Use, duplication, or disclosure by the United States Government is subject to restrictions as set
forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at
DFARS 252.227-7013.
Notwithstanding any other license agreement that may pertain to, or accompany the delivery of,
this computer software, the rights of the United States Government regarding its use,
reproduction, and disclosure are as set forth in the Commercial Computer Software-Restricted
Rights clause at FAR52.227-19.
IMPORTANT NOTE TO USERS
This software and hardware is provided by Nokia Inc. as is and any express or implied
warranties, including, but not limited to, implied warranties of merchantability and fitness for a
particular purpose are disclaimed. In no event shall Nokia, or its affiliates, subsidiaries or
suppliers be liable for any direct, indirect, incidental, special, exemplary, or consequential
damages (including, but not limited to, procurement of substitute goods or services; loss of use,
data, or profits; or business interruption) however caused and on any theory of liability, whether in
contract, strict liability, or tort (including negligence or otherwise) arising in any way out of the use
of this software, even if advised of the possibility of such damage.
Nokia reserves the right to make changes without further notice to any products herein.
TRADEMARKS
Nokia is a registered trademark of Nokia Corporation. Other products mentioned in this document
are trademarks or registered trademarks of their respective holders.
050110
2Nokia IP300 Series Security Platform Installation Guide
Nokia Contact Information
Corporate Headquarters
Web Sitehttp://www.nokia.com
Telephone1-888-477-4566 or
1-650-625-2000
Fax1-650-691-2170
Mail
Address
Regional Contact Information
AmericasNokia Inc.
Europe,
Middle East,
and Africa
Asia-Pacific 438B Alexandra Road
Nokia Customer Support
Web Site:https://support.nokia.com/
Email:tac.support@nokia.com
Nokia Inc.
313 Fairchild Drive
Mountain View, California
94043-2215 USA
313 Fairchild Drive
Mountain View, CA 94043-2215
USA
Nokia House, Summit Avenue
Southwood, Farnborough
Hampshire GU14 ONG UK
#07-00 Alexandra Technopark
Singapore 119968
Tel: 1-877-997-9199
Outside USA and Canada: +1 512-437-7089
email: info.ipnetworking_americas@nokia.com
Figure 22Battery Location in the Nokia IP300 Series Appliance 75
Nokia IP300 Series Security Platform Installation Guide1
2Nokia IP300 Series Security Platform Installation Guide
About this Guide
This guide describes how to install and use the Nokia IP300 Series security
platforms—Nokia IP350, Nokia IP355, Nokia IP380, and Nokia IP385.
Installation and maintenance should be performed by experienced technicians
or Nokia-approved service providers only.
This preface provides the following information:
In this Guide
Conventions t his Guide Uses
Related Documentation
In this Guide
This guide is organized into the following chapters and appendixes:
Chapter 1, “Overview” presents a general overview of the IP300 Series
appliance.
Chapter 2, “Installing the Appliance” describes how to rack-mount the
appliance and how to physically connect it to a network and power.
Chapter 3, “Performing the Initial Configuration” describes how to make
the appliance available on the network.
Chapter 4, “Installing and Replacing Network Interface Cards” describes
how to install, monitor, and replace network interface cards (NICs).
Nokia IP300 Series Security Platform Installation Guide3
Chapter 5, “Connecting PMC Network Interface Cards” describes how to
connect to and use each of the supported NICs.
Chapter 6, “Installing and Replacing Other Components” describes how
to install or replace PCMCIA modems, memory, the hard-disk drive, an
encryption accelerator card, and the battery.
Chapter 7, “Installing PC Cards” describes how to install the flash-
memory PC cards.
Chapter 8, “Using the Boot Manager” describes how to use the Nokia
IPSO boot manager.
Chapter 9, “Troubleshooting” discusses problems you might encounter
and proposes solutions to these problems.
Appendix A, “Technical Specifications” gives technical specifications
such as interface characteristics.
Appendix B, “Compliance Information” includes compliance and
regulatory information.
Conventions this Guide Uses
The following sections describe the conventions this guide uses, including
notices, text conventions, and command-line conventions.
Notices
Warning
Warnings advise the user that bodily injury might occur because of a
physical hazard.
4Nokia IP300 Series Security Platform Installation Guide
Caution
Cautions indicate potential equipment damage, equipment
malfunction, loss of performance, loss of data, or interruption of
service.
Note
Notes provide information of special interest or recommendations.
Command-Line Conventions
This section defines the elements of commands that are available in Nokia
Network Security Solutions products. You might encounter one or more of the
following elements on a command-line path.
Conventions t his Guide Uses
Table 1 Command-Line Conventions
ConventionDescription
commandThis required element is usually the product name or other
short word that invokes the product or calls the compiler or
preprocessor script for a compiled Nokia product. It might
appear alone or precede one or more options. You must
spell a command exactly as shown and use lowercase
letters.
ItalicsIndicates a variable in a command that you must supply. For
example:
delete interface if_name
Supply an interface name in place of the variable. For
example:
delete interface nic1
Nokia IP300 Series Security Platform Installation Guide5
Table 1 Command-Line Conventions (continued)
ConventionDescription
angle brackets < > Indicates arguments for which you must supply a value:
retry-limit <1–100>
Supply a value. For example:
retry-limit 60
Square brackets [ ] Indicates optional arguments.
delete [slot slot_num]
For example:
delete slot 3
-flagA flag is usually an abbreviation for a function, menu, or
option name, or for a compiler or preprocessor argument.
You must enter a flag exactly as shown, including the
preceding hyphen.
.extA filename extension, such as .ext, might follow a variable
that represents a filename. Type this extension exactly as
shown, immediately after the name of the file. The extension
might be optional in certain products.
( . , ; + * - / )Punctuation and mathematical notations are literal symbols
that you must enter exactly as shown.
' 'Single quotation marks are literal symbols that you must
enter as shown.
6Nokia IP300 Series Security Platform Installation Guide
Text Conventions
Table 2 describes the text conventions this guide uses.
Table 2 Text Conventions
ConventionDescription
Conventions t his Guide Uses
monospace font
Indicates command syntax, or represents computer
or screen output, for example:
Log error 12453
bold monospace font Indicates text you enter or type, for example:
# configure nat
Key namesKeys that you press simultaneously are linked by a
plus sign (+):
Press Ctrl + Alt + Del.
Menu commandsMenu commands are separated by a greater than
sign (>):
Choose File > Open.
The words enter and typeEnter indicates you type something and then press
the Return or Enter key.
Do not press the Return or Enter key when an
instruction says type.
Italics
• Emphasizes a point or denotes new terms at the
place where they are defined in the text.
• Indicates an external book title reference.
• Indicates a variable in a command:
delete interface
if_name
Nokia IP300 Series Security Platform Installation Guide7
Related Documentation
The documentation set for the Nokia IP300 Series security platform consists
of:
Getting Started Guide and Release Notes for the version of Nokia IPSO
you are using
Nokia IP300 Series Security Platform Installation Guide (this document)
Nokia Network Voyager inline help feature, and Nokia Network Voyager
Reference Guide (online)
CLI Reference Guide for the version of Nokia IPSO you are using
You can find the Nokia IP300 Series Security Platform Installation Guide in
PDF on the Nokia support site (https://support.nokia.com). You can access
inline help and the Nokia Network Voyager Reference Guide from Nokia
Network Voyager.
8Nokia IP300 Series Security Platform Installation Guide
1Overview
This guide describes the installation and use of the Nokia IP300 Series
appliances–the IP350 and IP380 disk-based appliances and the IP355 and
IP385 flash-based appliances. Most of the information for how to use these
appliances is the same. Where differences exist between different IP300
platforms, they are noted in the documentation.
The Nokia IP300 Series appliance combines the power of Nokia IPSO
software with your choice of firewall, VPN, and intrusion detection security
applications. These appliances are ideally suited for growing companies and
satellite offices that want high-performance IP routing combined with the
industry-leading Check Point VPN-1/FireWall-1 enterprise security suite. The
small size of the IP300 Series appliance makes them ideal for installations
that need to conserve space.
As network devices, these appliances support a comprehensive suite of IProuting functions and protocols, including RIPv1/RIPv2, IGRP, OSPF and
BGP4 for unicast traffic, and DVMRP for multicast traffic. The integrated
router functionality eliminates the need for separate intranet and access
routers in security applications.
This chapter provides an overview of the IP300 Series appliance and the
requirements for using it. The following topics are covered:
About the Nokia IP300 Series Disk-Based Appliance
About the Nokia IP300 Series Flash-Based Appliance
Managing the IP300 Series Appliance
About the IP300 Series Appliance
Nokia IP300 Series Security Platform Installation Guide9
Both the IP350 and the IP380 share the same one-rack unit (1 RU) size and
support the same selection of network interface cards. The IP350 appliance
supports a minimum memory configuration of 256 MB, and a maximum
memory configuration of 512 MB. The IP380 applianc e supports a minimum
memory configuration of 256 MB, and a maximum memory configuration of
1 GB.
The Nokia IP300 Series appliance provides built-in hardware-based
encryption acceleration. The IP380 appliance also supports an optional
encryption accelerator card to further enhance VPN performance.
Table 3 Specifications fo r IP300 Series Disk-Based Appliances
FeatureNokia IP350Nokia IP380
Maximum memory size512 MB1 GB
Optional encryption
accelerator card
Line cards
10Nokia IP300 Series Security Platform Installation Guide
NoYes
• 2 two-port 10/100 NICs
• 1 four-port 10/100 NIC
• 2 two-port V2 Copper
Gigabit Ethernet NICs
• 2 two-port Fiber
Gigabit Ethernet NICs
• 2 two-port 10/100 NICs
• 1 four-port 10/100 NIC
• 2 two-port V2 Copper
• 2 two-port Fiber
Gigabit Ethernet NICs
Gigabit Ethernet NICs
About the Nokia IP300 Series Flash-Based Appliance
Table 3 Specifications fo r IP300 Series Disk-Based Appliances
FeatureNokia IP350Nokia IP380
Nokia IPSO version3.93.9
Check Point
(Enforcement Module
support only)
Check Point NGX R60Check Point NGX R60
About the Nokia IP300 Series Flash-Based
Appliance
Both the IP355 and the IP385 share the same one-rack unit (1 RU) size. The
Nokia IP355 and IP385 flash-based appliances support the same cards as
IP350 and IP380 appliances. Both flash-based appliances have a maximum
memory size of 1GB.
Table 4 Specifications for IP300 Series Flash-Based Appliance s
FeatureNokia IP355Nokia IP385
Maximum memory size1 GB1 GB
Compact Flash512 MB512 MB
Optional PC card flash
for logging (PCMCIA slot)
Optional encryption
accelerator card
Nokia IP300 Series Security Platform Installation Guide11
1 GB1 GB
NoYes
1 Overview
Table 4 Specifications for IP300 Series Flash-Based Appliance s
FeatureNokia IP355Nokia IP385
Line cards
Optional diskNoNo
Nokia IPSO version3.93.9
Check Point
(Enforcement Module
support only)
• 2 two-port 10/100 NICs
• 1 four-port 10/100 NIC
• 2 two-port V2 Copper
Gigabit Ethernet NICs
• 1 two-port Fiber
Gigabit Ethernet NICs
Check Point NGX R60Check Point NGX R60
• 2 two-port 10/100 NICs
• 1 four-port 10/100 NIC
• 2 two-port V2 Copper
Gigabit Ethernet NICs
• 1 two-port Fiber
Gigabit Ethernet NICs
Managing the IP300 Series Appliance
You can manage the IP300 Series appliance by using one of the following
interfaces:
Nokia Network Voyage r—an SSL-secured, Web-based element
management interface to Nokia IP security platforms. Network V oyager is
preinstalled on the IP300 Series appliance and enabled through the IPSO
operating system. With Network Voyager, you can manage, monitor, and
configure the IP300 Series appliance from any authorized location within
the network by using a standard Web browser.
For information about how to access Network Voyager and the related
reference materials, see “Accessing Nokia Network Voyager” on page 30.
The IPSO command-line interface (CLI)—an SSHv2-secured interface
that enables you to easily configure Nokia IP security platforms from the
command line. Everything that you can accomplish with Network
Voyager—manage, monitor, and configure the IP300 Series appliance—
you can also accomplish with the CLI.
12Nokia IP300 Series Security Platform Installation Guide
For information about how to access the CLI, see the Nokia CLI
Reference Guide for the version of Nokia IPSO you are using.
management application. With Horizon Manager , you can securely install
and upgrade the Nokia IPSO operating system, plus hardware and thirdparty applications such as Check Point FireWall-1 for Nokia. Horizon
Manager can perform installations and upgrades on up to 2,500 Nokia IP
security platforms, offering administrators the most rapid and dependable
upgrade to Check Point NG.
About the IP300 Series Appliance
The following figures show component locations for the Nokia IP300 Series
appliance.
Figure 1 Component Locations Front View
About the IP300 Series Appliance
PMC interfaces
Status LEDsModem (AUX) port
PCMCIA slotsReset switch
Built-in Ethernet ports
(10/100 Mbps)
Console port
Nokia IP300 Series Security Platform Installation Guide13
1 Overview
Figure 2 Component Locations Rear View
Ethernet Management Ports
The Ethernet management ports are located on the front of the appliance.
Figure 3 shows the layout of the Ethernet management ports and link LEDs.
Note
The Ethernet management port s are i ntended for management purposes.
These ports do not provide the same performance as Ethernet cards in
the PMC slots.
00249
Power plugPower switch
Figure 3 Ethernet Management Ports Details
Activity LED (yellow)
Link LED (green)
RJ-45 connectors
00120
Caution
Cables that connect to the Ethernet ports must be IEEE 802.3
compliant to prevent potential data loss.
14Nokia IP300 Series Security Platform Installation Guide
About the IP300 Series Appliance
Note
Nokia recommends the use of shielded twisted-pair cables and
connectors for best Electromagnetic Interference and Immunity
performance.
The IP300 Series appliance includes two PMC (PCI mezzanine card)
expansion slots for Nokia supported network interface cards. For more
information, see “Four-Port and Two-Port 10/100 Mbps Ethernet Interface,
PMC” on page 46
.
The IP300 Series appliance also includes a PCMCIA slot that supports
PCMCIA modems. See “Installing a PCMCIA Modem” on page 56.
Note
Nokia products only support NICs purchased from Nokia Corpora tion or
Nokia-approved resellers. The Nokia Global Support Services group can
only provide support for Nokia products that use Nokia-approved
accessories. For sales or reseller information, contact a Nokia service
provider listed in the “Nokia Contact Information” on page 3.
Built-in Console Port
Use the built-in console port, shown in Figure 1, to supply the information
that makes the appliance available on the network. Figure 4 provides pin
assignment information for console connections.
Nokia IP300 Series Security Platform Installation Guide15
16Nokia IP300 Series Security Platform Installation Guide
Built-in AUX Port
1
You can use the AUX port, shown in Figure 1, to establish a modem
connection for managing the appliance. Figure 5 provides pin assignment
information for modem connections.
You can monitor the basic operation of IP300 Series appliance and network
interface cards (NICs) by checking their status LEDs. The system status LEDs
are located on the front panel of the appliance, as Figure 6 shows.
Figure 6 Appliance Status LEDs
Power-status
Voltage
Table 5 Appliance Status LEDs
Status IndicationExplanation
Solid Power on
Solid Unit is experiencing an
internal Voltage problem
Fan problem
LED Front Panel
Symbol
Blinking The unit is experiencing
Solid redOne or more fans are not
18Nokia IP300 Series Security Platform Installation Guide
a temperature problem
operating properly, or a
5V, 3.3V, or 12V fuse is
blown
The location and meaning of the status LEDs for network interface cards are
explained in Chapter 5, “Connecting PMC Network Interface Cards.”
For information on the built-in Ethernet interface LEDs, see “Ethernet
Management Ports” on page 14.
For information on the two-port Ethernet card LEDs, see “Four-Port and
Two-Port 10/100 Mbps Ethernet Interface, PMC” on page 46.
Site Requirements
Before you install a Nokia IP300 Series appliance, ensure that your computer
room or wiring closet conforms to the environmental specifications listed in
Appendix A, “Technical Specifications.”
Product Disposal
Site Requirements
At the end of its useful life, your appliance and all peripherals included with
it, including power cords and cables, must be disposed of in accordance with
all applicable national, state, and local laws and regulations. These devices
contain materials and components that must be disposed of properly.
Therefore, to help prevent damage to the environment, Nokia encourages you
to dispose of these devices in an environmentally-friendly manner.
The following resources are available to you to help with equipment-disposal
decisions:
Many Nokia products are labeled with information about the materials
used in their manufacture that can help those who will process equipment
after you have disposed of it.
The Nokia web site (http://www.nokia.com) provides information about
our environmental programs and practices, which includes details about
materials used in manufacturing and end-of-life practices. You can also
find your product’ s Eco Declaration , which provides basic information o n
the environmental attributes of the product covering material use,
packaging, disassembly, and recycling.
Nokia IP300 Series Security Platform Installation Guide19
1 Overview
Contact your local waste management agencies for guidelines specific to
your area.
The crossed-out wheeled bin means that within the European Union the product
must be taken to separate collection at the product end-of-life. This applies to your
device but also to any enhancements marked with this symbol. Do not dispose of
these products as unsorted municipal waste.
Warning
Hazardous radiation exposure can occur if you use controls, make
performance adjustments, or follow procedures that are not described in
this document.
Warning
An explosion can occur if the battery is incorrectly placed. Replace only
with the same or equivalent type battery recommended by the
manufacturer. Dispose of used batteries according to the manufacturer's
instructions.
Warning
To reduce the risk of fire, electric shock, and injury when you use
telephone equipment, follow basic safety precautions. Do not use the
product near water.
Caution
Do not place objects over the ventilation holes on the IP350 or IP380
appliance. The components might overheat and become damaged.
20Nokia IP300 Series Security Platform Installation Guide
Caution
For IP300 Series appliances intended for shipment outside of the
United States, the cord might be optional. If a cord is not provided,
use a power cord rated at 6A, 250V, maximum 15 feet long, made of
HAR cordage and IEC fittings approved by the country of end use.
Software Requirements
The Nokia IP300 Series appliance supports the following operating system
and applications:
Operating System Requirements—IPSO v3.5.1, v3.7 and later. Flash-
based appliances require IPSO v3.9 or later.
Firewall and VPN Software Requirements—Check Point NG VPN-1/
FW-1 FP2 or higher.
Software Requirements
For information about changes to the software requirements or additional
applications that have become available since this guide was published,
contact your Nokia service provider, as listed in “Nokia Contact Information”
on page 3.
Nokia IP300 Series Security Platform Installation Guide21
1 Overview
22Nokia IP300 Series Security Platform Installation Guide
Loading...
+ 100 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.