The information in this document is subject to change without notice. The statements, configurations, technical data, and
recommendations in this document are believed to be accurate and reliable, but are presented without express or implied
warranty. Users must take full responsibility for their applications of any products specified in this document. The
information in this document is proprietary to Nortel Networks Inc.
Trademarks
Nortel, the Nortel logo, the Globemark, and Contivity are trademarks of Nortel Networks.
Adobe and Acrobat Reader are trademarks of Adobe Systems Incorporated.
HyperTerminal is a trademark of Hilgraeve, Inc.
Intel is a trademark of Intel Corporation.
Microsoft, Windows, and Windows NT are trademarks of Microsoft Corporation.
Netscape and Netscape Navigator are trademarks of Netscape Communications Corporation.
All other trademarks are the property of their respective owners.
Statement of conditions
In the interest of improving internal design, operational function, and/or reliability, Nortel Networks Inc. reserves the
right to make changes to the products described in this document without notice.
Nortel Networks Inc. does not assume any liability that may occur due to the use or application of the product(s) or
circuit layout(s) described herein.
USA requirements only
Federal Communications Commission (FCC) Compliance Notice: Radio Frequency Notice
Note: This equipment has been tested and found to comply with the limits for a Class A digital device, pursuant to
Part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when
the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency
energy. If it is not installed and used in accordance with the instruction manual, it may cause harmful interference to
radio communications. Operation of this equipment in a residential area is likely to cause harmful interference, in which
case users will be required to take whatever measures may be necessary to correct the interference at their own expense.
European requirements only
EN 55 022 statement
This is to certify that the Nortel Networks VPN Router 600 is shielded against the generation of radio interference in
accordance with the application of Council Directive 89/336/EEC, Article 4a. Conformity is declared by the application
of EN 55 022 Class A (CISPR 22).
War ning: This is a Class A product. In a domestic environment, this product may cause radio interference, in which
case, the user may be required to take appropriate measures.
Achtung: Dieses ist ein Gerät der Funkstörgrenzwertklasse A. In Wohnbereichen können bei Betrieb dieses Gerätes
Rundfunkstörungen auftreten, in welchen Fällen der Benutzer für entsprechende Gegenmaßnahmen verantwortlich ist.
NN46110-308 02.01
Attention: Ceci est un produit de Classe A. Dans un environnement domestique, ce produit risque de créer des
interférences radioélectriques, il appartiendra alors à l’utilisateur de prendre les mesures spécifiques appropriées.
EC Declaration of Conformity
This product conforms (or these products conform) to the provisions of the R&TTE Directive 1999/5/EC.
Japan/Nippon requirements only
Denan statement
Voluntary Control Council for Interference (VCCI) statement
3
Taiwan requirements
Bureau of Standards, Metrology and Inspection (BSMI) statement
Canada requirements only
Canadian Department of Communications Radio Interference Regulations
This digital apparatus (VPN Router 600) does not exceed the Class A limits for radio-noise emissions from digital
apparatus as set out in the Radio Interference Regulations of the Canadian Department of Communications.
Nortel VPN Router Installation — VPN Router 600
4
Règlement sur le brouillage radioélectrique du ministère des Communications
Cet appareil numérique (VPN Router 600) respecte les limites de bruits radioélectriques visant les appareils numériques
de classe A prescrites dans le Règlement sur le brouillage radioélectrique du ministère des Communications du Canada.
Nortel Networks Inc. software license agreement
This Software License Agreement (“License Agreement”) is between you, the end-user (“Customer”) and Nortel
Networks Corporation and its subsidiaries and affiliates (“Nortel Networks”). PLEASE READ THE FOLLOWING
CAREFULLY. YOU MUST ACCEPT THESE LICENSE TERMS IN ORDER TO DOWNLOAD AND/OR USE THE
SOFTWARE. USE OF THE SOFTWARE CONSTITUTES YOUR ACCEPTANCE OF THIS LICENSE
AGREEMENT. If you do not accept these terms and conditions, return the Software, unused and in the original shipping
container, within 30 days of purchase to obtain a credit for the full purchase price.
“Software” is owned or licensed by Nortel Networks, its parent or one of its subsidiaries or affiliates, and is copyrighted
and licensed, not sold. Software consists of machine-readable instructions, its components, data, audio-visual content
(such as images, text, recordings or pictures) and related licensed materials including all whole or partial copies. Nortel
Networks grants you a license to use the Software only in the country where you acquired the Software. You obtain no
rights other than those granted to you under this License Agreement. You are responsible for the selection of the
Software and for the installation of, use of, and results obtained from the Software.
1.Licensed Use of Software. Nortel Networks grants Customer a nonexclusive license to use a copy of the Software
on only one machine at any one time or to the extent of the activation or authorized usage level, whichever is applicable.
To the extent Software is furnished for use with designated hardware or Customer furnished equipment (“CFE”),
Customer is granted a nonexclusive license to use Software only on such hardware or CFE, as applicable. Software
contains trade secrets and Customer agrees to treat Software as confidential information using the same care and
discretion Customer uses with its own similar information that it does not wish to disclose, publish or disseminate.
Customer will ensure that anyone who uses the Software does so only in compliance with the terms of this Agreement.
Customer shall not a) use, copy, modify, transfer or distribute the Software except as expressly authorized; b) reverse
assemble, reverse compile, reverse engineer or otherwise translate the Software; c) create derivative works or
modifications unless expressly authorized; or d) sublicense, rent or lease the Software. Licensors of intellectual property
to Nortel Networks are beneficiaries of this provision. Upon termination or breach of the license by Customer or in the
event designated hardware or CFE is no longer in use, Customer will promptly return the Software to Nortel Networks or
certify its destruction. Nortel Networks may audit by remote polling or other reasonable means to determine Customer’s
Software activation or usage levels. If suppliers of third party software included in Software require Nortel Networks to
include additional or different terms, Customer agrees to abide by such terms provided by Nortel Networks with respect
to such third party software.
2.Warranty. Except as may be otherwise expressly agreed to in writing between Nortel Networks and Customer,
Software is provided “AS IS” without any warranties (conditions) of any kind. NORTEL NETWORKS DISCLAIMS
ALL WARRANTIES (CONDITIONS) FOR THE SOFTWARE, EITHER EXPRESS OR IMPLIED, INCLUDING,
BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nortel Networks is not obligated to
provide support of any kind for the Software. Some jurisdictions do not allow exclusion of implied warranties, and, in
such event, the above exclusions may not apply.
3.Limitation of Remedies. IN NO EVENT SHALL NORTEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE
LIABLE FOR ANY OF THE FOLLOWING: a) DAMAGES BASED ON ANY THIRD PARTY CLAIM; b) LOSS OF,
OR DAMAGE TO, CUSTOMER’S RECORDS, FILES OR DATA; OR c) DIRECT, INDIRECT, SPECIAL,
INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING LOST PROFITS OR SAVINGS),
WHETHER IN CONTRACT, TORT OR OTHERWISE (INCLUDING NEGLIGENCE) ARISING OUT OF YOUR
USE OF THE SOFTWARE, EVEN IF NORTEL NETWORKS, ITS AGENTS OR SUPPLIERS HAVE BEEN
ADVISED OF THEIR POSSIBILITY. The forgoing limitations of remedies also apply to any developer and/or supplier
of the Software. Such developer and/or supplier is an intended beneficiary of this Section. Some jurisdictions do not
allow these limitations or exclusions and, in such event, they may not apply.
NN46110-308 02.01
4.General
a.If Customer is the United States Government, the following paragraph shall apply: All Nortel Networks
Software available under this License Agreement is commercial computer software and commercial computer
software documentation and, in the event Software is licensed for or on behalf of the United States
Government, the respective rights to the software and software documentation are governed by Nortel
Networks standard commercial license in accordance with U.S. Federal Regulations at 48 C.F.R. Sections
12.212 (for non-DoD entities) and 48 C.F.R. 227.7202 (for DoD entities).
b.Customer may terminate the license at any time. Nortel Networks may terminate the license if Customer fails
to comply with the terms and conditions of this license. In either event, upon termination, Customer must
either return the Software to Nortel Networks or certify its destruction.
c.Customer is responsible for payment of any taxes, including personal property taxes, resulting from
Customer’s use of the Software. Customer agrees to comply with all applicable laws including all applicable
export and import laws and regulations.
d.Neither party may bring an action, regardless of form, more than two years after the cause of the action arose.
e.The terms and conditions of this License Agreement form the complete and exclusive agreement between
Customer and Nortel Networks.
f.This License Agreement is governed by the laws of the country in which Customer acquires the Software. If
the Software is acquired in the United States, then this License Agreement is governed by the laws of the state
of New York.
The following section details what’s new in Nortel VPN Router Installation—
VPN Router 600 (NN46110-308) for Release 7.05.300:
Features
See the following section for information about feature changes:
1000BASE-T (1000 GT) Ethernet card
The 100 GT Ethernet card replaces the 10/ 100BASE-TX Ethernet card. See
“1000BASE-T (1000 GT) Ethernet interface card LEDs” on page 37 and
“1000BASE-T (1000 GT) Ethernet interface card” on page 77.
15
Nortel VPN Router Installation — VPN Router 600
16 New in this release
NN46110-308 02.01
How to get help
This chapter explains how to get help for Nortel products and services.
Finding the latest updates on the Nortel Web site
The content of this documentation was current at the time the product was
released. To check for updates to the latest documentation and software for the
VPN Router 600, go to:
www.nortel.com/support
Select Security & VPN and then, in the section called Virtual Private Networking
(VPN), IPSEC, and SSL, click the appropriate VPN Router product.
Getting help from the Nortel Web site
17
The best way to get technical support for Nortel products is from the Nortel
Technical Support Web site:
www.nortel.com/support
Nortel VPN Router Installation — VPN Router 600
18 How to get help
This site provides quick access to software, documentation, bulletins, and tools to
address issues with Nortel products. From this site you can:
•download software, documentation, and product bulletins
•search the Technical Support site and the Nortel Knowledge Base for answers
to technical issues
•sign up for automatic notification of new software and documentation for
Nortel equipment
•open and manage technical support cases
Getting help over the phone from a Nortel Solutions
Center
If you do not find the information you require on the Nortel Technical Support
Web site, and you have a Nortel support contract, you can also get help over the
phone from a Nortel Solutions Center.
In North America, call 1-800-4NORTEL (1-800-466-7835).
Outside North America, go to the following Web site to obtain the phone number
for your region:
www.nortel.com/callus
Getting help from a specialist by using an Express
Routing Code
To access some Nortel Technical Solutions Centers, you can use an Express
Routing Code (ERC) to quickly route your call to a specialist in your Nortel
product or service. To locate the ERC for your product or service, go to:
www.nortel.com/erc
NN46110-308 02.01
How to get help 19
Getting help through a Nortel distributor or reseller
If you purchased a service contract for your Nortel product from a distributor or
authorized reseller, contact the technical support staff for that distributor or
reseller.
Nortel VPN Router Installation — VPN Router 600
20 How to get help
NN46110-308 02.01
Preface
The VPN Router 600 is part of the Nortel VPN Router product family. Nortel
VPN Routers support secure, reliable IP VPNs in a single, integrated hardware
device. Throughout this guide, the VPN Router 600 is also referred to as the
gateway.
This guide provides instructions on how to install and start the VPN Router 600
and how to install and replace option cards and the dual inline memory module
(DIMM). This guide also provides some initial configuration information and
includes technical specifications for the gateway.
For complete information about configuring and monitoring the VPN Router 600,
see the documentation on the software CD. (For information about VPN Router
documentation, see “Related publications” on page 23.)
Before you begin
21
This guide is intended for qualified service personnel who are installing the VPN
Router 600 for the first time or who need to install or replace the following field
replaceable units (FRU):
•LAN, WAN, and serial option cards
•Dual inline memory module (DIMM)
Before you install the VPN Router 600, use standard cable system practices to
install all the network wiring on the premises.
Nortel VPN Router Installation — VPN Router 600
22 Preface
Text conventions
This guide uses the following text conventions:
Acronyms
bold Courier text
italic textIndicates new terms and book titles.
plain Courier
text
separator ( > )Shows menu paths.
This guide uses the following acronyms:
ADSLasymmetric digital subscriber line
AISalarm indication signal
BRIBasic Rate Interface
Indicates command names and options and text that
you need to enter.
Example: Use the
Example: Enter
Indicates system output, for example, prompts and
system messages.
Example:
Example: Choose Status > Health Check.
File not found.
show health command.
terminal paging {off | on}.
CSUchannel service unit
DIMMdual inline memory module
DSUdigital service unit
DTEdata terminal equipment
IPInternet Protocol
IPsecIP Security
ISDNIntegrated Services Digital Network
LANlocal area network
LEDlight emitting diode
NN46110-308 02.01
LOSloss of signal
OOFout of frame
PCIperipheral component interconnect
URLuniform resource locator
VPNvirtual private network
WANwide area network
Related publications
For complete information about configuring, monitoring, and managing the VPN
Router 600, formerly known as the Contivity Secure IP Services Gateway 600,
refer to the following publications:
•Release notes provide the latest information, including brief descriptions of
the new features, problems fixed in this release, and known problems and
workarounds.
•Nortel VPN Router Configuration — Basic Features (NN46110-500)
introduces the product and provides information about initial configuration.
•Nortel VPN Router Security — Servers, Authentication, and Certificates
(NN46110-600) provides instructions for configuring authentication servers
and services, as well as digital certificates.
•Nortel VPN Router Security — Firewalls, Filters, NAT, and QoS
(NN46110-601) provides instructions for configuring the VPN Router
Stateful Firewall, NAT, and VPN Router interface and tunnel filters.
•Nortel VPN Router Configuration — Tunneling Protocols) (NN46110-503)
provides instructions for configuring the tunneling protocols IPsec, L2TP,
PPTP, and L2F.
•Nortel VPN Router Configuration — Advanced Features (NN46110-502)
provides instructions for configuring 802.1Q VLANs, circuitless IP, advanced
WAN settings, PPP, PPPoE, frame relay, ADSL and ATM, T1/E1 CSU/DSU
interfaces, dial services and BIS, DLSw, IPX, and Hardware Accelerator
cards.
•Nortel VPN Router Configuration — Routing (NN46110-504) provides
instructions for configuring RIP, OSPF, and VRRP, as well as instructions for
configuring ECMP, routing policy services, and client address redistribution.
Preface 23
Nortel VPN Router Installation — VPN Router 600
24 Preface
•Nortel VPN Router Configuration — SSL VPN Services (NN46110-501)
provides instructions for configuring services on the SSL VPN Module 1000,
including authentication, networks, user groups, and portal links.
•Nortel VPN Router Using the Command Line Interface (NN46110-507)
provides syntax, descriptions, and examples for the commands that you can
use to configure, manage, and monitor the gateway.
•Nortel VPN Router Troubleshooting (NN46110-602) provides information
about backup and recovery, file management, upgrading software, and
troubleshooting. This guide also provides instructions for monitoring gateway
status and performance.
•Nortel VPN Router Configuration — Tunnel Guard (NN46110-307) provides
information about configuring and using the TunnelGuard feature.
Printed technical manuals
You can print selected technical manuals and release notes free, directly from the
Internet. Go to www.nortel.com/documentation, find the product for which you
need documentation, then locate the specific category and model or version for
your hardware or software product. Use Adobe Reader to open the manuals and
release notes, search for the sections you need, and print them on most standard
printers. Go to Adobe Systems at www.adobe.com to download a free copy of the
Adobe Reader.
NN46110-308 02.01
Chapter 1
Introducing the Nortel VPN Router 600
This chapter describes the VPN Router 600 and how to install it.
Note: Before you install the chassis, use standard cable system practices
to install all network wiring on the premises.
This chapter contains the following topics:
TopicPage
Description of the Nortel VPN Router 60025
Preparing to install the Nortel VPN Router 60026
Installing the chassis28
25
Description of the Nortel VPN Router 600
The VPN Router 600 enables scalable, secure, and robust IP virtual private
networks (VPNs) for up to 50 simultaneous users across the public data network.
The VPN Router 600 is for branch offices and small businesses that need to be
interconnected through managed Internet Protocol (IP) VPNs.
The VPN Router 600 provides routing, firewall, bandwidth management,
encryption, authentication, and data integrity services to ensure secure tunneling
across IP networks and the Internet. An individual user or group of users can be
associated with a set of attributes that provide custom access to an extranet.
Nortel VPN Router Installation — VPN Router 600
26 Chapter 1 Introducing the Nortel VPN Router 600
Figure 1 shows the front view of the VPN Router 600.
Figure 1 Front view of the VPN Router 600
Attention
Boot
Ready
Alert
The VPN Router 600 chassis provides the following:
•Two 10/100 Ethernet LAN ports on the base system
•One serial port for out-of-band management of the VPN Router 600
•One expansion PCI slot that can contain an optional interface card
•One 128 MB dual inline memory module (DIMM)
VPN Router
Power
600
CS60001A
Preparing to install the Nortel VPN Router 600
Before you install the VPN Router 600, verify that:
•Your shipment is complete and undamaged.
•You have the cables that you need.
•Your installation site meets the physical, electrical, and environmental
requirements.
The sections that follow provide information to help you prepare for installation.
NN46110-308 02.01
Shipment contents
In addition to the gateway and this guide, the shipping container for the VPN
Router 600 contains a number of hardware accessories and other items.
Note: Nortel does not ship a power cord with the VPN Router 600
unless you order one.
Tabl e 1 lists the hardware accessories and other items shipped with the gateway.
Table 1 Items shipped with the Nortel VPN Router 600
QuantityItemDescription
Chapter 1 Introducing the Nortel VPN Router 600 27
Inspect all items for shipping damage. If you detect any damage, do not install the
VPN Router 600. Call the Nortel Technical Solutions Center in your area (see
“How to get help” on page 17).
Cables
You need cables that are not included in the VPN Router 600 shipping container.
For information about which cables are shipped and which ones you can order,
see “Connecting communications cables VPN Router 600” on page 30. If you do
not have the proper cables, contact your network administrator.
1Molded serial cable
DB9/DB25-to-DB9/DB25
1AC-to-DC external power
supply pack
1Important Notice for the
VPN Router 600
1VPN Router software kitContains VPN Router software and
1VPN client kitContains VPN Client software and
Used to connect the VPN Router 600 to a PC or
to a local terminal
Provides power to the VPN Router 600
Provides shorter instructions for installing the
chassis
documentation (including this book) on CD
documentation on CD
Nortel VPN Router Installation — VPN Router 600
28 Chapter 1 Introducing the Nortel VPN Router 600
Site requirements
The installation site must provide sufficient free space around the VPN Router
600 to ensure proper ventilation and access for servicing. For information about
the physical, electrical, and environmental requirements for the VPN Router 600,
see “Chassis specifications” on page 71.
Installing the chassis
To install the VPN Router 600, position the chassis on a flat, sturdy, horizontal
surface. Make sure that the surface is large enough for the gateway and sturdy
enough to support the combined weight of the VPN Router 600 and the cables that
you attach to it.
NN46110-308 02.01
Chapter 2
Cabling the VPN Router and turning the power on
This chapter provides information about how to connect communications cables
and the power cord to the VPN Router 600.
Caution: Connect the cables to the built-in Ethernet ports and to the
interfaces on the optional interface card installed in the VPN Router 600
before you plug the power cord into the outlet.
This chapter contains the following topics:
TopicPage
Connecting communications cables VPN Router 60030
Connecting the power cord32
Understanding the LEDs33
29
Caution: Route the cable for all WAN, LAN, and serial connections
inside the building environment.
Nortel VPN Router Installation — VPN Router 600
Loading...
+ 65 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.