Page 1
Avaya™ SG203 and SG208 Security Gateway Hardware Installation Guide 670-100-101 Issue 1 June 2003...
Page 2
Such intrusions may be either to/through synchronous (time- Warranty multiplexed and/or circuit-based) or asynchronous Avaya Inc. provides a limited warranty on this product. Refer (character-, message-, or packet-based) equipment or to your sales agreement to establish the terms of the limited interfaces for reasons of: warranty.
Page 3
Standards Compliance equipment is operated in a commercial environment. This Avaya Inc. is not responsible for any radio or television equipment generates, uses, and can radiate radio frequency interference caused by unauthorized modifications of this...
Page 4
All Avaya media servers and media gateways are compliant China with FCC Part 68, but many have been registered with the BMSI (Chinese Warning Label) FCC before the SDoC process was available. A list of all Avaya registered products may be found at: http://www.part68.org/...
It is recommended that you read the entire installation guide before installing the security gateway. Contacting Technical Support Technical support is available to registered users of the Avaya security gateway products. Domestic support •...
Chapter 1 Introduction The Avaya ™ SG203 and SG208 Security Gateways are high- performance integrated firewall, security zone, and IPSec VPN gateway devices. They are designed to provide the high capacity, scalability and reliability required by your networks for IPSec/firewall services in one unit or multiple units for enterprise headquarter locations requiring a rack mountable device.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Figure 1 Typical SG203/SG208 security gateway installation Functional overview The SG203 and SG208 security gateways are dedicated hardware-based network security devices designed to provide overlay security services on an IP data network. The security gateway sits behind an edge router and has auto-detecting ethernet interfaces on the public and private ports.
CHAP, PAP Authentication VPNmanager Avaya VPNmanager is an optional Avaya application that lets network managers define, configure and manage VPNs from any location. Large networks would want to use VPNmanager to do distributed managed firewall rules as well as VPN management across the network.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Data authenticity is assured by using HMAC-MD5™ or HMAC-SHA-1 packet signatures to reject altered or forged packets. All security mechanisms employed by the security gateway conform to IPSec standards, in order to provide interoperability and broaden the use of VPN technology.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide the private interface. The administrator enters the name as root and the password as password for the user’s credentials. The quick set up guides the network administrator through the minimal network configuration. Hardware components...
Chapter 2 Installing SG203 and SG208 Security Gateway This chapter provides instructions for the physical installation of the SG203 and SG208 security gateways, including rack mounting, placement, and connection to the network. Site requirements This section describes the requirements your site must meet for safe installation and operation of the security gateway.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Required tools The security gateway chassis can be mounted in a standard 19-inch equipment rack. Rack mounting requires a Phillips-head screwdriver, the device rack mount bracket kit, and four screws to match the rack. (Screws for attaching the mounting brackets to the chassis are not provided.)
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Rackmount The SG203 and SG208 security gateways can be mounted in a standard 19-inch equipment rack. The location of the chassis and the layout of your equipment rack or wiring room are extremely important for proper system operation.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Overview of front panel Figure 5 Front panel of the security gateway Console port Ethernet port Expansion slot Private port Status Indicators Public port Multi interface ports Console port The console port accepts an RS-232 DB-9 connection from an asynchronous ASCII terminal or a PC running terminal emulation software.
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Multi-interface ports Four ports are available on the security gateway, public, private and two other interface ports that are not designated. The public port provides an interface to the public Internet network, while the private port provides an interface to the private local network.
Page 21
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Figure 6 Example of two security gateway’s hardware installations Private LAN Private LAN SG203 SG208 Crossover Cable Router Router DSU/CSU DSU/CSU Public Network Connect one end of the Cat5e cable to the public port (Ethernet1) on the security gateway.
Page 22
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Note: If DHCP related functionality (DHCP server on the private interface and DHCP client on the public network) disrupts your network, change the default settings via the console port, prior to plugging in the ethernet cables.
Once this has been done, the security gateway can be completely configured and incorporated into your Virtual private Network either by using the Web interface locally, or using Avaya VPNmanager from a central location. Connecting to the private port From the workstation’s control panel, select your TCP/IP network...
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Restart your workstation, if the operating system asks you to do so. As your workstation restarts, it automatically obtains its required IP address/ mask and default router IP address from the security gateway.
Page 25
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Figure 7 Security Gateway Login Window Enter the User Name, root and the Password, password. Click Log In, when it is highlighted. The first time you connect to the security gateway, two sequential pop- up messages appear over the main screen.
Page 26
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Figure 8 Quick Setup Dialog The Quick Setup wizard dialog appears. In the IP Configuration area, select one of the following IP Config Modes. • Static Addressing. If you are going to use static addressing on the public port, click the Static Addressing radio button and enter your IP address, network mask, and default route information.
Page 27
Avaya SG203/SG208 Security Gateway Hardware Installation Guide In the Centralized Management area, if VPNmanager is used, enter the superuser name and password. In the Date & Time area, enter the date, time, and time zone. A 24-hour clock is used. For example, 13:00:00 is equivalent to 1:00 PM.
Page 28
Avaya SG203/SG208 Security Gateway Hardware Installation Guide 28 Setting up the security gateway for configuration Issue 1, June 2003...
Avaya SG203/SG208 Security Gateway Hardware Installation Guide Index admin name hardware components humidity specification AES encryption authentication specification installation desktop back panel rackmount IPSec standards cat5e cables CE marks log out compliance configuring static addressing,DHCP,PPPoE password connecting the SG203/SG208 to network...
Page 30
Avaya SG203/SG208 Security Gateway Hardware Installation Guide safety recommendations security SHA1 specifications authentication encryption key management standards electromagnetic compatibility technical support temperature range tools rackmount triple DES user authentication warranty world wide web support 30 Index Issue 1, June 2003...
Need help?
Do you have a question about the SG203 and is the answer not in the manual?
Questions and answers