields. Table 118 describes the Rad

Page 518 - Adding a static route

Chapter 10 Configuring system settings 565Nortel Secure Network Access Switch 4050 User Guide Managing RADIUS authentication servers using the SREMTo

Page 519 - Removing a static route

566 Chapter 10 Configuring system settings320818-A Adding a RADIUS authentication serverTo add a new RADIUS authentication server, perform the followi

Page 520 - Figure 140

Chapter 10 Configuring system settings 567Nortel Secure Network Access Switch 4050 User Guide Removing an existing RADIUS serverTo remove an existing

Page 521 - Figure 141

568 Chapter 10 Configuring system settings320818-A

Page 522 - Table 102

569Nortel Secure Network Access Switch 4050 User Guide Chapter 11 Managing certificatesThis chapter includes the following topics:Topic PageOverview57

Page 523

Chapter 2 Initial setup 57Nortel Secure Network Access Switch 4050 User Guide 12 Configure the time settings.13 Specify the NTP server, if applicable.

Page 524 - Removing interface ports

570 Chapter 11 Managing certificates320818-A OverviewTo use the encryption capabilities of the Nortel SNAS 4050, you must add a key and certificate th

Page 525

Chapter 11 Managing certificates 571Nortel Secure Network Access Switch 4050 User Guide You can install new certificates or import or renew existing c

Page 526 - Adding an access list entry

572 Chapter 11 Managing certificates320818-A Netscape Enterprise ServerYes No Key only (proprietary format). Requires conversion. For information abou

Page 527 - Removing an Access List entry

Chapter 11 Managing certificates 573Nortel Secure Network Access Switch 4050 User Guide Creating certificatesThe basic steps to create a new certifica

Page 528 - Date & Time

574 Chapter 11 Managing certificates320818-A If you use the certificate index number of an installed certificate when adding a new certificate, the in

Page 529 - Date & Time fields

Chapter 11 Managing certificates 575Nortel Secure Network Access Switch 4050 User Guide The recommended steps to update an existing certificate are:1

Page 530 - Adding an NTP server

576 Chapter 11 Managing certificates320818-A • import certificates and private keys (see “Importing certificates and keys into the Nortel SNAS 4050 us

Page 531 - Removing an NTP server

Chapter 11 Managing certificates 577Nortel Secure Network Access Switch 4050 User Guide Managing and viewing certificates and keys using the CLITo vie

Page 532 - Figure 147

578 Chapter 11 Managing certificates320818-A gensigned server|clientGenerates a certificate that is signed using the private key associated with the c

Page 533 - Table 107

Chapter 11 Managing certificates 579Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the CLITo prepare a CSR

Page 534 - Managing syslog servers

58 Chapter 2 Initial setup320818-A 16 Change the admin user password, if desired.Make sure you remember the password you define for the admin user. Yo

Page 535 - Adding a new syslog server

580 Chapter 11 Managing certificates320818-A • to generate a CSR for a new certificate, <cert id> is an unused certificate number• to generate a

Page 536

Chapter 11 Managing certificates 581Nortel Secure Network Access Switch 4050 User Guide 3 Generate the CSR.After you have provided the required inform

Page 537

582 Chapter 11 Managing certificates320818-A Figure 166 shows sample output for the /cfg/cert #/request command. For more information about the Certif

Page 538 - Adding a DNS server

Chapter 11 Managing certificates 583Nortel Secure Network Access Switch 4050 User Guide 5 Save the CSR to a file.a Copy the entire CSR, including the

Page 539

584 Chapter 11 Managing certificates320818-A 8 The CA processes the CSR and returns a signed certificate. Create a backup copy of the certificate (see

Page 540 - Managing RSA servers

Chapter 11 Managing certificates 585Nortel Secure Network Access Switch 4050 User Guide To verify that the current certificate number is not in use by

Page 541 - Adding an RSA server

586 Chapter 11 Managing certificates320818-A Figure 167 shows sample output for the /cfg/cert #/cert command. For more information about the Certifica

Page 542 - Removing the RSA node secret

Chapter 11 Managing certificates 587Nortel Secure Network Access Switch 4050 User Guide Adding a private key to the Nortel SNAS 4050 using the CLI1 Ac

Page 543 - RSA Server fields

588 Chapter 11 Managing certificates320818-A Figure 168 shows sample output for the /cfg/cert #/key command. For more information about the Certificat

Page 544 - Importing sdconf.rec

Chapter 11 Managing certificates 589Nortel Secure Network Access Switch 4050 User Guide To import a certificate and private key into the Nortel SNAS 4

Page 545 - Figure 155

Chapter 2 Initial setup 59Nortel Secure Network Access Switch 4050 User Guide For example, if you entered company.com in the DNS search list, users ca

Page 546 - Import sdconf.rec fields

590 Chapter 11 Managing certificates320818-A 4 If the private key was not included in the certificate file, repeat step 3 on page 589 to import the ke

Page 547 - SRS Control Settings

Chapter 11 Managing certificates 591Nortel Secure Network Access Switch 4050 User Guide Displaying or saving a certificate and key using the CLIYou ca

Page 548 - Add SSH Key fields

592 Chapter 11 Managing certificates320818-A 5 Copy the private key, certificate, or both, as required.For the private key, ensure that you include th

Page 549 - Showing SSH keys

Chapter 11 Managing certificates 593Nortel Secure Network Access Switch 4050 User Guide Figure 170 shows sample output for the /cfg/cert #/display com

Page 550

594 Chapter 11 Managing certificates320818-A Exporting a certificate and key from the Nortel SNAS 4050 using the CLIYou can export certificate files a

Page 551 - SSH Keys – Hosts

Chapter 11 Managing certificates 595Nortel Secure Network Access Switch 4050 User Guide Export format The key and certificate format in which you want

Page 552 - SSH Keys Hosts field

596 Chapter 11 Managing certificates320818-A Figure 171 shows sample output for the /cfg/cert #/export command. For more information about the Certifi

Page 553 - Add SSH Key

Chapter 11 Managing certificates 597Nortel Secure Network Access Switch 4050 User Guide You are prompted to enter the following parameters. The combin

Page 554

598 Chapter 11 Managing certificates320818-A Viewing certificates using the SREMTo view basic information about all certificates configured for the No

Page 555 - NSNAS-SSL-Audit-Trail)

Chapter 11 Managing certificates 599Nortel Secure Network Access Switch 4050 User Guide 3 Click Yes.The certificate is removed from the Certificates l

Page 556

6 Contents320818-A Management IP address . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51Portal Virtual IP addres

Page 557 - Figure 160

60 Chapter 2 Initial setup320818-A The action to be performed when the TunnelGuard check fails depends on your selection in step f on page 59.Settings

Page 558 - Table 116

600 Chapter 11 Managing certificates320818-A 5 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the too

Page 559 - Audit Servers

Chapter 11 Managing certificates 601Nortel Secure Network Access Switch 4050 User Guide Generating and submitting a CSR using the SREMTo generate a CS

Page 560 - Adding a new Audit Server

602 Chapter 11 Managing certificates320818-A 2 Enter the certificate information in the applicable fields.Table 125 describes the CA Request fields.Ta

Page 561

Chapter 11 Managing certificates 603Nortel Secure Network Access Switch 4050 User Guide 3 Click Apply on the toolbar to send the information to the No

Page 562

604 Chapter 11 Managing certificates320818-A To import a certificate and private key into the Nortel SNAS 4050, perform the following steps.1 Upload t

Page 563 - Figure 163

Chapter 11 Managing certificates 605Nortel Secure Network Access Switch 4050 User Guide 3 Enter the import information in the applicable fields. Table

Page 564 - Table 118

606 Chapter 11 Managing certificates320818-A To display the current certificate and key or save a copy, perform the following steps:1 Select the Certi

Page 565 - Radius Server Table

Chapter 11 Managing certificates 607Nortel Secure Network Access Switch 4050 User Guide 2 If you want to encrypt the key, specify a password in the ap

Page 566 - Add Radius Server fields

608 Chapter 11 Managing certificates320818-A To export a certificate and key from the Nortel SNAS 4050, perform the following steps.1 Select the Certi

Page 567

Chapter 11 Managing certificates 609Nortel Secure Network Access Switch 4050 User Guide 2 Enter the export information in the applicable fields. Table

Page 568

Chapter 2 Initial setup 61Nortel Secure Network Access Switch 4050 User Guide The profiles determine the VLAN to which the user will be allocated. Tab

Page 569 - Managing certificates

610 Chapter 11 Managing certificates320818-A 3 Click Apply on the toolbar to export the certificate.The certificate and private key are immediately ex

Page 570

Chapter 11 Managing certificates 611Nortel Secure Network Access Switch 4050 User Guide The Configuration screen appears (see Figure 172).Figure 178

Page 571 - Key and certificate formats

612 Chapter 11 Managing certificates320818-A Viewing general informationTo view basic information about a certificate on the Nortel SNAS 4050 cluster,

Page 572

Chapter 11 Managing certificates 613Nortel Secure Network Access Switch 4050 User Guide The Info screen appears (see Figure 179).Figure 179 Info scr

Page 573 - Creating certificates

614 Chapter 11 Managing certificates320818-A Viewing certificate subject settingsTo view subject settings for a certificate on the Nortel SNAS 4050 cl

Page 574 - Updating certificates

Chapter 11 Managing certificates 615Nortel Secure Network Access Switch 4050 User Guide The Subject screen appears (see Figure 180).Figure 180 Subje

Page 575

616 Chapter 11 Managing certificates320818-A Organization The registered name of the organization. The organization must own the domain name that appe

Page 576

617Nortel Secure Network Access Switch 4050 User Guide Chapter 12 Configuring SNMPThis chapter includes the following topics:Topic PageConfiguring SNM

Page 577

618 Chapter 12 Configuring SNMP320818-A Simple Network Management Protocol (SNMP) is a set of protocols for managing complex networks. SNMP works by s

Page 578

Chapter 12 Configuring SNMP 619Nortel Secure Network Access Switch 4050 User Guide • SNMP monitors and events (see “Configuring SNMP events using the

Page 579

62 Chapter 2 Initial setup320818-A Before you beginLog on to the existing Nortel SNAS 4050 device to check the software version and system settings. U

Page 580

620 Chapter 12 Configuring SNMP320818-A Configuring SNMP settings using the CLITo configure SNMP management of the Nortel SNAS 4050 cluster, use the f

Page 581

Chapter 12 Configuring SNMP 621Nortel Secure Network Access Switch 4050 User Guide Configuring the SNMP v2 MIB using the CLITo configure parameters in

Page 582 - Figure 166

622 Chapter 12 Configuring SNMP320818-A The SNMPv2-MIB menu includes the following options:Configuring the SNMP community using the CLITo configure th

Page 583

Chapter 12 Configuring SNMP 623Nortel Secure Network Access Switch 4050 User Guide Configuring SNMPv3 users using the CLIThe Nortel SNAS 4050 manages

Page 584

624 Chapter 12 Configuring SNMP320818-A • set — USM user is authorized to perform SNMP set requests (write access to the MIB). Write access automatica

Page 585

Chapter 12 Configuring SNMP 625Nortel Secure Network Access Switch 4050 User Guide The SNMP User menu includes the following options:/cfg/sys/adm/snmp

Page 586

626 Chapter 12 Configuring SNMP320818-A Configuring SNMP notification targets using the CLISNMP managers function as the notification targets for SNMP

Page 587

Chapter 12 Configuring SNMP 627Nortel Secure Network Access Switch 4050 User Guide The Notification Target menu includes the following options:Configu

Page 588

628 Chapter 12 Configuring SNMP320818-A The event menu includes the following options:/cfg/sys/adm/snmp/eventfollowed by:addmonitor [<options>]

Page 589

Chapter 12 Configuring SNMP 629Nortel Secure Network Access Switch 4050 User Guide addmonitor [<options>] -t <name> <OID> <value

Page 590

Chapter 2 Initial setup 63Nortel Secure Network Access Switch 4050 User Guide • To change the version on the existing NSNAS, download the desired soft

Page 591

630 Chapter 12 Configuring SNMP320818-A addmonitor [<options>] -x <name> <OID> [present|absent|changed]Adds an existence monitor and

Page 592

Chapter 12 Configuring SNMP 631Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP settings using the SREMThis section contains infor

Page 593 - Figure 170

632 Chapter 12 Configuring SNMP320818-A Configuring SNMP using the SREMTo configure SNMP, perform the following steps:1 Select the System > Adminis

Page 594 - Parameter Description

Chapter 12 Configuring SNMP 633Nortel Secure Network Access Switch 4050 User Guide 2 Enter the SNMP Configuration information in the applicable fields

Page 595

634 Chapter 12 Configuring SNMP320818-A Configuring SNMP targets using the SREMSNMP managers function as the notification targets for SNMP monitoring.

Page 596

Chapter 12 Configuring SNMP 635Nortel Secure Network Access Switch 4050 User Guide Adding SNMP targetsTo add an SNMP target, perform the following ste

Page 597

636 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMP Target dialog box appears (see Figure 183).Figure 183 Add SNMP Target

Page 598 - Certificates screen

Chapter 12 Configuring SNMP 637Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMP target information in the applicable fields. Table

Page 599 - Add a Certificate Component

638 Chapter 12 Configuring SNMP320818-A Managing SNMP targetsTo manage SNMP targets, perform the following steps:1 Select the System > Administrati

Page 600

Chapter 12 Configuring SNMP 639Nortel Secure Network Access Switch 4050 User Guide 2 Modify the SNMP Target information in the applicable fields. Tabl

Page 601 - Figure 174

64 Chapter 2 Initial setup320818-A In a one-armed configuration, you are specifying the port you want to use for all network connectivity, since Inter

Page 602 - Table 125

640 Chapter 12 Configuring SNMP320818-A A dialog box appears asking for confirmation.4 Click Yes.5 Click Apply on the toolbar to send the current chan

Page 603

Chapter 12 Configuring SNMP 641Nortel Secure Network Access Switch 4050 User Guide Adding SNMPv3 usersTo add an SNMPv3 user, perform the following ste

Page 604 - Import Certificate screen

642 Chapter 12 Configuring SNMP320818-A 2 Click Add. The Add SNMPv3 User dialog box appears (see Figure 186).Figure 186 Add SNMPv3 User

Page 605

Chapter 12 Configuring SNMP 643Nortel Secure Network Access Switch 4050 User Guide 3 Enter the SNMPv3 User information in the applicable fields. Table

Page 606 - Figure 176

644 Chapter 12 Configuring SNMP320818-A 4 Click Apply. The new SNMPv3 user appears in the table.5 Click Apply on the toolbar to send the current chang

Page 607 - Display Certificates fields

Chapter 12 Configuring SNMP 645Nortel Secure Network Access Switch 4050 User Guide 2 Modify SNMPv3 User information in the applicable fields, as requi

Page 608 - Figure 177

646 Chapter 12 Configuring SNMP320818-A 3 Click Apply on the toolbar to send the current changes to the Nortel SNAS 4050. Click Commit on the toolbar

Page 609 - Table 128

Chapter 12 Configuring SNMP 647Nortel Secure Network Access Switch 4050 User Guide Configuring SNMP events using the SREMSNMP events can be added to m

Page 610 - Viewing configuration details

648 Chapter 12 Configuring SNMP320818-A Adding monitor eventsTo add monitor events, perform the following steps:1 Select the System > Administrativ

Page 611 - Table 129

Chapter 12 Configuring SNMP 649Nortel Secure Network Access Switch 4050 User Guide 2 Click Add.The Add a Monitor dialog box appears. Depending on the

Page 612 - Viewing general information

Chapter 2 Initial setup 65Nortel Secure Network Access Switch 4050 User Guide 8 Configure the interface for client portal traffic (Interface 2).a Spec

Page 613 - Table 130

650 Chapter 12 Configuring SNMP320818-A Depending on the type of monitor selected, the fields displayed on the Configuration tab will change. For desc

Page 614 - Table 130 Info fields

Chapter 12 Configuring SNMP 651Nortel Secure Network Access Switch 4050 User Guide Figure 189 Add a Monitor: BooleanFields used to add and configure

Page 615 - Table 131

652 Chapter 12 Configuring SNMP320818-A For details on adding a Boolean monitor, see “Adding monitor events” on page 648.Threshold monitorsThreshold m

Page 616 - Table 131 Subject fields

Chapter 12 Configuring SNMP 653Nortel Secure Network Access Switch 4050 User Guide Fields used to add and configure a Threshold monitor are listed in

Page 617 - Configuring SNMP

654 Chapter 12 Configuring SNMP320818-A Existence monitorsExistence monitors check the condition of a monitored OID to see determine if it is present,

Page 618 - /cfg/sys/adm/snmp

Chapter 12 Configuring SNMP 655Nortel Secure Network Access Switch 4050 User Guide For details on adding a Existence monitor, see “Adding monitor even

Page 619 - Roadmap of SNMP commands

656 Chapter 12 Configuring SNMP320818-A Adding notification eventsTo add notification events, perform the following steps:1 Select the System > Adm

Page 620

Chapter 12 Configuring SNMP 657Nortel Secure Network Access Switch 4050 User Guide 2 Click Add. The Add a Notification Event dialog box appears (see F

Page 621 - The SNMPv2-MIB menu displays

658 Chapter 12 Configuring SNMP320818-A Removing notification eventsTo delete a notification event, perform the following steps:1 Select the System &g

Page 622

659Nortel Secure Network Access Switch 4050 User Guide Chapter 13 Viewing system information and performance statisticsThis chapter includes the follo

Page 623

66 Chapter 2 Initial setup320818-A 12 Wait while the Setup utility finishes processing. When processing is complete, you will see Setup successful.The

Page 624

660 Chapter 13 Viewing system information and performance statistics320818-A Viewing system information and performance statistics using the CLITo vie

Page 625

Chapter 13 Viewing system information and performance statistics 661Nortel Secure Network Access Switch 4050 User Guide Viewing system information usi

Page 626

662 Chapter 13 Viewing system information and performance statistics320818-A The Information menu includes the following options:/infofollowed by:cert

Page 627

Chapter 13 Viewing system information and performance statistics 663Nortel Secure Network Access Switch 4050 User Guide kick <domain ID> <use

Page 628

664 Chapter 13 Viewing system information and performance statistics320818-A mac <MACaddr>Displays session information for a client based on a s

Page 629

Chapter 13 Viewing system information and performance statistics 665Nortel Secure Network Access Switch 4050 User Guide localDisplays the current soft

Page 630

666 Chapter 13 Viewing system information and performance statistics320818-A Viewing alarm events using the CLITo view active alarms, use the followin

Page 631

Chapter 13 Viewing system information and performance statistics 667Nortel Secure Network Access Switch 4050 User Guide Viewing log files using the CL

Page 632 - Figure 181

668 Chapter 13 Viewing system information and performance statistics320818-A The CLI reports statistics for all authentication methods configured in t

Page 633 - Table 132

Chapter 13 Viewing system information and performance statistics 669Nortel Secure Network Access Switch 4050 User Guide Figure 194 shows sample output

Page 634

Chapter 2 Initial setup 67Nortel Secure Network Access Switch 4050 User Guide 3 To finish connecting the Nortel SNAS 4050 to the rest of the network,

Page 635 - Adding SNMP targets

670 Chapter 13 Viewing system information and performance statistics320818-A Viewing all statistics using the CLITo view all available statistics for

Page 636 - Figure 183

Chapter 13 Viewing system information and performance statistics 671Nortel Secure Network Access Switch 4050 User Guide The Information screen appears

Page 637 - SNMP Target fields

672 Chapter 13 Viewing system information and performance statistics320818-A Viewing cluster information using the SREMTo view cluster information, se

Page 638 - Managing SNMP targets

Chapter 13 Viewing system information and performance statistics 673Nortel Secure Network Access Switch 4050 User Guide Viewing the controller list us

Page 639 - Removing SNMP targets

674 Chapter 13 Viewing system information and performance statistics320818-A Table 143 describes the Controller List fields. Table 143 Controller Li

Page 640

Chapter 13 Viewing system information and performance statistics 675Nortel Secure Network Access Switch 4050 User Guide Viewing SONMP topology informa

Page 641 - Adding SNMPv3 users

676 Chapter 13 Viewing system information and performance statistics320818-A Table 144 describes the SONMP State fields. Table 144 SONMP State field

Page 642 - Figure 186

Chapter 13 Viewing system information and performance statistics 677Nortel Secure Network Access Switch 4050 User Guide Viewing switch distribution us

Page 643 - Table 135

678 Chapter 13 Viewing system information and performance statistics320818-A Table 145 describes the Switch Distribution fields. Viewing port informat

Page 644 - Managing SNMPv3 users

Chapter 13 Viewing system information and performance statistics 679Nortel Secure Network Access Switch 4050 User Guide To view port information, sele

Page 645 - Table 136

68 Chapter 2 Initial setup320818-A Applying and saving the configuration using the CLIIf you have not already done so after each sequence of configura

Page 646 - Removing SNMPv3 users

680 Chapter 13 Viewing system information and performance statistics320818-A Viewing license information using the SREMYou can view information about

Page 647 - Managing monitor events

Chapter 13 Viewing system information and performance statistics 681Nortel Secure Network Access Switch 4050 User Guide Viewing global license informa

Page 648 - Adding monitor events

682 Chapter 13 Viewing system information and performance statistics320818-A Table 147 describes the Global Licenses fields. Table 147 Global Licens

Page 649 - Add a Monitor fields

Chapter 13 Viewing system information and performance statistics 683Nortel Secure Network Access Switch 4050 User Guide Viewing license information fo

Page 650 - Boolean monitors

684 Chapter 13 Viewing system information and performance statistics320818-A Table 148 describes the Per Domain Licenses fields. Viewing session detai

Page 651 - Table 138

Chapter 13 Viewing system information and performance statistics 685Nortel Secure Network Access Switch 4050 User Guide Viewing active sessions using

Page 652 - Threshold monitors

686 Chapter 13 Viewing system information and performance statistics320818-A Table 149 describes the Sessions parameters. Table 149 Sessions paramet

Page 653 - Table 139

Chapter 13 Viewing system information and performance statistics 687Nortel Secure Network Access Switch 4050 User Guide Viewing details for a particul

Page 654 - Existence monitors

688 Chapter 13 Viewing system information and performance statistics320818-A Table 150 describes the Session Properties parameters. Ending active user

Page 655 - Managing notification events

Chapter 13 Viewing system information and performance statistics 689Nortel Secure Network Access Switch 4050 User Guide Figure 204 KickOut User scre

Page 656 - Adding notification events

Chapter 2 Initial setup 69Nortel Secure Network Access Switch 4050 User Guide Figure 3 on page 69 shows the location of the Apply and Commit buttons.F

Page 657 - Add a Notification Event

690 Chapter 13 Viewing system information and performance statistics320818-A Viewing the number of active sessions using the SREMTo view the number of

Page 658 - Removing notification events

Chapter 13 Viewing system information and performance statistics 691Nortel Secure Network Access Switch 4050 User Guide Viewing alarms using the SREMY

Page 659 - Chapter 13

692 Chapter 13 Viewing system information and performance statistics320818-A Viewing active alarms using the SREMTo view the active alarms for the Nor

Page 660

Chapter 13 Viewing system information and performance statistics 693Nortel Secure Network Access Switch 4050 User Guide Table 153 describes the Active

Page 661

694 Chapter 13 Viewing system information and performance statistics320818-A Downloading alarms using the SREMTo download an alarm as a logged event,

Page 662

Chapter 13 Viewing system information and performance statistics 695Nortel Secure Network Access Switch 4050 User Guide Table 154 describes the Downlo

Page 663

696 Chapter 13 Viewing system information and performance statistics320818-A Viewing the log list using the SREMTo view a list of all active logs, sel

Page 664

Chapter 13 Viewing system information and performance statistics 697Nortel Secure Network Access Switch 4050 User Guide Downloading log files using th

Page 665

698 Chapter 13 Viewing system information and performance statistics320818-A Viewing AAA statistics using the SREMYou can view authentication statisti

Page 666 - The Events menu displays

Chapter 13 Viewing system information and performance statistics 699Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for a h

Page 667

Contents 7Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domain . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 668

70 Chapter 2 Initial setup320818-A

Page 669 - Figure 194

700 Chapter 13 Viewing system information and performance statistics320818-A b Expand the Statistics > AAA > Host Statistics > host navigatio

Page 670

Chapter 13 Viewing system information and performance statistics 701Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Page 671 - Table 142

702 Chapter 13 Viewing system information and performance statistics320818-A Viewing RADIUS statisticsTo view RADIUS statistics, select the Radius tab

Page 672

Chapter 13 Viewing system information and performance statistics 703Nortel Secure Network Access Switch 4050 User Guide For a description of the field

Page 673 - Figure 196

704 Chapter 13 Viewing system information and performance statistics320818-A Viewing Local database statisticsTo view Local database statistics, selec

Page 674 - Table 143

Chapter 13 Viewing system information and performance statistics 705Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Page 675 - Figure 197

706 Chapter 13 Viewing system information and performance statistics320818-A For a description of the fields, seeTable 159.Table 159 LDAP statistics

Page 676 - Table 144

Chapter 13 Viewing system information and performance statistics 707Nortel Secure Network Access Switch 4050 User Guide Viewing AAA statistics for the

Page 677 - Figure 198

708 Chapter 13 Viewing system information and performance statistics320818-A •LDAPSelect one of the following tasks:• Viewing License statistics (see

Page 678 - Switch Distribution fields

Chapter 13 Viewing system information and performance statistics 709Nortel Secure Network Access Switch 4050 User Guide Viewing License statisticsTo v

Page 679 - Table 146

71Nortel Secure Network Access Switch 4050 User Guide Chapter 3 Managing the network access devicesThis chapter includes the following topics:Topic Pa

Page 680

710 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Page 681 - Figure 200

Chapter 13 Viewing system information and performance statistics 711Nortel Secure Network Access Switch 4050 User Guide Viewing RADIUS statisticsTo vi

Page 682 - Table 147

712 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Page 683 - Figure 201

Chapter 13 Viewing system information and performance statistics 713Nortel Secure Network Access Switch 4050 User Guide Viewing Local database statist

Page 684 - Per Domain Licenses fields

714 Chapter 13 Viewing system information and performance statistics320818-A Logging Enables or disables statistics logging in the specified location.

Page 685 - Sessions screen

Chapter 13 Viewing system information and performance statistics 715Nortel Secure Network Access Switch 4050 User Guide Viewing LDAP statisticsTo view

Page 686 - Table 149

716 Chapter 13 Viewing system information and performance statistics320818-A Viewing Ethernet statistics using the SREMYou can view statistics for the

Page 687 - Figure 203

Chapter 13 Viewing system information and performance statistics 717Nortel Secure Network Access Switch 4050 User Guide To view Ethernet interface sta

Page 688 - Ending active user sessions

718 Chapter 13 Viewing system information and performance statistics320818-A Viewing Rx statisticsTo view Rx statistics for an interface, select the R

Page 689 - Table 151

Chapter 13 Viewing system information and performance statistics 719Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Page 690 - Number of Sessions fields

72 Chapter 3 Managing the network access devices320818-A Before you beginIn Trusted Computing Group (TCG) terminology, the edge switches in a Nortel S

Page 691 - Viewing alarms using the SREM

720 Chapter 13 Viewing system information and performance statistics320818-A Viewing Tx statisticsTo view Tx statistics for an interface, select Tx St

Page 692 - Figure 206

Chapter 13 Viewing system information and performance statistics 721Nortel Secure Network Access Switch 4050 User Guide Logging Enables or disables st

Page 693 - Table 153

722 Chapter 13 Viewing system information and performance statistics320818-A

Page 694 - Figure 207

723Nortel Secure Network Access Switch 4050 User Guide Chapter 14 Maintaining and managing the systemThis chapter includes the following topics:Topic

Page 695 - Table 154

724 Chapter 14 Maintaining and managing the system320818-A You can perform the following activities to manage and maintain the system and individual N

Page 696 - Figure 208

Chapter 14 Maintaining and managing the system 725Nortel Secure Network Access Switch 4050 User Guide To manage software versions and Nortel SNAS 4050

Page 697 - Table 155

726 Chapter 14 Maintaining and managing the system320818-A Performing maintenance using the CLITo check the applied configuration and to download log

Page 698

Chapter 14 Maintaining and managing the system 727Nortel Secure Network Access Switch 4050 User Guide The Maintenance menu includes the following opti

Page 699 - The Hosts table

728 Chapter 14 Maintaining and managing the system320818-A dumpstats <protocol> <server> <filename> <all-isds?>Collects curren

Page 700

Chapter 14 Maintaining and managing the system 729Nortel Secure Network Access Switch 4050 User Guide starttrace <tags> <domain ID> <ou

Page 701 - Viewing License statistics

Chapter 3 Managing the network access devices 73Nortel Secure Network Access Switch 4050 User Guide You require the following information for each net

Page 702 - Viewing RADIUS statistics

730 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the CLITo save the system configuration to

Page 703 - Table 157

Chapter 14 Maintaining and managing the system 731Nortel Secure Network Access Switch 4050 User Guide Table 166 provides more information about the ba

Page 704 - Table 158

732 Chapter 14 Maintaining and managing the system320818-A gtcfg <protocol> <server> <filename> <passphrase>Restores a configu

Page 705 - Viewing LDAP statistics

Chapter 14 Maintaining and managing the system 733Nortel Secure Network Access Switch 4050 User Guide Managing Nortel SNAS 4050 devices using the CLIT

Page 706 - Table 159

734 Chapter 14 Maintaining and managing the system320818-A Managing software for a Nortel SNAS 4050 device using the CLITo view, download, and activat

Page 707 - The Statistics table

Chapter 14 Maintaining and managing the system 735Nortel Secure Network Access Switch 4050 User Guide The Software Management menu includes the follow

Page 708

736 Chapter 14 Maintaining and managing the system320818-A Managing and maintaining the system using the SREMPerforming maintenance using the SREMTo p

Page 709

Chapter 14 Maintaining and managing the system 737Nortel Secure Network Access Switch 4050 User Guide • “Backing up or restoring the configuration usi

Page 710

738 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Dump information in the applicable fields. Table 167 describes the Dump fields.

Page 711

Chapter 14 Maintaining and managing the system 739Nortel Secure Network Access Switch 4050 User Guide To start or stop a trace, perform the following

Page 712

74 Chapter 3 Managing the network access devices320818-A resetenadisdelete/cfg/domain #/vlan add <name> <VLAN ID>del <index>list/cfg

Page 713 - Table 162

740 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Trace information in the applicable fields. Table 168 describes the Start/Stop

Page 714

Chapter 14 Maintaining and managing the system 741Nortel Secure Network Access Switch 4050 User Guide Checking configuration using the SREMYou can che

Page 715

742 Chapter 14 Maintaining and managing the system320818-A Backing up or restoring the configuration using the SREMYou can save the current configurat

Page 716

Chapter 14 Maintaining and managing the system 743Nortel Secure Network Access Switch 4050 User Guide 2 Enter the Backup/Restore information in the ap

Page 717 - The Ethernet Interface table

744 Chapter 14 Maintaining and managing the system320818-A • “Rebooting or deleting a Nortel SNAS 4050 device using the SREM” on page 750Managing soft

Page 718 - Viewing Rx statistics

Chapter 14 Maintaining and managing the system 745Nortel Secure Network Access Switch 4050 User Guide Table 170 describes the Image List fields.The fo

Page 719

746 Chapter 14 Maintaining and managing the system320818-A Viewing details of the active software imageTo view the details of the currently active sof

Page 720 - Viewing Tx statistics

Chapter 14 Maintaining and managing the system 747Nortel Secure Network Access Switch 4050 User Guide Activating a software imageTo activate an old or

Page 721

748 Chapter 14 Maintaining and managing the system320818-A 4 When prompted, click Yes.The Nortel SNAS 4050 reboots when you confirm the Activate comma

Page 722

Chapter 14 Maintaining and managing the system 749Nortel Secure Network Access Switch 4050 User Guide To download an image from a file exchange server

Page 723 - Chapter 14

Chapter 3 Managing the network access devices 75Nortel Secure Network Access Switch 4050 User Guide Adding a network access device using the CLIYou ca

Page 724

750 Chapter 14 Maintaining and managing the system320818-A 2 Enter the Download Image information in the applicable fields. Table 171 describes the Do

Page 725

Chapter 14 Maintaining and managing the system 751Nortel Secure Network Access Switch 4050 User Guide To reboot, shut down, or reset the Nortel SNAS 4

Page 726

752 Chapter 14 Maintaining and managing the system320818-A The command resets the device to its factory default configuration. All IP configuration is

Page 727

Chapter 14 Maintaining and managing the system 753Nortel Secure Network Access Switch 4050 User Guide The File Download screen appears (see Figure 232

Page 728

754 Chapter 14 Maintaining and managing the system320818-A Running Nortel SNAS 4050 diagnostics using the SREMTo run basic diagnostics on the Nortel S

Page 729

Chapter 14 Maintaining and managing the system 755Nortel Secure Network Access Switch 4050 User Guide Table 173 describes the Diagnostics fields. Tabl

Page 730

756 Chapter 14 Maintaining and managing the system320818-A

Page 731 - Table 166

757Nortel Secure Network Access Switch 4050 User Guide Chapter 15 Upgrading or reinstalling the softwareThis chapter includes the following topics:The

Page 732

758 Chapter 15 Upgrading or reinstalling the software320818-A Major release upgrade: This kind of release may contain bug fixes as well as feature enh

Page 733 - The Boot menu displays

Chapter 15 Upgrading or reinstalling the software 759Nortel Secure Network Access Switch 4050 User Guide The set of installed Nortel SNAS 4050 devices

Page 734

76 Chapter 3 Managing the network access devices320818-A 4 Specify the TCP port for communication between the Nortel SNAS 4050 and the network access

Page 735

760 Chapter 15 Upgrading or reinstalling the software320818-A If needed, the file name can be prefixed with a search path to the directory on the TFTP

Page 736

Chapter 15 Upgrading or reinstalling the software 761Nortel Secure Network Access Switch 4050 User Guide When you have downloaded the software upgrade

Page 737

762 Chapter 15 Upgrading or reinstalling the software320818-A 5 At the Software Management# prompt, enter:6 Log in again and verify the new software v

Page 738 - Table 167

Chapter 15 Upgrading or reinstalling the software 763Nortel Secure Network Access Switch 4050 User Guide Reinstalling the softwareIf you are adding a

Page 739 - Figure 224

764 Chapter 15 Upgrading or reinstalling the software320818-A • authorization to log on as the boot userIf a software CD was shipped with the Nortel S

Page 740 - Table 168

Chapter 15 Upgrading or reinstalling the software 765Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from an external fi

Page 741 - Check Configuration

766 Chapter 15 Upgrading or reinstalling the software320818-A e Specify the default gateway IP address. 3 Specify the download details:a protocol for

Page 742 - Backup & Restore

Chapter 15 Upgrading or reinstalling the software 767Nortel Secure Network Access Switch 4050 User Guide Reinstalling the software from a CDTo reinsta

Page 743 - Backup & Restore fields

768 Chapter 15 Upgrading or reinstalling the software320818-A

Page 744 - Image List

769Nortel Secure Network Access Switch 4050 User Guide Chapter 16 The Command Line InterfaceThis chapter explains how to access the Nortel SNAS 4050 t

Page 745

Chapter 3 Managing the network access devices 77Nortel Secure Network Access Switch 4050 User Guide d To continue, go to step 7 on page 77.7 Specify t

Page 746

770 Chapter 16 The Command Line Interface320818-A When using a Telnet or SSH client to connect to a cluster of Nortel SNAS 4050 devices, always connec

Page 747 - Activating a software image

Chapter 16 The Command Line Interface 771Nortel Secure Network Access Switch 4050 User Guide RequirementsTo establish a console connection with the No

Page 748

772 Chapter 16 The Command Line Interface320818-A Establishing a Telnet connectionA Telnet connection offers the convenience of accessing the Nortel S

Page 749 - Figure 230

Chapter 16 The Command Line Interface 773Nortel Secure Network Access Switch 4050 User Guide Running TelnetOnce the IP parameters on the Nortel SNAS 4

Page 750 - Download Image fields

774 Chapter 16 The Command Line Interface320818-A Running an SSH clientConnecting to the Nortel SNAS 4050 using an SSH client is similar to connecting

Page 751 - Reboot/Delete ISD Options

Chapter 16 The Command Line Interface 775Nortel Secure Network Access Switch 4050 User Guide Accessing the Nortel SNAS 4050 clusterTo enable better No

Page 752

776 Chapter 16 The Command Line Interface320818-A Access to the Nortel SNAS 4050 CLI and settings is controlled through the use of four predefined use

Page 753 - Table 172

Chapter 16 The Command Line Interface 777Nortel Secure Network Access Switch 4050 User Guide CLI Main Menu or SetupOnce the Administrator user passwor

Page 754 - Figure 233

778 Chapter 16 The Command Line Interface320818-A If you are automatically disconnected after the specified idle timeout interval, any unapplied confi

Page 755 - Table 173

779Nortel Secure Network Access Switch 4050 User Guide Chapter 17 Configuration exampleThis chapter provides an example of a basic Nortel SNA configur

Page 756

78 Chapter 3 Managing the network access devices320818-A Manually adding a switchTo add a network access device and configure it manually, use the fol

Page 757 - Chapter 15

780 Chapter 17 Configuration example320818-A Figure 235 Basic configurationTable 176 summarizes the devices connected in this environment and their

Page 758

Chapter 17 Configuration example 781Nortel Secure Network Access Switch 4050 User Guide Table 177 summarizes the VLANs for the Ethernet Routing Switch

Page 759

782 Chapter 17 Configuration example320818-A Steps1 “Configure the network DNS server” on page 7822 “Configure the network DHCP server” on page 7833 “

Page 760 - /boot/software/cur command

Chapter 17 Configuration example 783Nortel Secure Network Access Switch 4050 User Guide Configure the network DHCP serverTo configure a DHCP scope usi

Page 761

784 Chapter 17 Configuration example320818-A 4 Enter a descriptive name to identify the new scope (see Figure 238).In this example, you are creating a

Page 762

Chapter 17 Configuration example 785Nortel Secure Network Access Switch 4050 User Guide 5 Specify the IP address range for the DHCP scope (see Figure

Page 763 - Reinstalling the software

786 Chapter 17 Configuration example320818-A 6 Select the Yes, I want to configure these options now option button on the Configure DHCP Options windo

Page 764

Chapter 17 Configuration example 787Nortel Secure Network Access Switch 4050 User Guide 7 Enter the IP address of the default gateway (see Figure 241)

Page 765

788 Chapter 17 Configuration example320818-A 8 Enter the IP address of the DNS server (see Figure 242).Figure 242 Specifying the DNS server9 Repeat

Page 766

Chapter 17 Configuration example 789Nortel Secure Network Access Switch 4050 User Guide Figure 243 shows the DHCP scopes created for use in this examp

Page 767

Chapter 3 Managing the network access devices 79Nortel Secure Network Access Switch 4050 User Guide Figure 4 Adding a switch manuallyDeleting a netw

Page 768

790 Chapter 17 Configuration example320818-A 2 Assign the VLAN port members.Since the edge switches in this example are operating in Layer 2 mode, ena

Page 769 - The Command Line Interface

Chapter 17 Configuration example 791Nortel Secure Network Access Switch 4050 User Guide 7 “Configuring the NSNA ports” on page 7928 “Enabling NSNA glo

Page 770

792 Chapter 17 Configuration example320818-A Configuring the NSNA uplink filterPassport-8310:6# config filter acl 100 create ip acl-name "dhcp&qu

Page 771 - Procedure

Chapter 17 Configuration example 793Nortel Secure Network Access Switch 4050 User Guide Configure the Ethernet Routing Switch 5510The following config

Page 772

794 Chapter 17 Configuration example320818-A Configuring SSHIn this example, the assumption is that the Nortel SNAS 4050 public key has already been u

Page 773 - Running Telnet

Chapter 17 Configuration example 795Nortel Secure Network Access Switch 4050 User Guide Configuring the login domain controller filters5510-48T(config

Page 774 - Running an SSH client

796 Chapter 17 Configuration example320818-A 3 “Adding the network access devices” on page 7984 “Mapping the VLANs” on page 8005 “Enabling the network

Page 775

Chapter 17 Configuration example 797Nortel Secure Network Access Switch 4050 User Guide Enter a password for the "admin" user: Re-enter to c

Page 776 - User access levels

798 Chapter 17 Configuration example320818-A Generate and activate the SSH key for communication with the network access devices:>> Main# cfg/do

Page 777 - Idle timeout

Chapter 17 Configuration example 799Nortel Secure Network Access Switch 4050 User Guide Adding the Ethernet Routing Switch 8300Add the switch manually

Page 778

8 Contents320818-A Configuring domain parameters using the SREM . . . . . . . . . . . . . . . . . . . . . . . . 164Additional domain configuration in

Page 779 - Configuration example

80 Chapter 3 Managing the network access devices320818-A The delete command removes the current switch from the control of the Nortel SNAS 4050 cluste

Page 780 - Table 176

800 Chapter 17 Configuration example320818-A Adding the Ethernet Routing Switch 5510Use the quick switch wizard:>> Main# cfg/domain 1/quickEnter

Page 781

Chapter 17 Configuration example 801Nortel Secure Network Access Switch 4050 User Guide >> Domain Vlan# applyChanges applied successfully.Enabli

Page 782

802 Chapter 17 Configuration example320818-A

Page 783 - Creating a new DHCP scope

803Nortel Secure Network Access Switch 4050 User Guide Appendix ACLI referenceThe command line interface (CLI) allows you to view system information a

Page 784 - Naming the new DHCP scope

804 Appendix A CLI reference320818-A Using the CLICLI commands are grouped into a series of menus and submenus (see “CLI Main Menu” on page 812). Each

Page 785 - Figure 239

Appendix A CLI reference 805Nortel Secure Network Access Switch 4050 User Guide pasteRestores a saved configuration that includes private keys. TIP: B

Page 786 - Figure 240

806 Appendix A CLI reference320818-A Command line history and editingYou can use the CLI to retrieve and modify commands entered previously. Table 180

Page 787 - Figure 241

Appendix A CLI reference 807Nortel Secure Network Access Switch 4050 User Guide CLI shortcutsYou can use the following CLI command shortcuts:• “Comman

Page 788 - Specifying the DNS server

808 Appendix A CLI reference320818-A You can also use command stacking to proceed one or more levels in the menu system, and go directly to another su

Page 789

Appendix A CLI reference 809Nortel Secure Network Access Switch 4050 User Guide • To display the active menu:— Ensure that the command line is blank.—

Page 790

Chapter 3 Managing the network access devices 81Nortel Secure Network Access Switch 4050 User Guide The Switch menu includes the following options:/cf

Page 791 - Configuring the VoIP VLANs

810 Appendix A CLI reference320818-A If you use the cur command without the sys submenu argument, information related to the Configuration menu and al

Page 792 - Enabling NSNA globally

Appendix A CLI reference 811Nortel Secure Network Access Switch 4050 User Guide • 255.255.255.0 it can also be expressed as 24• 255.255.255.255 it can

Page 793 - Setting the switch IP address

812 Appendix A CLI reference320818-A CLI Main MenuThe Main menu appears after a successful connection and login. Figure 244 represents the Main menu a

Page 794 - Configuring SSH

Appendix A CLI reference 813Nortel Secure Network Access Switch 4050 User Guide • Maintenance — used for sending technical support information to an e

Page 795

814 Appendix A CLI reference320818-A Information menuThe Information menu contains commands used to display current information about the Nortel SNAS

Page 796 - Performing initial setup

Appendix A CLI reference 815Nortel Secure Network Access Switch 4050 User Guide Statistics menuThe Statistics menu contains commands used to view stat

Page 797 - Completing initial setup

816 Appendix A CLI reference320818-A Configuration menuThe Configuration menu contains commands used to configure the Nortel SNAS 4050. Table 184 list

Page 798

Appendix A CLI reference 817Nortel Secure Network Access Switch 4050 User Guide /cfg/domain <domain ID>name <name>pvips <IPaddr>aaas

Page 799 - Switch 8300:

818 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/ldapserverssearchbase <DN>groupattr <names>userattr <names>isdbinddn &

Page 800 - Mapping the VLANs

Appendix A CLI reference 819Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/auth #/localadd <user name> <password> &

Page 801

82 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the CLIThe VLANs are configured on the network access devices. You sp

Page 802

820 Appendix A CLI reference320818-A /cfg/domain #/aaa/auth #/radius/sessiontimvendorid <vendor ID>vendortype <vendor type>enadisConfigure

Page 803 - CLI reference

Appendix A CLI reference 821Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/aaa/group #/extend #/linksetlistdel <index number>

Page 804 - Using the CLI

822 Appendix A CLI reference320818-A /cfg/domain #/aaa/tg quickrecheck <interval>heartbeat <interval>hbretrycnt <count>status-quo on

Page 805

Appendix A CLI reference 823Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/linkset <linkset ID>name <name>text <text

Page 806

824 Appendix A CLI reference320818-A /cfg/domain #/portal/colorscolor1 <code>color2 <code>color3 <code>color4 <code>theme defa

Page 807 - CLI shortcuts

Appendix A CLI reference 825Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/server/adv/traflogsysloghost <IPaddr>udpport <p

Page 808 - Tab completion

826 Appendix A CLI reference320818-A /cfg/domain #/switch <switch ID>name <name>type ERS8300|ERS5500ip <IPaddr>port <port>hlth

Page 809

Appendix A CLI reference 827Nortel Secure Network Access Switch 4050 User Guide /cfg/domain #/vlan add <name> <VLAN ID>del <index>li

Page 810 - Network masks

828 Appendix A CLI reference320818-A /cfg/sys/accesslist listdel <index number>add <IPaddr> <mask>Manage the Access List in order to

Page 811 - Variables

Appendix A CLI reference 829Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/auth/serverslistdel <index number>add <IPaddr>

Page 812 - CLI command reference

Chapter 3 Managing the network access devices 83Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 maintains separate maps for t

Page 813 - Appendix A CLI reference 813

830 Appendix A CLI reference320818-A /cfg/sys/adm/snmp/eventaddmonitor [<options>] -b <name> <OID> <op> <value>addmonito

Page 814 - Information menu

Appendix A CLI reference 831Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/adm/snmp/users <user ID>name <name>seclevel none|

Page 815 - Statistics menu

832 Appendix A CLI reference320818-A /cfg/sys/dns/servers listdel <index number>add <IPaddr> insert <index number> <IPaddr>mov

Page 816 - Configuration menu

Appendix A CLI reference 833Nortel Secure Network Access Switch 4050 User Guide /cfg/sys/host <host ID>ip <IPaddr>sysName <name>sysL

Page 817

834 Appendix A CLI reference320818-A /cfg/sys/time date <date>time <time>tzonentpConfigure date and time settings for the cluster.page 475

Page 818

Appendix A CLI reference 835Nortel Secure Network Access Switch 4050 User Guide Boot menuThe Boot menu contains commands for management of Nortel SNAS

Page 819

836 Appendix A CLI reference320818-A Maintenance menuThe Maintenance menu contains commands used to perform maintenance and management activities for

Page 820

837Nortel Secure Network Access Switch 4050 User Guide Chapter 18 TroubleshootingThis chapter includes the following topics:Troubleshooting tipsThis c

Page 821

838 Chapter 18 Troubleshooting320818-A Cannot connect to the Nortel SNAS 4050 using Telnet or SSHVerify the current configurationConnect with a consol

Page 822

Chapter 18 Troubleshooting 839Nortel Secure Network Access Switch 4050 User Guide When Telnet or SSH access is enabled, only those hosts listed in the

Page 823

84 Chapter 3 Managing the network access devices320818-A Managing SSH keys using the CLIThe Nortel SNAS 4050 and the network access devices controlled

Page 824

840 Chapter 18 Troubleshooting320818-A Ensure that you ping the host IP address (RIP) of the Nortel SNAS 4050, and not the Management IP address (MIP)

Page 825

Chapter 18 Troubleshooting 841Nortel Secure Network Access Switch 4050 User Guide Cannot add the Nortel SNAS 4050 to a clusterWhen you try to add a No

Page 826

842 Chapter 18 Troubleshooting320818-A The problem may be that there are existing entries in the Access List. When Telnet or SSH access is enabled, on

Page 827

Chapter 18 Troubleshooting 843Nortel Secure Network Access Switch 4050 User Guide The Nortel SNAS 4050 stops respondingTelnet or SSH connection to the

Page 828

844 Chapter 18 Troubleshooting320818-A If the operational status of the Nortel SNAS 4050 is still down, reboot the machine. On the device, press the P

Page 829

Chapter 18 Troubleshooting 845Nortel Secure Network Access Switch 4050 User Guide Boot user passwordThe default Boot user password cannot be changed,

Page 830

846 Chapter 18 Troubleshooting320818-A For more information about the starttrace command, the tags you can specify for the trace, and the available ou

Page 831

Chapter 18 Troubleshooting 847Nortel Secure Network Access Switch 4050 User Guide System diagnosticsThe following are useful diagnostic display comman

Page 832

848 Chapter 18 Troubleshooting320818-A To check network settings for a specific Nortel SNAS 4050, access the Cluster Host menu by typing the following

Page 833

Chapter 18 Troubleshooting 849Nortel Secure Network Access Switch 4050 User Guide To capture and analyze TCP traffic between clients and the virtual S

Page 834

Chapter 3 Managing the network access devices 85Nortel Secure Network Access Switch 4050 User Guide If you regenerate the key at any time, you must re

Page 835 - Boot menu

850 Chapter 18 Troubleshooting320818-A server you specify. The information can then be used for technical support purposes. The file sent to the TFTP/

Page 836 - Maintenance menu

851Nortel Secure Network Access Switch 4050 User Guide Appendix BSyslog messagesThis appendix contains a list of the syslog messages that are sent fro

Page 837 - Troubleshooting

852 Appendix B Syslog messages320818-A Operating system (OS) messagesThere are three categories of operating system (OS) system messages:• EMERG (see

Page 838 - Check the Access List

Appendix B Syslog messages 853Nortel Secure Network Access Switch 4050 User Guide Table 190 lists the operating system EMERG messages.System Control P

Page 839

854 Appendix B Syslog messages320818-A Table 191 lists the System Control Process INFO messages.About alarm messagesAlarms are sent at a syslog level

Page 840

Appendix B Syslog messages 855Nortel Secure Network Access Switch 4050 User Guide Table 193 lists the System Control Process ALARM messages. To simpli

Page 841 - Cannot contact the MIP

856 Appendix B Syslog messages320818-A About event messagesEvents are sent at the NOTICE syslog level. Event messages are formatted according to the f

Page 842

Appendix B Syslog messages 857Nortel Secure Network Access Switch 4050 User Guide Traffic Processing Subsystem messagesThere are four categories of Tr

Page 843 - Console connection

858 Appendix B Syslog messages320818-A css error: <reason> ERROR Problem encountered when parsing a style sheet. The problem could be in the Nor

Page 844 - A user password is lost

Appendix B Syslog messages 859Nortel Secure Network Access Switch 4050 User Guide Table 197 lists the Traffic Processing WARNING messages.socks error:

Page 845 - Trace tools

86 Chapter 3 Managing the network access devices320818-A The NSNAS SSH key menu includes the following options:/cfg/domain #/sshkeyfollowed by:generat

Page 846

860 Appendix B Syslog messages320818-A Table 198 lists the Traffic Processing INFO messages.Start-up messagesThe Traffic Processing Subsystem Start-up

Page 847 - System diagnostics

Appendix B Syslog messages 861Nortel Secure Network Access Switch 4050 User Guide Table 199 lists the Start-up INFO messages.AAA subsystem messagesThe

Page 848

862 Appendix B Syslog messages320818-A Table 201 lists the AAA INFO messages. INFO messages are generated only if the CLI command /cfg/domain #/adv/lo

Page 849 - Error log files

Appendix B Syslog messages 863Nortel Secure Network Access Switch 4050 User Guide NSNAS subsystem messagesThere are two categories of NSNAS subsystem

Page 850

864 Appendix B Syslog messages320818-A Table 202 lists the NSNAS ERROR messages.Table 203 lists the NSNAS INFO messages.Table 202 NSNAS — ERRORMessa

Page 851 - Syslog messages

Appendix B Syslog messages 865Nortel Secure Network Access Switch 4050 User Guide Syslog messages in alphabetical orderTable 204 lists the syslog mess

Page 852

866 Appendix B Syslog messages320818-A audit EVENT System Control Sent when a CLI system administrator enters, enters, exits or updates the CLI if aud

Page 853

Appendix B Syslog messages 867Nortel Secure Network Access Switch 4050 User Guide copy_software_release_failed ALARM (CRITICAL)System Control A Nortel

Page 854 - About alarm messages

868 Appendix B Syslog messages320818-A gzip warning: <reason> INFO Traffic ProcessingProblem encountered when processing compressed content.HC:

Page 855 - Table 193

Appendix B Syslog messages 869Nortel Secure Network Access Switch 4050 User Guide isd_down ALARM (CRITICAL)System Control A member of the Nortel SNAS

Page 856 - About event messages

Chapter 3 Managing the network access devices 87Nortel Secure Network Access Switch 4050 User Guide Figure 5 shows sample output for the /cfg/domain #

Page 857

870 Appendix B Syslog messages320818-A make_software_release_permanent_failedALARM (CRITICAL)System Control Failed to make a new software release perm

Page 858

Appendix B Syslog messages 871Nortel Secure Network Access Switch 4050 User Guide NSNAS LoginSucceeded Domain=”<id>” Method=<”ssl”> SrcIp=

Page 859

872 Appendix B Syslog messages320818-A Root filesystem repaired - rebootingERROR OS fsck found and fixed errors. Probably OK.Server <id> uses de

Page 860 - Start-up messages

Appendix B Syslog messages 873Nortel Secure Network Access Switch 4050 User Guide switch controller:switch [1:<switchID>] – DisconnectedINFO NSN

Page 861 - AAA subsystem messages

874 Appendix B Syslog messages320818-A Unable to use the certificate for <server nr>ERROR Traffic ProcessingUnsuitable certificate configured fo

Page 862 - Table 201

875Nortel Secure Network Access Switch 4050 User Guide Appendix CSupported MIBsThis appendix describes the Management Information Bases (MIB) and trap

Page 863 - NSNAS subsystem messages

876 Appendix C Supported MIBs320818-A • ALTEON-SSL-VPN-MIB• ANAifType-MIB• DISMAN-EVENT-MIB•ENTITY-MIB•IF-MIB• IP-FORWARD-MIB•IP-MIB• NORTEL-SECURE-AC

Page 864 - Table 202

Appendix C Supported MIBs 877Nortel Secure Network Access Switch 4050 User Guide ALTEON-ISD-SSL-MIB Contains objects for monitoring the SSL gateways.

Page 865 - NSNAS — INFO (Sheet 2 of 2)

878 Appendix C Supported MIBs320818-A NORTEL-SECURE-ACCESS-SWITCH-MIBContains objects for monitoring the Nortel SNAS 4050 devices. The following group

Page 866

Appendix C Supported MIBs 879Nortel Secure Network Access Switch 4050 User Guide Supported trapsTable 206 describes the traps supported by the Nortel

Page 867

88 Chapter 3 Managing the network access devices320818-A Managing SSH keys for Nortel SNA communication using the CLITo retrieve the public key for th

Page 868

880 Appendix C Supported MIBs320818-A

Page 869 - /cfg/sys/cur

881Nortel Secure Network Access Switch 4050 User Guide Appendix DSupported ciphersThe Nortel SNAS 4050 supports SSL version 2.0, SSL version 3.0, and

Page 870

882 Appendix D Supported ciphers320818-A EDH-RSA-DES-CBC-SHA SSLv3 DH, RSA DES (56) SHA1DES-CBC-SHA SSLv3 RSA, RSA DES (56) SHA1DES-CBC-MD5 SSLv2 RSA,

Page 871

883Nortel Secure Network Access Switch 4050 User Guide Appendix EAdding User Preferences attribute to Active DirectoryFor the remote user to be able t

Page 872

884 Appendix E Adding User Preferences attribute to Active Directory320818-A Add the Active Directory Schema Snap-in (Windows 2000 Server and Windows

Page 873

Appendix E Adding User Preferences attribute to Active Directory 885Nortel Secure Network Access Switch 4050 User Guide The Add/Remove Snap-in window

Page 874

886 Appendix E Adding User Preferences attribute to Active Directory320818-A 8 Click OK.The Console window redisplays.9 To save the console (including

Page 875 - Supported MIBs

Appendix E Adding User Preferences attribute to Active Directory 887Nortel Secure Network Access Switch 4050 User Guide 3 Select the check box The Sch

Page 876 - Supported MIBs (Sheet 1 of 3)

888 Appendix E Adding User Preferences attribute to Active Directory320818-A Create the new classTo create the nortelSSLOffload class, proceed as foll

Page 877 - Supported MIBs (Sheet 2 of 3)

Appendix E Adding User Preferences attribute to Active Directory 889Nortel Secure Network Access Switch 4050 User Guide 5 Add the isdUserPrefs attribu

Page 878 - Supported MIBs (Sheet 3 of 3)

Chapter 3 Managing the network access devices 89Nortel Secure Network Access Switch 4050 User Guide Reimporting the network access device SSH key usin

Page 879 - Supported traps

890 Appendix E Adding User Preferences attribute to Active Directory320818-A 5 Add the nortelSSLOffload class as an auxiliary class as shown below: 6

Page 880 - 880 Appendix C Supported MIBs

891Nortel Secure Network Access Switch 4050 User Guide Appendix FConfiguring DHCP to auto-configure IP PhonesThe DHCP server and the IP Phone 2002, IP

Page 881 - Supported ciphers

892 Appendix F Configuring DHCP to auto-configure IP Phones320818-A For information on the minimum firmware versions required to support IP Phones in

Page 882 - Table 207 Supported ciphers

Appendix F Configuring DHCP to auto-configure IP Phones 893Nortel Secure Network Access Switch 4050 User Guide Figure 245 The DHCP Management Consol

Page 883 - Directory

894 Appendix F Configuring DHCP to auto-configure IP Phones320818-A The Predefined Options and Values dialog box opens (see Figure 246).Figure 246 T

Page 884

Appendix F Configuring DHCP to auto-configure IP Phones 895Nortel Secure Network Access Switch 4050 User Guide Figure 247 The Option Type dialog box

Page 885

896 Appendix F Configuring DHCP to auto-configure IP Phones320818-A b In the Option Type dialog box, enter the required information (see Table 209).c

Page 886 - (Windows 2000 Server)

Appendix F Configuring DHCP to auto-configure IP Phones 897Nortel Secure Network Access Switch 4050 User Guide The Scope Options dialog box displays (

Page 887 - Create a new attribute

898 Appendix F Configuring DHCP to auto-configure IP Phones320818-A 4 Configure Call Server Information:a Select the check box beside 128 Call Server

Page 888 - Create the new class

Appendix F Configuring DHCP to auto-configure IP Phones 899Nortel Secure Network Access Switch 4050 User Guide 5 Configure VLAN Information:a In the S

Page 889

Contents 9Nortel Secure Network Access Switch 4050 User Guide Modifying a client filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Page 890

90 Chapter 3 Managing the network access devices320818-A The HealthCheck menu includes the following options:Controlling communication with the networ

Page 891 - Appendix F

900 Appendix F Configuring DHCP to auto-configure IP Phones320818-A

Page 892 - Creating the DHCP options

901Nortel Secure Network Access Switch 4050 User Guide Appendix GUsing a Windows domain logon script to launch the Nortel SNAS 4050 portalThis appendi

Page 893 - The DHCP Management Console

902 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 2 On a Windows 2000 domain controller, save the scrip

Page 894 - 4 Click Add

Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal 903Nortel Secure Network Access Switch 4050 User Guide 2 Compose

Page 895 - The Option Type dialog box

904 Appendix G Using a Windows domain logon script to launch the Nortel SNAS 4050 portal320818-A 3 On the Group Policy tab, click Open.4 Double-click

Page 896 - Information options

905Nortel Secure Network Access Switch 4050 User Guide Appendix HSoftware licensing informationOpenSSL License issuesThe OpenSSL toolkit stays under a

Page 897 - Figure 248

906 Appendix H Software licensing information320818-A conditions apply to all code found in this distribution, be it the RC4, RSA, lhash, DES, etc., c

Page 898

Appendix H Software licensing information 907Nortel Secure Network Access Switch 4050 User Guide warranty; keep intact all the notices that refer to t

Page 899 - Setting up the IP Phone

908 Appendix H Software licensing information320818-A 4. You may not copy, modify, sublicense, or distribute the Program except as expressly provided

Page 900

Appendix H Software licensing information 909Nortel Secure Network Access Switch 4050 User Guide LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY

Page 901 - Appendix G

Chapter 3 Managing the network access devices 91Nortel Secure Network Access Switch 4050 User Guide To restart communication between the Nortel SNAS 4

Page 902 - Creating a logon script

910 Appendix H Software licensing information320818-A Bouncy Castle licenseCopyright (c) 2000 - 2004 The Legion Of The Bouncy Castle (http://www.bounc

Page 903 - Assigning the logon script

Nortel Secure Network Access Switch 4050 User Guide911 IndexSymbols/ (in CLI) 804? (help, in CLI) 804Aaborting commands (CLI) 807accessenable for SSH

Page 904 - Assigning a logon script

912 Index320818-A automatic redirection, from portal 396autorun linksets 394Bbackend interfaceconfigure 145backupcertificates and keys 574, 591, 605c

Page 905 - Appendix H

Index 913Nortel Secure Network Access Switch 4050 User Guide create 214modify 217clusteradd Nortel SNAS 4050 device 61and Access List 62benefits 39c

Page 906 - GNU General Public License

914 Index320818-A RADIUS authentication method 242, 272CSR (Certificate Signing Request)and associated private key 583generate 579, 601information re

Page 907

Index 915Nortel Secure Network Access Switch 4050 User Guide create 203, 220map linksets 206, 223, 227modify 222remove linksets 229reorder linksets

Page 908

916 Index320818-A IP addresses 51in two-armed configuration 52MIP 51pVIP 51RIP 52subnet requirements 52IP Phones, supported in Nortel SNA 33Jjoin a c

Page 909

Index 917Nortel Secure Network Access Switch 4050 User Guide MmacrosLDAP 258, 294used on portal page 395major release upgrade 758manageActive Direct

Page 910 - Bouncy Castle license

918 Index320818-A RIP 52role in Nortel SNA solution 33SSH public key, export 84nslookup (CLI global command) 805Oone-armed configuration 40, 41online

Page 911

Index 919Nortel Secure Network Access Switch 4050 User Guide create method 242, 272in Nortel SNA 36manage servers 247, 279, 281modify configuration

Page 912

92 Chapter 3 Managing the network access devices320818-A The Switches screen appears (see “Switch Configuration screen” on page 116).2 Click Add.The A

Page 913

920 Index320818-A existence monitor 627, 654in Nortel SNA 618manage events 655manage monitor events 647manage targets 638monitors 627supported MIBs 8

Page 914

Index 921Nortel Secure Network Access Switch 4050 User Guide network diagnostics 847Ttechnical publications 29technical support 29Telnetenable acces

Page 915

922 Index320818-A default mapping, domain quick setup wizard 128in Nortel SNA solution 34mapping 82, 96VoIP phones, supported in Nortel SNA 33VoIP VL

Page 916

Chapter 3 Managing the network access devices 93Nortel Secure Network Access Switch 4050 User Guide 4 Click Apply.The network access device appears in

Page 917

94 Chapter 3 Managing the network access devices320818-A To reconfigure the VLAN mappings for an existing network access device, you must first disabl

Page 918

Chapter 3 Managing the network access devices 95Nortel Secure Network Access Switch 4050 User Guide 2 Enter the network access device information in t

Page 919

96 Chapter 3 Managing the network access devices320818-A Mapping the VLANs using the SREMThe VLANs are configured on the network access devices. You s

Page 920

Chapter 3 Managing the network access devices 97Nortel Secure Network Access Switch 4050 User Guide Mapping VLANs by domainTo map VLANs in a domain, s

Page 921

98 Chapter 3 Managing the network access devices320818-A Adding VLANs to a domainTo add VLANs to a domain, complete the following steps:1 Select the S

Page 922

Chapter 3 Managing the network access devices 99Nortel Secure Network Access Switch 4050 User Guide Removing VLANs from a domainTo remove existing VLA

Commentaires sur ces manuels

Pas de commentaire