PortMaster, ComOS, and ChoiceNet are registered trademarks of Lucent Technologies. RADIUS ABM, PMVision,
PMconsole, and IRX are trademarks of Lucent Technologies, Inc. ProVision is a service mark of Lucent
Technologies, Inc. All other marks are the property of their respective owners.
Disclaimer
Lucent Technologies, Inc. makes no express or implied representations or warranties with respect to the contents
or use of this manual, and specifically disclaims any implied warranties of merchantability or fitness for a
particular purpose. Lucent Technologies, Inc. further reserves the right to revise this manual and to make changes
to its content at any time, without obligation to notify any person or entity of such revisions or changes.
The
network configuration as well as specific information needed to configure PortMaster
products. Review this guide thoroughly before configuring your PortMaster. This guide
provides the settings required for the most commonly used PortMaster configurations.
To use this guide you must have successfully installed your PortMaster according to the
instructions provided in the relevant installation guide. This guide provides
configuration information only.
You can use either of two interfaces to configure the PortMaster:
provides general information about networking and
•Command line interface—use this guide and the
Reference
•PMVision™ graphical user interface (GUI).
This guide assumes you are using the command line interface and provides examples of
command line usage.
for more detailed command descriptions and instructions.
Audience
This guide is designed for qualified system administrators and network managers, and
for persons with a working knowledge of networking and routing. Appendix A,
“Networking Concepts,” provides an overview of network address conventions but is
intended as a quick refresher and should not be used as a substitute for careful study of
these principles.
Refer to “Additional References” in this Preface for appropriate RFCs and other
suggested reading. See the
protocols and routing with PortMaster products.
PortMaster Documentation
The following manuals are available from Lucent Technologies. The hardware
installation guides are included with most PortMaster products; other manuals can be
ordered through your
PortMaster
PortMaster Routing Guide
distributor or directly from Lucent.
PortMaster Command Line
for advanced information on routing
xvii
PortMaster Documentation
The manuals are also provided as PDF and PostScript files on the
shipped with your PortMaster.
In addition, you can download PortMaster information and documentation from
http://www.livingston.com.
•ChoiceNet® Administrator’s Guide
This guide provides complete installation and configuration instructions for
ChoiceNet server software.
•PortMaster Command Line Reference
This guide provides the complete description and syntax of each command in the
ComOS command set.
•PortMaster Configuration Guide
This guide provides a comprehensive overview of networking and configuration
issues related to PortMaster products.
•PortMaster hardware installation guides
These guides contain complete hardware installation instructions. An installation
guide is available for each PortMaster product line—IRX™, Office Router,
Communications Server, and Integrated Access Server.
•PMconsole™ for Windows Administrator’s Guide
PortMaster Software CD
This guide covers PMconsole Administration Software for Microsoft Windows, a
graphical tool for configuring the PortMaster. The majority of the material in this
guide also applies to the UNIX version of PMconsole. Lucent recommends that you
use the Java GUI PMVision rather than PMconsole to configure and manage a
PortMaster.
•PortMaster Routing Guide
This guide describes routing protocols supported by PortMaster products, and how
to use them for a wide range of routing applications.
xviiiPortMaster Configuration Guide
•PortMaster Troubleshooting Guide
This guide can be used to identify and solve software and hardware problems in the
PortMaster family of products.
•RADIUS Administrator’s Guide
This guide provides complete installation and configuration instructions for Lucent
Remote Authentication Dial-In User Service (RADIUS) software.
Additional References
RFCs
Use any World Wide Web browser to find a Request for Comments (RFC) online.
User Datagram Protocol
Internet Protocol
Internet Control Message Protocol
Transmission Control Protocol
Telnet Protocol Specification
Internet Standard Subnetting Procedure
Routing Information Protocol
Host Extensions for IP Multicasting
Compressing TCP/IP Headers for Low-Speed Serial Links
A Simple Network Management Protocol (SNMP)
Internet Numbers
Management Information Base for Network Management of TCP/IP-based Internets:
ICMP Router Discovery Messages
The MD5 Message-Digest Algorithm
The Point-to-Point Protocol (PPP) for the Transmission of Multiprotocol Datagrams
The PPP Internet Protocol Control Protocol (IPCP)
PPP Authentication Protocols
Type of Service in the Internet Protocol Suite
Identification Protocol
Multiprotocol Interconnect Over Frame Relay
Dynamic Host Configuration Protocol
Clarifications and Extensions for the Bootstrap Protocol
, The PPP Internet Packet Exchange Control Protocol (IPXCP)
OSPF NSSA Options
Address Allocations for Private Internets
Network 10 Considered Harmful (Some Practices Shouldn’t be Codified)
Novell IPX Over Various WAN Media (IPXWAN)
The Point-to-Point Protocol (PPP)
Assigned Numbers
A Border Gateway Protocol 4 (BGP-4)
Requirements for IP Version 4 Routers
Unique Addresses are Good
Best Current Practices
Requirements for IP Version 4 Routers
Security Architecture for the Internet Protocol
IP Authentication Header
IP Encapsulating Payload
IP Authentication Using Keyed MD5
The ESP DES-CBC Transform
PPP Internet Protocol Control Protocol Extensions for Name Server Addresses
Variable Length Subnet Table for IPv4
Address Allocation for Private Internets
Autonomous System Confederations for BGP
BGP Route Reflection, An Alternative to Full Mesh IBGP
, PPP Stac LZS Compression Protocol
, The PPP Multilink Protocol (MP)
The PPP Bandwidth Allocation Protocol (BAP), The PPP Bandwidth Allocation
Remote Authentication Dial In User Service (RADIUS)
RADIUS Accounting
OSPF Version 2
xxPortMaster Configuration Guide
ITU-T Recommendations
The following documents are recommendations of the International Telecommunication
Union Telecommunication Standardization Sector (ITU-T), formerly known as CCITT:
Additional References
Books
•Recommendation V.25bis (1988)—
general switched telephone network (GSTN) using the 100-series interchange circuits
•Recommendation V.120 (09/92)—
V-series type interfaces for statistical multiplexing
Firewalls and Internet Security: Repelling the Wily Hacker.
M. Bellovin. Reading, MA: Addison-Wesley Publishing Company, 1994. (ISBN 0-20163357-4) Japanese translation is available (ISBN 4-89052-672-2). Errata are available
from ftp://ftp.research.att.com/dist/internet_security/firewall.book.
Internetworking with TCP/IP Volume 1: Principles, Protocols, and Architecture,
E. Comer. Englewood Cliffs, NJ: Prentice-Hall, Inc., 1995. (ISBN 0-13-216987-8)
The ISDN Consultant.
(ISBN 0-13-259052-2)
2nd ed. Paul Albitz and Cricket Liu. Sebastopol, CA: O’Reilly &
entry—a
command, menu
option, button, or
key—or the name
of a file, directory,
or utility, except
in code samples.
command-line
placeholder.
Replace with a
real name or
value.
number.
• Press Enter.
•Open the permit_list file.
set Ether0 address Ipaddress
•
•Replace
OSPF area.
Area
with the name of the
set nameserver [2] Ipaddress
Square brackets ([ ])Enclose optional
keywords and
values in
command syntax.
Curly braces ({ })Enclose a
required choice
between
keywords and/or
values in
command syntax.
xxiiPortMaster Configuration Guide
•
set S0 destination Ipaddress
•
[Ipmask]
set syslogLogtype {[disabled]
[Facility.Priority]}
ConventionUseExamples
Document Advisories
Vertical bar (|)Separates two or
more possible
options in
command syntax.
• setS0|W1ospfon|off
• setS0host default|prompt|Ipaddress
Document Advisories
Note – means take note. Notes contain information of importance or special interest.
✍
Caution – means be careful. You might do something—or fail to do something—that
!
Contacting Lucent Remote Access Technical Support
results in equipment failure or loss of data.
War ning – means danger. You might do something—or fail to do something—that
results in personal injury or equipment damage.
The PortMaster comes with a 1-year hardware warranty.
For all technical support requests, record your PortMaster ComOS version number and
report it to the technical support staff or your
authorized sales channel partner
.
New releases and upgrades of PortMaster software are available by anonymous FTP from
ftp://ftp.livingston.com.pub/le/.
In North America you can schedule a 1-hour software installation appointment by
calling the technical support telephone number listed below. Appointments must be
scheduled at least one business day in advance.
About This Guidexxiii
PortMaster Training Courses
For the EMEA Region
If you are an Internet service provider (ISP) or other end user in Europe, the Middle
East, Africa, India, or Pakistan, contact your local Lucent Remote Access sales channel
partner. For a list of authorized sales channel partners, see the World Wide Web at
If you are an authorized Lucent Remote Access sales channel partner in this region,
contact the Lucent Remote Access EMEA Support Center Monday through Friday
between the hours of 8 a.m. and 8 p.m. (GMT+1), excluding French public holidays.
•By voice, dial +33-4-92-92-48-88.
•By fax, dial +33-4-92-92-48-40.
•By electronic mail (email) send mail to emea-support@livingston.com
For North America, Latin America, and the Asia Pacific Region
Contact Lucent Remote Access Monday through Friday between the hours of 6 a.m.
and 6 p.m. (GMT –8).
.
•By voice, dial 800-458-9966 within the United States (including Alaska and
Hawaii), Canada, and the Caribbean, or +1-925-737-2100 from elsewhere.
•By fax, dial +1-925-737-2110.
•By email, send mail as follows:
–From North America and Latin America to support@livingston.com.
–From the Asia Pacific Region to asia-support@livingston.com.
•Using t he World Wid e Web, se e http://www.livingston.com/.
PortMaster Training Courses
Lucent Remote Access offers hands-on, technical training courses on PortMaster
products and their applications. For course information, schedules, and pricing, visit the
Lucent Remote Access website at http://www.livingston.com, click Services
then click Training.
xxivPortMaster Configuration Guide
,
and
Subscribing to PortMaster Mailing Lists
Lucent maintains the following Internet mailing lists for PortMaster users:
•portmaster-users—a discussion of general and specific PortMaster issues, including
configuration and troubleshooting suggestions. To subscribe, send email to
majordomo@livingston.com with subscribe portmaster-users in the body of
the message.
The mailing list is also available in a daily digest format. To receive the digest, send
email to majordomo@livingston.com with subscribe portmaster-users-digest
in the body of the message.
•portmaster-radius—a discussion of general and specific RADIUS issues, including
configuration and troubleshooting suggestions. To subscribe, send email to
majordomo@livingston.com with subscribe portmaster-radius in the body of
the message.
The mailing list is also available in a daily digest format. To receive the digest, send
email to majordomo@livingston.com with subscribe portmaster-radius-digest in the body of the message.
Subscribing to PortMaster Mailing Lists
•portmaster-announce—announcements of new PortMaster products and software
releases. To subscribe, send email to majordomo@livingston.com with subscribe portmaster-announce in the body of the message. All announcements to this list
also go to the portmaster-users list. You do not need to subscribe to both lists.
About This Guidexxv
Subscribing to PortMaster Mailing Lists
xxviPortMaster Configuration Guide
This chapter discusses the following topics:
•“PortMaster Software” on page 1-1
•“Preconfiguration Planning” on page 1-2
•“Configuration Tips” on page 1-3
•“Basic Configuration Steps” on page 1-4
PortMaster Software
All PortMasters are shipped with the following software:
•ComOS®—The communication software operating system already loaded in Flash
RAM on each PortMaster. You can use the ComOS command line interface to
configure your PortMaster through a console.
•PMVision—A GUI companion to the ComOS command line interface for Microsoft
Windows, UNIX, and other platforms that support the Java Virtual Machine (JVM).
Because PMVision also supports command entry, you can use a combination of GUI
panels and ComOS commands to configure, monitor, and debug a PortMaster.
When connected to one or more PortMaster products, PMVision allows you to
monitor activity and edit existing configurations. PMVision replaces the PMConsole
interface to ComOS.
Introduction
1
•pmd or in.pmd—The optional PortMaster daemon software that can be installed
on UNIX hosts to allow the host to connect to printers or modems attached to a
PortMaster. The daemon also allows the PortMaster to multiplex incoming users
onto the host using one TCP stream instead of multiple streams like rlogin. The
daemon is available for SunOS, Solaris, AIX, HP-UX, and other platforms.
For installation and configuration instructions, copy the PortMaster software to the
UNIX host as described in the
PortMaster Software CD
booklet.
1-1
Preconfiguration Planning
•RADIUS—The RADIUS server, radiusd, runs as a daemon on UNIX systems,
providing centralized authentication for dial-in users. The radiusd daemon is
provided to customers in binary and source form for SunOS, Solaris, Solaris/X8.6,
AIX, HP-UX, IRIX, Alpha OSF/1, Linux, and BSD/OS platforms.
For installation and configuration instructions, see the
•ChoiceNet—ChoiceNet is a security technology invented by Lucent to provide a
traffic filtering mechanism for networks using dial-up remote access, synchronous
leased-line, or Ethernet connections. When used with RADIUS, ChoiceNet provides
exceptional flexibility in fine-tuning the level of access provided to users.
For installation and configuration instructions, see the
Guide
.
Preconfiguration Planning
Before the PortMaster can be used to connect wide area networks (WANs), you must
install the hardware using the instructions in the installation guide for your system.
This configuration guide is designed to introduce the most common configuration
options available for PortMaster products. Review this material before you configure
your PortMaster and, if possible, answer the following questions:
•What general configuration do you want to implement?
•Do you want to use a synchronous connection to a high-speed line?
•Will your high-speed lines use Frame Relay, ISDN, switched 56Kbps, or PPP?
•If you want dial-on-demand routing, do you want multiline load-balancing?
RADIUS Administrator’s Guide.
ChoiceNet Administrator’s
•Do you want multilink PPP (RFC 1717)?
•Do you want packet filtering for Internet connections?
•Do you want packet filtering for connections to other offices?
•Do you want dial-in users to use SLIP, PPP, or both?
•If you use PPP, do you want PAP or CHAP authentication?
•Are you using a name service—DNS or NIS?
•Have you obtained the necessary network addresses?
1-2PortMaster Configuration Guide
Configuration Tips
•Are you running IP, IPX, or both?
•Do you want to enable SNMP for network monitoring?
•Do you want dial-in only, dial-out only, or two-way communication on each port?
•What characteristics do you want to assign to the dial-out locations?
•How do you want to configure dial-in users?
•Do you want to use RADIUS to authenticate dial-in users, or the internal user table
on the PortMaster?
•Do you want to use ChoiceNet to filter network traffic?
•Do you want to use the console port for administration functions, or do you want to
attach an external modem to the port?
•For dial-in uses, do you receive service on analog lines, ISDN BRI, ISDN PRI,
channelized T1, or E1?
Many other decisions must be made during the configuration process. This guide
discusses the various configuration options and their implications.
Configuration Tips
PortMaster configuration can be confusing because settings can be configured for a port,
a user, or a remote location. Use the following tips to determine how to configure your
PortMaster:
If You Are Configuring...Then Configure Settings on...
A network hardwired port or
hardwired multiline load
balancing
One or more ports for dial-out
operation
One or more ports for dial-in
operation
A callback network userThe callback location in the location table, and
Introduction1-3
The port
Dial-out locations using the location table
Dial-in users using the user table or RADIUS
refer to the location name in the user table
Basic Configuration Steps
Basic Configuration Steps
The exact PortMaster configuration steps you follow depend upon the hardware you are
installing and your network configuration. However, the following general configuration
steps are the same for all PortMaster products:
1. Install the PortMaster hardware and assign an IP address and a password
as described in the installation guide shipped with your PortMaster.
Note – This guide assumes that you have completed Step 1 and does not give details on
hardware installation or IP address assignment.
✍
2. Boot the system and log in with the administrative password.
You can configure the PortMaster from a terminal attached to the console port, by
an administrative Telnet session, or by a network connection.
3. If you want to use PMVision software to configure your PortMaster, install
it on a workstation anywhere on your network.
See the PMVision online help for more information.
4. Configure the global settings.
PortMaster global settings are described in Chapter 3, “Configuring Global Settings.”
5. Configure the Ethernet settings, and configure the IP and IPX protocol
settings for your network.
PortMaster Ethernet settings are described in Chapter 4, “Configuring the Ethernet
Interface.”
6. Configure the asynchronous port(s).
PortMaster asynchronous port settings are described in Chapter 6, “Configuring a
Synchronous WAN Port.”
7. Configure the synchronous port(s), if available.
PortMaster synchronous port settings are described in Chapter 6, “Configuring a
Synchronous WAN Port.”
8. Configure ISDN BRI connection(s), if available.
1-4PortMaster Configuration Guide
Loading...
+ 334 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.