background image

Aurorean Installation & Service Guide

47

Chapter 3

Configuring General Values of the ANG-3000/7000

Installing Software & Setting Networking Configurables

Figure 32   

Internet Explorer Certificate Manager Import Wizard Window

5

Click Next.

The Select a Certificate Store window appears as shown in Figure 33.

Summary of Contents for ANG-1000

Page 1: ...ion 3 5 Version 3 5 Version 3 5 Aurorean Policy Server Aurorean Policy Server Aurorean Policy Server Aurorean Policy Server Aurorean Network Gateway Aurorean Network Gateway Aurorean Network Gateway A...

Page 2: ...hrough PerlClinic at http www ActiveState com Peer support resources for ActivePerl issues can also be found at the ActiveState Web site under support at http ActiveState com support The ActiveStae Re...

Page 3: ...ipment standard entitled Digital Apparatus ICES 003 of the Department of Communications Cet appareil num rique respecte les limites bruits radio lectriques applicables aux appareils num riques de Clas...

Page 4: ...make sure that the total ampere rating of the equipment plugged into the extension cord does not exceed the extension cord ampere rating Also make sure that the total rating of all products plugged i...

Page 5: ...2 Aurorean Policy Server 3 Standard Features 5 Aurorean Network Gateway 6 Standard Features 8 RiverMaster Management Application 9 Aurorean Web Config 11 Aurorean Software Update Service 11 Installati...

Page 6: ...stem in the Rack 22 Secure the System to the Rack 23 Removing the System From the Rack 23 Connecting Cables 25 Ethernet Cables 25 Connecting an Aurorean Policy Server 25 Connecting an ANG 3000 7000 26...

Page 7: ...net Explorer 5 x or greater versions only 43 Using Netscape 4 x or higher versions only 49 Logging On the ANG 57 Configuring General Parameters 59 ANG 3000 7000 Installation and Configuration Checklis...

Page 8: ...91 Checking LEDs 93 APS ANG 3000 7000 Front Panel LEDs 93 Resetting a System 96 APS ANG 3000 7000 Series 96 Appendix A Specifications Aurorean Policy Server Specifications 100 Aurorean Network Gatewa...

Page 9: ...m Release 2 x to 3 5 115 Backup APS Management Database on RiverMaster PC 115 Reconfigure the APS 3000 7000 117 FTP the New Linux Kernel to the ANG 119 Install the New Linux Kernel 120 FTP the ANG Ins...

Page 10: ......

Page 11: ...r up to 25 tunnels in a home or small office the ANG 3000 for small to medium sized networks up to 500 simultaneous tunnels and the ANG 7000 for large enterprise networks up to 5000 simultaneous tunne...

Page 12: ...tting the server changing keyboard and time zone settings and provides instructions for correcting hardware related problems Appendix A Specifications provides essential physical and operational chara...

Page 13: ...from damaging the product or losing data WARNING Warnings provide directions that you must follow to avoid harming yourself Bold Text in boldface indicates values you type using the keyboard or selec...

Page 14: ...tings and track activity The ANG 1100 User s Guide that details how to install and configure the small office home office Network Gateway The Aurorean Client User s Guide which describes installation...

Page 15: ...computer to set up and monitor your Aurorean Virtual Network System Description The Aurorean Virtual Network family of enterprise VPN products consists of the following components Aurorean Client Sof...

Page 16: ...ork For more information on the Aurorean Client refer to the Aurorean Client Software User s Guide or Quick Reference Card Aurorean Client ANG 3000 7000 APS3000 7000 Firewall Selects closest ISP POP D...

Page 17: ...vity and alarm messages exchanged throughout the Aurorean Virtual Network this information is viewed from the RiverMaster management application Contains the master TollSaver database which is customi...

Page 18: ...Overview Figure 2 Aurorean Policy Server Front Rear View 10 100BaseT Ethernet port to connect trusted LAN behind firewall CD ROM drive for installing Aurorean Software updates APS 3000 7000 FRONT APS...

Page 19: ...z Celeron in the APS 3000 CD ROM drive for loading up to date ISP POP databases and diagnostic scripts as part of the Aurorean Software Update Service and for upgrading system software Floppy Drive fo...

Page 20: ...ed in a Site to Site configuration only Compresses and encrypts the data passing over the tunnel connection to improve performance and ensure security Reports detailed statistics on each tunnel connec...

Page 21: ...rean Network Gateways Front Rear Views ANG 3000 7000 FRONT ANG 1100 Front ANG 1100 Rear ANG 3000 7000 REAR 10 100BaseT Ethernet port to connect trusted LAN behind firewall 10 100BaseT Ethernet port to...

Page 22: ...floppy based configuration of remote Network Gateways Complete set of diagnostic LEDs that show the server s operational status and alert you when to check the RiverMaster message alarm log Two 10 10...

Page 23: ...s software is provided on a CD ROM shipped with every Aurorean Policy Server Figure 4 illustrates the interaction between the Policy Server Network Gateway and RiverMaster computer Figure 4 RiverMaste...

Page 24: ...ted by each part of the interface Figure 5 RiverMaster Management Application For complete information on RiverMaster software refer to the RiverMaster Administrator s Guide supplied with the APS Chec...

Page 25: ...entially as you navigate down the menu options Configuration changes appear in the display windows immediately after they are entered Figure 6 ANG Welcome Window Aurorean Software Update Service The A...

Page 26: ...if necessary 3 Mount the system s into a rack if necessary 4 Connect Ethernet cable s to the LAN port s Both the Aurorean Policy Server and Aurorean Network Gateway provide two Ethernet ports only on...

Page 27: ...gin Before you start to install an Aurorean Virtual Network system review the following information Tools Cables Rack mounting and sliding rail kits including brackets and screws are supplied with eve...

Page 28: ...elay style rack using the two right angle midmount brackets provided Installed in a four post 19 rack or cabinet using the sliding rails kit Placing on a Tabletop or Shelf Place the system on a clean...

Page 29: ...the rack posts Do not tighten 4 Properly align the system in the rack and securely tighten the screws to the rack posts Figure 8 Attaching the Mounting Brackets CAUTION Do not block the vents at the f...

Page 30: ...k and nut for each screw They are used to attach the brackets to the rail rack sections To mount a Aurorean Virtual Network system in a 19 rack or cabinet begin assembly below Remove the Chassis Secti...

Page 31: ...em 2 Fasten the chassis section to the side of the system with four 10 24 x 0 25 panhead Phillips screws Figure 10 Attaching Chassis Sections to the System Attach Front Brackets to the Rail Assemblies...

Page 32: ...g the Front Bracket Determine Correct Position for the Rear Brackets The exact position of the rear bracket in relation to the rail assembly is determined by the depth of the rack Because the rack sec...

Page 33: ...ts align with the two sets of three holes in the rack section of the rail 4 Remove the rail assembly from the rack Attach the Rear Brackets to the Rail Assemblies Since you have determined which slots...

Page 34: ...r of the rack 6 Hold the rail assembly in place and tighten the screws Make sure the fit of the rail assembly to the rack is snug Figure 13 Attaching the Rear Bracket to the Rail Assembly Install the...

Page 35: ...Attaching Rail Front to the Rack 2 Attach the rear bracket to the rack with two screws provided with the rack as shown in Figure 15 Figure 15 Attaching Back of Rail to the Rack Screws provided with th...

Page 36: ...Install the System in the Rack 1 Hold the system so that the front is facing you 2 Line up the system so the rollers on the chassis section will enter the channel of the slider section of the rail as...

Page 37: ...e 17 System Fastened to Rack Removing the System From the Rack If you need to remove the system from the rack perform the following steps 1 Unscrew the two screws holding the system flanges to the rac...

Page 38: ...tem from the Rack CAUTION Do not block the vents at the front and rear of the server For electrical safety verify that the branch circuit supplying power to equipment in the rack can accommodate the a...

Page 39: ...equipped with two Ethernet ports although only one port is needed for connection to a trusted network segment one protected by a firewall Aurorean Network Gateways provide a similar port as well as a...

Page 40: ...an be connected to an Ethernet network segment residing outside a firewall using the EXTERNAL port In this configuration the ANG performs some routing functions and ensures that only GRE packets from...

Page 41: ...ht through Ethernet cable supplied with the ANG into the EXTERNAL port as shown in Figure 20 4 Plug the opposite end of this cable into a wall jack patch panel or hub linked to an unprotected network...

Page 42: ...this cord on ANG 3000 7000s perform the following steps 1 Plug the cord into the system s power socket as shown in Figure 21 Figure 21 Connecting AC Power to the ANG 3000 7000 2 Plug the opposite end...

Page 43: ...have connected Ethernet cables to the systems your only remaining hardware setup task is to connect a Windows 95 NT 4 0 laptop or desktop computer to the same LAN segment that the ANG APS will reside...

Page 44: ......

Page 45: ...oftware on the ANG 3000 7000 Configuring general values of the ANG 3000 7000 Configuring the Remote ANG 3000 7000 Configuring the ANG 1100 Backing up the ANG configuration optional Viewing ANG statist...

Page 46: ...ontrol application Figure 23 illustrates the process of installing system software on the APS by connecting it and the remote control PC with a hub or the provided crossover cable Figure 23 Installing...

Page 47: ...1 3 5800 The VNC authentication window appears as shown in Figure 24 The IP address you typed includes the port number 5800 with which to access the APS Figure 24 Starting VNC Remote Control 4 Type w...

Page 48: ...erver Desktop To install APS system software perform the following steps 1 Using Windows Explorer open the directory PolicyServer on the CD ROM 2 Double click on the Setup EXE file to launch the appli...

Page 49: ...following new parameters Consult your VPN Configuration Worksheet as needed VPN Name Designation of the VPN system IP address IP address of the APS Subnet Mask Subnet mask of the APS Default Gateway I...

Page 50: ...ANG now transmits information to the APS Failure to reboot the ANG will cause a client kit build to fail Using the APS 3000 7000 Checklist Use the following checklist to verify you have completed the...

Page 51: ...s Optional Upgrade Linux kernel from V3 x to V3 5 Transfer the ANG installation file to the ANG via FTP Install new ANG system software Verify the ANG s date time and update if necessary Reboot the AN...

Page 52: ...ere xxx xxx xxx xxx is the IP address of the Trusted interface of the ANG 6 Log in as ftp using ftp as the password 7 Type bin and press ENTER 8 Type put Linux 2 2 16 2 i386 rpm and press ENTER 9 When...

Page 53: ...a DOS command window 4 Change directory to Aurorean_3 x xx xx NetworkGateway on the CD ROM and press ENTER 5 Open an FTP session to the ANG by typing FTP 192 168 1 2 and press ENTER 6 Login as anonymo...

Page 54: ...file by typing rpm e allmatches rts and press ENTER Then install as directed above Verify ANG s Date and Time On the ANG command line type date and press ENTER The command line will show the date time...

Page 55: ...he command line type setclock then press ENTER Reboot the ANG 1 On the ANG command line type reboot and press ENTER This action will disconnect your Telnet session You must wait a few minutes before t...

Page 56: ...nfig This section describes how to use AWC to configure the general parameters of the ANG The process is organized by the following categories Installing the Indus River Certificate Accessing Aurorean...

Page 57: ...e ANG or for all subsequent sessions until the certificate expiration date If you are using Internet Explorer begin installing the certificate below Skip to page 49 if you are using the Netscape brows...

Page 58: ...Gateway by typing the IP address in the Location field as shown in Figure 29 The Security Alert dialog box appears as shown in Figure 30 This dialog box indicates two problems because the certifying...

Page 59: ...valid for the current session only click Yes The ANG Log On window appears as shown in Figure 29 The IE Security Alert window will appear in all subsequent logins to the ANG Skip to Logging On the ANG...

Page 60: ...Figure 31 Internet Explorer Certificate Window 4 Click Install Certificate to begin the Indus River Certificate installation process The Welcome window of the Certificate Manager Import Wizard appears...

Page 61: ...onfiguring General Values of the ANG 3000 7000 Installing Software Setting Networking Configurables Figure 32 Internet Explorer Certificate Manager Import Wizard Window 5 Click Next The Select a Certi...

Page 62: ...Completing window appears Click OK when the successful import pop up box appears Click OK and Yes to close the Certificate and Security Alert windows respectively The ANG Log On window appears as show...

Page 63: ...te is in force Using Netscape 4 x or higher versions only To install the Indus River Certificate perform the following steps 1 Be sure your remote control computer s IP address is still set to an addr...

Page 64: ...igurables Figure 34 Netscape New Site Certificate Window 3 Click Next The Netscape More Information window appears as shown in Figure 35 If you want to view the certificate and additional details clic...

Page 65: ...51 Chapter 3 Configuring General Values of the ANG 3000 7000 Installing Software Setting Networking Configurables Figure 35 Netscape More Information Window 4 Click Next The Certificate Acceptance wi...

Page 66: ...eptance Window 5 Make one of the following choices Accept the certificate for this session only and click Next The Netscape Warn Me window appears as shown in Figure 37 Accept the certificate until it...

Page 67: ...Values of the ANG 3000 7000 Installing Software Setting Networking Configurables Figure 37 Netscape Warn Me Window 6 Click Next Optionally you may mark the checkbox to be warned when you next connect...

Page 68: ...ing Configurables Figure 38 Netscape Finish Window 7 Click Finish The Certificate Name Check window appears as shown in Figure 39 Netscape reports in this window that the certificate name for the ANG...

Page 69: ...Figure 39 Certificate Name Check Window 8 Click Continue The AWC window appears as shown in Figure 41 Skip to Logging On the ANG on page 57 to continue ANG configuration 9 If you chose to examine the...

Page 70: ...etscape View A Certificate Window The Indus River Certificate is now either accepted for your current Aurorean Virtual Network session or installed permanently for all sessions Your Netscape browser w...

Page 71: ...Config on the ANG perform the following steps CAUTION Aurorean Web Config times out after 10 minutes if no configuration changes have been made or keys struck If this occurs after you log on you will...

Page 72: ...al Values of the ANG 3000 7000 Chapter 3 Installing Software Setting Networking Configurables 2 Enter the default User Name netadmin and Password netadmin values and click Log On The Welcome window ap...

Page 73: ...eral Configuration Window appears as shown in Figure 43 Figure 43 ANG General Configuration Window 2 Enter the name that will be shared by all Aurorean devices on your corporate network in the VPN Dom...

Page 74: ...ndow you will be directed to continue set up using the RiverMaster application If you are configuring a remote ANG you will be permitted to continue set up using Aurorean Web Config 4 Specify a Hostna...

Page 75: ...y This is the IP address of a router that can forward packets from the ANG s trusted port to other subnets It must be on the same subnet as the internal interface of the ANG CAUTION The IP Address spe...

Page 76: ...000 7000 Installation and Configuration Checklist on page 63 16 Re launch AWC using the newly specified IP address of the ANG trusted IP address you set earlier NOTE After completing General configura...

Page 77: ...licy Server at IP Address 167 51 178 56 is providing the authentication for this configuration There were no configuration problems found Press RETURN to continue ANG 3000 7000 Installation and Config...

Page 78: ...the worksheet enter the information as solicited Check Local if you were configuring an APS ANG 3000 7000 pair and Remote if you were configuring a stand alone remote ANG 3000 7000 Enter the APS IP a...

Page 79: ...e remote ANG perform the following steps 1 Click on the Routing option The Routing Configuration window appears with the RIP tab selected by default as shown in Figure 44 If you do not want to configu...

Page 80: ...routes Authentication simple algorithm or none 2 If used type the RIP Password and then confirm the entry in the fields provided 3 Click Apply Changes Setting OSPF Properties If your trusted network u...

Page 81: ...ntry in the fields provided 7 Click Apply Changes Setting Static Routes The trusted interface should be connected to a protected network segment one behind a firewall or router that offers protection...

Page 82: ...ote ANG 3000 7000 Chapter 3 Installing Software Setting Networking Configurables Figure 46 ANG Static Route Configuration Window 2 Click Add Route The Add Static Routes window appears as shown in Figu...

Page 83: ...hop address for a packet enter an address of 0 0 0 0 and a subnet mask of 0 0 0 0 CAUTION Configuring a default static route 0 0 0 0 0 0 0 0 on the Trusted interface of the ANG disables Intelligent C...

Page 84: ...0 7000 Chapter 3 Installing Software Setting Networking Configurables Figure 48 ANG External Routes Configuration Window 2 Click Add Route The Add External Routes configuration window appears as shown...

Page 85: ...reachable next hop address for a packet enter an address of 0 0 0 0 and a subnet mask of 0 0 0 0 5 Click Add Static Route Configuring Subnet Parameters Virtual Subnets for ANGs in a site to site conf...

Page 86: ...arned of that route So if a remote client and a site to site tunnel obtain their virtual IP addresses from the same virtual subnet on the Network Gateway then that remote user will not be able to lear...

Page 87: ...k skip to Configuring Authentication Parameters on page 74 To set the Name Server parameters of the ANG perform the following steps 1 Click on the Name Servers option The Name Servers Configuration wi...

Page 88: ...ting Network Gateway skip to Configuring Protocols Parameters on page 78 To set the Authentication parameters of the ANG perform the following steps We recommend configuring Group values before User v...

Page 89: ...ers and some symbols NOTE The following symbols are not permitted in the Group Name field comma plus sign at sign space Tab single and double quotes space apostrophe tilde percent sign ampersand excla...

Page 90: ...re access to the Aurorean Web Config tool To set User parameters on the ANG perform the following steps 1 Click on the Authentication main menu option The Users configuration window appears as shown i...

Page 91: ...d at this terminating ANG There is no character limit to user names and they may contain letters numbers and some symbols NOTE The following symbols are not permitted in the User Name fields comma plu...

Page 92: ...osoft 3Com and others uses the Point to Point PPP protocol and Generic Routing Encapsulation GRE to route packets through the Internet For each tunnel protocol you can configure encryption data integr...

Page 93: ...nd then another encryption with a third key The result is equivalent to DES with a 112 bit key ARCFOUR 128 Enables a 128 bit key version of ARCFOUR described below DES Enables Data Encryption Standard...

Page 94: ...descending order of protection HMAC SHA Enables hashing message authentication codes HMAC that are generated using the SHA cryptographic hashing function HMAC SHA is generally regarded as stronger mor...

Page 95: ...in Figure 57 2 Click on the PPTP tab The PPTP configuration window appears as shown in Figure 58 Figure 58 ANG PPTP Configuration Window 3 Choose to Enable or Disable 128 bit Encryption This option c...

Page 96: ...ys Microsoft Point to Point Compression MPPC 6 Click Apply Changes Configuring Site to Site Parameters Both Local and Remote Aurorean Network Gateways can be configured as site to site ANGs but if the...

Page 97: ...ANG 3000 7000 Installing Software Setting Networking Configurables Figure 59 ANG Site to Site Configuration Window 2 Click Add Site to Site to initiate the tunnel The Add Site to Site configuration wi...

Page 98: ...clamation point backslash forward slash and asterisk 7 Enter a Password for the terminating Network Gateway 8 Click Add Site to Site Tunnel 9 In the Site to Site window click Enabled and Apply Changes...

Page 99: ...twork site or a floppy disk The configuration file created by this backup process is compressed in a WinZip file as a Unix tar file config gz which bundles the auser irx group irx and config irx files...

Page 100: ...to change the file name It cannot be renamed The Download complete window pops up as shown in Figure 62 displaying the file size and the directory where it was stored Figure 62 Download Complete Windo...

Page 101: ...val the ANG is operating since the last reboot time of day number of users logged on and average load System Memory kilobytes of RAM as well as free shared buffered and cached memory Disk Usage availa...

Page 102: ...88 Aurorean Installation Service Guide Viewing ANG Statistics Chapter 3 Installing Software Setting Networking Configurables...

Page 103: ...Aurorean Installation Service Guide 89 Chapter 3 Viewing ANG Statistics Installing Software Setting Networking Configurables Figure 63 ANG About Window...

Page 104: ......

Page 105: ...s that collectively perform all VPN functions Using the RiverMaster management application except for site to site installations you can view the status running or stopped of each service on the Auror...

Page 106: ...on 5 FTP provides the mechanism for transferring files between Aurorean VN systems and RiverMaster FTP also allows Aurorean Client computers to synchronize their TollSaver databases against the master...

Page 107: ...powered on or off If this LED remains off even when the system is connected to a working power source the power supply is no longer functional On No action required Off Verify that the power cord is...

Page 108: ...rd is plugged into a functional wall outlet or UPS and into the receptacle on the system s rear panel Green Controller detects and configures for 100Mb operation On No action required Off Link on Exte...

Page 109: ...e received Off Check the Ethernet ports and LEDs on the system rear panel to ensure the cables are securely connected and that the Ethernet link is active Check the IP addresses assigned to each Ether...

Page 110: ...n Location In general you need to manually reset an APS ANG 3000 7000 series only under the following conditions After changing one of the system s IP addresses After one of the systems has automatica...

Page 111: ...Common Specifications Category Parameters Chipset APS ANG 3000 7000 Intel 82440BX AGPSet System Memory Memory Capacity Four 25 angle DIMM sockets for 16MB to 1 GB SDRAM Form Factor APS ANG 3000 7000 1...

Page 112: ...ply APS ANG 3000 7000 AC Voltage Frequency 90 135 180 265 VAC 40 63 Hz DC Power Supply Single 125W 5VDC 13A maximum 12VDC 3 0A maximum 3 3VDC 6 0A maximum 12VS DC 0 2A maximum Safety Regulations APS A...

Page 113: ...A Limit Radiated and Conducted Emissions EN50024 Immunity Standard for Information Technology Equipment EN61000 3 2 Harmonic Currents EN61000 3 3 Voltage Flicker Japan VCCI V 3 Class A ITE CISPR 22 Cl...

Page 114: ...via RADIUS Key Management 40 bit or 128 bit RC4 compatible Microsoft Point to Point Encryption MPPE Internet Key Exchange IKE Authenticated Diffie Hellman based key exchange protocol CPU Processor AP...

Page 115: ...10 or 100 Mbps auto sensing Connector 8 position modular jack RJ 45 Stewart 88 360808 or equivalent Cabling Unshielded twisted pair UTP 328 ft 100 m maximum length with standard receiver squelch leve...

Page 116: ...Tunnel Protocols IP Security Protocol IPSec as defined in RFC 2401 and 2409 Point to Point Tunneling Protocol PPTP as defined in RFC 1234 Generic Routing Encapsulation GRE as defined in RFC 1701 and...

Page 117: ...E hard disk boot device Floppy Drive Standard 3 5 diskette drive Ethernet Number of Ports Two Data Transfer Rate 10 or 100 Mbps auto sensing Connector 8 position modular jack RJ 45 Stewart 88 360808 o...

Page 118: ......

Page 119: ...ted at the rear of the chasses supporting full duplex 10 100Base T transmission These LAN connectors are routed to four LEDs two Link and 100Mbps LEDs per each interface on the front panel refer to Ap...

Page 120: ...ments Replacement Ethernet cables must meet the following requirements Category 3 4 or 5 unshielded twisted pair UTP wiring Length cannot exceed 328 feet 100 meters Link 2 Link 1 Pin 1 Pin 8 Pin 1 Pin...

Page 121: ...rial ports are rarely used and employ industry standard male DB 9 connectors serial cables are not provided with the system You can use standard PC serial cables available from any computer supply ret...

Page 122: ...oard port supports a PS 2 style keyboard with a 6 pin mini DIN connector Figure 3 shows the pin assignments for the Aurorean server keyboard port Figure 3 Keyboard Port Pin Assignments The mouse port...

Page 123: ...eement Agreement between You the end user and Enterasys Networks Inc Enterasys that sets forth your rights and obligations with respect to the Enterasys software program Program in the package The Pro...

Page 124: ...S Government including the U S Department of Commerce which prohibit export or diversion of certain technical products to certain countries unless a license to export the product is obtained from the...

Page 125: ...ontrols under the U S Munitions List United States Government Restricted Rights The enclosed Product i was developed solely at private expense ii contains restricted computer software submitted with r...

Page 126: ...D OF THE POSSIBILITY OF SUCH DAMAGES BECAUSE SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES OR IN THE DURATION OR LIMITATION OF IMPLIED WARRA...

Page 127: ...o recommends that you have the RiverMaster Administrator s Guide on hand when you call Returning Products for Repair After discussing the problem with Enterasys Networks Customer Support or your autho...

Page 128: ......

Page 129: ...ement database on the RiverMaster computer Reconfigure the APS FTP the new Linus kernel and install on the ANG FTP the ANG installation kit to the ANG Install the new ANG software Verify the VPN is up...

Page 130: ...network A window similar to Figure 6 appears Figure 6 Select a Path to Save the Database Click here to view the list of services Select the Access Click here to open the Configuration Click here to s...

Page 131: ...e the RiverMaster software connected to the RMS database s Reconfigure the APS 3000 7000 1 Insert the floppy disk with the backup files into the APS 3000 7000 floppy drive 2 Start the VNC application...

Page 132: ...Figure 8 Figure 8 Policy Server Desktop 5 If necessary click SEND CTRL ALT DEL on the VNC menu if using VNC client or from the tab at the top of the VNC window if using a browser The default Administr...

Page 133: ...ify the information displayed is accurate or change as required Figure 9 APS Perl Script Screen 12 Restart the APS All Enterasys services are started the APS reboots and the VNC remote control session...

Page 134: ...Type rpm i force Linux 2 2 16 2 i386 rpm and press ENTER Ignore several warning messages which appear during installation 5 When the Linux prompt returns type reboot and press ENTER FTP the ANG Insta...

Page 135: ...nd of installation the following message appears Building devices for the River This can take several minutes 7 When the Linux prompt returns type reboot Verify the VPN is Up and Running Perform the f...

Page 136: ...the menu Type q to quit 7 Close the Telnet connection by typing bye You are now ready to connect the servers to the customer s network Any remaining configuration must be performed using RiverMaster U...

Page 137: ...ication or your Internet browser by pointing your Web browser at the APS In the Location field type http xxx xxx xxx xxx 5800 where xxx xxx xxx xxx is the IP address of the APS 3 Press the SEND CTRL A...

Page 138: ...ry 2 Copy the Linux 2 2 16 2 i386 rpm file to the c temp directory on the APS or your laptop 3 From the APS console using VNC or your laptop connected to the ANG using Windows Explorer search the Auro...

Page 139: ...Telnet to the trusted interface of the ANG 2 Log in as netadmin with the password netadmin 3 Type su and press ENTER Type the root password welcome and press ENTER 4 Type cd home ftp pub and press ENT...

Page 140: ...Check 3 IPSec Configuration 4 Diagnostics 5 Interfaces and Routing 6 System log files 7 Quit 5 Choose Option 2 VPN Configuration and Installation Check The following message will appear 1 The IPSec Li...

Page 141: ...ations 100 standard features 5 system description 3 authentication 3 100 102 Authorization service 92 B backing up the configuration 63 brackets attaching the brackets 14 C cables connecting Ethernet...

Page 142: ...cabinet with sliding rails 16 24 overview 12 sliding rails 16 IP Security Protocol IPSEC 102 K keyboard port 108 L LAN protocols 102 LEDs 93 license agreement 109 112 Link 1 LED 94 Link 2 LED 94 log f...

Page 143: ...RJ 45 connecting cables 25 27 connector pin assignments 105 specifications 101 103 RMA number 113 routing 102 S safety compliance 98 serial port 107 services running on APS 91 92 Set hardware clock 4...

Reviews: