background image

Part No. N450000897 Rev 001

Published March 2009

Check Point

IP2450 Security Platform

Installation Guide

Summary of Contents for Check Point IP2450

Page 1: ...Part No N450000897 Rev 001 Published March 2009 Check Point IP2450 Security Platform Installation Guide ...

Page 2: ...ein are subject to change without notice RESTRICTED RIGHTS LEGEND Use duplication or disclosure by the government is subject to restrictions as set forth in subparagraph c 1 ii of the Rights in Technical Data and Computer Software clause at DFARS 252 227 7013 and FAR 52 227 19 TRADEMARKS Please refer to http www checkpoint com copyright html for a list of our trademarks For third party notices see...

Page 3: ...orm 16 Check Point IP2450 Security Platform Overview 17 Built In Ethernet Ports 17 Expansion Slots 18 Console Port 18 Auxiliary Port 19 System Status LEDs 19 Hard Disk Drives 21 Using RAID 1 21 Hard Disk Drive Hot Swap Feature 22 Hard Disk Drive LEDs 22 Power Supplies and Fan Unit 24 Power Supplies 24 Fan Unit 26 Site Requirements 26 Safety Warnings and Cautions 26 Software Requirements 27 Product...

Page 4: ...atures 62 Ethernet NIC Connectors and Cables 63 Two Port Fiber Optic Gigabit Ethernet NICs 64 Fiber Optic Gigabit Ethernet NIC Features 64 Fiber Optic Gigabit Ethernet NIC Connectors and Cables 65 Performance Considerations 65 Two Port and Four Port Copper Gigabit Ethernet NIC 66 Copper Gigabit Ethernet NIC Features 66 Performance Considerations 67 Two Port Copper Gigabit Ethernet NIC Connectors a...

Page 5: ...a PC Card 95 Storing System Logs on the Flash Memory PC Card 101 Disabling Flash Memory PC Cards 101 Transferring Files with the Flash Memory PC Card 102 Replacing the Compact Flash Memory Card 103 Replacing or Upgrading Memory 106 Before You Begin 107 Installing or Replacing a Fan Unit 112 Before You Begin 112 Installing or Replacing a Power Supply 114 Before You Begin 115 Monitoring the Power Su...

Page 6: ...6 Check Point IP2450 Security Platform Installation Guide ...

Page 7: ...Network Voyager Reference Access Points 43 Figure 11 Four Port 10 100 Ethernet NIC Front Panel Details 62 Figure 12 Output Connector for the Ethernet Cable 63 Figure 13 Ethernet Crossover Cable Pin Connections 63 Figure 14 PMC Two Port Short Range Gigabit Ethernet NIC 64 Figure 15 PMC Two Port Long Range Gigabit Ethernet NIC 65 Figure 16 Two Port Copper Gigabit Ethernet NIC Front Panel Details 66 ...

Page 8: ...8 Check Point IP2450 Security Platform Installation Guide ...

Page 9: ... Cable 18 Table 3 System Status LEDs 20 Table 4 Hard Disk Drive LEDs 23 Table 5 Power Supply Status LEDs 25 Table 6 Check Point IP2450 Disk Based Security Platform Software Requirements 27 Table 7 Check Point IP2450 Flash Based Security Platform Software Requirements 28 Table 8 NIC PCI Frequency 61 Table 9 Identifying ADP Modules and Transceivers 75 ...

Page 10: ...10 Check Point IP2450 Security Platform Installation Guide ...

Page 11: ...e available on the network Chapter 4 Installing and Replacing Network Interface Cards and ADP Modules describes how to install monitor and replace network interface cards NICs and Check Point Accelerated Data Path ADP services modules for IP appliances Chapter 5 About IP2450 Appliance Network Interface Cards describes how to connect to and use each of the supported NICs Chapter 6 About IP2450 Appl...

Page 12: ...indicate potential equipment damage equipment malfunction loss of performance loss of data or interruption of service Note Notes provide information of special interest or recommendations Text Conventions Table 1 describes the text conventions this guide uses Table 1 Text Conventions Convention Description monospace font Indicates command syntax or represents computer or screen output for example ...

Page 13: ... and then press the Return or Enter key Do not press the Return or Enter key when an instruction says type Italics Emphasizes a point or denotes new terms at the place where they are defined in the text Indicates an external book title reference Indicates a variable in a command delete interface if_name Table 1 Text Conventions Convention Description ...

Page 14: ...2 About this Guide 14 Check Point IP2450 Security Platform Installation Guide ...

Page 15: ...scalability reliability and investment protection into the next decade In addition the IP2450 allows you to boost performance as needed through next generation high end Check Point Accelerated Data Path ADP services modules for IP appliances and Check Point IPSO for IP appliances system upgrades The IP2450 appliance is available as either a disk based or flash based platform In base configurations...

Page 16: ...ng the following interfaces Check Point Network Voyager for IP appliances an SSL secured Web based element management interface to Check Point IP security platforms Check Point Network Voyager is preinstalled on the IP2450 security platform and enabled through the Check Point IPSO operating system With Check Point Network Voyager you can manage monitor and configure the IP2450 security platform fr...

Page 17: ...s are located in slot 4 Figure 2 shows the layout of the Ethernet ports and link LEDs The top link LED represents the left most port port 1 The remaining LEDs represent the remaining ports from top to bottom and left to right IP2450 RESET 00616 1 CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS S...

Page 18: ...products support only NICs and ADP modules purchased from Check Point or Check Point approved resellers Check Point support services can provide support only for Check Point products that use Check Point approved accessories For sales or reseller information see the Check Point Web site at www checkpoint com Console Port The default configuration of the serial ports are 9600 baud 8 bits no parity ...

Page 19: ...rt shown in Figure 1 to establish a modem connection for managing the appliance remotely or out of band Use USB cables with a standard USB A style connector and pinout for the AUX port For Check Point approved modem connections you will need a USB to RS232 adaptor Note The only modem approved for use with Check Point security appliances with USB AUX ports is the Radicom model V92MB U E and you mus...

Page 20: ...cified Table 3 shows the system status LEDs and describes their meaning Table 3 System Status LEDs Status Indicator Meaning Symbol Solid yellow Appliance is experiencing an internal voltage problem Blinking yellow Appliance is experiencing a temperature problem Solid red One or more fans are not operating properly Power supply over temperature fault Blinking green System activity indicator 00617 1...

Page 21: ...apacity or larger than your primary drive If the two drives are completely synchronized you can remove either drive after first pressing the hot swap button and waiting until the Hot Swap Ready LED illuminates solid blue The RAID 1 volume consists of a master or source hard disk drive which holds the active copy of the operating system and a slave or mirror hard disk drive The slave hard disk driv...

Page 22: ...ton shown in Figure 4 before you remove or replace a hard disk drive without shutting the appliance down If you replace or remove drives with the IP2450 shut off the RAID firmware will lose track of RAID volume data For information about how to remove and replace a hard disk drive see Installing or Replacing Hard Disk Drives on page 88 Hard Disk Drive LEDs The hard disk drive LEDs are located on t...

Page 23: ...ctioning Solid green Hard disk drive is turned on and is functioning Off One of the following The hard disk drive failed its test and was powered off The hard disk drive is ready to be removed using the hot swap feature Blinking green One of the following The system is booting up The hard disk drive is starting up The system is testing the hard disk drive Note Do not remove the hard disk drive if ...

Page 24: ...liance supports up to two power supplies for power sharing and redundancy The IP2450 comes with two power supplies as the standard package The power supplies are hot swappable and perform load sharing while two active power supplies are installed increasing the life of the power supplies 700W AC FAULT OVER TEMP PWR OK 00623 700W AC FAULT OVER TEMP PWR OK Power cord receptacle Power switches Power ...

Page 25: ...pply on page 114 DC Power Supplies Caution Do not use a combination of one AC power supply and one DC supply Your IP2450 does not work with such a configuration For IP2450 appliances that use DC power supplies the following specifications apply for Check Point approved components Input voltage 48 volts DC nominal Voltage Current range 40VDC 20A and 60VDC 13A Power Supply Status LEDs The power supp...

Page 26: ...system status LEDs on the front panel of the appliance show the status of the fan unit For more information about the system status LEDs see System Status LEDs on page 19 Site Requirements Before you install an IP2450 appliance ensure that your computer room or wiring closet conforms to the environmental specifications listed in Appendix A Technical Specifications Safety Warnings and Cautions Warn...

Page 27: ...anufacturer s instructions Caution Do not block any of the ventilation holes on the appliance The components might overheat and become damaged Note A readily accessible disconnect device shall be incorporated in the building installation wiring Note Installation instructions indicate listed circuit breaker or branch rated fuse rating number of poles and special characteristics Software Requirement...

Page 28: ... Point IPSO you are using This symbol on the product or on its packaging indicates that this product must not be disposed of with your other household waste Instead it is your responsibility to dispose of your waste equipment by handing it over to a designated collection point for the recycling of waste electrical and electronic equipment The separate collection and recycling of your waste equipme...

Page 29: ...ou handle the components or open the appliance The grounding plug on the front of the appliance shown in Figure 1 on page 17 provides a chassis grounding point If you do not have a grounding wrist strap make sure you are properly grounded before you touch any electronic component Rack Mounting the Appliance The Check Point IP2450 appliance mounts in a standard 19 inch equipment rack with four moun...

Page 30: ...result in damage to the appliance when it is turned on Before You Begin To rack mount the appliance you need Phillips head screwdriver Disposable grounding wrist strap Suitable grounded work surface on which to place the chassis tray assembly IP2450 RESET 00616 1 CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HA...

Page 31: ...shers included in the grounding cable kit Torque the screws to 80 inch ounces Note The green yellow insulated copper ground connector should be a minimum of 12 AWG minimum 2 5 mm2 cross sectional areas 3 Use the 1 4 inch screw and kep washer included with the appliance or gateway to attach the other end of the cable to the appliance or gateway rack mount hardware or other appropriate earth ground ...

Page 32: ...ng 2 Optionally remove the fan unit from the back of the appliance a Locate the fan unit and the four retaining screws that secure it on the back of the IP2450 b Loosen the retaining screws by turning them counterclockwise c Slowly pull the fan unit out of the chassis tray assembly toward the rear 700W AC FAULT OVER TEMP PWR OK 00623 700W AC FAULT OVER TEMP PWR OK Fan unit 00631 700W AC FAULT OVER...

Page 33: ...50 and the two screws that secure it b Remove the two retaining screws c Remove the grounding lugs d Use the handles to gently pull the power supply out of the chassis tray assembly 4 Optionally remove the chassis tray assembly from the appliance 700W AC FAULT OVER TEMP PWR OK 00623 700W AC FAULT OVER TEMP PWR OK Power supplies 00630 700W AC FAULT OVER TEMP PWR OK 700W AC FAULT OVER TEMP PWR OK ...

Page 34: ... grounded surface 5 Adjust the front mounting brackets on the side of the appliance if necessary IP2450 RESET 00616 1 CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT PC CARD 1 2 3 4 SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB S...

Page 35: ...the rear mounting brackets included with your appliance as shown in the following figure 8 Slide the chassis tray assembly back into the appliance until it clicks into place and resecure the four chassis tray assembly retaining screws 9 Reinstall the fan unit into the rear of the appliance 10 Reinstall the power supplies 00554a Apply 160 inch ounces of torque when you secure the two mounting screw...

Page 36: ...2 Installing the Check Point IP2450 Appliance 36 Check Point IP2450 Security Platform Installation Guide ...

Page 37: ...er and Turning the Power On Performing the Initial Configuration Connecting Network Interfaces Using Check Point Network Voyager Using the Command Line Interface Using Check Point Horizon Manager For information about how to use the DHCP client for initial configuration see the Read Me First document Using DHCP to Configure Your Appliance included with the appliance Note Check Point recommends tha...

Page 38: ... of the IP2450 appliance Note The supplied console cable is Cisco compatible Use only the DB9 port labeled Console on the front panel the serial AUX port is an auxiliary port If you connect the console port to a data communications equipment DCE device use a straight through cable For cable pin assignments for the console connection see Console Port on page 18 2 Connect the other end of the cable ...

Page 39: ...liance To connect the power supply 1 Connect the power cord securely into the power cord receptacle on the power supply 2 Plug the other end of the power cord into a three wire grounded power strip or wall outlet 3 Toggle the 1 O power switch to the 1 position to provide power to the IP2450 appliance The fan unit on the power supply turns on when you press the power switch Verify that the power su...

Page 40: ... longer need the console connection To perform the initial configuration 1 Turn on the appliance At the console a series of startup messages appears then the following prompt appears Type any character to enter command mode The prompt remains on the screen for about five seconds If you type any character during this time the system activates the Check Point IPSO boot manager Note For information a...

Page 41: ...to respond to the prompts during the initial configuration process see the release notes for the Check Point software release you are running 4 When you are prompted to select an interface Check Point recommends that you select one of the Ethernet management interface ports To select an interface enter the number adjacent to the physical ID in the list of connected interfaces Note A physical ID id...

Page 42: ...The destination end of the cable can be either LC or SC depending on the type of connector required for the destination Gigabit Ethernet device For details see Fiber Optic Gigabit Ethernet NIC Connectors and Cables on page 65 Using Check Point Network Voyager Use Check Point Network Voyager to configure and monitor your appliance To open Check Point Network Voyager 1 Open a Web browser on the host...

Page 43: ...on the left side of the window as shown in Figure 10 You can also access this guide and other Check Point IPSO documentation at the Check Point Support Center at http support checkpoint com Network Voyager online help You can access online help when you use Check Point Network Voyager Online help is the context sensitive information source for Check Point Network Voyager To access online help for ...

Page 44: ...I shell and the Check Point IPSO shell The Check Point IPSO shell is what you see when you initially log on to the appliance For more information about how to access and use the CLI see the CLI Reference Guide for the version of Check Point IPSO you are using Using Check Point Horizon Manager Check Point Horizon Manager is an extension of the Check Point Network Voyager management functionality Wh...

Page 45: ... potential human error and improving productivity Using Check Point Horizon Manager a network security professional can manage multiple devices simultaneously perform parallel software upgrades device verifications device configuration file backups and more Check Point Horizon Manager is designed to manage and configure a large number of Check Point IP security appliances that reside on a corporat...

Page 46: ...3 Performing the Initial Configuration 46 Check Point IP2450 Security Platform Installation Guide ...

Page 47: ...e them Note ADP modules can be installed only in slots 1 and 2 This chapter describes the following topics Removing Installing and Replacing NICs and ADP Modules To remove and install 6U card carriers or ADP modules and to replace network interface cards NICs in 6U PMC carriers To replace a network interface card NIC in slot 3 or 4 Configuring and Activating Interfaces Monitoring Network Interface...

Page 48: ...ts slot before you can remove or install a NIC or ADP module You must also remove both PMC carriers or ADP modules to install or replace NICs in slot 3 or 4 To install or replace ADP modules you only need to refer to the steps related to removing and installing 6U PMC carriers in this section but you also need to refer to Chapter 6 About IP2450 Appliance ADP Services Modules Note Check Point recom...

Page 49: ...ier with an open paper clip or similar device and wait for the hot swap LED to illuminate solid blue For ADP modules do the following a Use Check Point Network Voyager or the CLI to perform an orderly shutdown of the IP2450 For information about how to access Check Point Network Voyager and the related reference materials see Using Check Point Network Voyager on page 42 b Press the power switches ...

Page 50: ...of the IP2450 6 Continue to press or push the levers outward until the 6U PMC carrier or ADP module is released and extends slightly beyond the front panel of the IP2450 00645 IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS 1000BaseT 1 2 3 4 SUB SLO T 1 SUB SLO T 2 POW ...

Page 51: ...illips screwdriver Note If you are installing a NIC in an unoccupied slot on the 6U PMC carrier remove the blank bezel that covers the slot and retain it for future use Proceed to step 12 00643 IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS ACT STA T SLOT 4 HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS 1000BaseT 1 2 3 4 ...

Page 52: ...ck Point IP2450 Security Platform Installation Guide 10 Locate and remove the two NIC retaining screws from the back of the NIC 11 Remove the NIC by lifting the back of the NIC away from the chassis tray assembly and pulling it gently away from the front panel 00312 00313 1 ...

Page 53: ...lacing a NIC you are removing insert a blank bezel into the location formerly occupied by the NIC Make sure that the bezel is completely seated onto the slot on the front of the 6U PMC carrier and that the screw holes on the bottom of the bezel align with those on the bottom of the PMC carrier Proceed to step 14 Note To reduce electromagnetic interference EMI a blank bezel needs to be installed in...

Page 54: ...e of the same type the Check Point IPSO operating system automatically recognizes the NIC or ADP module and applies the original configuration to the new NIC or ADP module If you are installing a new or different NIC or ADP module configure the new NIC or ADP module by using Check Point Network Voyager For information about how to access Check Point Network Voyager see Using Check Point Network Vo...

Page 55: ...h slots 3 and 4 1 Use Check Point Network Voyager or the CLI to perform an orderly shutdown of the IP2450 For information about how to access Check Point Network Voyager and the related reference materials see Using Check Point Network Voyager on page 42 2 Loosen the four front panel retaining screws IP2450 RESET 00616 1 CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACT...

Page 56: ...d remove the shield IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWAP HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 00637 1000BaseT 1 2 3 4 SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B L...

Page 57: ...re not occupied 6 Remove the two front bezel screws and remove the slot 3 or slot 4 filler panel or installed NIC IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 00654 1 1000BaseT 1 2 3 4 Remove 6U PMC carriers Remove six screws and 6U PMC carrier shield ...

Page 58: ...e NIC approximately 45 degrees as you insert the front end into slot 3 in the front panel 00657 2 IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT 1 2 3 4 LINK ACT V2 LINK ACT 100 0Ba seT LINK ACT V2 LINK ACT 100 0Ba seT ...

Page 59: ...sure that you turn on both power supplies If you are replacing a NIC with a new NIC of the same type the Check Point IPSO operating system automatically recognizes the NIC and applies the original configuration to the new NIC If you are installing a new or different NIC configure the new NIC by using Check Point Network Voyager For information about how to access Check Point Network Voyager see Us...

Page 60: ...etwork Voyager and the related reference materials see Using Check Point Network Voyager on page 42 Monitoring Network Interface Cards or ADP Modules You can assess the general operating condition of the NICs or ADP modules in your appliance by looking at the LED status indicators on each NIC or ADP module The status indicators for each NIC are explained in Chapter 5 About IP2450 Appliance Network...

Page 61: ...e peripheral component interconnect PCI frequency listed in Table 8 Caution To protect the IP2450 and the memory modules from electrostatic discharge damage make sure you are properly grounded before you touch these components Use a grounding wrist strap and follow the instructions provided with the wrist strap before you handle the components or open the appliance The grounding plug on the front ...

Page 62: ...r port and two port Ethernet NICs support the following features Hot swappability Tracing through tcpdump PCI operation at 33 MHz and 66 MHz Compliance with IEEE 802 3z Gigabit Ethernet specification You can configure and monitor Ethernet NIC interfaces by using Check Point Network Voyager Specifically you set the port speed and full duplex or half duplex mode with Check Point Network Voyager For ...

Page 63: ...f duplex cable You can order appropriate adapter cables separately from a cable vendor of your choice Caution Cables that connect to the Ethernet card must be IEEE 802 3 compliant to prevent potential data loss Figure 12 shows the pin assignments for the RJ 45 cable The connector is numbered from right to left with the copper tabs facing up and toward you Figure 12 Output Connector for the Etherne...

Page 64: ...pport Link speed auto advertising Tracing through tcpdump Compliance with IEEE 802 3z Gigabit Ethernet specification The short range multi mode fiber MMF fiber optic Gigabit Ethernet NICs in the IP2450 run on Check Point IPSO 4 2 or higher The long range single mode fiber SMF fiber optic Gigabit Ethernet NICs in the IP2450 run on Check Point IPSO 4 2 or higher You can configure and monitor Gigabit...

Page 65: ...tic cable with an LC connector for each NIC interface The destination end of the cable can be either LC or SC depending on the type of connector required for the destination Gigabit Ethernet device You can also use a half duplex LC to LC cable to loop back the transmit port of an interface to the receiver port LC and SC define the fiber optic connector types LC connectors are smaller than SC conne...

Page 66: ...dwidth Full duplex mode operation up to 1 Gbps Link speed auto advertising 10 100 1000 Hot swapping PCI operation at 33 MHz 66 MHz and 133 Mhz Compliance with IEEE 802 3z and 802 3ab Gigabit Ethernet specifications You can configure and monitor Gigabit Ethernet NIC interfaces with Check Point Network Voyager Specifically you can use Check Point Network Voyager to set the port speed and full duplex...

Page 67: ... in an IP2450 place one NIC in each of the two 6U PMC carrier units to get maximum system throughput Each 6U PMC carrier unit has a separate PCI bus connection to the main system motherboard In the configuration described here each of the two copper Gigabit Ethernet NICs access a separate PCI bus Two Port Copper Gigabit Ethernet NIC Connectors and Cables The IP2450 receptacles are RJ45 connectors ...

Page 68: ...thernet Crossover Cable Pin Connections Note After you turn on the appliance the Ethernet link LEDs on both the appliance and on the remote equipment illuminate to indicate the connection As data is transmitted or received the activity LEDs on the appliance illuminate To connect the IP2450 to other network components you can order appropriate adapter cables separately from a cable vendor of your c...

Page 69: ... throughput ADP is a technology designed to forward packets at the highest possible rate Check Point ADP modules provide this technology by offloading processing from the CPU to network processors For IP2450 appliances ADP is implemented with a single module on connections that benefit from the Check Point SecureXL feature Note You can use up to two ADP module at a time and you can install single ...

Page 70: ...placing ADP Modules Note Before you begin this procedure you should review all ADP module information in the Getting Started Guide and Release Notes for the version of Check Point IPSO you are using Use these instructions to install an ADP module in your appliance Before You Begin To install a Check Point ADP module you need the following A Phillips head screwdriver Physical access to the applianc...

Page 71: ...SO software to the required version as described in the Getting Started Guide and Release Notes that you received with your ADP module Remove the installed PMC card carrier for a slot that you are installing ADP modules in For the card carrier removal procedure see Chapter 4 Installing and Replacing Network Interface Cards and ADP Modules Note You must first power down your appliance before you re...

Page 72: ...ou might notice that the orange Activity LED as shown in the following figure might blink at longer intervals than typical for traffic when an ADP module port is connected to a switch This likely indicates that the switch is sending ARP address restoration protocol requests to the port and no traffic is present ...

Page 73: ...the ADP module is under power Ejector and locking levers Twelve port copper Gigabit Ethernet ADP module Twelve port copper and fiber Gigabit Ethernet ADP module fiber in this example Link 10 100 Mbps Orange solid 1000 Mbps Green solid Activity Orange blinking Activity Orange blinking Link 1000 Mbps Green solid Ejector and locking levers Link 10 Gbps Green solid Activity Orange blinking Ejector and...

Page 74: ...To identify the types of transceivers you are using in your ADP modules refer to Table 9 on page 75 To install or remove ADP transceivers in a Check Point ADP module To install an ADP transceiver Push the transceiver into an available port in the ADP module Rotate the transceiver latch lever down to secure the transceiver in the ADP module Note Depending on the design of your ADP transceiver you m...

Page 75: ...ith Latch Lever Color Codes To identify the types of ADP modules and transceivers you are using refer to the color of the latch levers as described in the following table Check Point ADP Module LED Reference Information All Check Point IP2450 ADP modules provide two LEDs for each port to indicate Link and Activity status For information about the LEDs see Figure 20 on page 73 Table 9 Identifying A...

Page 76: ...nce the names and configuration information for all the interfaces previously installed in an affected slot become invalid These changes can affect any features or protocols that use the existing interfaces or their addresses including the following Dynamic routing protocols Multicast routing protocols Static routing configuration VRRP IP clustering Transparent mode Link aggregation Link redundanc...

Page 77: ...IC interfaces even if the NIC interfaces are Gigabit Ethernet Using a configuration of this type can significantly degrade throughput due to the need for packets to traverse multiple PC backplane buses When you install an ADP module in an IP2450 appliance the network processor in the module performs all VPN encryption and decryption even for VPN packets that are sent through PMC NIC interfaces The...

Page 78: ...nterfaces are installed in slots 1 2 and 3 For this example legacy monitored circuit VRRP is enabled and configured with these settings Interface eth s1 s1p1c0 is assigned the IP address 10 1 1 1 not shown and uses 10 1 1 99 as the VRRP backup address Interface eth s1 s1p2c0 backs up interface eth s1 s1p1c0 ...

Page 79: ...PMC NIC card carriers that you are replacing with ADP modules you need to delete the configuration information for those interfaces If VRRP is active at that time you will not be able to delete the configuration information for the interfaces used by VRRP Therefore you should begin by deleting the existing VRRP configuration Note It is best to perform the procedures in this section on the VRRP bac...

Page 80: ...terface information as described below To reconfigure interfaces for ADP modules 1 Log into the appliance using Check Point Network Voyager 2 Navigate to the Interface Configuration page The removed interfaces are still listed on this page and you see a blue indicator next to each of them in the Up column Also notice that the ADP logical interfaces are named eth s2p1c0 through eth s2p12c0 ...

Page 81: ...Configuring Check Point IPSO for IP2450 ADP Interfaces Check Point IP2450 Security Platform Installation Guide 81 ...

Page 82: ...eature that uses the interface This is why you deleted the VRRP configuration before you installed the ADP module 4 Click a physical interface name Check Point Network Voyager displays the Physical Configuration page for that interface 5 In the Physical Status area click the Delete check box 6 Click Apply 7 Delete the configuration information for the rest of interfaces that you removed by restart...

Page 83: ...appropriate configure the ADP interfaces to use the IP addresses previously assigned to the removed interfaces In this example you need to assign the address 10 1 1 1 to the new interface eth s2p1c0 Reconfiguring VRRP After you finish reconfiguring interfaces you need to reconfigure any protocols and features that used the removed interfaces to use the ADP interfaces In this example you need to re...

Page 84: ...nce ADP Services Modules 84 Check Point IP2450 Security Platform Installation Guide eth s2p1c0 and eth s2p2c0 The following figure shows the example system after you recreate the VRRP configuration using the new interfaces ...

Page 85: ...therboard Battery For information about how to add or replace NICs see Chapter 4 Installing and Replacing Network Interface Cards and ADP Modules You should have a working knowledge of networking equipment before you attempt to service an IP2450 Limit service of the appliance to the procedures described in this chapter Caution To protect the IP2450 and the memory modules from electrostatic dischar...

Page 86: ...ccelerator card To install the Check Point encryption accelerator card To install a Check Point encryption accelerator card you need Physical access to the appliance The Check Point encryption accelerator card and installation kit Phillips head screwdriver Four screws included in kit Grounding wrist strap included in kit Caution To avoid potential equipment malfunction Check Point recommends that ...

Page 87: ...P HOT SWAP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT PC CARD 1 2 3 4 SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK V2 1000BaseT ACT LINK ACT LINK V2 1000BaseT ACT LINK ACT LINK Chassis tray assembly screws 00659 IP2450 RESET CONS OLE AUX AUX2 HDD B SLOT 3 SLOT 2 HDD A HOT SWA...

Page 88: ...cceleration the Check Point encryption accelerator card performs cryptographic operations for IPsec tunnel negotiation To enable IKE acceleration 1 From the Check Point Network Voyager home page click Security and Access Configuration then click IKE Acceleration For information about how to access Check Point Network Voyager and the related reference materials see Using Check Point Network Voyager...

Page 89: ...grounded before you touch these components Use a grounding wrist strap and follow the instructions provided with the wrist strap before you handle the components or open the appliance The grounding plug on the front of the appliance shown in Figure 1 on page 17 provides a chassis grounding point If you do not have a grounding wrist strap make sure you are properly grounded before you touch any ele...

Page 90: ...ting down the appliance You must replace the hard disk drive with a drive that has a capacity equal to or larger than the drive you are replacing Back up your hard disk drive files to a remote system on a regular basis For backup and restore procedures see the documentation for Check Point Network Voyager or Check Point Horizon Manager and the online help for both products To replace a hard disk d...

Page 91: ...the hard disk drive with an open paper clip or similar device and wait for the hot swap LED to illuminate solid blue 3 Loosen the retaining screws on both sides of the hard disk drive Caution To avoid damage to the ejector and locking lever loosen the retaining screw behind each ejector and locking lever before you remove the hard disk drive 00621 ACTIVITY HARD DRIVE STATUS HOT SWAP READY POWER RE...

Page 92: ...UX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A SLOT 4 HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS 1000BaseT 1 2 3 4 SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K V2 1000BaseT ACT LIN K ACT LIN K V2 10...

Page 93: ...emoving a hard disk drive used as part of a RAID 1 implementation and The hard disk drive is not active you need to perform an orderly shutdown of your appliance before completing the rest of this procedure 2 Loosen the retaining screws on both sides of the hard disk drive Caution To avoid damage to the ejector and locking lever loosen the retaining screw behind each ejector and locking lever befo...

Page 94: ...AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A SLOT 4 HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS 1000BaseT 1 2 3 4 SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K V2 1000BaseT ACT LIN K ACT LIN K ...

Page 95: ... you can purchase from Check Point the IP2450 supports a PC card with 1 GB flash memory that Check Point offers with or without system software included You can use the carrier card in slot 3 which is located on the front panel of the appliance as shown in Figure 22 Check Point supports only PC cards purchased from Check Point or Check Point approved resellers For more information see the Check Po...

Page 96: ...eb site at www checkpoint com Note Because power to an IP2450 is automatically disconnected when the chassis assembly is opened you do not need to manually disconnect the power for this procedure Any servicing of the appliance however should be completed with the chassis assembly fully removed from the appliance 1 Use Check Point Network Voyager or the CLI to perform an orderly shutdown of the IP2...

Page 97: ... SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK V2 1000BaseT ACT LINK ACT LINK V2 1000BaseT ACT LINK ACT LINK Chassis tray assembly screws IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWAP HOT SWA P POW ER...

Page 98: ...that both slot 1 and slot 2 are not occupied 6 Remove the two front bezel screws and remove the slot 3 filler panel or installed NIC IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 00654 1 1000BaseT 1 2 3 4 Remove 6U PMC carriers Remove six screws and 6U PMC carrier ...

Page 99: ...tely 45 degrees as you insert the front end into slot 3 in the front panel 00657 2 IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT 1 2 3 4 LINK ACT V2 LINK ACT 100 0Ba seT LINK ACT V2 LINK ACT 100 0Ba seT ...

Page 100: ...er switches located on each power supply at the back of the appliance to turn on the power to the appliance Note Make sure that you turn on both power supplies To install the PC card 1 Insert the PC card into the PC card slot until it snaps in place 2 Press gently on the card until it is firmly seated in the slot The eject button to the left of the slot should be flush with the card 00644 2 IP2450...

Page 101: ... configure system logging options For more information see the Check Point Network Voyager documentation or online help Disabling Flash Memory PC Cards If you configure the flash memory PC card as an optional disk you must disable the card before you remove it You can disable the card by using Check Point Network Voyager or the CLI To use Check Point Network Voyager to disable a flash memory PC ca...

Page 102: ...before you remove it You do not need to reboot or shut down the system if you manually mount and unmount the flash memory PC card To transfer Check Point IPSO images or configuration files to the flash memory PC card 1 Insert the flash memory PC card into the IP2450 appliance 2 Connect to the IP2450 appliance by using a console or terminal connection 3 Mount the flash memory PC card by using the f...

Page 103: ...and turn the power off whenever you open the chassis assembly to service internal components Caution You risk damage to the appliance or loss of data if you do not use the following procedure when you replace the compact flash memory To replace the compact flash memory card 1 Use Check Point Network Voyager or the CLI halt command to perform an orderly shutdown of the IP2450 appliance For informat...

Page 104: ...VE STATUS SLOT 4 1000BaseT PC CARD 1 2 3 4 SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK V2 1000BaseT ACT LINK ACT LINK V2 1000BaseT ACT LINK ACT LINK Chassis tray assembly screws IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWA P POW ER ACT IVI TY HAR ...

Page 105: ... IP2450 Security Platform Installation Guide 105 7 Locate the compact flash memory card socket and remove the stopper screw and spacer located between the module and the edge of the motherboard as shown in the following figure 00653 Stopper screw Spacer ...

Page 106: ...w with a screwdriver 11 Slide the chassis assembly back into the appliance until it clicks into place 12 Resecure the chassis assembly retaining screws 13 Replace the hard disk drives 14 Press the power switches located on each power supply at the back of the appliance to turn on the power to the appliance Note Make sure that you turn on both power supplies Replacing or Upgrading Memory The Check ...

Page 107: ...tructions provided with the wrist strap before you handle the components or open the appliance The grounding plug on the front of the appliance shown in Figure 1 on page 17 provides a chassis grounding point If you do not have a grounding wrist strap make sure you are properly grounded before you touch any electronic component Note Because power to an IP2450 is automatically disconnected when the ...

Page 108: ...NSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS HOT SWAP HOT SWAP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT PC CARD 1 2 3 4 SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK V2 1000BaseT ACT LINK ACT LINK V2 1000BaseT ACT LINK AC...

Page 109: ... AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWAP HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 00637 1000BaseT 1 2 3 4 SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K SUB SLO T 1 SUB SLO T 2 POW ER REA DY REQ UES T HOT SWA P FIO CAR RIE R 1000B LX ACT LIN K V2 1000BaseT ACT LIN K ACT LIN K...

Page 110: ...l DIMMs are installed slots J8 J9 J45 and J47 must also be completely populated Each of these sets of four DIMMs must all be the same identical type 00636 IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 1000BaseT 1 2 3 4 00636 1 SLOT 1 ACT ACT STA T LIN K SUB SLO T 1...

Page 111: ...uide 111 5 Remove the DIMM by pressing the two retaining clips outward and carefully pulling each DIMM upward You might need to pull opposite ends of the DIMM alternately to gradually free it from the contact pins 6 Press the new DIMM into the socket until it clicks into place 0634 ...

Page 112: ...k into the appliance until it clicks into place 8 Resecure the four chassis assembly retaining screws 9 Press the power switches located on each power supply at the back of the appliance to turn on the power to the appliance The IP2450 automatically recognizes the new memory configuration You can verify the configuration by using Check Point Network Voyager or the CLI Installing or Replacing a Fan...

Page 113: ...ing a failed fan unit and do not completely remove power to the appliance do not allow the appliance to run without a fan unit for any longer than necessary To replace a fan unit 1 Locate the fan unit on the back of the IP2450 appliance and the four retaining screws that secure it 2 Loosen the retaining screws by turning them counterclockwise 700W AC FAULT OVER TEMP PWR OK 00623 700W AC FAULT OVER...

Page 114: ...ed in parallel Load sharing increases the life of the power supplies Note On an appliance with two active power supplies installed both power supplies should be turned on for load sharing and redundancy If both power supplies are not turned on the Fault LED illuminates For more information about the Fault LED see Power Supply Status LEDs on page 25 The power supplies are autosensing and can accept...

Page 115: ...ouch when the power supply unit is plugged in to an AC power source and the power supply is not turned on Caution Do not use a combination of one AC power supply and one DC supply Your IP1280 does not work with such a configuration Before You Begin To replace a power supply you need Physical access to the IP2450 appliance Phillips head screwdriver Replacement power supply and appropriate documenta...

Page 116: ... monitor the status of the Check Point IP2450 appliance power supply with Check Point Network Voyager Similarly you can also use the command line interface CLI For information about the CLI see the CLI Reference Guide To monitor the power supply by using Check Point Network Voyager 1 Log on to the appliance by using Check Point Network Voyager 2 Click Monitor 3 Click Hardware Monitoring System Sta...

Page 117: ...nce to protect against electrostatic discharge damage to the appliance Use the disposable grounding wrist strap included in the battery replacement kit To replace the battery To replace an IP2450 battery you need Physical access to the appliance A replacement battery Access to the appliance by using Check Point Network Voyager or the CLI Note Because power to an IP2450 is automatically disconnecte...

Page 118: ...AP POWER ACTIVITY HARD DRIVE STATUS SLOT 4 1000BaseT PC CARD 1 2 3 4 SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK SUB SLOT 1 SUB SLOT 2 POWER READY REQUEST HOT SWAP FIO CARRIER 1000B LX ACT LINK V2 1000BaseT ACT LINK ACT LINK V2 1000BaseT ACT LINK ACT LINK Chassis tray assembly screws IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 SLOT 1 HDD A HOT SWAP HOT SW...

Page 119: ... PMC carriers so that both slot 1 and slot 2 are not occupied IP2450 RESET CONSOLE AUX AUX2 HDD B SLOT 3 SLOT 2 HDD A HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS HOT SWA P HOT SWA P POW ER ACT IVI TY HAR D DRI VE STA TUS SLOT 4 00654 1 1000BaseT 1 2 3 4 Remove 6U PMC carriers Remove 6U PMC carrier shield ...

Page 120: ...tery holder Make sure that the battery is securely installed in the battery holder 10 Reassemble the appliance 11 Press the power switches located on each power supply at the back of the appliance to turn on the power to the appliance The appliance should start up normally with the new battery installed If it does not repeat Step 1 through Step 6 If the appliance does not start up normally after t...

Page 121: ...devices are not configured for the same VC and VP value Solution Set remote and local devices to the same VC and VP values Consult your 1483 device documentation Problem Remote and local devices are not in the supported VC range of the network interface card Solution Use ipsctl to determine the VC range Enter the following command ipsctl ifphys logical interface max_rxlabel Problem Encapsulation i...

Page 122: ... the terminal or cable and not with the appliance Problem No console connection to the IP2450 Solution For information about how to create a console connection see To connect to the console on page 38 Problem Not connected with a null modem cable Solution Verify that you are using a null modem cable For pinout information see To connect to the console on page 38 Problem Wrong terminal settings Sol...

Page 123: ...URN for sh Press Enter 3 Type etc overpw at the prompt When the response asks if you want to continue type y When you are returned to the prompt type Ctrl d to reboot with admin user and a new password 4 The admin password defaults to no password for admin Continue to boot to multiuser mode 5 Reconfigure the password as you normally would Note Blank passwords are not accepted in Check Point Networ...

Page 124: ...e on the appliance For information about how to complete the full installation procedure see the current release notes The release notes are located on the Check Point Support Center at http support checkpoint com Not Able to Connect to Check Point Network Voyager Using the Ethernet Port But Console Access Works Problem Using the wrong Ethernet cable Solution Use a crossover Ethernet cable if you ...

Page 125: ...uld be with the interface slot Try installing the NIC or ADP module in another slot Common Ethernet Problems Connectivity with Attached Device Problem No link light Solution You might have used the wrong cable Use a crossover cable between the IP2450 and a host and a straight through cable between an appliance and a hub Problem Solid activity LED Solution You might have set the wrong speed Verify ...

Page 126: ...cognize New Memory Configuration Problem The DIMMs are not properly seated in DIMM sockets Solution Repeat memory installation procedures Make sure DIMMs are fully seated in sockets Be sure DIMMs click into place Make sure DIMMs are installed as described in Replacing or Upgrading Memory on page 106 ...

Page 127: ...rs behind the front panel of the rack 6 inches 15 centimeters behind the IP2450 to allow the back exit fan to move air through the appliances Caution Do not block the ventilation holes on the IP2450 The appliance might overheat and get damaged Dimensions Height 3 5 in 8 89 cm Width 17 in 44 cm 19 in 48 cm rack mountable Depth 21 in 53 34 cm Operational Temperature 5 C to 40 C 23 F to 104 F Humidit...

Page 128: ...A Technical Specifications 128 Check Point IP2450 Security Platform Installation Guide ...

Page 129: ...irements of the Low Voltage Directive 73 23 EEC and the EMC Directive 2004 108 EC Manufacturer s Name Nokia Inc Manufacturer s Address 313 Fairchild Drive Mountain View CA 94043 2215 USA Model Number IP2450 Product Options All Serial Number 1 to 100 000 Date First Applied 2007 Safety EN60950 1 2001 A11 IEC60950 1 2001 UL60950 Third Edition 2000 CAN CSA C22 2 No 60950 2000 EMC EN55024 1998 EN55022A...

Page 130: ...rmful interference when the equipment is operated in a commercial environment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instruction manual may cause harmful interference to radio communications Operation of this equipment in a residential area is likely to cause harmful FCC Part 15 Subpart B Class A US Canada EN55022 C...

Page 131: ... Guide 131 interference in which case the user will be required to correct the interference at his own expense Caution Any changes or modifications not expressly approved by the grantee of this device could void the user s authority to operate the equipment 060425 ...

Page 132: ...B Compliance Information 132 Check Point IP2450 Security Platform Installation Guide ...

Page 133: ...console connection 38 connecting Ethernet devices 42 connecting network interfaces 42 connections Ethernet network interface cards 63 67 fiber optic Gigabit Ethernet NIC 65 modem 19 power 39 connector pin assignments Ethernet network interface cards 63 connectors for Ethernet network interface cards 63 console cable 38 pin assignments 18 console connection 38 console port 16 cooling 16 cryptograph...

Page 134: ...acing 48 two port Ethernet 64 65 two port fiber optic Gigabit Ethernet 64 network interfaces connecting 42 null modem cable 38 O opening Check Point Network Voyager 42 output connector Ethernet cable 63 P PC card removing 101 pin assignments console connection 18 power connections 39 power supplies load sharing 25 40 114 redundancy 25 40 114 status LEDs 25 power supply status 116 R rack space 15 r...

Page 135: ...ex 135 T technical specifications 127 text conventions 12 troubleshooting 121 two port Ethernet network interface card 64 65 U upgrading memory 106 UTP5 dual mode Ethernet 62 V VPN performance 86 VT100 compatible terminal 38 W warning notices 12 Y yellow LED 20 ...

Page 136: ...Index 136 Check Point IP2450 Security Platform Installation Guide ...

Reviews: