Compatible Systems IntraPort Enterprise-2 User Manual

Vpn access server
Table of Contents

Advertisement

Quick Links

IntraPort Enterprise-2
VPN Access Server
Administrator's Guide
Compatible Systems Corporation
4730 Walnut Street
Suite 102
Boulder, Colorado 80301
303-444-9532
800-356-0283
http://www.compatible.com

Advertisement

Table of Contents
loading

Summary of Contents for Compatible Systems IntraPort Enterprise-2

  • Page 1 IntraPort Enterprise-2 VPN Access Server Administrator’s Guide Compatible Systems Corporation 4730 Walnut Street Suite 102 Boulder, Colorado 80301 303-444-9532 800-356-0283 http://www.compatible.com...
  • Page 2 IntraPort Enterprise-2 VPN Access Server Administrator’s Guide, Version 1 Copyright © 1999, Compatible Systems Corporation All rights reserved. IntraPort Enterprise, RISC Router, MicroRouter and CompatiView are trademarks of Compatible Systems Corporation. Other trademarks are the property of their respective holders. Part number: A00-1855 FCC Notice: This product has been certified to comply with the limits for a Class A computing device, pursuant to Subpart J of Part 15 of FCC Rules.
  • Page 3: Table Of Contents

    ANUAL VERVIEW Chapter 1 - Getting Started OTES Please Read the Manuals Warranty and Service Getting Help with the IntraPort Enterprise-2 EED TO TARTED Supplied with the IntraPort Enterprise-2 Additional Items Needed for Installation Chapter 2 - Mounting Instructions HANGING THE...
  • Page 4 Required for Client Tunnel Configurations Suggested for Client Tunnel Configurations VPN User Database Setting up RADIUS Authentication Setting the IntraPort Enterprise-2 for a RADIUS Server RADIUS Server User Authentication Settings Setting up SecurID Authentication Setting the IntraPort Enterprise-2 for an ACE/Server...
  • Page 5 Table of Contents Appendix B - Downloading Software From Compatible Systems Appendix C - Security Dynamics ACE/Server Information Appendix D - When the “Over Temp” Light Comes On -2 A EPLACING OR LEANING THE NTRAPORT NTERPRISE ILTER Appendix E - Terms and Conditions...
  • Page 6 Figure 3.1. Mounting the IntraPort Enterprise-2 in the Standard Rack Figure 4. Installing Bracket Extenders Figure 4.1. Installing Earthquake Rack-Mount Brackets Figure 4.2 Mounting the IntraPort Enterprise-2 Chassis in the Earthquake Rack Figure 5. Installing Telco Rack-Mount Brackets Figure 5.1. Mounting the IntraPort Enterprise-2 Chassis in the Telco Rack Figure 6.
  • Page 7: Introduction To The Intraport Enterprise-2

    IntraPort Enterprise-2 Installation Overview This manual will help you mount the IntraPort Enterprise-2 VPN Access Server in a rack and install it on your Local Area Network. It also includes general maintenance information and some technical specifications. For the most up-to-date information available on the IntraPort Enterprise-2 VPN Access Server, please visit the Technical Support section of our Web site at: http://www.compatible.com.
  • Page 8: Intraport Enterprise-2 Manual Overview

    The manual is divided into several sections that should provide you with the basic information you will need to use the IntraPort Enterprise-2 on your network. For the latest documentation on Compatible Systems products, including the most current version of this manual, visit the Technical Support section of our Web site.
  • Page 9: Chapter 1 - Getting Started

    Appendix Getting Help with the IntraPort Enterprise-2 If you have a question about the IntraPort Enterprise-2 and can’t find the answer in one of the manuals included with the product, please visit the technical support section of our Web site (http://www.compatible.com).
  • Page 10: What You Will Need To Get Started

    • Warranty registration card Figure 1. Mounting Screws Additional Items Needed for Installation Before connecting the IntraPort Enterprise-2 to your network, you need to make sure that you have the necessary equipment. See Chapter 3 - Network Installation for details.
  • Page 11: Chapter 2 - Mounting Instructions

    Chapter 2 - Mounting Instructions The IntraPort Enterprise-2 VPN Access Server can be left stand-alone on a desktop or equip- ment table or it can be mounted in a 19-inch rack, in a Telco rack or on a wall. Compatible Systems provides all the parts necessary for securing the supplied mounting brackets to the device;...
  • Page 12: Rack Mounting Instructions

    Standard 19-inch Rack Mount Figure 3. Standard Rack-Mount Installation Brackets are provided for mounting the IntraPort Enterprise-2 in a standard 19-inch equipment rack. To rack-mount the server in a standard equipment rack: Determine the desired location. The IntraPort Enterprise-2 requires 6.5 vertical inches (4 shelf positions) of rack space.
  • Page 13: Figure 3.1. Mounting The Intraport Enterprise-2 In The Standard Rack

    Chapter 2 - Mounting Instructions Figure 3.1. Mounting the IntraPort Enterprise-2 in the Standard Rack Using your screws or clips, fasten the mounting brackets to the equipment rack as shown in Figure 3.1.
  • Page 14: Earthquake Mount In A 19-Inch Rack

    Earthquake Mount in a 19-inch Rack Figure 4. Installing Bracket Extenders Earthquake brackets are provided for mounting the IntraPort Enterprise-2 in a standard 19-inch equipment rack. If the server will be located in an area prone to earthquakes, it is strongly recommended that you use the earthquake brackets for mounting the device.
  • Page 15: Figure 4.1. Installing Earthquake Rack-Mount Brackets

    Chapter 2 - Mounting Instructions...
  • Page 16: Figure 4.2 Mounting The Intraport Enterprise-2 Chassis In The Earthquake Rack

    Chapter 2 - Mounting Instructions Figure 4.2 Mounting the IntraPort Enterprise-2 Chassis in the Earthquake Rack While supporting the chassis, slide the rack-mount brackets into the installed rear extenders as shown in Figure 4.2. Using your screws or clips, fasten the front bracket to the equipment rack as shown in Figure 4.2.
  • Page 17: Telco Rack Mount

    Telco Rack Mount Figure 5. Installing Telco Rack-Mount Brackets Brackets are provided for mounting the IntraPort Enterprise-2 chassis in a Telco rack. To rack-mount the server into a Telco rack: Determine the desired location. The IntraPort Enterprise-2 chassis requires 6.5 verti- cal inches (4 shelf positions) of rack space.
  • Page 18: Figure 5.1. Mounting The Intraport Enterprise-2 Chassis In The Telco Rack

    Chapter 2 - Mounting Instructions Figure 5.1. Mounting the IntraPort Enterprise-2 Chassis in the Telco Rack While supporting the chassis, move the device and the mounting brackets into the desired rack position and use your own screws or clips to fasten the server and bracket...
  • Page 19: Wall Mount

    Chapter 2 - Mounting Instructions Wall Mount Figure 6. Installing Wall-Mount Brackets Brackets are provided for mounting the IntraPort Enterprise-2 on a wall. To wall-mount the server: Determine the desired location. The IntraPort Enterprise-2 chassis requires 6.5 verti- cal inches and a mounting backboard measuring at least 24” x 24” x 1/2” (not sup- plied).
  • Page 20: Figure 6.1. Securing The Intraport Enterprise-2 Chassis To The Board

    Note: The IntraPort Enterprise-2 should be wall-mounted with the front and rear of the chassis perpendicular to the floor and at eye level, so you can read the front LEDs. All four mounting screws must be anchored to solid wood.
  • Page 21: Power Cord Retainer Installation

    Chapter 2 - Mounting Instructions Power Cord Retainer Installation Figure 7. Attaching the IntraPort Enterprise-2 Power Cord Retainer v Note: It is recommended that you determine the setting of your voltage switch before installing the power cord retainer. For more information on power supply voltage settings, see Changing the Power Supply Voltage Settings at the beginning of this chapter.
  • Page 22: Chapter 3 - Network Installation

    Ethernet connection setup. The IPSec-only slot should only be used if you are planning to set the IntraPort Enterprise-2 to operate in parallel with your existing firewall. This is the recommended setup. In this scenario,...
  • Page 23: Connecting A Management Console

    Changing the Power Supply Voltage Settings). Connect the supplied power cord to the front of the IntraPort Enterprise-2 and set the power switch to “On.” At power-up, the server will take approximately one minute to become visible to CompatiView (see Chapter 4 - CompatiView Software Installation for more information) .
  • Page 24: Chapter 4 - Compatiview Software Installation

    Chapter 4 - CompatiView Software Installation Chapter 4 - CompatiView Software Installation All of the products in Compatible Systems’ internetworking and VPN families, including the IntraPort Enterprise-2, can be managed from a single GUI management platform called CompatiView. CompatiView for Windows is included on the CD-ROM which was shipped with your IntraPort Enterprise-2 VPN Access Server.
  • Page 25: Transport Protocols And Compatiview

    The IP protocol does not provide a method for CompatiView to automatically discover the IntraPort Enterprise-2 VPN Access Server. To initially contact the server over IP using CompatiView, you must first enter a valid IP address into the server. You can do this either on a console directly connected to the server or by setting a workstation’s IP address to...
  • Page 26: Chapter 5 - Command Line Management

    Chapter 5 - Command Line Management Chapter 5 - Command Line Management The command line interface allows you to configure and monitor the IntraPort Enterprise-2 VPN Access Server in-band via Telnet or out-of-band with a terminal connected to the server’s Console interface.
  • Page 27: Setting Up Telnet Operation

    Telnet is a remote terminal communications protocol based on TCP/IP. With Telnet you can log into and manage the IntraPort Enterprise-2 from anywhere on your IP internetwork, including across the Internet if your security setup allows it. To manage the server with Telnet,...
  • Page 28: Chapter 6 - Basic Configuration Guide

    Command Line Management Reference Guide regarding IP, IPX and AppleTalk packet filters for more information. The IntraPort Enterprise-2 can be set up in two different ways. One is to configure it using both Ethernet ports to operate in parallel with your existing firewall and serve as the IPSec compo- nent of your security system.
  • Page 29: Ip Settings For Single-Ethernet Setups

    Chapter 6 - Basic Configuration Guide Use the configure command and set the IPAddress, SubnetMask and IPBroadcast keywords in the IP Ethernet 1:0 section. No other keywords should be configured for this section. Use the configure command and set the IPSecGateway keyword in the General section.
  • Page 30: Appletalk Protocol

    Configuring the Server for IP and IPX Client Tunnels To configure the IntraPort Enterprise-2 for IP and IPX client tunnels, each user must be entered into the VPN user database or a RADIUS server database and assigned a tunnel configuration.
  • Page 31: Suggested For Client Tunnel Configurations

    The RADIUS server will also log the real IP address of the client and the IP address assigned to the client by the IntraPort Enterprise-2 as it begins to account for the client. To use this feature, the two attribute numbers for these two IP address strings must also be configured in the RADIUS server’s dictionary file and in the RADIUS section of the IntraPort’s configura-...
  • Page 32: Setting Up Securid Authentication

    Appendix C for information on how to obtain ACE/Server soft- ware and SecurID tokens. To use ACE/Server software with the IntraPort Enterprise-2, you will need the following: • ACE/Server software running on a supported platform (see the ACE/Server Installa- tion Guide or README document for a current list of ACE/Server-supported plat- forms and other server requirements) •...
  • Page 33: Setting The Intraport Enterprise-2 For An Ace/Server

    Chapter 6 - Basic Configuration Guide Setting the IntraPort Enterprise-2 for an ACE/Server Just a few basic settings are required for the IntraPort Enterprise-2 to communicate with an ACE/Server. • SecurID on • Encryption method • ACE/Server IP address •...
  • Page 34: Chapter 7 - Shipping Defaults

    Chapter 7 - Shipping Defaults Chapter 7 - Shipping Defaults Default Password • letmein Ethernet Interfaces IP Defaults • Ethernet 0:0 is on • Address: 198.41.12.1 • Subnet mask: 255.255.255.0 • Broadcast address: 198.41.12.255 • Mode: Routed • Ethernet 1:0 is off IPX Defaults •...
  • Page 35: Chapter 8 - Led Patterns And Test Switch Settings

    Chapter 8 - LED Patterns and Test Switch Settings IntraPort Enterprise-2 LED Patterns The IntraPort Enterprise-2 VPN Access Server uses a number of light patterns on its front LED bars to indicate operating conditions. v Note : Any continuous flashing pattern not noted in this chapter may be caused by a hard- ware failure.
  • Page 36: Intraport Enterprise-2 Switch Settings

    Erase Flash ROM (Configuration Only) Unused* Unused* Allow letmein password for 5 minutes after powerup M Caution: Settings marked with an asterisk may erase your Flash ROM. Please do not use these settings without first contacting Compatible Systems’ Technical Support.
  • Page 37: Appendix A - Connector And Cable Pin Outs

    Appendix A - Connector and Cable Pin Outs Pin Outs for DB-25 Male to DB-25 Female Console Cable The cable supplied with the IntraPort Enterprise-2 is twenty-five conductors, straight through. Connections on the console interface follow the standard RS-232C pin outs.
  • Page 38: Appendix B - Downloading Software From Compatible Systems

    Appendix B - Downloading Software From Compatible Systems The latest versions of operating software for all Compatible Systems products are available at our Web site. The latest version of CompatiView management software is also available. To download software, follow the instructions below: Use your browser to access http://www.compatible.com/, and find the link on our...
  • Page 39: Appendix C - Security Dynamics Ace/Server Information

    Appendix C - Security Dynamics ACE/Server Information Appendix C - Security Dynamics ACE/Server Information ACE/Server software and SecurID tokens can be purchased directly from Security Dynamics Technologies, Inc. Use the following information to contact Security Dynamics for more information: Security Dynamics Technologies, Inc. 20 Crosby Drive Bedford, MA 01730, U.S.A.
  • Page 40: Appendix D - When The "Over Temp" Light Comes On

    Appendix D - When the “Over Temp” Light Comes On Appendix D - When the “Over Temp” Light Comes On The Intraport Enterprise-2 is designed to operate reliably in a normal computer room, and requires no special environmental control. If operating within its published temperature and humidity specifications (0°...
  • Page 41: Replacing Or Cleaning The Intraport Enterprise-2 Air Filter

    Chapter 2 - Mounting Instructions. v Note: If either of the supplied filters is worn out or cannot be thoroughly cleaned, you may order a replacement filter from Compatible Systems Corporation at the number in the front of this manual.
  • Page 42: Appendix E - Terms And Conditions

    (c) that as a result of the purchase of the Products from Compatible Systems, the Customer will have good title to the Products, free and clear of all liens and encumbrances.
  • Page 43 3. Payment Terms. Payment shall be made prior to shipment or upon delivery, unless otherwise agreed to in writing. Payment shall not constitute acceptance of the goods. 4. Force Majeure. All orders accepted by Compatible Systems are subject to postponement or cancellation for any cause beyond the reasonable control of Compatible Systems, including without limitation: inability to obtain necessary materials and components;...

Table of Contents