Page 1
Nortel Switched Firewall 5100 Series Release 2.3.3 Hardware Installation Guide part number: 216382-D, October 2005 4655 Great America Parkway Santa Clara, CA 95054 Phone 1-800-4Nortel http://www.nortel.com...
Page 2
FAR 12.211- 12.212 (Oct 1995), DFARS 227.7202 (JUN 1995) and DFARS 252.227-7015 (Nov 1995). Nortel Networks, Inc. reserves the right to change any products described herein at any time, and without notice. Nortel Networks, Inc. assumes no responsibility or liability arising from the use of products described herein, except as expressly agreed to in writing by Nortel Networks, Inc.
Page 3
Regulatory Compliance International regulatory statements of conformity This is to certify that the Nortel Networks 5100 Series is evaluated to the international regulatory standards for electromagnetic compliance (EMC) and safety and were found to have met the requirements for the following international standards: EMC - Electromagnetic Emissions –...
Page 4
EN 55 024 statement This is to certify that the Nortel Networks equipment is shielded against the susceptibility to radio interference in accordance with the application of Council Directive 89/336/EEC. Conformity is declared by the application of EN 55 024 (CISPR 24).
Page 5
CE marking statement (Europe only) EN 60 950 statement This is to certify that the Nortel Networks equipment are in compliance with the requirements of EN 60 950 in accordance with the Low Voltage Directive. Additional national differences for all European Union countries have been evaluated for compliance.
Page 6
Norma Oficial Méxicana (NOM): Exportador: Nortel Networks, Inc. 4655 Great America Parkway Santa Clara, CA 95054 USA Importador: Nortel Networks de México, S.A. de C.V. Avenida Insurgentes Sur #1605 Piso 30, Oficina Col. San Jose Insurgentes Deleg-Benito Juarez México D.F.
How to get help 13 Getting help from the Nortel web site 13 Getting help over the telephone from a Nortel Solutions Center 13 Using an Express Routing Code to get help from a specialist 14 Getting help through a Nortel distributor or reseller 14...
Page 8
NSF 5114-NE1 36 Mounting the NSF 5106, NSF 5109, or NSF 5114 37 Stand-alone or tabletop installation 38 Chapter 3: Connecting 39 Connecting network cables 40 Example Switched Firewall network topology 40 Network connector and cable specifications 43 RJ-45 Connector specifications for 10/100/1000 Mbps Ethernet 43...
Page 9
NSF 5109 and NSF 5114 60 Physical characteristics 60 Power requirements 60 Port specifications for NSF 5109 and NSF 5114 60 Supported standards 61 Environmental specifications 61 Hardware Installation Guide...
How this book is organized The chapters in this book are organized as follows: Introduction, provides an overview of the major features of the Nortel Switched Chapter 1, Firewall, including the physical layout of its components and the basic concepts behind component operation.
Typographic conventions The following table describes the typographic styles used in this book. Table 1 Typographic Conventions Typeface or Symbol AaBbCc123 AaBbCc123 AaBbCc123 <AaBbCc123> Italicized type within angle-brackets appears <Key> Preface Meaning This fixed-width type is used for names of commands, files, and directories used within the text.
Getting help over the telephone from a Nortel Solutions Center If you do not find the information you require on the Nortel Technical Support web site, you can get help over the telephone from a Nortel Solutions Center. You must have a Nortel support contract to use the Nortel Solutions Center.
Using an Express Routing Code to get help from a specialist You can find Express Routing Codes (ERC) for many Nortel products and services on the Nortel Technical Support web site. ERCs allow you to connect directly to service and support organizations based on specific products or services.
HAPTER Introduction This hardware installation guide describes the Nortel Switched Firewall 5100 Series hardware platforms and how to install them. This chapter discusses the following topics: Related documentation on page 16 Platform summary on page 16 Hardware platforms on page 17...
The Nortel Switched Firewall 5100 Series hardware platforms are shipped with the following hardware systems: Existing systems: NSF 5111-NE1, NSF 5114-NE1, NSF 5106, NSF 5109, and NSF 5114. The platforms differ with respect to hardware features and performance; however, in all other operational aspects—software, certification, system management, logging, and monitoring—...
Table 3 describes the hardware features for the NSF 5106, NSF 5109, and NSF 5114 platforms. Table 3 Hardware Features for the NSF 5106, NSF 5109, and NSF 5114 Platforms Switched Firewall Features Port capacity hard drive capacity Dimension/ Chassis Hardware platforms This section describes the hardware platforms.
Page 18
The reset button is equivalent to quickly pressing the power off/on button twice on a running system. Nortel recommends that you to power off using the power button, wait for 10 seconds, and then power on the system, instead of using the reset button.
Page 19
USB storage memory stick (having FAT filesystem) APC Uninterruptible Power Supply (UPS) with USB interface Figure 3 shows the rear panel of the NSF 5111-NE1 Figure 3 NSF 5111-NE1 rear panel. Power on/off switch Power socket or AC receptacle Power supply fan Auxiliary cooling fan Serial port (DCE, for console connection) Port 1 10/100/1000 Mbps copper Ethernet...
The reset button is equivalent to quickly pressing the power off /on button twice on a running system. Nortel recommends that you power off using the power button, wait for 10 seconds, and then power on the system, instead of using the reset button.
Page 21
Power button System status LED (amber) The system status LED indicates the operation of the four fans, CPU temperature, chassis ambient temperature, and the voltage (+5v, +12v). LED is normally off. If the system detects a problem with any of the system voltages, temperature sensors, or fans, this LED blinks amber.When the system is reset, the LED is off.
Port 2, 10/100/1000 Mbps Copper Ethernet Ports 1 and 2 are 1000BaseT ports. See conditions. Port 3, 1 gigabit fiber Ethernet Port 4, 1 gigabit fiber Ethernet Ports 3 and 4 interface media type is 1000BaseSX connector type LC. See for ports 3 and 4 LED status conditions.
Page 23
The reset button is equivalent to quickly pressing the power off /on button twice on a running system. But Nortel recommends that you to power off using the power button, wait for 10 seconds and then power on the system, instead of using the reset button.
NSF 5109 with the front bezel. Figure 10 NSF 5109 with front bezel Figure 11 shows the Switched Firewall 5109 with the bezel removed. For instructions on how to remove the bezel, refer to Figure 11 NSF 5109 front panel...
Page 25
The reset button is equivalent to quickly pressing the power off /on button twice on a running system. Nortel recommends that you power off using the power button, wait for 10 seconds and then power on the system, instead of using the reset button.
Table 17 on page 50 Serial connector (DCE, for console connection) Switched Firewall 5114 The Switched Firewall 5114 front panel bezel is identical to the 5109 front panel bezel (see Figure 10 on page how to remove or attach the 5114 front panel bezel.
Page 27
The reset button is equivalent to quickly pressing the power off /on button twice on a running system. Nortel recommends that you power off using the power button, wait for 10 seconds and then power on the system, instead of using the reset button.
Table 19 on page 51 Serial connector (DCE, for console connection) Removing and attaching the bezel This section applies to Switched Firewall 5111-NE1, 5114-NE1, 5106, 5109, and 5114. To remove the bezel, open the flap (see 2 in pull the bezel off the faceplate.
Page 29
Figure 15 illustrates bezel installation. Figure 15 Installing the bezel Follow these steps to attach the bezel. Lift the flap that is located at the left end of the bezel. Slide the bezel on the faceplate from right to left, until the edge of the bezel aligns with the edge of the faceplate lengthwise (see 1 in Keep sliding until you hear a click, which means the bezel has locked on to the faceplate.
Page 30
Nortel Switched Firewall 5100 Series Hardware Installation Guide Chapter 1: Introduction 216382-D, October 2005...
Installing This chapter provides step-by-step instructions for physically installing the components of the Nortel Switched Firewall after you physically install the other components of your network (routers, servers, hubs, and so on). Physical installation of the Nortel Switched Firewall involves the following tasks:...
The Nortel Switched Firewall system requires the following minimum components: One Nortel Switched Firewall The Nortel Switched Firewall can be rack-mounted in a standard 19" rack or located on a shelf or other flat surface. Each Nortel Switched Firewall is shipped with the following...
Safety precautions Always observe the precautions in the manuals for this and all other equipment you are installing. Assembly —Before installing the components, secure and stabilize the two-post open-frame AUTION relay rack according to the rack manufacturer or industry specifications.The four-post cabinet rack must meet the relevant ANSI/EIA-310-D-92, IEC 297, or DIN 41494 specifications.
Rack installation The following procedure is for installing the Firewall in a standard 19-inch two-post open- frame relay rack or a four-post enclosed rack cabinet. Removing the bezel Unpack the Firewall from its shipping box. If previously attached, remove the bezel from the front panel of the Firewall (see ing and attaching the bezel on page Loosen the captive thumbscrews next to the chassis bezel clips on each side of the front panel.
Page 35
Attach the front bezel to the system. This completes the two-post rack installation procedure. 216382-D, October 2005 0.5" 0.625" 0.625" 0.5" Table Mounting the NSF 5111-NE1 and NSF 5114-NE1 Mounting the NSF 5106, NSF 5109, or NSF 5114 Chapter 2: Installing...
Mounting the NSF 5111-NE1 and NSF 5114-NE1 The 5111-NE1 and 5114-NE1 can be flush-mounted in a rack or mounted on a table. Follow the initial instructions for rack mounting as described in follow the steps shown in Figure 17 Rack mounting the 5111-NE1 and 5114-NE1 Step 1 Attach the 2 mounting brackets to the appliance using 5 screws on...
Mounting the NSF 5106, NSF 5109, or NSF 5114 You can install the NSF 5106, NSF 5109 or NSF 5114 in a standard 19-inch relay rack, or on a suitable tabletop. Follow the general instructions for rack mounting as described in...
Stand-alone or tabletop installation If you installed the unit in a cabinet, reattach the cabinet rack doors and side panels according to the instructions that came with your cabinet. Unpack the Firewall from its shipping box. Remove the heavy-duty rack-mounting brackets from each side of the unit. Store the brackets and any unused screws in a safe place for possible future use.
Console connector and cable specifications on page 53 Establishing a connection on page 54 Each task is detailed in this chapter. Required software setup is described in the Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference (Part number –The instructions in this chapter are for installing a single unit. Interconnecting Switched Firewalls in a high-availability configuration is described in the Nortel Switched Firewall 2.3.3...
Port LED indicators on page 46 Example Switched Firewall network topology When the Nortel Switched Firewall (NSF) equipment is physically mounted in a rack system, the required network cables can be attached. The precise network topology depends on your specific network, a basic Nortel Switched Firewall topology—with Check Point Management Server—suggested for initial configuration...
Page 41
Figure 20 Example network using NSF 5109 Intranet Trusted Networks Figure 21 Example network using NSF 5114-NE1 Intranet Trusted Networks 216382-D, October 2005 port 3-6 ext_ft int_ft operational power (optional) Remote console for SMART Client, Telnet, BBI, and SSH access...
Page 42
Figure 22 Example network using NSF 5114 Trusted Networks Intranet Figure 23 Example network using NSF 5106 Intranet Trusted Networks Remote console for SMART Client, Telnet, BBI, and SSH access Attach the network segments to the Firewall network ports. Chapter 3: Connecting ports 4 3 Remote console for SMART Client,Telnet,...
The Nortel Switched Firewall has the following network ports, which are auto-negotiating and support half- or full-duplex operation: Use the RJ-45 jack to connect the 10/100/1000 Mbps Ethernet (10Base-T, 100Base-TX, or 1000Base-T) segments to the port. Nortel recommends these ports for connecting upstream and downstream networks and for connecting a Check Point SmartCenter Server or, optionally, a De-Militarized Zone (DMZ).
Network cables: straight-through versus crossover The 10/100/1000 Mbps port cables can be wired as straight-through or crossover, depending on the devices being connected. When connecting different classes of devices (a computing device and a network device), a straight-through cable is generally used. In a straight-through cable, each pin on one connector is wired to the same numbered pin on the other connector (pin 1 is wired to pin 1, and so on).
LC fiber-optic connector specifications for Gigabit Ethernet For connecting to high-speed networks, the 5114-NE1 and 5114 features Gigabit fiber optic connectors on two ports. 5114-NE1 and 5114. The LC fiber-optic connectors support the 1000Base-SX Gigabit Ethernet standards, and are designed to operate with multimode fiber optic cables that have compatible terminals. Figure 25 LC fiber-optic connector for the NSF 5114-NE1 and NSF 5114.
Port LED indicators This section describes the port status LEDs on the NIC panel and on the embedded ports for Switched Firewalls 5109 NIC panel., and NSF 5111-NE1 Figure 26 shows the NSF 5111-NE1 NIC panel. Figure 26 5111-NE1 quad NIC panel (RJ-45 connectors) describes the status of the NSF 5111-NE1 Quad NIC/Port LEDs.
Table 11 describes the states of the NSF 5111-NE1 embedded port LEDs. Table 11 NSF 5111-NE1 10/100/1000 Mbps Port LEDs 5111- NE1 10/100/1000 Mbps Port Link Link 10/100 Mbps (RJ-45) 10/100/1000 Mbps (RJ-45) NSF 5114-NE1 Figure 27 shows the NSF 5114-NE1 NIC panel Figure 27 NSF 5114-NE1 NIC panel (LC connectors) .
Table 13 describes the states of the NSF 5114-NE1 NIC/port LEDs. Table 13 NSF 5114-NE1 10/100/1000 Mbps Port LEDs 5114-NE1 10/100/1000 Mbps Port LED Link Link 10/100 Mbps (RJ-45) 10/100/1000 Mbps (RJ-45) NSF 5106 Figure 28 shows the NSF 5106 NIC panel (two per system). Figure 28 5106 NIC panel (RJ-45 connectors) 10 100 1000 ACT/LNK...
Table 17 describes the states of the 5109 embedded port LEDs Table 17 5109 10/100/1000 Mbps Port LEDs 5109 10/100/1000 Mbps Port Link Link 10/100 Mbps (RJ-45) 10/100/1000 Mbps (RJ-45) NSF 5114 Figure 30 shows the NSF 5114 NIC panel.
Switched Firewall 5111-NE1 on page 17 Switched Firewall 5114-NE1 on page 20 Switched Firewall 5106 on page 22 Switched Firewall 5109 on page 24 Switched Firewall 5114 on page 26 Connect the power cord to the AC power receptacle on the back of the unit.
The serial port on the rear panel of the NSF 5111-NE1, NSF 5114-NE1, NSF 5106, NSF 5109, and NSF 5114 is used to access the system for initial configuration and to collect system information and statistics.
Power on the terminal. To establish the connection, press <Enter> on your terminal. The login prompt appears. See Users and Passwords in the Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference (213455-L) for more login information. Chapter 3: Connecting...
PPENDIX Specifications This appendix describes the specifications, standards, and certifications for the Nortel Switched Firewall models 5111-NE1, 5114-NE1, 5106, 5109, and 5114. NSF 5111-NE1 and NSF 5114-NE1 on page 56 NSF 5106 on page 58 NSF 5109 and NSF 5114 on page 60...
NSF 5111-NE1 and NSF 5114-NE1 The Nortel Switched Firewall models 5111-NE1 and 5114-NE1 share the same physical characteristics and power supply, but have different port specifications. Physical characteristics Characteristic Chassis Weight Memory Storage Power requirements Specification Auto-ranging power supply Maximum power consumption...
NSF 5106 The Nortel Switched Firewall model 5106 has the following specifications. Physical characteristics Characteristic Form Factor Dimensions (H x W x D) Weight Processor Memory Storage Drives Network Interface Ports Warranty Power requirements Specification AC Power Power Supply Input Voltage...
NSF 5109 and NSF 5114 The Nortel Switched Firewall models 5109 and 5114 share the same physical characteristics and power supply, but have different port specifications. Physical characteristics Characteristic Chassis Weight Memory Storage Power requirements Specification AC Power Power Supply...
Supported standards Logical Link Control (IEEE 802.2) 10Base-T/100Base-TX (IEEE 802.3, 802.3u) 1000Base-SC (IEEE 802.3, 802.3z) TFTP (RFC 783) Environmental specifications Condition Temperature Relative humidity Altitude Shock Vibration Certifications Category Emissions (EMC) CISPR22, CISPR24 Safety 216382-D, October 2005 Operating Specification 10º C to 35º C (50º F to 95º F) 8% to 80% (non-condensing) –16m to 3,048m (–50 ft to 10,000 ft) 6 shock pulses of 41G for up to 2ms...
Page 62
Nortel Switched Firewall 5100 Series Hardware Installation Guide Appendix A: Specifications 216382-D, October 2005...
Need help?
Do you have a question about the 5109 and is the answer not in the manual?
Questions and answers