
AG 5500
Introduction
5
Access Control and Authentication
The AG 5500 ensures that all traffic to the Internet is blocked until authentication has been
completed, creating an additional level of security in the network. Also, allows service
providers to create their own unique “walled garden,” enabling users to access only certain
predetermined Web sites before they have been authenticated.
Nomadix simultaneously supports the secure browser-based Universal Access Method
(UAM), IEEE 802.1x, and Smart Clients for companies such as Adjungo Networks, Boingo
Wireless, GRIC and iPass. MAC-based authentication is also available.
Security
The patent-pending iNAT™ (Intelligent Network Address Translation) feature creates an
intelligent mapping of IP Addresses and their associated VPN tunnels—by far the most
reliable multi-session VPN passthrough to be tested against diverse VPN termination servers
from companies such as Cisco, Checkpoint, Nortel and Microsoft. Nomadix’ iNAT feature
allows multiple tunnels to be established to the same VPN server, creating a seamless
connection for all users on the network.
The AG 5500 provides fine-grain management of DoS (Denial of Service) attacks through its
Session Rate Limiting (SRL) feature, and MAC filtering for improved network reliability.
5-Step Service Branding
A network enabled with the Nomadix AG 5500 (or any other Nomadix Access Gateway)
offers a 5-Step service branding methodology for service providers and their partners,
comprising:
1.
Initial Flash Page branding.
2.
Initial Portal Page Redirect (Pre-Authentication). Typically, this is used to redirect the
user to a venue-specific Welcome and Login page.
3.
Home Page Redirect (Post-Authentication). This redirect page can be tailored to the
individual user (as part of the RADIUS Reply message, the URL is received by the NSE)
or set to re-display itself at freely configurable intervals.
4.
The Information and Control Console (ICC) contains multiple opportunities for an
operator to display its branding or the branding of partners during the user’s session. As an
alternative to the ICC, a simple pop-up window provides the opportunity to display a
single logo.
5.
The “Goodbye” page is a post-session page that can be defined either as a RADIUS VSA
or be driven by the Internal Web Server (IWS) in the NSE. Using the IWS option means
that this functionality is also available for other post-paid billing mechanisms (for
example, post-paid PMS).
ag5500_userguide.book Page 5 Tuesday, June 5, 2007 7:31 PM
Summary of Contents for AG 5500
Page 1: ......
Page 6: ...This page intentionally left blank AG 5500 vi...
Page 40: ...This page intentionally left blank AG 5500 28 Introduction...
Page 46: ...AG 5500 34 Installing the AG 5500...
Page 68: ...This page intentionally left blank AG 5500 56 Installing the AG 5500...
Page 73: ...AG 5500 System Administration 61...
Page 106: ...AG 5500 94 System Administration IPSec Tunnel Security Policies...
Page 110: ...AG 5500 98 System Administration...
Page 115: ...AG 5500 System Administration 103...
Page 126: ...AG 5500 114 System Administration...
Page 174: ...AG 5500 162 System Administration...
Page 203: ...AG 5500 System Administration 191 The Internal Billing Options Setup screen appears...
Page 205: ...AG 5500 System Administration 193 Sample of Internal Billing Options XoverY Plan Setup Screen...
Page 210: ...AG 5500 198 System Administration...
Page 231: ...AG 5500 System Administration 219 4 Repeat Steps 1 3 for page 2 of 2 see following screen...
Page 234: ...AG 5500 222 System Administration 5 Repeat Steps 1 3 for page 3 of 3 see following screen...
Page 268: ...This page intentionally left blank AG 5500 256 The Subscriber Interface...
Page 299: ...AG 5500 Quick Reference Guide 287 Here is the output of cakey pem...
Page 301: ...AG 5500 Quick Reference Guide 289 Here is the output of server csr...
Page 316: ...This page intentionally left blank AG 5500 304 Troubleshooting...
Page 318: ...This page intentionally left blank AG 5500 306 Appendix A Technical Support...
Page 338: ...This page intentionally left blank AG 5500 326 Index...