Page 1
Nortel VPN Router Installation — VPN Router 1750 Version 7.05.300 NN46110-316 02.01 318022-C Rev 01 November 2007 Standard 600 Technology Park Drive Billerica, MA 01821-4130...
Page 2
In the interest of improving internal design, operational function, and/or reliability, Nortel Networks Inc. reserves the right to make changes to the products described in this document without notice. Nortel Networks Inc. does not assume any liability that may occur due to the use or application of the product(s) or circuit layout(s) described herein.
Page 3
EN 55 022 statement This is to certify that the Nortel Networks VPN Router 1750 is shielded against the generation of radio interference in accordance with the application of Council Directive 89/336/EEC, Article 4a. Conformity is declared by the application of EN 55 022 Class A (CISPR 22).
Page 4
30 days of purchase to obtain a credit for the full purchase price. “Software” is owned or licensed by Nortel Networks, its parent or one of its subsidiaries or affiliates, and is copyrighted and licensed, not sold. Software consists of machine-readable instructions, its components, data, audio-visual content (such as images, text, recordings or pictures) and related licensed materials including all whole or partial copies.
Page 5
CFE is no longer in use, Customer will promptly return the Software to Nortel Networks or certify its destruction. Nortel Networks may audit by remote polling or other reasonable means to determine Customer’s Software activation or usage levels. If suppliers of third party software included in Software require Nortel Networks to include additional or different terms, Customer agrees to abide by such terms provided by Nortel Networks with respect to such third party software.
New in this release The following section details what’s new in Nortel VPN Router Installation— VPN Router 1750 (NN46110-316) for Release 7.05.300: Features See the following section for information about feature changes: 1000BASE-T (1000 GT) Ethernet card The 1000BASE-T (1000 GT) Ethernet card replaces the 10/100BASE-TX Ethernet card.
Select Security & VPN and then, in the section called Virtual Private Networking (VPN), IPSEC, and SSL, click the appropriate VPN Router product. Getting help from the Nortel Web site The best way to get technical support for Nortel products is from the Nortel Technical Support Web site: www.nortel.com/support...
Center If you do not find the information you require on the Nortel Technical Support Web site, and you have a Nortel support contract, you can also get help over the phone from a Nortel Solutions Center. In North America, call 1-800-4NORTEL (1-800-466-7835).
How to get help 19 Getting help through a Nortel distributor or reseller If you purchased a service contract for your Nortel product from a distributor or authorized reseller, contact the technical support staff for that distributor or reseller. Nortel VPN Router Installation — VPN Router 1750...
Router documentation, see Before you begin This guide is intended for qualified service personnel who are installing the VPN Router 1750 for the first time or who need to install or replace any of the following field replaceable units (FRU): •...
Text conventions This guide uses the following text conventions: bold Courier text italic text plain Courier text separator ( > ) Acronyms This guide uses the following acronyms: ADSL CSU/DSU DIMM HSSI IPsec NN46110-316 02.01 Indicates command names and options and text that you need to enter.
3DES Related publications For complete information about configuring, monitoring, and managing the VPN Router 1750, formerly known as the Contivity Secure IP Services Gateway 1750, refer to the following publications (included on the software CD): • Release notes provide the latest information, including brief descriptions of the new features, problems fixed in this release, and known problems and workarounds.
Printed technical manuals You can print selected technical manuals and release notes free, directly from the Internet. Go to www.nortel.com/documentation, find the product for which you need documentation, then locate the specific category and model or version for your hardware or software product. Use Adobe Reader to open the manuals and release notes, search for the sections you need, and print them on most standard printers.
VPN Router 1750. Caution: Connect the cables to the built-in Ethernet ports and to the interfaces on the option cards installed in the VPN Router 1750 before you plug the power cord into the outlet.
Table 1 lists the system ports and the ports provided on the optional interface cards that you can install in the VPN Router 1750. The table also indicates whether you can obtain cables for the ports from Nortel. Table 1 Interfaces and cables for the Nortel VPN Router 1750...
Figure 1 shows the back of the VPN Router 1750. All interface cables and the power cord attach to the rear of the gateway. Figure 1 Rear view of the Nortel VPN Router 1750 VPN Router 2750 100 - 240 V~...
Connect the power cord to the power outlet. Caution: Risk of equipment damage Protect the VPN Router 1750 by plugging it into a surge suppressor. Press and release the power switch on the rear of the VPN Router 1750 (Figure 1 on page NN46110-316 02.01...
The Alert LED lights yellow because the gateway is not configured. For a newly installed VPN Router 1750, a yellow Alert LED does not indicate an alarm condition. After you configure the gateway, the Alert LED turns off.
LAN and WAN interfaces by examining the LEDs. Front panel LEDs The front panel of the VPN Router 1750 has a lighted Nortel logo and two LEDs (Figure 2). These LEDs indicate the status of the VPN Router 1750.
The cable connections between the LAN port and the hub are faulty. The LAN port is sending or receiving network data. The frequency of the flashes increases with increased traffic. Nortel VPN Router Installation — VPN Router 1750...
10/100BASE-TX Ethernet interface card LEDs Figure 4 shows the LEDs on the 10/100BASE-TX Ethernet interface card. Figure 4 LEDs on the 10/100BASE-TX Ethernet interface card Table 5 describes the LEDs on the 10/100BASE-TX Ethernet interface card. Table 5 LED indicators on the 10/100BASE-TX Ethernet interface card ACT/LINK 10/100TX 1000BASE-T (1000 GT) Ethernet interface card LEDs...
The port is operating at 10 Mb/s. 10/100/1000 ACT/LNK Description The port is connected to a valid link partner. The LAN port is sending or receiving network data. The port is not linked to a valid partner. Nortel VPN Router Installation — VPN Router 1750 11287EA...
Table 7 LED indicators on the 1000BASE-T (1000 MT) Ethernet interface card 10/100/1000 1000BASE-SX Ethernet interface card LED Figure 7 shows the LED on the 1000BASE-SX Ethernet interface card. Figure 7 LED on the 1000BASE-SX Ethernet interface card Table 8 describes the LED on the 1000BASE-SX Ethernet interface card.
The green LED is lit when the interface card receives valid DDS signal and framing (this LED indicates normal operation of the card.) All LEDs off The port is disabled. Red LED 56/64K Yellow LED Nortel VPN Router Installation — VPN Router 1750...
ADSL WAN interface card LEDs Figure 9 shows the LEDs on the asymmetric digital subscriber line (ADSL) WAN interface card. Figure 9 LEDs on the ADSL WAN interface card Table 10 describes the LEDs on the ADSL WAN interface card. Table 10 LED indicators on the ADSL WAN interface card CONN LED Steady green...
(AIS). The yellow alarm LED is lit when the far-end equipment is in the red alarm condition. The green LED is lit when the condition is normal operation. Nortel VPN Router Installation — VPN Router 1750 CS160012A...
Quad T1/E1 CSU/DSU WAN interface card LEDs Figure 11 shows the LEDs on the quad T1/E1 channel service unit/digital service unit (CSU/DSU) WAN interface card. Figure 11 LEDs on the quad T1/E1 CSU/DSU WAN interface card Table 12 describes the LEDs on the quad T1/E1 CSU/DSU WAN interface card. Table 12 LED indicators on the quad T1/E1 CSU/DSU WAN interface card LED 1 LED 2...
The signals CDC and DSR are on between the DSU and the adapter. LED 2 detects receive link status. Power to the adapter is on and the onboard microcode is loaded. Cable is detected. Nortel VPN Router Installation — VPN Router 1750...
SSL VPN Module 1000 LEDs Figure 13 shows the LEDs on the Secure Sockets Layer (SSL) VPN Module 1000. Figure 13 LEDs on the SSL VPN Module 1000 Table 14 describes the LEDs on the SSL VPN Module 1000. Table 14 LED indicators on the SSL VPN Module 1000 LEDs Online Activity LED 1...
Installing the chassis Description of the Nortel VPN Router 1750 With the VPN Router 1750, you can supply scalable, secure, and robust Internet Protocol (IP) virtual private networks (VPN) across the public data network. The VPN Router 1750 provides routing, firewall, bandwidth management, encryption, authentication, and data integrity services to ensure secure tunneling across IP networks and the Internet.
The VPN Router 1750 chassis provides the following: • two 10/100 Etherne • one serial port for out-of-band management of the VPN Router 1750 • four expansion peripheral component interconnect (PCI) slots that can contain interface cards, a VPN Accelerator card (VPN Router Security Accelerator...
VPN client kit Sheet of labels Inspect all items for shipping damage. If you detect any damage, do not install the VPN Router 1750. Call the Nortel Technical Solutions Center in your area (see “How to get help” on page Purpose...
Additional equipment You need items that are not included in the VPN Router 1750 shipping container. Before you begin the installation, ensure that you have all the cables, tools, and other equipment that you need. Cables You need cables that are not included in the VPN Router 1750 shipping container.
Installing the chassis on a flat surface If you decide to place the VPN Router 1750 on a flat surface, make sure that the surface is large enough for the gateway and sturdy enough to support the combined weight of the VPN Router 1750 and the cables that you attach to it.
Attaching the shelf in the equipment rack The VPN Router 1750 ships with a rack-mount shelf to support the chassis in the equipment rack. To attach the shelf to the inside of the equipment rack:...
Insert one of the supplied panhead screws through the top hole on each side of the shelf into the hole in the rack, and tighten the screws CS260003A Rack edge Flange (Figure 17). Ensure that the alignment pin Nortel VPN Router Installation — VPN Router 1750 Figure CS260003A (Figure 17).
Caution: Risk of equipment damage Do not use the piece with the Nortel logo and the LEDs as a handle. The first several times that you remove the front bezel, the bezel can stick because the ball studs and socket clips are new.
Hold the two handles on the bezel, and push it onto the chassis. b Use the Phillips screwdriver to tighten the two screws that secure the bezel to the chassis. Figure 19 Replacing the front bezel (Figure 19). Press here Nortel VPN Router Installation — VPN Router 1750 (Figure 17 on CS260005E...
Chapter 3 Installing option cards and DIMMs This chapter provides instructions about how to install and replace the following field replaceable units (FRU) in the VPN Router 1750: • LAN, WAN, and serial interface cards • Secure Sockets Layer (SSL) VPN Module 1000 •...
27). Warning: Risk of electric shock Make sure to turn off the VPN Router 1750 and unplug the power cord before you attempt to remove or install an option card or DIMM. NN46110-316 02.01 command to shut down the system. For example, reload reload power-off disable-logins “Upgrade hardware”...
To install option cards or DIMMs, you must remove the front bezel and the top cover from the gateway. To remove the front bezel: Shut down the VPN Router 1750 using the Web GUI or the CLI, and then unplug it as described in hardware” on page...
Page 54
Caution: Risk of equipment damage Do not use the piece with the Nortel logo and the LEDs as a handle. The first several times that you remove the front bezel, the bezel can stick because the ball studs and socket clips are new.
Chapter 3 Installing option cards and DIMMs 55 Figure 21 Removing the top cover Remove these 4 screws Alert Boot/Ready Slide cover forward and lift up CS260006A Slide the top cover forward approximately 1/4 inch. Nortel VPN Router Installation — VPN Router 1750...
In spite of this warning, which is mandated for regulatory approval, you must not change the battery. If you suspect a dead battery, contact Nortel Customer Support. NN46110-316 02.01...
Attaching the antistatic wrist strap Nortel ships the VPN Router 1750 with an antistatic wrist strap. The antistatic wrist strap directs the discharge of static electricity from your body to the chassis of the gateway to avoid damage to sensitive electronic components.
Installing and replacing option cards The VPN Router 1750 has four slots for option cards section provides instructions on adding new option cards to the VPN Router 1750 or, if necessary, replacing an existing card. Table 16 lists the option cards that you can install in the VPN Router 1750.
1 The VPN Router 1750 must be running Version 5.0 or later. 2 The VPN Router 1750 must be running Version 4.90 or later. 3 The VPN Router 1750 must be running Version 5.05.330, 6.05.140 and later, 7.00.062, 7.05.100 and later, or 7.05.300 and later.
Installing and replacing an option card To install or replace an interface card or a Hardware Accelerator card: Shut down the VPN Router 1750 using the Web GUI or the CLI, and then unplug it as described in hardware” on page...
Use a screwdriver to insert and tighten the four screws that secure the cover to the chassis. 10 If the VPN Router 1750 is installed in an equipment rack, mount it in the rack. Set the VPN Router 1750 on the rack-mount shelf in the rack.
The VPN Router 1750 has two slots for dual inline memory modules (DIMM) (Figure 22 on page 1750 is shipped with one 128 MB DIMM installed. You can upgrade memory in the gateway by installing a second 128 MB DIMM.
Page 63
For example, do not install a 256 MB DIMM in the VPN Router 1750. To install or replace a DIMM: Shut down the VPN Router 1750 using the Web GUI or the CLI, and then unplug it as described in hardware” on page...
If you are replacing a DIMM, remove the installed DIMM as follows: Press down the locking lever on either side of the DIMM b Pull the DIMM up to remove it from the slot. Press down the locking lever on either side of the slot where you plan to install the new DIMM Place the new or replacement DIMM in the slot Use the alignment keys to properly position the DIMM in the slot.
Page 65
Insert the four screws that secure the cover to the chassis, and use a screwdriver to tighten the screws. 11 If the VPN Router 1750 is installed in an equipment rack, mount it in the rack. Set the VPN Router 1750 on the rack-mount shelf in the rack.
This chapter describes how to configure a management Internet Protocol (IP) address, subnet mask, and default gateway address on a newly installed VPN Router 1750. After you complete the procedures in this chapter, you can configure and manage the VPN Router 1750 using a Web browser from a PC.
IP address for the management interface The management IP address must be accessible from one of the private physical interfaces on the VPN Router 1750. For example, if you plan to assign IP address 10.2.3.3 with subnet mask 255.255.0.0 to the private physical interface, the management IP address must reside in the 10.2...
Configuring the management IP address You use the serial interface to assign the VPN Router 1750 a management IP address and subnet mask so that you can then use a Web browser for management. To configure the management IP address using the serial interface: Turn on the terminal or PC.
Page 70
The serial main menu appears. Main Menu: System is currently in NORMAL mode. 0) Management Address 1) Interfaces 2) Administrator 3) Default Private Route Menu 4) Default Public Route Menu 5) Create A User Control Tunnel (IPsec) Profile 6) Restricted Management Mode 7) Allow HTTP Management 8) Firewall Options 9) Shutdown...
Page 71
Subnet Mask = 0.0.0.0 Speed/Duplex = AutoNegotiate 1) Slot 0, Port 1, Private LAN IP Address =192.167.120.14 Subnet Mask = 255.255.255.0 Speed/Duplex = AutoNegotiate R) Return to the Main Menu. Please select a menu choice: Nortel VPN Router Installation — VPN Router 1750...
Page 72
IP address and mask, and to exit the serial menu. 15 Go to the next VPN Router 1750 section, page 73, to verify that you can access the VPN Router 1750 from a Web browser. NN46110-316 02.01 “Testing the configuration” on...
After you assign a management IP address to the VPN Router 1750, start your Web browser to verify that you can access the gateway from the browser. To manage the VPN Router 1750 using the GUI, your PC must be running one of the following browsers: •...
Check the physical connections on the VPN Router 1750, especially the LAN cables and the power cord. If you still cannot connect to the VPN Router 1750 using a browser, connect a terminal or PC to the gateway with the serial cable and check the management IP...
Appendix A Technical specifications This appendix provides technical specifications for the VPN Router 1750 chassis and the chassis interfaces. Chassis specifications Table 17 lists physical, electrical, and environmental specifications for the chassis. Table 17 Physical, electrical, and environmental specifications Specification...
Table 17 Physical, electrical, and environmental specifications (continued) Specification Operating altitude Storage altitude System ports The VPN Router 1750 system board provides the following built-in interfaces: • two 10/100BASE-TX Ethernet local area network (LAN) ports • serial port This section provides information about the 10/100BASE-TX Ethernet LAN ports and the serial port on the system board.
(for more information, see Chapter 4, “Configuring the management IP interface,” on page The serial cable provided with the VPN Router 1750 is a DB9/DB25-to-DB9/ DB25 cable. This cable provides a crossover connection (transmit-to-receive and receive-to-transmit).
Ground Modem cable specifications If you need to connect a modem to a VPN Router 1750, you must obtain an appropriate modem cable. The modem cable must have a 9-pin D-sub plug that connects to the VPN Router 1750 serial port and a 25-pin D-sub plug that connects to the RS-232-C modem port NN46110-316 02.01...
Data Terminal Ready Clear to Send Request to Send Hardware option cards The VPN Router 1750 provides four peripheral component interconnect (PCI) slots that support a combination of the following option cards: • VPN Router Security Accelerator and Hardware Accelerator cards •...
VPN Router Security Accelerator card Nortel supports the VPN Router Security Accelerator option card that performs bulk encryption and compression algorithms for IPsec tunnel traffic: The VPN Router Security Accelerator card uses a single Hifn 7854 chip for encryption and compression and has 64 MB of onboard RAM.
The VPN Router Security Accelerator card is the successor to the Hardware Accelerator card. The Hardware Accelerator Hifn 7811 card has been discontinued effective January 2006 although Nortel still supports this card. Along with providing support for AES, the VPN Router Security Accelerator card provides increased encryption throughput and improved compression performance.
The SSL VPN Module 1000 has no external access: all traffic to and from the SSL VPN Module 1000 card occurs over an internal high-speed link. The SSL VPN Module 1000 is supported on VPN Router 5000, 2700, and 1750 gateways running VPN Router Version 5.0 software. You must install the SSL VPN Module 1000 in slot 1 of the VPN Router 5000, 2700, or 1750.
• 7.05.100 and all subsequent versions (FIPS branch) • 7.05.300 and all subsequent versions The 1000 GT card does not replace the high-performance 1000BASE-T 1000 MT card (see the following section). CS260009A Nortel VPN Router Installation — VPN Router 1750...
• For 1000BASE-T operation, use Category 5 four-pair Ethernet wiring. The cable must comply with the TIA 568 wiring specification. Nortel recommends a maximum length of 100 meters for the cable segment. •...
Select cables for this port as follows: • For 1000BASE-T operation, use Category 5 four-pair Ethernet wiring. The cable must comply with the TIA 568 wiring specification. Nortel recommends a maximum length of 100 meters for the cable segment. •...
50-micron MMF cable: provides a distance range of 500–550 meters (m) • 62.5-micron MMF cable: provides a distance range of 220–275 m You can order a 10-foot MMF cable from Nortel: • Order no. DM0011117 provides an LC-to-LC connector •...
Use cable that is wired in accordance with ANSI T1.410 wiring style. This wiring style ensures that a twisted pair inside the patch cord carries the transmit signal (pins 1 and 2) and the receive signal (pins 7 and 8). Nortel strongly recommends that you use professionally manufactured patch cords.
Transmit tip Transmit ring Remote termination Pin # to Pin # Signal Transmit tip Transmit ring not used not used not used not used Receive tip Receive ring Nortel VPN Router Installation — VPN Router 1750...
ADSL WAN interface card The ADSL Annex A and Annex B WAN interface cards have a single RJ-11 connector that provides the signals needed to interface to the ADSL-provisioned telephone line. Figure 37 shows the ADSL WAN interface card. Note: The ADSL Annex A and ADSL Annex B cards look identical. Figure 37 ADSL WAN interface card Included in the accessory box with the ADSL WAN interface card is a 7-foot cable to attach to the DSLAM.
The connector on the ISDN BRI S/T and ISDN BRI U interface cards accommodates an 8-pin RJ-45 modular patch cord. These cables are sold as Category 5, or Ethernet, cables. Note: Nortel does not supply a cable with the ISDN BRI interface cards. RJ-45 termination Pin # to Pin #...
Use cable that is wired in accordance with EIA-568-A wiring style. This wiring style ensures that a twisted pair inside the patch cord carries the transmit signal (pins 4 and 5) and the receive signal (pins 1 and 2).Nortel strongly recommends that you use professionally manufactured patch cords.
You connect the T1/E1 CSU/DSU WAN interface card to the service provider network using a straight-through cable or a crossover cable, depending on how the service provider wired its jack. • For a straight-through connection, you can use a standard Category 5 (Ethernet) straight-through cable.
Each connector on the quad T1/E1 CSU/DSU WAN interface card accommodates an 8-pin RJ-48 modular patch cord. These cables are commonly sold as Category 5, or Ethernet, cables. Note: Nortel does not supply cables with the quad T1/E1 CSU/DSU interface card. Remote termination...
Use cable that is wired in accordance with EIA-568-A wiring style. This wiring style ensures that a twisted pair inside the patch cord carries the transmit signal (pins 4 and 5) and the receive signal (pins 1 and 2). nortel strongly recommends that you use professionally manufactured patch cords.
CS160011A Table 33 on page 99 Pair number and conductor pair 1A pair 1B pair 2A pair 2B pair 3A pair 3B Nortel VPN Router Installation — VPN Router 1750 Figure 43 provides the X.21 Special-wired end 34-pin male Notes...
Page 98
Table 32 V.35 cable pinouts (continued) Standard-wired end 28-pin male Signal name RXCA RXCB SCTEA SCTEB RTSA RTSB CTSA CTSB DSRA DSRB DTRA DTRB DCDA DCDB M0<-SIGNAL GROUND M1<-SIGNAL GROUND SHIELD SIGNAL GROUND The following notes apply to the single V.35 DTE cable: 1.
Table 33 X.21 cable pinouts (continued) Standard-wired end 28-pin male Signal name SHIELD SIGNAL GROUND The following notes apply to the single X.21 cable: 1. Wires of pair 4 connect to wires of pair 5, but not to any pins in the DA-15. 2.
Page 101
Table 34 T3 cable pinouts (continued) 50-pin SCSI male Signal name TESTB TESTA 50-pin SCSI male Nortel VPN Router Installation — VPN Router 1750...
Page 102
102 Appendix A Technical specifications NN46110-316 02.01...
Page 103
58 LEDs 36 antistatic wrist strap, attaching 57 bezel, front removing 48, 53 replacing 49, 62 browsers, supported 73 cables available from Nortel 26 connecting to the gateway 27 ordering 26 Nortel VPN Router Installation — VPN Router 1750...
Page 104
power. See AC power cord technical specifications 1000BASE-SX connector 87 1000BASE-T (1000 MT) connector 85 100BASE-TX connector 76 10BASE-T connector 76 56/64K CSU/DSU WAN interface 88 ADSL WAN interface 90 HSSI WAN interface 100 ISDN BRI interface 91 modem 79 quad T1/E1 CSU/DSU WAN interface 96 serial interface 77 single V.35/X.21 WAN interface 97...
Page 106
56/64K CSU/DSU WAN interface card 35 ADSL WAN interface card 36 front panel 30 quad T1/E1 CSU/DSU WAN interface card 38 single V.35/X.21 WAN interface card 39 SSL VPN Module 1000 40 system LAN port 31 T1/E1 CSU/DSU WAN interface card 37 used to verify correct installation 29 main menu, serial interface 70 management IP address...
Page 107
29 verifying the management IP interface 73 VPN Router 1750 configuring management IP address for 67 connecting cables to 25 connecting power cord 28 description 41 installing option cards and DIMMs 51 Nortel VPN Router Installation — VPN Router 1750...
Page 108
installing the chassis 45 shipment contents 43 shutting down 52 technical specifications 75 verifying a successful installation 29 verifying connectivity 73 VPN Router Security Accelerator card described 80 installing 58 WAN interface cards installing 58 LEDs 56/64K CSU/DSU 35 ADSL 36 quad T1/E1 CSU/DSU 38 single V.35/X.21 39 T1/E1 CSU/DSU 37...