In the interest of improving internal design, operational function, and/or reliability, Nortel Networks Inc. reserves the right to make changes to the products described in this document without notice. Nortel Networks Inc. does not assume any liability that may occur due to the use or application of the product(s) or circuit layout(s) described herein.
Canadian Department of Communications Radio Interference Regulations This digital apparatus (VPN Router 600) does not exceed the Class A limits for radio-noise emissions from digital apparatus as set out in the Radio Interference Regulations of the Canadian Department of Communications.
Page 4
30 days of purchase to obtain a credit for the full purchase price. “Software” is owned or licensed by Nortel Networks, its parent or one of its subsidiaries or affiliates, and is copyrighted and licensed, not sold. Software consists of machine-readable instructions, its components, data, audio-visual content (such as images, text, recordings or pictures) and related licensed materials including all whole or partial copies.
Page 5
12.212 (for non-DoD entities) and 48 C.F.R. 227.7202 (for DoD entities). Customer may terminate the license at any time. Nortel Networks may terminate the license if Customer fails to comply with the terms and conditions of this license. In either event, upon termination, Customer must either return the Software to Nortel Networks or certify its destruction.
Page 11
Figure 13 VPN Router 600 system board ....... . . 55 Figure 14 Removing the blank bracket from the option card slot .
Page 12
Figure 30 Single V.35/X.21 WAN interface card ......86 Figure 31 V.90 modem interface card ........89 NN46110-308 02.01...
Page 13
Items shipped with the Nortel VPN Router 600 ....27 Table 2 Interfaces and cables for the VPN Router 600 ..... 30 Table 3 Power cord requirements .
New in this release The following section details what’s new in Nortel VPN Router Installation— VPN Router 600 (NN46110-308) for Release 7.05.300: Features See the following section for information about feature changes: 1000BASE-T (1000 GT) Ethernet card The 100 GT Ethernet card replaces the 10/ 100BASE-TX Ethernet card. See “1000BASE-T (1000 GT) Ethernet interface card LEDs”...
Select Security & VPN and then, in the section called Virtual Private Networking (VPN), IPSEC, and SSL, click the appropriate VPN Router product. Getting help from the Nortel Web site The best way to get technical support for Nortel products is from the Nortel Technical Support Web site: www.nortel.com/support...
Center If you do not find the information you require on the Nortel Technical Support Web site, and you have a Nortel support contract, you can also get help over the phone from a Nortel Solutions Center. In North America, call 1-800-4NORTEL (1-800-466-7835).
How to get help 19 Getting help through a Nortel distributor or reseller If you purchased a service contract for your Nortel product from a distributor or authorized reseller, contact the technical support staff for that distributor or reseller. Nortel VPN Router Installation — VPN Router 600...
Before you begin This guide is intended for qualified service personnel who are installing the VPN Router 600 for the first time or who need to install or replace the following field replaceable units (FRU): • LAN, WAN, and serial option cards •...
Text conventions This guide uses the following text conventions: bold Courier text italic text plain Courier text separator ( > ) Acronyms This guide uses the following acronyms: ADSL DIMM IPsec ISDN NN46110-308 02.01 Indicates command names and options and text that you need to enter.
Related publications For complete information about configuring, monitoring, and managing the VPN Router 600, formerly known as the Contivity Secure IP Services Gateway 600, refer to the following publications: • Release notes provide the latest information, including brief descriptions of the new features, problems fixed in this release, and known problems and workarounds.
Printed technical manuals You can print selected technical manuals and release notes free, directly from the Internet. Go to www.nortel.com/documentation, find the product for which you need documentation, then locate the specific category and model or version for your hardware or software product. Use Adobe Reader to open the manuals and release notes, search for the sections you need, and print them on most standard printers.
The VPN Router 600 enables scalable, secure, and robust IP virtual private networks (VPNs) for up to 50 simultaneous users across the public data network. The VPN Router 600 is for branch offices and small businesses that need to be interconnected through managed Internet Protocol (IP) VPNs.
The VPN Router 600 chassis provides the following: • Two 10/100 Ethernet LAN ports on the base system • One serial port for out-of-band management of the VPN Router 600 • One expansion PCI slot that can contain an optional interface card •...
“How to get help” on page Cables You need cables that are not included in the VPN Router 600 shipping container. For information about which cables are shipped and which ones you can order, “Connecting communications cables VPN Router 600” on page not have the proper cables, contact your network administrator.
To install the VPN Router 600, position the chassis on a flat, sturdy, horizontal surface. Make sure that the surface is large enough for the gateway and sturdy enough to support the combined weight of the VPN Router 600 and the cables that you attach to it.
VPN Router 600. Caution: Connect the cables to the built-in Ethernet ports and to the interfaces on the optional interface card installed in the VPN Router 600 before you plug the power cord into the outlet.
Table 2 lists the system ports and the ports provided on the optional interface cards that you can install in the VPN Router 600. The table also indicates whether you can obtain cables for the ports from Nortel. Table 2 Interfaces and cables for the VPN Router 600...
Connect the 10/100BASE-TX RJ-45 cables to the built-in 10/100BASE-TX Ethernet LAN ports on the gateway Connect the serial cable shipped with the VPN Router 600 to the serial port (Figure 2), if you plan to connect a terminal or PC to the gateway.
Connecting the power cord You must order the power cord for the VPN Router 600 separately. Caution: Risk of equipment damage Do not modify or use the AC power cord if it is not the exact type that is required for your power outlet.
Solutions Center (see Understanding the LEDs This section describes the LEDs on the front panel of the VPN Router 600 and on the interface cards that have LEDs. You can confirm that the LAN and WAN interfaces are cabled properly by examining the LEDs.
Front panel LEDs The front panel of the VPN Router 600 has five LEDs indicate the status of the VPN Router 600. Figure 3 Front panel LEDs Table 4 describes the LEDs on the VPN Router 600 front panel. Table 4 Front panel LED indicators...
The cable connections between the LAN port and the hub are faulty. The LAN port is sending or receiving network data. The frequency of the flashes increases with increased traffic. Nortel VPN Router Installation — VPN Router 600...
10/100BASE-TX Ethernet interface card LEDs Figure 5 shows the LEDs on the 10/100BASE-TX Ethernet interface card. Figure 5 LEDs on the 10/100BASE-TX Ethernet interface card The following describes the LEDs on the 10/100BASE-TX Ethernet interface card. Table 6 LED indicators on the 10/100BASE-TX Ethernet interface card ACT/LINK 10/100TX NN46110-308 02.01...
1000BASE-T Ethernet interface card. Note: The 1000BASE-T (100 GT) Ethernet interface card can only operate at 10/100 Mbit/s on the VPN Router 600. Figure 6 LEDs on the 1000BASE-T (100 GT) Ethernet interface card The following table describes the LEDs on the1000BASE-T (100 GT) Ethernet interface card.
56/64K CSU/DSU WAN interface card LEDs Figure 7 shows the LEDs on the 56/64K CSU/DSU WAN interface card. Figure 7 LEDs on the 56/64K CSU/DSU WAN interface card Table 8 describes the LEDs on the 56/64K CSU/DSU WAN interface card. Table 8 LED indicators on the 56/64K CSU/DSU WAN interface card Blue Yellow...
ADSL network. The ADSL interface card has established a link with the ADSL network. The ADSL interface card is sending or receiving network data. (The LED can be dim.) Nortel VPN Router Installation — VPN Router 600...
T1/E1 CSU/DSU WAN interface card LEDs Figure 9 shows the LEDs on the T1/E1 CSU/DSU WAN interface card. Figure 9 LEDs on the T1/E1 CSU/DSU WAN interface card Table 10 describes the LEDs on the T1/E1 CSU/DSU WAN interface card. Table 10 LED indicators on the T1/E1 CSU/DSU WAN interface card LED 1 LED 2...
The signals CDC and DSR are on between the DSU and the adapter. LED 2 detects receive link status. Power to the adapter is on and the onboard microcode is loaded. Cable is detected. Nortel VPN Router Installation — VPN Router 600...
Page 42
42 Chapter 2 Cabling the VPN Router and turning the power on NN46110-308 02.01...
Configuring the management IP interface This chapter describes how to configure a management IP address, subnet mask, and default gateway address on a newly installed VPN Router 600. After you complete the procedures in this chapter, you can configure and manage the VPN Router 600 using a Web browser from a PC.
IP address for the management interface The management IP address must be accessible from one of the private physical interfaces on the VPN Router 600. For example, if you plan to assign IP address 10.2.3.3 with subnet mask 255.255.0.0 to the private physical interface, the management IP address must reside in the 10.2 network.
Configuring the management IP address You use the serial interface to assign the VPN Router 600 a management IP address and subnet mask so that you can then use a Web browser for management. To configure the management IP address using the serial interface: Turn on the terminal or PC.
Page 46
The serial main menu appears. Main Menu: System is currently in NORMAL mode. 0) Management Address 1) Interfaces 2) Administrator 3) Default Private Route Menu 4) Default Public Route Menu 5) Create A User Control Tunnel (IPsec) Profile 6) Restricted Management Mode 7) Allow HTTP Management 8) Firewall Options 9) Shutdown...
Page 47
Subnet Mask = 0.0.0.0 Speed/Duplex = AutoNegotiate 1) Slot 0, Port 1, Private LAN IP Address =192.167.120.14 Subnet Mask = 255.255.255.0 Speed/Duplex = AutoNegotiate R) Return to the Main Menu. Please select a menu choice: Nortel VPN Router Installation — VPN Router 600...
Page 48
14 From the serial main menu, type E, and press Enter to save the new management IP address and mask, and to exit the serial menu. 15 Go to the next section, you can access the VPN Router 600 from a Web browser. NN46110-308 02.01 “Testing the configuration” on page...
VPN Router software CD. Testing the configuration After you assign a management IP address to the VPN Router 600, start your Web browser to verify that you can access the gateway from the browser.
Check the physical connections on the VPN Router 600, especially the LAN cable and the power cord. If you still cannot connect to the VPN Router 600 using a browser, connect a terminal or PC to the gateway with the serial cable and check the management IP...
• LAN, WAN, and serial interface cards • Dual inline memory module (DIMM) To install an interface card or DIMM, you must remove the VPN Router 600 chassis from its steel enclosure. This chapter contains the following topics: Topic Shutting down the system to add or replace hardware...
Shutting down the system to add or replace hardware Shut down the VPN Router 600, and unplug it to install or replace an option card or to replace the DIMM. To shut down the VPN Router 600: Use the Web graphic user interface (GUI) or the command line interface (CLI) to shut down the gateway.
Shut down the VPN Router 600, and then unplug it as described in down the system to add or replace hardware” on page Warning: Risk of electric shock Turn off the VPN Router 600 and unplug it before you attempt to remove or install an option card or DIMM.
Figure 12 Removing the chassis from the steel enclosure I/ O E X P C O N S O The system board is now exposed. option card slot and the DIMM slot on the VPN Router 600 system board. NN46110-308 02.01 (Figure A N S IO...
In spite of this warning, which is mandated for regulatory approval, you must not change the battery. If you suspect a dead battery, contact Nortel Customer Support. Nortel VPN Router Installation — VPN Router 600...
Single V.35/X.21 WAN interface (full-height) Single V.35/X.21 WAN interface (half-height) 1 The VPN Router 600 must be running Version 5.05.330, 6.05.140 and later, 7.00.062, 7.05.100 and later, or 7.05.300 and later. The VPN Router 600 supports 10/100 Mbps operation only.
Page 57
To install or replace a LAN, WAN, or serial interface card: Shut down the VPN Router 600 using the Web GUI or the CLI, and then unplug it as described in hardware” on page Warning: Risk of electric shock Turn off the VPN Router 600 and unplug it before you attempt to install an option card.
Remove the blank PCI bracket by inserting a Phillips screwdriver into the slot at the right of the blank PCI bracket and rotating the screw counterclockwise (Figure Figure 14 Removing the blank bracket from the option card slot Motherboard Slide the option card into the option card slot Do not bend the copper fingers in the slot.
If you do not seat the card properly, it does not work. Replace the screw at the right end of the PCI bracket Option card (Figure 16 on page Nortel VPN Router Installation — VPN Router 600 CS60006A 60).
Figure 16 Securing the option card in the slot Motherboard Slide the chassis into the steel enclosure Figure 17 Replacing the chassis in the steel enclosure I/ O E X P C O N S O NN46110-308 02.01 Option card slot Option card A N S IO N B A Y...
Router 600 to a power supply turns the gateway on. Replacing a DIMM The VPN Router 600 has one slot for a dual inline memory module (DIMM). If you have a VPN Router 600 with a 64 MB DIMM, you can upgrade system memory by replacing the installed DIMM with a 128 MB DIMM.
Page 62
To replace the DIMM in the VPN Router 600: Shut down the VPN Router 600 using the Web GUI or the CLI, and then unplug it as described in hardware” on page Warning: Risk of electric shock Turn off the VPN Router 600 and unplug it before you attempt to replace the DIMM.
14 Plug the male end of the power cord into a surge protector 15 Plug the surge protector into the power outlet. The VPN Router 600 begins to boot. Note: The VPN Router 600 has no power switch. Connecting the VPN Router 600 to a power supply turns the gateway on. Motherboard...
Chapter 5 Using recovery mode The VPN Router 600 does not have a floppy disk drive, so the software image is built into the onboard flash operating system. Recovery mode on the VPN Router 600 is also built into the flash operating system. You use recovery mode to restore software to a VPN Router 600.
Page 66
Note: The switch marked FD is reserved for future use. Pressing this switch has no effect. From the Web browser, enter the management IP address of the VPN Router 600. The Recovery Diskette screen appears you can perform the following tasks: •...
Page 68
• Restore the factory default configuration by selecting Restore Factory Configuration, then clicking Restore to return the VPN Router 600 to its original factory default configuration. This option erases data contained in flash memory and also in the configuration file.
Page 69
Alternatively, you can restore a new factory default software image and file system to the VPN Router 600 hard disk. Specify the name or address and path of the network file server onto which the software from the Nortel CD has been installed.
Page 70
70 Chapter 5 Using recovery mode NN46110-308 02.01...
Appendix A Technical specifications This appendix provides technical specifications for the VPN Router 600 chassis and its interfaces. Chassis specifications Table 13 lists physical, electrical, and environmental specifications for the chassis. Table 13 Physical, electrical, and environmental specifications Specification Physical...
System ports The VPN Router 600 system board provides the following built-in interfaces: • 10/100BASE-TX Ethernet LAN ports • Serial port This section provides information about the 10/100BASE-TX Ethernet LAN ports and the serial port on the system board. 10/100BASE-TX Ethernet LAN port The system board provides two 10/100BASE-TX Ethernet LAN interfaces on the rear of the chassis.
IP address and subnet mask to the newly installed gateway (for more information, Chapter 3, “Configuring the management IP interface,” on page The serial cable provided with the VPN Router 600 is a DB9/DB25-to-DB9/DB25 cable. This cable provides a crossover connection (transmit-to-receive and receive-to-transmit).
Modem cable specifications If you need to connect a modem to a VPN Router 600, you must obtain an appropriate modem cable. The modem cable must have a 9-pin D-sub plug that connects to the VPN Router 600 serial port and a 25-pin D-sub plug that connects...
Hardware option cards The VPN Router 600 has one expansion PCI slot that supports any of the following option cards: • 10/100BASE-TX Ethernet interface card • 1000BASE-T (1000 GT) Ethernet interface card • 56/64K CSU/DSU WAN interface card • ADSL WAN interface card •...
Note: The 1000BASE-T (1000 GT) Ethernet interface card can only operate at 10/100 Mbit/s on the VPN Router 600. The VPN Router 600, 1100, 1600 and 2600 only support 10/100 Mbit/s operation for the 1000BASE-T (1000 GT) Ethernet card. To ensure reliable speed/duplex...
• For 100BASE-TX operation, use Category 5 twisted-pair wiring: one pair each for transmit and receive operations. The cable must comply with the EIA 568 wiring specification. Nortel recommends a maximum length of 100 meters for the cable segment. •...
Use cable that is wired in accordance with EIA-568-A wiring style. This wiring style ensures that a twisted pair inside the patch cord carries the transmit signal (pins 1 and 2) and the receive signal (pins 7 and 8). Nortel recommends that you use factory-made patch cords.
Table 18 56/64K CSU/DSU cable pinouts for crossover connection Nortel termination not used not used not used not used Receive tip Receive ring The cable operates properly if you do not connect pins 3, 4, 5, and 6. Caution: For crossover connections, do not use Ethernet cable. If you use Ethernet cable, the link cannot be established.
Included in the accessory box is a 7-foot RJ-11 cable to attach to the DSLAM. Table 20 provides the ADSL port pinouts. Table 20 ADSL cable pinouts Function Ring RX/TX ADSL CONN Nortel VPN Router Installation — VPN Router 600...
8-pin RJ-45 modular patch cord. These cables are commonly sold as Category 5, or Ethernet, cables. Note: Nortel does not supply a cable with the ISDN BRI interface cards. Table 21 provides the ISDN BRI S/T cable pinouts.
Figure 28 T1/E1 CSU/DSU WAN interface card (half-height card) Note: For E1 service, you must install the half-height version of the T1/E1 CSU/DSU WAN interface card. Figure 29 on page 84 (full-height card). shows the T1/E1 CSU/DSU WAN interface card Nortel VPN Router Installation — VPN Router 600...
8-pin RJ-48 modular patch cord. These cables are sold as Category 5, or Ethernet, cables. Note: Nortel does not supply the T1/E1 CSU/DSU WAN interface cable with the WAN interface card. Use cable that is wired in accordance with EIA-568-A wiring style. This wiring style ensures that the transmit signal (pins 4 and 5) and the receive signal (pins 1 and 2) are carried on a twisted pair inside the patch cord.
Remote termination Pin # to Pin # Signal Receive A (RXDA) Receive B (RXDB) not used Transmit B (TXDB) Transmit A (TXDA) not used not used not used Nortel VPN Router Installation — VPN Router 600 Special-wired end 8-pin male...
Single V.35/X.21 WAN interface card The single V.35/X.21 WAN interface card has a single DB28S connector that provides the signals needed to interface to V.35 and X.21 equipment. shows the single V.35/X.21 WAN interface card. Figure 30 Single V.35/X.21 WAN interface card You need a DSU/CSU (digital service unit/channel service unit) between the WAN connection and the gateway.
Table 26 provides the X.21 cable pinouts. (The pair suffix A or B refers to an individual wire within a twisted pair.) Table 26 X.21 cable pinouts Standard-wired end 28-pin male Signal name TXDA TXDB RXDA RXDB TXCA TXCB RXCA RXCB SCTEA SCTEB...
73 single V.35/X.21 WAN interface 86 T1/E1 CSU/DSU WAN interface 84 V.90 modem interface 89 Category 5 wiring requirements 72 chassis installing 28 specifications 71 configuring the management IP address 45 connecting Nortel VPN Router Installation — VPN Router 600...
Page 92
NN46110-308 02.01 by Express Routing Code 18 by phone 18 latest updates 17 Nortel distributor 18 Nortel Web site 17 Help, how to get 17 installing the chassis on a flat surface 28 prerequisites 26 interfaces, option card, technical specifications 76...
Need help?
Do you have a question about the 600 and is the answer not in the manual?
Questions and answers