The information in this document is subject to change without notice. The statements, configurations, technical data, and
recommendations in this document are believed to be accurate and reliable, but are presented without express or implied
warranty. Users must take full responsibility for their applications of any products specified in this document. The
information in this document is proprietary to Nortel Networks.
The software described in this document is furnished under a license agreement and may be used only in accordance
with the terms of that license. The software license agreement is included in this document.
Trademarks
Nortel Networks, the Nortel Networks logo, the Globemark, Unified Networks, and Nortel VPN Router are trademarks
of Nortel Networks.
Adobe, Acrobat, and Acrobat Reader are trademarks of Adobe Systems Incorporated.
Macintosh is a trademark of Apple Computer, Inc.
Cisco and Cisco Systems are trademarks of Cisco Technology, Inc.
SafeNet is a trademark of SafeNet, Inc.
Linux is a trademark of Linus Torvalds.
Microsoft, MS-DOS, Windows, and Windows NT are trademarks of Microsoft Corporation.
Netscape and Netscape Communicator are trademarks of Netscape Communications Corporation.
Network General Sniffer is a trademark of Network Associates, Inc.
NetWare, IPX, NetWare, and Novell are trademarks of Novell, Inc.
RSA and SecurID are trademarks of RSA Security Inc.
Java and JavaScript are trademarks of Sun Microsystems, Inc.
Ethernet is a trademark of Xerox Corporation.
The asterisk after a name denotes a trademarked item.
Restricted rights legend
Use, duplication, or disclosure by the United States Government is subject to restrictions as set forth in subparagraph
(c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013.
Notwithstanding any other license agreement that may pertain to, or accompany the delivery of, this computer software,
the rights of the United States Government regarding its use, reproduction, and disclosure are as set forth in the
Commercial Computer Software-Restricted Rights clause at FAR 52.227-19.
Statement of conditions
In the interest of improving internal design, operational function, and/or reliability, Nortel Networks Inc. reserves the
right to make changes to the products described in this document without notice.
Nortel Networks Inc. does not assume any liability that may occur due to the use or application of the product(s) or
circuit layout(s) described herein.
SUCH PORTIONS OF THE SOFTWARE ARE PROVIDED “AS IS” AND WITHOUT ANY EXPRESS OR IMPLIED
WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
In addition, the program and information contained herein are licensed only pursuant to a license agreement that contains
restrictions on use and disclosure (that may incorporate by reference certain limitations and notices imposed by third
parties).
Nortel Networks Inc. software license agreement
This Software License Agreement (“License Agreement”) is between you, the end-user (“Customer”) and Nortel
Networks Corporation and its subsidiaries and affiliates (“Nortel Networks”). PLEASE READ THE FOLLOWING
CAREFULLY. YOU MUST ACCEPT THESE LICENSE TERMS IN ORDER TO DOWNLOAD AND/OR USE THE
SOFTWARE. USE OF THE SOFTWARE CONSTITUTES YOUR ACCEPTANCE OF THIS LICENSE
AGREEMENT. If you do not accept these terms and conditions, return the Software, unused and in the original shipping
container, within 30 days of purchase to obtain a credit for the full purchase price.
“Software” is owned or licensed by Nortel Networks, its parent or one of its subsidiaries or affiliates, and is copyrighted
and licensed, not sold. Software consists of machine-readable instructions, its components, data, audio-visual content
(such as images, text, recordings or pictures) and related licensed materials including all whole or partial copies. Nortel
Networks grants you a license to use the Software only in the country where you acquired the Software. You obtain no
rights other than those granted to you under this License Agreement. You are responsible for the selection of the
Software and for the installation of, use of, and results obtained from the Software.
1.Licensed Use of Software. Nortel Networks grants Customer a nonexclusive license to use a copy of the Software
on only one machine at any one time or to the extent of the activation or authorized usage level, whichever is applicable.
To the extent Software is furnished for use with designated hardware or Customer furnished equipment (“CFE”),
Customer is granted a nonexclusive license to use Software only on such hardware or CFE, as applicable. Software
contains trade secrets and Customer agrees to treat Software as confidential information using the same care and
discretion Customer uses with its own similar information that it does not wish to disclose, publish or disseminate.
Customer will ensure that anyone who uses the Software does so only in compliance with the terms of this Agreement.
Customer shall not a) use, copy, modify, transfer or distribute the Software except as expressly authorized; b) reverse
assemble, reverse compile, reverse engineer or otherwise translate the Software; c) create derivative works or
modifications unless expressly authorized; or d) sublicense, rent or lease the Software. Licensors of intellectual property
to Nortel Networks are beneficiaries of this provision. Upon termination or breach of the license by Customer or in the
event designated hardware or CFE is no longer in use, Customer will promptly return the Software to Nortel Networks or
certify its destruction. Nortel Networks may audit by remote polling or other reasonable means to determine Customer’s
Software activation or usage levels. If suppliers of third party software included in Software require Nortel Networks to
include additional or different terms, Customer agrees to abide by such terms provided by Nortel Networks with respect
to such third party software.
2.Warranty. Except as may be otherwise expressly agreed to in writing between Nortel Networks and Customer,
Software is provided “AS IS” without any warranties (conditions) of any kind. NORTEL NETWORKS DISCLAIMS
ALL WARRANTIES (CONDITIONS) FOR THE SOFTWARE, EITHER EXPRESS OR IMPLIED, INCLUDING,
BUT NOT LIMITED TO THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE AND ANY WARRANTY OF NON-INFRINGEMENT. Nortel Networks is not obligated to
provide support of any kind for the Software. Some jurisdictions do not allow exclusion of implied warranties, and, in
such event, the above exclusions may not apply.
Nortel VPN Router Troubleshooting
4
3.Limitation of Remedies. IN NO EVENT SHALL NORTEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE
LIABLE FOR ANY OF THE FOLLOWING: a) DAMAGES BASED ON ANY THIRD PARTY CLAIM; b) LOSS OF,
OR DAMAGE TO, CUSTOMER’S RECORDS, FILES OR DATA; OR c) DIRECT, INDIRECT, SPECIAL,
INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES (INCLUDING LOST PROFITS OR SAVINGS),
WHETHER IN CONTRACT, TORT OR OTHERWISE (INCLUDING NEGLIGENCE) ARISING OUT OF YOUR
USE OF THE SOFTWARE, EVEN IF NORTEL NETWORKS, ITS AGENTS OR SUPPLIERS HAVE BEEN
ADVISED OF THEIR POSSIBILITY. The forgoing limitations of remedies also apply to any developer and/or supplier
of the Software. Such developer and/or supplier is an intended beneficiary of this Section. Some jurisdictions do not
allow these limitations or exclusions and, in such event, they may not apply.
4.General
a.If Customer is the United States Government, the following paragraph shall apply: All Nortel Networks
Software available under this License Agreement is commercial computer software and commercial computer
software documentation and, in the event Software is licensed for or on behalf of the United States
Government, the respective rights to the software and software documentation are governed by Nortel
Networks standard commercial license in accordance with U.S. Federal Regulations at 48 C.F.R. Sections
12.212 (for non-DoD entities) and 48 C.F.R. 227.7202 (for DoD entities).
b.Customer may terminate the license at any time. Nortel Networks may terminate the license if Customer fails
to comply with the terms and conditions of this license. In either event, upon termination, Customer must
either return the Software to Nortel Networks or certify its destruction.
c.Customer is responsible for payment of any taxes, including personal property taxes, resulting from
Customer’s use of the Software. Customer agrees to comply with all applicable laws including all applicable
export and import laws and regulations.
d.Neither party may bring an action, regardless of form, more than two years after the cause of the action arose.
e.The terms and conditions of this License Agreement form the complete and exclusive agreement between
Customer and Nortel Networks.
f.This License Agreement is governed by the laws of the country in which Customer acquires the Software. If
the Software is acquired in the United States, then this License Agreement is governed by the laws of the state
of New York.
This guide provides information about how to manage and troubleshoot the Nortel
VPN Router.
Before you begin
This guide is for network managers who monitor and maintain the Nortel VPN
Router. This guide assumes that you have experience with system administration
and familiarity with network management.
Text conventions
This guide uses the following text conventions:
angle brackets (< >)Indicate that you choose the text to enter based on the
17
description inside the brackets. Do not type the
brackets when entering the command.
Example: If the command syntax is
ping <ip_address>, you enter
ping 192.32.10.12
bold Courier text
Indicates command names and options and text that
you need to enter.
Example: Use the
Example: Enter
show health command.
terminal paging {off | on}.
Nortel VPN Router Troubleshooting
18 Preface
braces ({})Indicate required elements in syntax descriptions where
there is more than one option. You must choose only
one of the options. Do not type the braces when
entering the command.
Example: If the command syntax is
source {external | internal}
ldap-server source external or
either
ldap-server source internal
ldap-server
, you must enter
, but not both.
brackets ([ ])Indicate optional elements in syntax descriptions. Do
not type the brackets when entering the command.
Example: If the command syntax is
show ntp [associations], you can enter
show ntp orshow ntp associations.
either
Example: If the command syntax is default rsvp
ellipsis points (. . . )Indicate that you repeat the last element of the
command as needed.
Example: If the command syntax is
more diskn:<directory>/...<file_name>,
you enter
more and the fully qualified name of the file.
NN46110-602
italic textIndicates new terms, book titles, and variables in
command syntax descriptions. Where a variable is two
or more words, the words are connected by an
underscore.
Example: If the command syntax is
ping<ip_address>, ip_address is one variable
and you substitute one value for it.
plain Courier
text
Indicates system output, for example, prompts and
system messages.
Example:
File not found.
separator ( > )Shows menu paths.
Example: Choose Status > Health Check.
Preface 19
Acronyms
vertical line (
| )Separates choices for command keywords and
arguments. Enter only one of the choices. Do not type
the vertical line when entering the command.
Example: If the command syntax is
terminal paging {off | on}, you enter either
terminal paging off or terminal paging on,
but not both.
This guide uses the following acronyms:
ADSL
ARP
AT M
CA
CHAP
asynchronous digital subscriber line
Address Resolution Protocol
asynchronous transfer mode
certificate authority
Challenge Handshake Authentication Protocol
CMPInternet Control Message Protocol
DHCPDynamic Host Configuration Protocol
DNSDomain Name System
FTPFile Transfer Protocol
HTTPHypertext Transfer Protocol
ICMPCertificate Management Protocol
IKEIPsec Key Exchange
IPInternet Protocol
IPsecIP Security
IPXInternetwork Packet Exchange
ISDN BRIintegrated services digital network basic-rate
interface
ISPInternet service provider
L2FLayer 2 Forwarding
Nortel VPN Router Troubleshooting
20 Preface
L2TPLayer 2 Tunneling Protocol
LANlocal area network
LDAPLightweight Directory Access Protocol
NATNetwork Address Translation
OSIOpen Systems Interconnection
OSPFOpen Shortest Path First
PAPPassword Authentication Protocol
PCAPpacket capture
PDNpublic data network
POPpoint of presence
PPPPoint-to-Point Protocol
PPTPPoint-to-Point Tunneling Protocol
RADIUSRemote Authentication Dial-In User Service
RIPRouting Information Protocol
SNMPSimple Network Management Protocol
NN46110-602
UDPUser Datagram Protocol
URLuniform resource locator
VPNvirtual private network
VRRPVirtual Router Redundancy Protocol
WANwide area network
XNSXerox Networking System
Related publications
For more information about the Nortel VPN Router, see the following
publications:
•Release notes provide the latest information, including brief descriptions of
the new features, problems fixed in this release, and known problems and
workarounds.
•Nortel VPN Router Configuration — Basic Features (NN46110-500)
introduces the product and provides information about initial setup and
configuration.
•Nortel VPN Router Configuration — SSL VPN Services (NN46110-501)
provides instructions for configuring services on the SSL VPN Module 1000,
including authentication, networks, user groups, and portal links.
•Nortel VPN Router Security — Servers, Authentication, and Certificates
(NN46110-600) provides instructions for configuring authentication services
and digital certificates.
•Nortel VPN Router Security — Firewalls, Filters, NAT, and QoS
(NN46110-601) provides instructions for configuring the Stateful Firewall
and VPN Router interface and tunnel filters.
•Nortel VPN Router Configuration — Advanced Features (NN46110-502)
provides instructions for configuring advanced LAN and WAN settings, PPP,
frame relay, PPPoE, ADSL and ATM, T1CSU/DSU, dial services and BIS,
DLSw, IPX, and SSL VPN.
•Nortel VPN Router Configuration — Tunneling Protocols (NN46110-503)
configuration information for the tunneling protocols IPsec, L2TP, PPTP, and
L2F.
•Nortel VPN Router Configuration—Routing (NN46110-504) provides
instructions for configuring RIP, OSPF, and VRRP, as well as instructions for
configuring ECMP, routing policy services, and client address redistribution
(CAR).
•Nortel VPN Router Using the Command Line Interface (NN46110-507)
provides syntax, descriptions, and examples for the commands that you can
use from the command line interface.
•Nortel VPN Router Configuration — TunnelGuard (NN46110-307) provides
information about configuring and using the TunnelGuard feature.
Preface 21
Nortel VPN Router Troubleshooting
22 Preface
Hard-copy technical manuals
You can print selected technical manuals and release notes free, directly from the
Internet. Go to www.nortelnetworks.com/documentation, find the product for
which you need documentation, then locate the specific category and model or
version for your hardware or software product. Use Adobe Reader to open the
manuals and release notes, search for the sections you need, and print them on
most standard printers. Go to the Adobe Web site at the www.adobe.com to
download a free copy of the Adobe Reader.
How to get help
This section explains how to get help for Nortel products and services.
Finding the latest updates on the Nortel Web site
The content of this documentation was current at the time the product was
released. To check for updates to the latest documentation and software for VPN
Router, click one of the following links:
NN46110-602
Link toTakes you directly to the
Latest softwareNortel page for VPN Router software located at:
The best way to get technical support for Nortel products is from the Nortel
Technical Support Web site:
www.nortel.com/support
This site provides quick access to software, documentation, bulletins, and tools to
address issues with Nortel products. From this site, you can:
•download software, documentation, and product bulletins
•search the Technical Support Web site and the Nortel Knowledge Base for
answers to technical issues
•sign up for automatic notification of new software and documentation for
Nortel equipment
•open and manage technical support cases
Getting help over the phone from a Nortel Solutions Center
If you do not find the information you require on the Nortel Technical Support
Web site, and you have a Nortel support contract, you can also get help over the
phone from a Nortel Solutions Center.
In North America, call 1-800-4NORTEL (1-800-466-7835).
Outside North America, go to the following web site to obtain the phone number
for your region:
www.nortel.com/callus
Getting help from a specialist by using an Express Routing
Code
To access some Nortel Technical Solutions Centers, you can use an Express
Routing Code (ERC) to quickly route your call to a specialist in your Nortel
product or service. To locate the ERC for your product or service, go to:
www.nortel.com/erc
Nortel VPN Router Troubleshooting
24 Preface
Getting help through a Nortel distributor or reseller
If you purchased a service contract for your Nortel product from a distributor or
authorized reseller, contact the technical support staff for that distributor or
reseller.
NN46110-602
New in this release
The following section details what is new in Nortel VPN Router Troubleshooting
for Release 7.0.
Features
See the following sections for information about feature changes:
•SNMP traps when an IP address pool reaches the configured threshold
•Automatic backups
•PCAP enhancements
•SNMP interface index enhancement
SNMP traps when an IP address pool reaches the
configured threshold
25
You can configure the VPN Router so that a Simple Network Management
Protocol (SNMP) trap sends a notification about an exhausted pool when a
defined IP address pool reaches a configured limit. The list of IP address pools is
periodically traversed and sends a trap if any pool is over the quota. You can set
the limit and the default is 70%.
For more information about trap notification when the IP pool reaches a certain
capacity, see “Configuring SNMP traps to send notification when an IP address
pool reaches the configured threshold” on page 32.
Nortel VPN Router Troubleshooting
26 New in this release
Automatic backups
You can now back up a file or a directory, as well as trigger a backup, when a file
changes. Previously, you could only back up system, configuration, and log files.
You can use either the graphical user interface (GUI) or the command line
interface (CLI) to configure automated backup.
You can also now use a Secure File Transfer Protocol (SFTP) client as well as File
Transfer Protocol (FTP) to transfer backup files. You can use either the GUI or the
CLI to activate SFTP.
For more information about automatic backups, see “Automatic backups” on
page 52.
PCAP enhancements
You can now capture packets to disk files. Previously, you could capture packets
to random access memory (RAM) only. There are five new commands for the
command line interface (CLI) of the VPN Router. You must use the CLI to
configure Packet Capture (PCAP).
SNMP interface index enhancement
NN46110-602
For more information about PCAP enhancements, see “Capturing packets to disk
file” on page 113.
Third-party network management systems (NMS) rely on interface index
(IfIndex) numbers to monitor and gather statistics for devices through SNMP.
These locally significant numbers are assigned to the physical and virtual
interfaces on the device and enable the NMS to associate statistics with interfaces.
Previously, when a branch office tunnel came up, it was assigned a dynamic
IfIndex number. Only up tunnels were reported; any down tunnels were not
reported.
With the enhancement, each branch office is assigned a static IfIndex, the IfIndex
is saved in LDAP, and tunnels are reported even when they are down.
For more information about the IfIndex enhancement, see “RFC 1213—Network
Management of TCP/IP-Based Internets MIB” on page 132.
Chapter 1
VPN Router administration
This chapter introduces administrator settings, tools, system configuration, and
file management. It also includes information about SNMP traps.
Administrator settings
The VPN Router supports multiple administrators. You can assign different rights
to allow or prevent administrative users from managing or viewing the VPN
Router and user configuration information. You assign administrative privileges
and rights on the Profiles > User > Edit window. The VPN Router also supports a
primary administrator.
You can assign one of the following priviledge levels to the Manage Switch and
Manage Users:
27
•None—This user does not have administrator rights to manage the VPN
Router or to manage users; the user cannot view or manage configuration or
user settings.
•View—This user has administrator rights to view (monitor) VPN Router
configuration or user rights settings; however, the user cannot manage
(change) them. This is the lowest level of administrator rights.
•Manage—This user has administrator rights to view (monitor) and manage
(configure) other VPN Router configuration or user rights settings. This is the
highest level of administrative rights.
•Add Subgroups is a check box that gives the user the authority to add and
delete subgroups under the given directory when the user has View only
authority with Manage Switch access rights.
Nortel VPN Router Troubleshooting
28 Chapter 1 VPN Router administration
You use the Administrator Settings window to do the following:
•change the primary administrator user ID and password
•control the Administrator Idle Timeout Setting for all administrators
•control the default language
•control the serial port settings
There is only one primary administrator. The primary administrator user ID and
password combination do the following:
•provide the user with access to all windows and control settings
•allows access to the serial port and the recovery disk
Note: Once you set the primary administrator user ID and password,
you must implement an Admin > Shutdown to save the new settings.
Doing a reset (using the Reset button on the back of the VPN Router)
does not save the settings.
You can change the primary administrator user ID and password on the Admin >
Administrator window.
Lost user name and password—resetting the VPN Router to
factory defaults
NN46110-602
You can set the VPN Router back to the factory default configuration even if you
do not know the administrator username and password. To do this:
1Boot the VPN Router into recovery mode.
2Open a browser to the management IP address of the VPN Router. You do not
need a user name and password for this step.
3Reset to factory default. After you reset to factory default, the administrator
user name is admin and the password is setup.
Caution: Resetting to factory default removes all existing configuration
information.
Dynamic password
Two types of administrative users exist on the VPN Router:
•one super-user (Administrator)
•as many administrative users as needed
There is dynamic password support for administrative users only. The
Administrator still requires a static password.
RADIUS manages the dynamic password. The external RADIUS service acts as
an intermediary between the VPN Router and the dynamic password
authentication system.
When enabled, this forces administrative users to authenticate through
RADIUS, which then forwards authentication credentials to a dynamic
password authentication system, such as SecurID. The privileges associated
with this administrative user are configured as before.
Chapter 1 VPN Router administration 29
Tools
The VPN Router supports standard IP tools such as ping, Traceroute, and ARP
show and delete. You access these tools through the Admin > Too ls wi nd ow.
The
ping command generates an ICMP echo-request message, which any host
can send to test node reachability across a network. The ICMP echo-reply
message indicates that the node is successfully reached.
Nortel VPN Router Troubleshooting
30 Chapter 1 VPN Router administration
The Traceroute tool measures a network round-trip delay. Messages are sent per
hop and the wait occurs between each message. If the address is unreachable, it
uses the following formula to determine how long it takes for the Traceroute to
time out.
maximum hops (30) x the wait timeout (5) x 3 seconds
The Address Resolution Protocol (ARP) dynamically discovers the low-level
physical network hardware address that corresponds to the high-level IP address
for a host. ARP is limited to physical network systems that support broadcast
packets that are heard by all hosts on the network.
System configuration
Use the Admin > Config window to save the current or delete existing system
configuration files. Additionally, you can select one of the previously named
configurations and restore it as the current configuration.
File management
Use the Admin > File System > File System Maintenance window to navigate
through the VPN Router file system. This window lists the devices (drives) and
directories, which provides flexibility in viewing details of a file or directory and
allows you to delete unnecessary files. For example, if you have problems
performing an FTP transfer with a specific file, you can view the file details to
learn its file size and when it was last modified for troubleshooting purposes.
Additionally, you can toggle between hard drives when a backup drive is
available.
NN46110-602
Loading...
+ 200 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.