background image

Index

Numerics

1 GB Full Duplex 17
1 GB Half Duplex 17
100 MB Full Duplex 17
10G Network Active Bypass unit

audience xvii
back up settings 24
connecting 11
default IP address 12
default settings 24
email notifications 19
firmware update 25
front panel 3
hardware interface 3
management interface 12
network segment configuration 13
operation modes 7
overview 1
password 25
port statistics 25
power supply 23
remote authentication 26
restore settings 24
setting time zone 21
SNMP traps 20
supported Network IPS appliance

models xvii

switching modes 5
system logs 18
system status 23
 26
user accounts 25

A

access control 26
alert triggers 27
alerting 27
analyzer panel 23
auto negotiation 17

B

bypass mode 5

C

cold boot 27
command-line interface 30
config.txt file 24

E

email notification 27
Email Notification page 19
email notifications 19

F

factory defaults 24
Fail mode 13
firmware update 25
Firmware Update page 25
front panel 3
full duplex 17

H

half duplex 17
hardware interface 3

I

IBM Security

support portal xviii
technical support xviii
troubleshooting xviii

inline mode 5

L

Link Mode 17
Log Setting page 18

M

Manage Settings page 24
management interface 12, 23
Management Port page 17
management ports

configuring 17

Manual Active Bypass 7
Manual Active Inline 7

N

network segments 3
Network Time Protocol 21
Normal Active Bypass 7
Normal Active Inline 7
NTP

See

Network Time Protocol

NTP Setting page 21

O

operation modes

Manual Active Bypass 7
Manual Active Inline 7
Normal Active Bypass 7
Normal Active Inline 7

overview 1

P

parameter, command-line 30
Port Statistics page 25
port status 25
power fail protection 1

R

Remote Authentication page 26

S

safety notices vii
Segment Settings page 13
segment status 23
SNMP notification 27
SNMP Settings page 20
SNMP traps

configuring 20

SSH port 29
status 23
Status page 23
support xviii
switching modes 5
syslog notification 27
system logging 18
system status 23

T

 26
TAP mode 15
TAP port 15
TAP ports 9
technical support, IBM Security xviii
Time Setting page 21
time zone 21

U

user interface 23
Users page 25

W

warm boot 27

© Copyright IBM Corp. 2011, 2014

35

Summary of Contents for 10G Network Active Bypass

Page 1: ...IBM Security 10G Network Active Bypass User Guide V ersion 3 4...

Page 2: ...yright statement Copyright IBM Corporation 2011 2014 U S Government Users Restricted Rights Use duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp Publication Date April 2...

Page 3: ...ve Bypass unit on your network 11 Logging in to the management interface 12 Bypass settings 13 HA Service 16 Bond service 16 Link SFP 17 Management port settings 17 System logging 18 Email notificatio...

Page 4: ...iv 10G Network Active Bypass V3 4 User Guide...

Page 5: ...tion statement regulation notice This product is not intended to be connected directly or indirectly by any means whatsoever to interfaces of public telecommunications networks Copyright IBM Corp 2011...

Page 6: ...vi 10G Network Active Bypass V3 4 User Guide...

Page 7: ...n conditions To avoid these hazards ensure that your system electrical requirements do not exceed branch circuit protection requirements Refer to the information that is provided with your device or t...

Page 8: ...t signal cables v Never turn on any equipment when there is evidence of fire water or structural damage v Disconnect the attached power cords telecommunications systems networks and modems before you...

Page 9: ...n To provide the correct power connection to a rack refer to the rating labels located on the equipment in the rack to determine the total power requirement of the supply circuit v For sliding drawers...

Page 10: ...roduct you must first become familiar with the related safety information in the booklet You should also refer to the booklet any time you do not clearly understand any safety information in the US En...

Page 11: ...a los propietarios de equipos a reciclar sus productos de TI Se puede encontrar informaci n sobre las ofertas de reciclado de productos de IBM en el sitio web de IBM http www ibm com ibm environment p...

Page 12: ...m nickel metal hydride and other battery packs from IBM equipment For information on proper disposal of these batteries contact IBM at 1 800 426 4333 Please have the IBM part number listed on the batt...

Page 13: ...roducts intended for use with this product will appear in their accompanying manuals Federal Communications Commission FCC Statement Note This equipment has been tested and found to comply with the li...

Page 14: ...1176 Fax 0049 0 711 785 1283 e mail tjahn de ibm com EC Declaration of Conformity In German Deutschsprachiger EU Hinweis Hinweis f r Ger te der Klasse A EU Richtlinie zur Elektromagnetischen Vertr gl...

Page 15: ...55022 Klasse A update 2004 12 07 People s Republic of China Class A Compliance Statement This is a Class A product In a domestic environment this product may cause radio interference in which case the...

Page 16: ...xvi 10G Network Active Bypass V3 4 User Guide...

Page 17: ...IP network configuration is helpful Supported Network IPS appliance model The 10G Network Active Bypass unit supports the GX7800 Network IPS appliance model Latest product documentation For the latest...

Page 18: ...roblem to IBM Support in one of the following ways v By using IBM Support Assistant ISA if the Service Request tool is enabled on your product Any data that has been collected can be attached to the s...

Page 19: ...k IPS appliances Extensive bypass configuration You can configure these bypass options v Heartbeat pattern v Heartbeat interval v Bypass on link loss or power loss v Configuration of the number of lin...

Page 20: ...2 168 0 111 The default management port Web address is https 192 168 0 111 Extensive command line interface The 10G Network Active Bypass unit includes a command line interface that provides these fea...

Page 21: ...console interface through the network 4 TAP ports Ports used to passively monitor and mirror network traffic Note The 10G Network Active Bypass unit provides seven functioning TAP ports 1 through 7 T...

Page 22: ...PS appliance 2 Appliance link activity LED Link and activity status of the connected Network IPS appliance 10G uses orange LED Blinking orange Traffic activity blinks only when receiving traffic not w...

Page 23: ...e Bypass unit is placed inline with the Network IPS appliance and is connected to the Network IPS appliance and to the networks Inline mode When the 10G Network Active Bypass unit is in inline mode ne...

Page 24: ...conds or 10 heartbeat packets per second Port A2 appliance out must receive the same heartbeat packet from the Network IPS appliance Note By default the heartbeat packet is sent every 100 milliseconds...

Page 25: ...e Bypass unit but the traffic bypasses the appliance ports The 10G Network Active Bypass unit continues to inject heartbeats from the Network IPS appliance into the stream out of the Network IPS appli...

Page 26: ...ic flows between the network ports but the 10G Network Active Bypass unit does not send heartbeat packets In this mode the 10G Network Active Bypass unit tries to negotiate at the link speed and duple...

Page 27: ...TX The port mirrors both the receiving traffic and the transmitting traffic to the user defined TAP port Power failure protection You can program the 10G Network Active Bypass unit to open a network...

Page 28: ...ctive Bypass unit Table 5 Supported transceivers and orderable transceiver kits Form Factor Speed Mode IBM Part Number IBM Orderable PN kit of 2 SFP 1G SX multi mode 51J1701 51J2260 SFP 1G LX single m...

Page 29: ...nd to two different power sources for added redundancy Tip Use independent AC power sources to maximize power redundancy in the event of AC power loss from a single source 4 Check the Power LEDs on th...

Page 30: ...web browser 3 Type https 192 168 0 111 The 10G Network Active Bypass unit uses a default IP address of 192 168 0 111 These default values remain in effect until you change them You can use the Managem...

Page 31: ...of power If a power failure is detected Power Fail Protection Operation is triggered which initiates a switch to bypass mode During this no power state the network ports connect physically to create...

Page 32: ...ypass unit does not receive heartbeat signals within the Timeout period it will change to or remain inline By default without a heartbeat 10G Network Active Bypass unit remains inline Manual Active By...

Page 33: ...3 Bidirectional heartbeat When enabled the system sends heartbeat packets on both the A1 and A2 ports of the specified segment instead of just A1 No Link fault detection Generates an SNMP trap if a ne...

Page 34: ...d Primary Primary segment of the pair where traffic usually flows Secondary Backup segment used if the primary segment fails Bond service Use the Bond Service page to configure a pair of segments in a...

Page 35: ...0 1 DNS 2 IP address of the secondary domain name system server 0 0 0 0 Link Mode Auto negotiation Allows the 10G Network Active Bypass unit to select the best common mode automatically over the link...

Page 36: ...r Identification Host name of the syslog server Heartbeat status template Log entry template for heartbeat status change messages Heartbeat Segment segment state hb_state_name OpMode op_mode_name Powe...

Page 37: ...assword for the outgoing SMTP mail server if applicable Outgoing Server SMTP Security SSL encryption used between the SMTP mail server and mail client Enabled Secured From Sender s Email Address The n...

Page 38: ...p server public Alias SNMP Alias of trap manager Heartbeat status template Log entry template for heartbeat status change messages bypassInOut bypassTrapModuleId u segment bypassTrapStateBypass s hb_s...

Page 39: ...tive Bypass unit time with a network time server Disabled NTP server Public domain of a collection of computers that provide time using NTP us pool ntp org Use the Time Zone page to set the time zone...

Page 40: ...22 10G Network Active Bypass V3 4 User Guide...

Page 41: ...s unit Management IP IP address for the management port Tip Use the Management Port page if you want to change IP settings for the management port 192 168 0 111 Current temperature Current temperature...

Page 42: ...Table 18 Backup or restore settings Field Description Save Settings Saves a copy of the current settings on the 10G Network Active Bypass unit in a file named config txt Load Settings Location of a s...

Page 43: ...Bypass unit and to view a snapshot of traffic activity The information on this page is updated every 10 seconds User account settings Use the Users page to change the user name and password required t...

Page 44: ...CACS settings Field Description Default TACACS Allows TACACS protocol for access control Disabled Server IP address of the server providing access services 0 0 0 0 Protocol Protocol used for the conne...

Page 45: ...ge The 10G Network Active Bypass unit sends a notice when one of the two power cables is disconnected If both power cables are disconnected then the 10G Network Active Bypass unit sends a coldboot not...

Page 46: ...28 10G Network Active Bypass V3 4 User Guide...

Page 47: ...nd the SSH remote shell emulator Connection type Port on 10G Network Active Bypass unit Cable Serial terminal emulator Console port Console cable SSH remote shell emulator Management port Management c...

Page 48: ...onfigure Enter configuration mode exit Exit from the CLI show Display system or configuration information statistics Port statistics operations system System action Select the show command and then ty...

Page 49: ...etection information links Configure link status management if Configure management interface information notification Configure notification setting sfp Configure sfp information statistics Configure...

Page 50: ...32 10G Network Active Bypass V3 4 User Guide...

Page 51: ...ectual Property Law IBM Japan Ltd 19 21 Nihonbashi Hakozakicho Chuo ku Tokyo 103 8510 Japan The following paragraph does not apply to the United Kingdom or any other country where such provisions are...

Page 52: ...between us All statements regarding IBM s future direction or intent are subject to change or withdrawal without notice and represent goals and objectives only Trademarks IBM the IBM logo and ibm com...

Page 53: ...uplex 17 hardware interface 3 I IBM Security support portal xviii technical support xviii troubleshooting xviii inline mode 5 L Link Mode 17 Log Setting page 18 M Manage Settings page 24 management in...

Page 54: ...36 10G Network Active Bypass V3 4 User Guide...

Page 55: ......

Page 56: ...Printed in USA...

Reviews: