Allot Communications Ltd. ("Allot") is not a party to the purchase agreement under which NetEnforcer was purchased, and
will not be liable for any damages of any kind whatsoever caused to the end users using this manual, regardless of the form of
action, whether in contract, tort (including negligence), strict liability or otherwise.
SPECIFICATIONS AND INFORMATION CONTAINED IN THIS MANUAL ARE FURNISHED FOR
INFORMATIONAL USE ONLY, AND ARE SUBJECT TO CHANGE AT ANY TIME WITHOUT NOTICE, AND
SHOULD NOT BE CONSTRUED AS A COMMITMENT BY ALLOT OR ANY OF ITS SUBSIDIARIES. ALLOT
ASSUMES NO RESPONSIBILITY OR LIABILITY FOR ANY ERRORS OR INACCURACIES THAT MAY APPEAR IN
THIS MANUAL, INCLUDING THE PRODUCTS AND SOFTWARE DESCRIBED IN IT.
Please read the End User License Agreement and Warranty Certificate provided with this product before using the product.
Please note that using the products indicates that you accept the terms of the End User License Agreement and Warranty
Certificate.
WITHOUT DEROGATING IN ANY WAY FROM THE AFORESAID, ALLOT WILL NOT BE LIABLE FOR ANY
SPECIAL, EXEMPLARY, INDIRECT, INCIDENTAL OR CONSEQUENTIAL DAMAGES OF ANY KIND,
REGARDLESS OF THE FORM OF ACTION WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE),
STRICT LIABILITY OR OTHERWISE, INCLUDING, BUT NOT LIMITED TO, LOSS OF REVENUE OR
ANTICIPATED PROFITS, OR LOST BUSINESS, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Products and corporate names appearing in this manual may or may not be registered trademarks or copyrights of their
respective companies, and are used only for identification or explanation and to the owners' benefit, without intent to infringe.
Allot and the Allot Communications logo are registered trademarks of Allot Communications Ltd.
NOTE: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to Part 15 of
the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment
is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency energy and, if not
installed and used in accordance with the instruction manual, may cause harmful interference to radio communications.
Operation of this equipment in a residential area is likely to cause harmful interference in which case the user will be
required to correct the interference at his own expense.
Changes or modifications not expressly approved by Allot Communication Ltd. could void the user's authority to operate the
equipment.
AC-1000 Series Hardware Guide
iii
Important Notice
Printing History
First Edition: July, 2006
Second Edition: September, 2007
AC-1000 Series Hardware Guide
iv
Table of Contents
Important Notice .......................................................................................................................... iii
Printing History ............................................................................................................................. iv
Table of Contents ........................................................................................................................... v
Table of Figures ........................................................................................................................... vii
CHAPTER 1: AC-1000 SERIES HARDWARE ......................................................... 1-1
AC-1000 Series Packing List ..................................................................................................... 1-2
NetEnforcer Front Panel ........................................................................................................... 1-3
AC-1000 Series Front Panels ................................................................................................... 1-4
4-7 – Serial Redundancy – Normal Scenario .................................................................. 4-19
4-8 – Serial Redundancy – Failover Scenario ................................................................. 4-20
4-9 – Serial Redundancy – Bypass Scenario ................................................................... 4-21
4-10 – Serial Redundancy – Mesh Scenario ................................................................... 4-22
viii
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
This chapter describes the NetEnforcer AC-1000 series hardware and the initial
installation and setup of the device. The NetEnforcer is a transparent learning bridge
that is IEEE 802.1-compliant and works with a Bypass Unit to ensure that data
continues flowing should any hardware or software problem occur. While the
NetEnforcer is bypassed, all traffic goes through passive elements only and still allows
the network to function.
NetEnforcer AC-1000 series offers carrier-grade design with redundant critical
components for fail-safe operation. Redundant hardware components include system
fans and dual hot-swappable power supplies. The NetEnforcer AC-1000 series is
designed to meet ETSI standards.
All AC-1000 series units come with an additional Bypass Unit.
CAUTIONAll AC-1000 Series models only function when the appropriate
Bypass Unit is connected to it. This is to ensure continuous service
in the event of failure.
NOTE AC-1000 NetEnforcer NIC default factory setting is always Auto-
Negotiation enabled, with the exception of the AC-1010 Copper whose
default NIC setting is 1000 full, Auto-Negotiation disabled.
It is recommended to keep the NetEnforcer’s default setting. Changing
NIC settings is done via LCD panel only.
Several NetEnforcer models are available to support large and small sites and different
data network speeds.
All NetEnforcer AC-1000 series units support 1M connections (2M flows), 2,000 pipes
and 8,000 Virtual Channels. Additional Pipes and Virtual Channels can also be
purchased separately per device. Allot basic management software is included with all
AC-1000 series devices. Allot NetXplorer Centralized Management software can be
purchased for any AC-1000 series device using software version S7.1.0 or later,
replacing the basic management.
NetEnforcer AC-1000 Hardware Guide
1-1
Chapter 1: AC-1000 Series Hardware
The NetEnforcer AC-1010 is a general-purpose carrier grade device with one line (two
port) connectivity. The device is available with either AC or DC power supplies and
with copper, SX fiber, LX5 fiber, LX20 fiber or ZX fiber interface connectors. The AC1010 may be ordered with an upgradable throughput of 155 Mbps, 310 Mbps, 622
Mbps or 1 Gbps.
The NetEnforcer AC-1020 is intended to be used in a mesh network configuration
where redundancy is kept by connecting each path to a different network device. The
AC-1020 has two line (four port) connectivity. The device is available with either AC or
DC power supplies and with copper, SX fiber, LX5 fiber, LX20 fiber or ZX fiber
interface connectors. The AC-1020 may be ordered with an upgradable throughput of
155 Mbps, 310 Mbps, 622 Mbps, 1 Gbps or 2 Gbps.
The NetEnforcer AC-1040 is a carrier grade unit intended for large service providers or
carriers with four line (eight port) connectivity. The unit is available with either AC or
DC power supplies and with copper interface connectors. The AC-1040 is provided
with a non-upgradable throughput of 400 Mbps,
AC-1000 Series Packing List
Verify that the following items are included with NetEnforcer:
• NetEnforcer (hardware with pre-installed software)
• NetEnforcer Hardware Guide
• Two mains power cables according to National Electrical Code (NEC) with
molded IEC sockets
• 1 Serial Console Cable
• 1 Ethernet Cross Management Cable
• 2 19" Side Mounting Brackets
• 8 Mounting Bracket Screws
• 1 D-type High Density Backup Cable
NOTE The maximum Ethernet cable length is generally up to 50 meters.
1-2
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
NetEnforcer Front Panel
The AC-1000 series connects to your network via Link Connection connectors. The
LCD panel, connectors and LED indicators on the front panel, are shown in the
following diagrams.
The front panel of each AC-1000 series unit is separated into four areas as shown
below:
Figure
1-1 – Front Panel: AC-1000 Series
The front panel of NetEnforcer is laid out as follows:
• LCD panel, described on page 1-6
• The Link Connections area
• Power Supply Modules, described on page 1-8.
• Accessory area, including the following:
• Management Port, described on page 1-11
• Management LEDs, described on page 1-12
• Console Connector described on page 1-12
• Backup High Density D-type Connector (see Bypass Units on page 1-
19)
• Two power cable connectors described on page 1-13.
NetEnforcer AC-1000 Hardware Guide
1-3
Chapter 1: AC-1000 Series Hardware
AC-1000 Series Front Panels
AC-1010 Front Panels
Figure
AC-1020 Front Panel
1-2 – Front Panel: AC-1010 Copper
Figure
1-4
NetEnforcer AC-1000 Hardware Guide
1-3 – Front Panel: AC-1020 Fiber
Chapter 1: AC-1000 Series Hardware
AC-1040 Front Panels
Figure
CAUTIONCLASS 1 LASER PRODUCT. DANGER!
1-4 – Front Panel: AC-1040 Copper
Invisible laser radiation when opened.
AVOID DIRECT EXPOSURE TO BEAM.
NetEnforcer AC-1000 Hardware Guide
1-5
Chapter 1: AC-1000 Series Hardware
LCD Panel
The NetEnforcer LCD panel provides an indication of traffic usage and enables you to
configure NetEnforcer directly without the need to connect a terminal. You can also
start, reboot and shutdown NetEnforcer from the front panel.
Display Area
Display Area
Standby Indicator
Standby Indicator
Up Arrow
Up Arrow
Left A rrow
Left A rrow
Down Arro w
Down Arro w
Figure
Ri ght Arrow
Ri ght Arrow
On/OffEnter
On/OffEnter
Sel ec t
Sel ec t
1-5 – NetEnforcer LCD Panel
Active Indicator
Active Indicator
P ower Indicator
P ower Indicator
For a description of how to configure NetEnforcer using the LCD panel, refer to
Configuring Via the LCD Panel, page 3-12.
For a description of the Standby, Active and Power LEDs, refer to Interface Status Indicators, page 1-8.
1-6
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
Unit Status Indicators
The modes of operation of the Standby, Active and Power LEDs on the LCD panel are
described in the table below.
Indicator Status NetEnforcer Status
Standby
Off This NetEnforcer is the primary system. If you have one
On Two NetEnforcers are connected in Parallel Redundancy
mode and this NetEnforcer is the secondary system.
NetEnforcer, this should be the normal state of the LED. If
you have two NetEnforcers configured in Parallel
Redundancy mode, this NetEnforcer is the primary system.
Active
Off NetEnforcer is in Bypass mode, or this is the secondary
Power
Off NetEnforcer is shut down.
Table 1-1 – Standby/Active/Power LED Conditions
On NetEnforcer is in Active mode.
NetEnforcer in a Parallel Redundancy configuration and it
is not active. Traffic passes through NetEnforcer with no
Quality of Service or traffic shaping.
On NetEnforcer is powered up.
NetEnforcer AC-1000 Hardware Guide
1-7
Chapter 1: AC-1000 Series Hardware
Interface Status Indicators
The modes of operation of the Link (External and Internal) LEDs are described in the
table below.
Link Status Indicators – AC-1010/1020
Ext/Int LED NetEnforcer Status
Green
A lit green LED indicates that a link is detected.
Amber
Off
Table 1-2 – External/Internal LED Conditions – AC-1010/1020
Link Status Indicators – AC-1040
Ext/Int LED NetEnforcer Status
Green
Red
Off
Table 1-3 – External/Internal LED Conditions – AC-1040
A blinking amber LED indicates that traffic is detected on
the interface.
An unlit LED indicates that neither links nor activities were
detected.
A lit green LED indicates that a link is detected.
A blinking red LED indicates that traffic is detected on the
interface.
An unlit LED indicates that neither links nor activities were
detected.
Power Supply Modules
NetEnforcer includes two hot-swappable power supply modules and a dual line feed for
Redundancy purposes. Each line feed is driving one power supply.
1-8
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
NOTE The AC power supply automatically adapts to voltages between 100 V and
240 V, 50/60 Hz. The DC power supply automatically adapts to voltages
of 48 V or 60 V DC.
This equipment is for use in a restricted access area by qualified
personnel only. To avoid shock, do not perform any servicing other than
those contained in the unpacking instructions.
Should you need to, you can replace one of the power supplies while NetEnforcer is
connected and operating. Replacing a power supply while the unit is operating is
possible since the remaining power supply will take the full load and maintain full
operation.
NOTE To remove a power supply module, undo the two screws in the lower left
and right corners, lift the handle and slide the module out.
NetEnforcer AC-1000 Hardware Guide
1-9
Chapter 1: AC-1000 Series Hardware
Each power supply has two LEDs located beneath the power supply handles.
CAUTIONThe power entry modules (AC supply option) include two fuses (T2A
250 V, 5 x 20 mm) at each power entry. One is a spare fuse for
replacement purposes. You can open the fuse box and change when
necessary. For continued protection against risk of fire, replace only
with same type and rating of fuse.
Disconnect the product from the power line before removing the
cover. Any adjustment and maintenance of the opened device
should be done only while the device is disconnected from its
source of power and should only be performed by qualified
personnel
1-10
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
Accessories Area
Management Port (Out of Band Management)
Out-of-band management provides the following:
• Offers physical separation between shaped traffic and management traffic.
• Enables access to NetEnforcer even if there is a problem in the network (for
example, DoS attack).
• Prevents management traffic from interfering with shaped traffic.
• Permits NetEnforcer management from a DMZ.
The NetEnforcer includes a dedicated Management port for out-of-band management of
the device. The dedicated Management port provides a secure solution for device
management for enterprise and service providers. It enables you to permit access solely
to a closed group of network administrators, so that ISP customers cannot "see" the
Management port and therefore cannot access the NetEnforcer management. Operating
through the Management port denies management access to the device from Internal or
External ports. Moreover, when there is a problem in the regular network, for example,
a DoS (Denial of Service) attack, you can still manage and monitor the NetEnforcer.
Using a Management port has the following benefits:
• Provides a security feature that prevents ISP customers from "seeing" the
Management port and thus prevents access to NetEnforcer. The Internal and
External ports are functioning solely to forward traffic, consequently only the
administrator (the only one who has access to the Management port) has
access to NetEnforcer.
• Enables configuring, installing and upgrading while the unit is in Bypass
mode. This is particularly important when NetEnforcer is in carrier
environments.
• Improves NetEnforcer's forwarding performance by separating the
management traffic from the regular traffic. In addition, if a problem exists in
the regular network you can still communicate with NetEnforcer in order to
repair the problem.
NetEnforcer AC-1000 Hardware Guide
1-11
Chapter 1: AC-1000 Series Hardware
• Provides an infrastructure for improvement of the redundancy capabilities.
NOTE The Management port has its own MAC and IP address.
Management Port Status Indicators
Management Port Status Indicators – AC-1010/1020
The modes of operation of the Management port LEDs are described in the table below.
Mgmnt LED NetEnforcer Status
Green
A lit green LED indicates that a link is detected.
Amber
Off
Table 1-4 –Management LED Conditions – AC-1010/1020
Management Port Status Indicators – AC-1040
Mgmnt LED NetEnforcer Status
Green
Red
Off
Table 1-5 –Management LED Conditions – AC-1040
A blinking amber LED indicates that traffic is detected on
the interface.
An unlit LED indicates that neither links nor activities were
detected.
A lit green LED indicates that a link is detected.
A blinking red LED indicates that traffic is detected on the
interface.
An unlit LED indicates that neither links nor activities were
detected.
Console Port
The Console Port allows the connection of a PC to the NetEnforcer in order to monitor
or configure the unit via the Command Line Interface (CLI)
1-12
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
Power Cable Connectors
The unit power cables (AC or DC) plug in here. The power cables should not be
removed while swapping the power modules.
CAUTIONThis equipment has a connection between the earthed conductor of the DC
supply circuit and the earthing conductor. Before connecting the product to
the power line, make sure that the protective ground terminal of the device is
connected to the safety ground conductor of the mains power cord. The
mains plug should only be inserted in a socket outlet provided with a
connected safety ground. The protective action must not be negated by use
of an extension cord (power cable) without a protective conductor
(grounding). Any interruption of the protective (grounding) conductor or
disconnection of the protective ground terminal can make the device unsafe
to use. Intentional interruption is prohibited.
NetEnforcer AC-1000 Hardware Guide
1-13
Chapter 1: AC-1000 Series Hardware
Cabling
AC-1000 Series Copper
NOTE Ethernet Cables may be Straight or Cross, depending upon your network.
Shielded cables must be used in order to insure compliance.
Connections Cable Type Connector Type
To NetEnforcer
Management Port
To NetEnforcer Console
Port
Primary NetEnforcer
Internal/Eternal to
Bypass Unit
Internal/External
Secondary NetEnforcer
Internal/External to
Network
NetEnforcer Backup
Connector to Bypass
Unit
Bypass Unit Internal to
Switch
Bypass Unit External to
Router
Ethernet (Cat-6) (Included,
P/N C411011)
Ethernet (Cat-6) (Included,
P/N C002005B)
Ethernet (Cat 6) (Included,
P/N C411008 x2)
Ethernet (Cat 6) RJ-45
DB-9 Cable (Included, P/N
C002009)
Ethernet (Cat 6) RJ-45
Ethernet (Cat 6) RJ-45
RJ-45
RJ-45
RJ-45
D-Type 9-Pin/26-Pin
1-14
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
NetEnforcer AC-1000 Hardware Guide
1-15
Chapter 1: AC-1000 Series Hardware
AC-1000 Multi Mode (SX) Fiber
NOTE Ethernet Cables may be Straight or Cross, depending upon your network.
Connections Cable Type Connector Type
To NetEnforcer
Management Port
To NetEnforcer Console
Port
Primary NetEnforcer to
Bypass Unit
(Internal/External)
NetEnforcer Backup
Connector to Bypass
Unit
Secondary NetEnforcer
to Network
(Internal/External)
Bypass Unit Internal to
Switch
Bypass Unit External to
Router
Ethernet (Cat-6) (Included,
P/N C411011)
Ethernet (Cat-6) (Included,
P/N C002005B)
Built In Built In
DB-9 Cable (Included,
P/N C002009)
62.5/125μ fiber optic cable
62.5/125μ fiber optic cable
62.5/125μ fiber optic cable Dual SC
RJ-45
RJ-45
D-Type 9-Pin/26-Pin
Dual SC
Dual SC
1-16
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
AC-1000 Series Single Mode (LX5, LX20, ZX) Fiber
NOTE Ethernet Cables may be Straight or Cross, depending upon your network.
Connections Cable Type Connector Type
To NetEnforcer
Management Port
To NetEnforcer Console
Port
Primary NetEnforcer to
Bypass Unit
(Internal/External)
NetEnforcer Backup
Connector to Bypass
Unit
Secondary NetEnforcer
to Network
(Internal/External)
Bypass Unit Internal to
Switch
Bypass Unit External to
Router
Ethernet (Cat-6) (Included,
P/N C411011)
Ethernet (Cat-6) (Included,
P/N C002005B)
9/125μ fiber optic cable
(Included, P/N C411015)
DB-9 Cable (Included,
P/N C002009)
9/125μ fiber optic cable
9/125μ fiber optic cable
9/125μ fiber optic cable Dual LC
RJ-45
RJ-45
Dual LC
D-Type 9-Pin/26-Pin
Dual LC
Dual LC
NetEnforcer AC-1000 Hardware Guide
1-17
Chapter 1: AC-1000 Series Hardware
Connectors
NetEnforcer Bypass Units using Multi Mode fiber (SX) utilize dual SC Connectors.
Figure
NetEnforcer Bypass Units using Single Mode fiber (LX5, LX20 and ZX) utilize dual
LC connectors.
1-6 – Dual SC Connector (Multi Mode Fiber)
Figure
NOTE Color and appearance of actual connectors may vary.
1-7 – Dual LC Connector (Single Mode Fiber)
1-18
NetEnforcer AC-1000 Hardware Guide
Chapter 1: AC-1000 Series Hardware
Bypass Units
The AC-1000 series operates with an external Bypass Unit. The Bypass Unit is a
mission-critical subsystem designed to ensure network connectivity at all times. The
Bypass mechanism provides "connectivity insurance" in the event of a NetEnforcer
subsystems failure.
NetEnforcer is supplied with a Bypass Unit appropriate to the Unit. The AC-1010 Fiber
operates with a Fiber Bypass and the AC-1010 Copper operates with a Copper Bypass.
The AC-1020 Fiber operates with a Double Fiber Bypass and the AC-1020 Copper
operates with a Double Copper Bypass. The AC-1040 operates with a Multi-port
Copper Bypass.
CAUTIONANetEnforcer AC-1000 unit must be connected to the appropriate
Bypass Unit. This is to ensure continuous service in the event of
failure.
A separate NetEnforcer Bypass package is included with your AC-1000 series
shipment.
AC-1010 Bypass Units
Single Copper Bypass Unit
The Single Copper Bypass Unit works in conjunction with NetEnforcer AC-802 Copper
models.
Figure
NOTE Use UTP CAT-6 straight Ethernet cables to connect link connections
NetEnforcer AC-1000 Hardware Guide
1-8 – Single Copper Bypass Unit
marked with Internal and External labels. The maximum Ethernet cable
length is generally 50 meters.
1-19
Chapter 1: AC-1000 Series Hardware
The Single Copper Bypass Unit includes RJ-45 connectors for Ethernet cables and two
D-type 9-pin connectors for primary and redundant unit to backup connection.
The following procedure describes how to connect a Single Copper Bypass Unit to
NetEnforcer.
To External
Router
To Internal
Switch
Figure
1-9 – Connecting the NetEnforcer AC-802 Copper to the Single Copper
Bypass Unit
To connect the Single Copper Bypass to the NetEnforcer:
NOTE For important information regarding cable and connector types, see
Cabling on page 1-14.
Connect the External cable from the External port on the Bypass Unit
1.
to the External port on NetEnforcer.
2. Connect the Internal cable from the Internal port on the Bypass Unit, to
the Internal port on NetEnforcer.
1-20
NetEnforcer AC-1000 Hardware Guide
Loading...
+ 67 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.