The information in this document is subject to change without notice. The statements, configurations, technical data, and
recommendations in this document are believed to be accurate and reliable, but are presented without express or implied
warranty. Users must take full responsibility for their applications of any products specified in this document. The
information in this document is proprietary to Nortel Networks Inc.
Trademarks
Nortel, the Nortel logo, and the Globemark are trademarks of Nortel Networks.
Adobe and Acrobat Reader are trademarks of Adobe Systems Incorporated.
HyperTerminal is a trademark of Hilgraeve, Inc.
Intel is a trademark of Intel Corporation.
Microsoft, Windows, and Windows NT are trademarks of Microsoft Corporation.
Netscape and Netscape Navigator are trademarks of Netscape Communications Corporation.
All other trademarks are the property of their respective owners.
Statement of conditions
In the interest of improving internal design, operational function, and/or reliability, Nortel Networks Inc. reserves the
right to make changes to the products described in this document without notice.
Nortel Networks Inc. does not assume any liability that may occur due to the use or application of the product(s) or
circuit layout(s) described herein.
USA requirements only
Federal Communications Commission (FCC) Compliance Notice: Radio Frequency Notice
Note: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to
Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when
the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency
energy. If it is not installed and used in accordance with the instruction manual, it may cause harmful interference to
radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which
case users will be required to take whatever measures may be necessary to correct the interference at their own expense.
European requirements only
EN 55 022 statement
This is to certify that the Nortel Networks VPN Router 2750 is shielded against the generation of radio interference in
accordance with the application of Council Directive 89/336/EEC, Article 4a. Conformity is declared by the application
of EN 55 022 Class A (CISPR 22).
NN46110-318 02.01
War ning: This is a Class A product. In a domestic environment, this product may cause radio interference, in which
case, the user may be required to take appropriate measures.
Achtung: Dieses ist ein Gerät der Funkstörgrenzwertklasse A. In Wohnbereichen können bei Betrieb dieses Gerätes
Rundfunkstörungen auftreten, in welchen Fällen der Benutzer für entsprechende Gegenmaßnahmen verantwortlich ist.
Attention: Ceci est un produit de Classe A. Dans un environnement domestique, ce produit risque de créer des
interférences radioélectriques, il appartiendra alors à l’utilisateur de prendre les mesures spécifiques appropriées.
EC Declaration of Conformity
This product conforms (or these products conform) to the provisions of the R&TTE Directive 1999/5/EC.
Japan/Nippon requirements only
Denan statement
3
Voluntary Control Council for Interference (VCCI) statement
Taiwan requirements
Bureau of Standards, Metrology and Inspection (BSMI) statement
Nortel VPN Router Installation — VPN Router 2750
4
Canada requirements only
Canadian Department of Communications Radio Interference Regulations
This digital apparatus (VPN Router 2750) does not exceed the Class A limits for radio-noise emissions from digital
apparatus as set out in the Radio Interference Regulations of the Canadian Department of Communications.
Règlement sur le brouillage radioélectrique du ministère des Communications
Cet appareil numérique (VPN Router 2750) respecte les limites de bruits radioélectriques visant les appareils
numériques de classe A prescrites dans le Règlement sur le brouillage radioélectrique du ministère des Communications
du Canada.
Nortel Networks Inc. software license agreement
This Software License Agreement (“License Agreement”) is between you, the end-user (“Customer”) and Nortel
Networks Corporation and its subsidiaries and affiliates (“Nortel Networks”). PLEASE READ THE FOLLOWING
CAREFULLY. YOU MUST ACCEPT THESE LICENSE TERMS IN ORDER TO DOWNLOAD AND/OR USE THE
SOFTWARE. USE OF THE SOFTWARE CONSTITUTES YOUR ACCEPTANCE OF THIS LICENSE
AGREEMENT. If you do not accept these terms and conditions, return the Software, unused and in the original shipping
container, within 30 days of purchase to obtain a credit for the full purchase price.
“Software” is owned or licensed by Nortel Networks, its parent or one of its subsidiaries or affiliates, and is copyrighted
and licensed, not sold. Software consists of machine-readable instructions, its components, data, audio-visual content
(such as images, text, recordings or pictures) and related licensed materials including all whole or partial copies. Nortel
Networks grants you a license to use the Software only in the country where you acquired the Software. You obtain no
rights other than those granted to you under this License Agreement. You are responsible for the selection of the
Software and for the installation of, use of, and results obtained from the Software.
1.Licensed Use of Software. Nortel Networks grants Customer a nonexclusive license to use a copy of the Software
on only one machine at any one time or to the extent of the activation or authorized usage level, whichever is applicable.
To the extent Software is furnished for use with designated hardware or Customer furnished equipment (“CFE”),
Customer is granted a nonexclusive license to use Software only on such hardware or CFE, as applicable. Software
contains trade secrets and Customer agrees to treat Software as confidential information using the same care and
discretion Customer uses with its own similar information that it does not wish to disclose, publish or disseminate.
Customer will ensure that anyone who uses the Software does so only in compliance with the terms of this Agreement.
Customer shall not a) use, copy, modify, transfer or distribute the Software except as expressly authorized; b) reverse
assemble, reverse compile, reverse engineer or otherwise translate the Software; c) create derivative works or
modifications unless expressly authorized; or d) sublicense, rent or lease the Software. Licensors of intellectual property
to Nortel Networks are beneficiaries of this provision. Upon termination or breach of the license by Customer or in the
event designated hardware or CFE is no longer in use, Customer will promptly return the Software to Nortel Networks or
certify its destruction. Nortel Networks may audit by remote polling or other reasonable means to determine Customer’s
Software activation or usage levels. If suppliers of third party software included in Software require Nortel Networks to
include additional or different terms, Customer agrees to abide by such terms provided by Nortel Networks with respect
to such third party software.
2.Warranty. Except as may be otherwise expressly agreed to in writing between Nortel Networks and Customer,
Software is provided “AS IS” without any warranties (conditions) of any kind. NORTEL NETWORKS DISCLAIMS
ALL WARRANTIES (CONDITIONS) FOR THE SOFTWARE, EITHER EXPRESS OR IMPLIED, INCLUDING,
BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nortel Networks is not obligated to
provide support of any kind for the Software. Some jurisdictions do not allow exclusion of implied warranties, and, in
such event, the above exclusions may not apply.
NN46110-318 02.01
3.Limitation of Remedies. IN NO EVENT SHALL NORTEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE
LIABLE FOR ANY OF THE FOLLOWING: a) DAMAGES BASED ON ANY THIRD PARTY CLAIM; b) LOSS OF,
OR DAMAGE TO, CUSTOMER’S RECORDS, FILES OR DATA; OR c) DIRECT, INDIRECT, SPECIAL,
INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING LOST PROFITS OR SAVINGS),
WHETHER IN CONTRACT, TORT OR OTHERWISE (INCLUDING NEGLIGENCE) ARISING OUT OF YOUR
USE OF THE SOFTWARE, EVEN IF NORTEL NETWORKS, ITS AGENTS OR SUPPLIERS HAVE BEEN
ADVISED OF THEIR POSSIBILITY. The forgoing limitations of remedies also apply to any developer and/or supplier
of the Software. Such developer and/or supplier is an intended beneficiary of this Section. Some jurisdictions do not
allow these limitations or exclusions and, in such event, they may not apply.
4.General
a.If Customer is the United States Government, the following paragraph shall apply: All Nortel Networks
Software available under this License Agreement is commercial computer software and commercial computer
software documentation and, in the event Software is licensed for or on behalf of the United States
Government, the respective rights to the software and software documentation are governed by Nortel
Networks standard commercial license in accordance with U.S. Federal Regulations at 48 C.F.R. Sections
12.212 (for non-DoD entities) and 48 C.F.R. 227.7202 (for DoD entities).
b.Customer may terminate the license at any time. Nortel Networks may terminate the license if Customer fails
to comply with the terms and conditions of this license. In either event, upon termination, Customer must
either return the Software to Nortel Networks or certify its destruction.
c.Customer is responsible for payment of any taxes, including personal property taxes, resulting from
Customer’s use of the Software. Customer agrees to comply with all applicable laws including all applicable
export and import laws and regulations.
d.Neither party may bring an action, regardless of form, more than two years after the cause of the action arose.
e.The terms and conditions of this License Agreement form the complete and exclusive agreement between
Customer and Nortel Networks.
f.This License Agreement is governed by the laws of the country in which Customer acquires the Software. If
the Software is acquired in the United States, then this License Agreement is governed by the laws of the state
of New York.
The following section details what’s new in Nortel VPN Router Installation—
VPN Router 2750 (NN46110-318) for Release 7.05.300.
Features
See the following sections for information about feature-related changes.
1000BASE-T (1000 GT) Ethernet card
The 1000BASE-T (1000 GT) Ethernet card is new for Release 7.05.300. See
“1000BASE-T (1000 GT) Ethernet interface card LEDs” on page 43 and
“1000BASE-T (1000 GT) Ethernet interface card” on page 85.
15
Nortel VPN Router Installation — VPN Router 2750
16 New in this release
NN46110-318 02.01
How to get help
This chapter explains how to get help for Nortel products and services.
Finding the latest updates on the Nortel Web site
The content of this documentation was current at the time the product was
released. To check for updates to the latest documentation and software for the
VPN Router 2750, go to:
www.nortel.com/support
Select Security & VPN and then, in the section called Virtual Private Networking
(VPN), IPSEC, and SSL, click the appropriate VPN Router product.
Getting help from the Nortel Web site
17
The best way to get technical support for Nortel products is from the Nortel
Technical Support Web site:
www.nortel.com/support
Nortel VPN Router Installation — VPN Router 2750
18 How to get help
This site provides quick access to software, documentation, bulletins, and tools to
address issues with Nortel products. From this site you can:
•download software, documentation, and product bulletins
•search the Technical Support site and the Nortel Knowledge Base for answers
to technical issues
•sign up for automatic notification of new software and documentation for
Nortel equipment
•open and manage technical support cases
Getting help over the phone from a Nortel Solutions
Center
If you do not find the information you require on the Nortel Technical Support
Web site, and you have a Nortel support contract, you can also get help over the
phone from a Nortel Solutions Center.
In North America, call 1-800-4NORTEL (1-800-466-7835).
Outside North America, go to the following Web site to obtain the phone number
for your region:
www.nortel.com/callus
Getting help from a specialist by using an Express
Routing Code
To access some Nortel Technical Solutions Centers, you can use an Express
Routing Code (ERC) to quickly route your call to a specialist in your Nortel
product or service. To locate the ERC for your product or service, go to:
www.nortel.com/erc
NN46110-318 02.01
How to get help 19
Getting help through a Nortel distributor or reseller
If you purchased a service contract for your Nortel product from a distributor or
authorized reseller, contact the technical support staff for that distributor or
reseller.
Nortel VPN Router Installation — VPN Router 2750
20 How to get help
NN46110-318 02.01
Preface
The Nortel VPN Router 2750 is part of the Nortel VPN router product family. The
VPN Nortel Routers support secure, reliable IP VPNs in a single, integrated
hardware device. Throughout this guide, the VPN Router is also referred to as the gateway.
This guide provides instructions for installing the VPN Router 2750 for the first
time and for replacing any field replaceable unit (FRU). This guide also provides
some initial configuration information and includes technical specifications for
the VPN Router 2750.
For complete information about configuring and monitoring the VPN Router
2750, see the documentation on the software CD. For information about VPN
Router documentation, see “Related publications” on page 23.
Before you begin
21
This guide is intended for qualified service personnel who are installing the VPN
Router 2750 for the first time or who need to install or replace any of the
following field replaceable units (FRU):
•LAN, WAN, and serial interface cards
•VPN Router Security Accelerator card
•SSL VPN Module 1000
•dual inline memory modules (DIMM)
Before you install the VPN Router 2750, ensure that you install all network wiring
on the premises using standard cable system practices.
Nortel VPN Router Installation — VPN Router 2750
22 Preface
Text conventions
This guide uses the following text conventions:
Acronyms
bold Courier text
italic textIndicates new terms and book titles.
plain Courier
text
separator ( > )Shows menu paths.
This guide uses the following acronyms:
ADSLasymmetric digital subscriber line
AESAdvanced Encryption Standard
AISalarm indication signal
Indicates command names and options and text that
you need to enter.
Example: Use the
Example: Enter
Indicates system output, for example, prompts and
system messages.
Example:
Example: Choose Status > Health Check.
File not found.
show health command.
terminal paging {off | on}.
CSU/DSUchannel service unit/digital service unit
DESData Encryption Standard
DIMMdual inline memory module
DTEdata terminal equipment
FRUfield replaceable unit
GUIgraphical user interface
HSSIHigh Speed Serial Interface
IPInternet Protocol
IPsecIP Security
NN46110-318 02.01
ISDNIntegrated Services Digital Network
LANlocal area network
LEDlight emitting diode
LOSloss of signal
OOFout of frame
PCIperipheral component interconnect
SSLSecure Sockets Layer
VPNvirtual private network
WANwide area network
Related publications
For complete information about configuring, monitoring, and managing the VPN
Router 2750, refer to the following publications (included on the software CD):
Preface 23
•Release notes provide the latest information, including brief descriptions of
the new features, problems fixed in this release, and known problems and
workarounds.
•Nortel VPN Router Configuration — Basic Features (NN46110-500)
introduces the product and provides information about initial configuration.
•Nortel VPN Router Security — Servers, Authentication, and Certificates
(NN46110-600) provides instructions for configuring authentication servers
and services, as well as digital certificates.
•Nortel VPN Router Security — Firewalls, Filters, NAT, and QoS
(NN46110-601) provides instructions for configuring the Stateful Firewall,
NAT, and VPN Router interface and tunnel filters.
•Nortel VPN Router Configuration — Tunneling Protocols (NN46110-503)
provides instructions for configuring the tunneling protocols IPsec, L2TP,
PPTP, and L2F.
•Nortel VPN Router Configuration— Advanced Features (NN46110-502)
provides instructions for configuring 802.1Q VLANs, circuitless IP, advanced
WAN settings, PPP, PPPoE, frame relay, ADSL and ATM, T1/E1 CSU/DSU
interfaces, dial services and BIS, DLSw, IPX, and Hardware Accelerator
cards.
Nortel VPN Router Installation — VPN Router 2750
24 Preface
•Nortel VPN Router Configuration — Routing (NN46110-504) provides
instructions for configuring RIP, OSPF, and VRRP, as well as instructions for
configuring ECMP, routing policy services, and client address redistribution.
•Nortel VPN Router Configuration — SSL VPN Services (NN46110-501)
provides instructions for configuring services on the SSL VPN Module 1000,
including authentication, networks, user groups, and portal links.
•Nortel VPN Router Using the Command Line Interface (NN46110-507)
provides syntax, descriptions, and examples for the commands that you can
use to configure, manage, and monitor the gateway.
•Nortel VPN Router Troubleshooting (NN46110-602) provides information
about backup and recovery, file management, upgrading software, and
troubleshooting. This guide also provides instructions for monitoring gateway
status and performance.
Printed technical manuals
You can print selected technical manuals and release notes free, directly from the
Internet. Go to www.nortel.com/documentation, find the product for which you
need documentation, then locate the specific category and model or version for
your hardware or software product. Use Adobe Reader to open the manuals and
release notes, search for the sections you need, and print them on most standard
printers. Go to Adobe Systems at www.adobe.com to download a free copy of the
Adobe Reader.
NN46110-318 02.01
Chapter 1
Installing the Nortel VPN Router 2750 chassis
This chapter describes how to install the VPN Router 2750 chassis.
Note: Before you install the chassis, ensure that you install all network
wiring on the premises using standard cable system practices.
This chapter contains the following topics:
TopicPage
Description of the Nortel VPN Router 275025
Preparing to install the Nortel VPN Router 275026
Installing the chassis29
25
Description of the Nortel VPN Router 2750
With the VPN Router 2750, you can supply scalable, secure, and robust Internet
Protocol (IP) virtual private networks (VPN) across the public data network. The
VPN Router 2750 provides routing, firewall, bandwidth management, encryption,
authentication, and data integrity services to ensure secure tunneling across IP
networks and the Internet.
The VPN Router 2750 is available in two models:
•VPN Router 2750 with five tunnels (128-bit)
•VPN Router 2750 with 2 000 tunnels (128-bit)
Nortel VPN Router Installation — VPN Router 2750
26 Chapter 1 Installing the Nortel VPN Router 2750 chassis
Figure 1 shows the front view of the Nortel VPN Router 2750.
Figure 1 Front view of the Nortel VPN Router 2750
Alert
Boot/Ready
VPN Router 2750
The VPN Router 2750 chassis provides the following:
•two 10/100 Ethernet local area network (LAN) ports on the base system
•one serial port for out-of-band management of the VPN Router 2750
•four expansion peripheral component interconnect (PCI) slots that can contain
optional interface cards, a VPN Router Security Accelerator card, and the
Secure Sockets Layer (SSL) VPN Module 1000
•a memory of 256 MB that is upgradable to 512 MB total
CS260001D
Preparing to install the Nortel VPN Router 2750
Before you begin the installation, verify that:
•Your shipment is complete and undamaged.
•You have the cables, tools, and other equipment that you need.
•Your installation site meets the physical, electrical, and environmental
requirements.
The sections that follow provide information to help you prepare for installation.
NN46110-318 02.01
Shipment contents
In addition to the gateway and this guide, the shipping container for the VPN
Router 2750 contains a number of hardware accessories and other items (Table 1).
Note: Nortel does not ship a power cord with the VPN Router 2750
unless you order one.
Table 1 Items shipped with the Nortel VPN Router 2750
QuantityItemPurpose
1Rack mount shelfSupports the chassis in the equipment rack
410-32 panhead screwsSecures the rack-mount shelf and the chassis to
410-32 panhead cage nutsUsed if the equipment rack does not have
4Rubber feetUsed to install the chassis on a surface
1Antistatic wrist strapDirects the discharge of static electricity from
1Molded serial cable
DB9/DB25-to-DB9/DB25
1Nortel VPN Router
Installation — VPN Router
2750 (this book)
1Recovery disketteUsed to restore the software image and file
1Nortel VPN Router
software kit
1Nortel VPN client kitContains VPN Client software and
1Sheet of labelsUsed to note IP address (apply to front bezel)
Chapter 1 Installing the Nortel VPN Router 2750 chassis 27
the equipment rack
threaded rail holes
your body to the chassis to prevent damage to
sensitive electronic components
Connects the VPN Router 2750 to a PC or to a
local terminal
Provides instructions for installing the chassis
and hardware options
system
Contains VPN Router software and
documentation on CD
documentation on CD
Inspect all items for shipping damage. If you detect any damage, do not install the
VPN Router 2750. Call the Nortel Technical Solutions Center in your area (see
“How to get help” on page 17).
Nortel VPN Router Installation — VPN Router 2750
28 Chapter 1 Installing the Nortel VPN Router 2750 chassis
Additional equipment
You need items that are not included in the VPN Router 2750 shipping container.
Before you begin the installation, ensure that you have all the cables, tools, and
other equipment that you need.
Cables
You need cables that are not included in the VPN Router 2750 shipping container.
For information about which cables are shipped and which ones you can order,
see “Connecting communications cables” on page 36. If you do not have the
proper cables, contact your network administrator.
Hardware for mounting the chassis in an equipment rack
To install the VPN Router 2750 in an equipment rack, you need a Phillips
screwdriver and an equipment rack that meets the following specifications:
•heavy-duty steel construction
•width of 19 in. (48.26 cm) and depth of 24 in. (60.96 cm)
•Electronic Industries Association (EIA) standard hole-spacing
If the rack does not have threaded rail holes, you must use the cage nuts shipped
with the VPN Router 2750.
Site requirements
The installation site must provide sufficient free space around the VPN Router
2750 to ensure proper ventilation and access for servicing. For information about
the physical, electrical, and environmental requirements for the VPN Router
2750, see Appendix A, “Technical specifications,” on page 77.
NN46110-318 02.01
Installing the chassis
To install the VPN Router 2750, do one of the following:
•Position the chassis on a flat, sturdy, horizontal surface.
•Mount the chassis in a standard equipment rack (see “Installing the chassis in
an equipment rack” on page 30).
Installing the chassis on a flat surface
If you decide to place the VPN Router 2750 on a flat surface, ensure that the
surface is large enough for the gateway and sturdy enough to support the
combined weight of the VPN Router 2750 and the cables that you attach to it.
The VPN Router 2750 accessory kit includes four rubber feet that you can attach
to the bottom of the gateway. Figure 2 shows the placement of these rubber feet.
Figure 2 Placement of rubber feet on the bottom of the chassis
Chapter 1 Installing the Nortel VPN Router 2750 chassis 29
Attach feet (4)
CS160016A
Nortel VPN Router Installation — VPN Router 2750
30 Chapter 1 Installing the Nortel VPN Router 2750 chassis
Installing the chassis in an equipment rack
To mount the VPN Router 2750 in an equipment rack, you need the following
equipment:
•a standard 19-inch equipment rack
•four screws (supplied with the chassis)
•four cage nuts (supplied with the chassis) if the rack does not have threaded
rail holes
•a #2 Phillips screwdriver
Rack-mount recommendations
When you mount the chassis in the equipment rack, observe the following
standard recommendations:
•Nortel recommends a maximum ambient temperature of 40
that the internal temperature of the rack does not exceed (104
o
C (104oF). Ensure
o
F).
•Do not block the power supply vents or otherwise restrict air flow when
installing the chassis in the rack.
•Stabilize your rack so that it does not tip over under the weight of the gateway
and other devices.
•Ensure that the electrical branch circuits can handle the VPN Router 2750 and
other units in the rack before you install and turn on the gateway.
•Maintain a reliable earth-ground path in the rack system. You must connect
the gateway to an earth ground.
Attaching the shelf in the equipment rack
The VPN Router 2750 ships with a rack-mount shelf to support the chassis in the
equipment rack.
To attach the shelf to the inside of the equipment rack:
1If the holes in the rack’s vertical supports are not threaded, attach a cage nut in
four locations at the front of the rack (Figure 3 on page 31).
NN46110-318 02.01
Loading...
+ 78 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.