Use, duplication, or disclosure by the United States Government is subject to restrictions as set
forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at
DFARS 252.227-7013.
Notwithstanding any other license agreement that may pertain to, or accompany the delivery of,
this computer software, the rights of the United States Government regarding its use,
reproduction, and disclosure are as set forth in the Commercial Computer Software-Restricted
Rights clause at FAR 52.227-19.
IMPORTANT NOTE TO USERS
This software and hardware is provided by Nokia Inc. as is and any express or implied
warranties, including, but not limited to, implied warranties of merchantability and fitness for a
particular purpose are disclaimed. In no event shall Nokia, or its affiliates, subsidiaries or
suppliers be liable for any direct, indirect, incidental, special, exemplary, or consequential
damages (including, but not limited to, procurement of substitute goods or services; loss of use,
data, or profits; or business interruption) however caused and on any theory of liability, whether in
contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use
of this software, even if advised of the possibility of such damage.
Nokia reserves the right to make changes without further notice to any products herein.
TRADEMARKS
Nokia is a registered trademark of Nokia Corporation. Other products mentioned in this document
are trademarks or registered trademarks of their respective holders.
This manual is written for network administrators. It provides information for
the installation and use of the Nokia IP2255 Security Platform. Installation
and maintenance should be performed by experienced technicians or
Nokia-approved service providers only.
This preface provides the following information:
In this Guide
Conventions this Guide Uses
Related Documentation
In this Guide
This guide is organized into the following chapters and appendixes:
Chapter 1, “Overview” presents a general overview of the IP2255
security platform.
Chapter 2, “Installing Nokia IP2255 Appliances” describes how to rack
mount the appliance.
Chapter 3, “Performing the Initial Configuration” describes how to
connect the power and make the appliance available on the network.
Chapter 4, “Connecting to the Network Interface Cards” describes how to
connect to and use each of the supported NICs.
Nokia IP2255 Security Platform Installation Guide13
Chapter 6, “Installing and Replacing Network Interface Cards” describes
how to install, monitor, and replace supported network interface cards.
Chapter 5, “Installing, Replacing, and Configuring the Nokia Encryption
Accelerator Card” describes how to install and replace the Nokia
encryption accelerator card and how to configure software to use the
Nokia encryption accelerator card.
Chapter 7, “Installing and Replacing Other Components” describes how
to install or replace the compact-flash memory card, DIMMs, the fan tray
unit, power supplies, and the Ethernet management ports.
Chapter 8, “Troubleshooting” describes problems you might encounter
and proposes solutions to these problems.
Appendix A, “Technical Specifications” provides physical technical
specifications.
Appendix B, “Compliance Information” provides compliance and
regulatory information.
Conventions this Guide Uses
The following sections describe the conventions this guide uses, including
notices, text conventions, and command-line conventions.
Notices
Warning
Warnings advise the user that either bodily injury might occur because of
a physical hazard, or that damage to a structure, such as a room or
equipment closet, might occur because of equipment damage.
This chapter provides an overview of the Nokia IP2255 appliance and the
requirements for its use. The following topics are covered:
About the Nokia IP2255 Security Platform
Managing the Nokia IP2255 Appliance
Nokia IP2255 Appliance Overview
Product Disposal
Site Requirements, Warnings, and Cautions
Software Requirements
About the Nokia IP2255 Security Platform
The Nokia IP2255 appliance combines the power of Nokia IPSO software
with Check Point VPN-1 enterprise applications.
Nokia IP2255 appliances are ideally suited to handle small packet sizes, shortlived sessions and short-lived connections, and to provide secure Internet
connectivity.
The Nokia IP2255 appliances use accelerated data path (ADP) technology to
deliver gigabit firewall and VPN forwarding performance when running
Check Point VPN-1 enterprise applications. The ADP technology also allows
the Nokia operating system and Check Point VPN-1 enterprise applications to
accelerate other data link, network, and transport layer functions.
Nokia IP2255 Security Platform Installation Guide19
1
Overview
Additionally, the Nokia IP2255 appliances support an encryption accelerator
card to further enhance VPN performance.
Nokia IP2255 is a three-rack unit (3U) appliance that incorporates a
serviceable slide-out tray into the chassis design. Nokia IP2255 appliances are
designed to meet high-end availability requirements and they have port
density for connections to redundant internal, external, DMZ, and
management networks.
As network devices, Nokia IP2255 appliances support a comprehensive suite
of IP-routing functions and protocols, including RIPv1/RIPv2, IGRP, OSPF
and BGP4 for unicast traffic, and DVMRP for multicast traffic. The integrated
router functionality eliminates the need for separate intranet and access
routers in security applications.
Managing the Nokia IP2255 Appliance
You can manage the Nokia IP2255 appliance by using one of the following
interfaces:
Nokia Network Voyager—an SSL-secured, Web-based element
management interface to Nokia IP Security Platforms. Network Voyager
is preinstalled on the IP2255 appliance and enabled through the IPSO
operating system. With Network Voyager, you can manage, monitor, and
configure the appliances from any authorized location within the network
by using a standard Web browser.
For information about how to access Network Voyager and the related
reference materials, see “Using Nokia Network Voyager” on page 53.
The Nokia IPSO command-line interface (CLI)—an SSHv2-secured
interface that enables you to easily configure Nokia IP Security Platforms
from the command line. Everything that you can accomplish with
Network Voyager—manage, monitor, and configure the your appliance—
you can also do with the CLI.
For information about how to access the CLI, see “Using the Command-
management application. With Horizon Manager, you can securely install
and upgrade the Nokia proprietary IPSO operating system, plus hardware
and third-party applications such as Check Point VPN-1. Horizon
Manager can perform installations and upgrades on up to 2,500 Nokia IP
Security Platforms, offering administrators the most rapid and dependable
method to perform Check Point application upgrades.
For information about how to obtain Horizon Manager, see the “Nokia
Contact Information” on page 3.
Nokia IP2255 Appliance Overview
The front panel of the Nokia IP2255 appliance includes the following
components:
Four 10/100/1000 Ethernet management ports
Four network interface card (NIC) slots, controlled by two Nokia ADP
subsystems
Console port
Serial (AUX) port for a modem connection
Two PC-card slots that support compact-flash memory
Fan tray unit with N + 1 cooling
Nokia IP2255 Security Platform Installation Guide21
1
Overview
Figure 1 shows the component locations for IP2255 appliances.
Figure 1 Component Locations Front View
Fan traySystem status LEDs
SLOT 1
10Base-SR X2
A
L
10Base-SR X2
A
L
SLOT 2
CONSOLEAUXPCMCIA
RESET
Network interface cards (4)
SLOT 3
1357
10/100 BaseT
10/100 BaseT
2468
1357
2468
SLOT 4
10/100/1000BaseT
1357
L
A
L
A
2468
1357
L
A
L
A
2468
SLOT 5
1234
IP2255
00010
Console port
Serial (AUX) port
PC-card slots
10/100/1000 Ethernet
management ports
The flash memory in the internal compact-flash slot provides the primary
application and operating system storage.
The power supplies are located at the back of the IP2255 appliance, as shown
in Figure 2.
The Ethernet management ports support 10-Mbps and 100-Mbps link speeds
and are located in the external cPCI slot.
The Ethernet management ports on IP2255 appliances are designed to be used
for the following purposes:
Managing the platform
Firewall synchronization traffic
IP cluster protocol traffic
Connection to a log server
The Nokia IP2255 appliance management ports are not suitable for
forwarding production data traffic. Do not use them for this purpose.
PWROKFAULT OVR
TEMP
00034
Status LEDsPower supply fan
Nokia recommends that you configure one port as the primary management
interface and a second port as the backup management interface.
Nokia IP2255 Security Platform Installation Guide23
1
Overview
Figure 3 shows the details of the Ethernet management ports and LEDs.
Figure 3 Ethernet Management Port Details
Ports 1 trough 4
10/100/1000BaseT
1234
Link LED (yellow for 10/100, and green for 1000 Mbps)
Activity LED (yellow)
The physical names of the Ethernet management ports are eth-s5p1, eth-s5p2,
eth-s5p3, and eth-s5p4.
Note
For IP2255 appliances, Nokia recommends the use of shielded twistedpair cables and connectors for best Electromagnetic Interference and
Immunity performance.
Nokia Network Interface Cards
The Nokia IP2255 appliances have four network interface card (NIC) slots.
Each slot can accommodate one NIC. The NICs interface with the ADP
subsystem. Figure 4 shows the slot numbers for the NIC slots.
Slot 5 contains the cPCI Ethernet management ports and does not connect to
the ADP subsystem.
Nokia IP2255 appliances support the ADP format network interface cards
listed in Table 2.
Table 2 NICs Available for the Network Interface Card Slots
ADP format NICFor details, see...
Two-port copper Gigabit Ethernet
NIC
Two-port fiber-optic Gigabit
Ethernet NIC
“Two-Port and Four-Port Copper Gigabit
Ethernet NIC” on page 64
“Two-Port and Four-Port Fiber-Optic Gigabit
Ethernet NIC” on page 67
Eight-port 10/100 Ethernet NIC“Eight-Port 10/100 Ethernet NIC” on page 60
One-port fiber-optic 10 Gigabit
Ethernet NIC
Nokia encryption accelerator card“Installing, Replacing, and Configuring the
Nokia IP2255 Security Platform Installation Guide25
“Fiber-Optic 10 Gigabit Ethernet NIC
Features” on page 69
Nokia Encryption Accelerator Card” on
page 73
1
Overview
Note
Nokia products support network interface cards purchased from Nokia or
Nokia-approved resellers only. The Nokia Global Support Services group
can provide support only for Nokia products that use Nokia-approved
accessories. For sales or reseller information, contact a Nokia service
provider listed in the “Nokia Contact Information” on page 3.
Console Port
Use the built-in console port, shown in Figure 1 on page 22, to supply
information that makes the appliance available on the network. Figure 5
provides pin assignment information for console connections.
Use the built-in serial (AUX) port, shown in Figure 1 on page 22 to establish a
modem connection to manage the appliance. Figure 6 provides pin-
assignment information for modem connections.
Nokia IP2255 Security Platform Installation Guide27
You can monitor the basic operation of the your appliance by checking the
system status LEDs. The system status LEDs are located on the front panel of
the appliance, as shown in Figure 7.
Figure 7 System Status LEDs
Nokia IP2255 Appliance Overview
Power and status
10Base-SR X2
Voltage
A
L
Fan unit and power supply
00025
Table 3 shows the system status LEDs and describes their meaning.
Table 3 System Status LEDs
Status indicatorMeaning Symbol
Solid bluePower on
Solid yellowAppliance is experiencing an
internal voltage problem.
!
Nokia IP2255 Security Platform Installation Guide29
1
Overview
Table 3 shows the system status LEDs and describes their meaning.
Table 3 System Status LEDs
Status indicatorMeaning Symbol
Blinking yellowAppliance is experiencing a
temperature problem.
Solid redOne or more fans are not
operating properly or one of the
connected power supplies is
experiencing a problem.
!
The location and meaning of the status LEDs for the installed NICs is
described in Chapter 4, “Connecting to the Network Interface Cards.”
Fan Unit
The Nokia IP2255 appliance fan unit is a single unit made up of four
individual fans to provide the air flow required to maintain a proper operating
temperature. The fan unit provides N + 1 cooling, so it can provide proper
airflow even if an individual fan fails.
Caution
If an individual fan fails, replace the fan unit as soon as possible. For
information about how to replace a failed fan unit, see “Replacing the
Fan Unit” on page 96.
The system status LEDs on the front panel of the appliance show the status of
the fan unit. For more information about the system status LEDs, see “System