background image

47

NETWORK ACCESS—

WAN ROUTERS

LOW-COST WAN ROUTERS

visit us online

www.patton.com

FAST Delivery From Your AUTHORIZED DISTRIBUTOR!

CATALOG

Network Access & Connectivity

O R D E R I N G I N F O R M A T I O N

2823/UI

: Secure DMZ Router; external UI power supply

2823/48

: Secure DMZ Router; 48-VDC power supply

DMZ Secure Router

IPLink™ 2823 Managed VPN Routers

Patton DMZ Secure Routers streamline DMZ implementation and secure-firewall configura-
tions for enterprise networks without sacrificing QoS for critical business traffic.

IPLink Managed VPN Routers are a family of next generation
appliances that address both the security and the traffic pri-
oritization needs of enterprises. The Model 2823 Secure
DMZ Router with integrated QoS makes it easy for enterpris-
es to isolate their web servers in a secure demilitarized zone
(DMZ). The three-port router physically provides and logical-
ly separates connections to a private LAN and a DMZ net-
work, while still allowing secure business-class Internet
access with traffic-shaping services.

As with all IPLink VPN Routers, the Secure DMZ Router imple-
ments a comprehensive security environment. It all starts
with IPsec. By supporting ESP as well as AH, IPLink VPN
Routers provide data integrity, authentication, anti-replay and

data confidentiality to any traffic flow. DES, 3DES, and AES
provide standard encryption up to 256 bits. Firewall capabil-
ities of the IPLink VPN Routers include Access Control Lists
(ACLs), IP address and port filtering, and protection against
Denial of Service (DoS) attacks. Likewise, PPPoE protocols
include support for PAP and CHAP authentication.

QoS features include ToS/DiffServ marking and the configu-
ration of eight service class tags per IEEE 802.1p/Q. With
traffic scheduling and shaping, create dedicated bandwidth
guarantees, configurable burst tolerance, and policing to
include excess traffic discard. IP fragmentation is config-
urable to help minimize jitter in traffic flows.

Advanced IP features include RIPv1 & RIPv2 routing and
static route configuration. Static and dynamic NAT, NAPT,
DNS resolver and relay, dynamic DNS, and DHCP server fur-
ther add to the capabilities of the IPLink VPN Router. All
IPLink VPN routers can be managed via a web browser
(HTTP), command line interface (Telnet), or an SNMP man-
agement platform.

F E A T U R E S & B E N E F I T S

Triple-Port Power DMZ—Use to configure the 3rd
10/100 Ethernet port as a physical and logical DMZ to
keep traffic off the local network.

VPN Tunnels—Standard IPsec with AH and ESP ensures
maximum protection when traversing unsecured net-
works.

Strong Encryption—DES, 3DES, and AES offer standards
based encryption algorithms from 56 to 256 bits.

QoS/CoS Profiles—Configurable burst tolerance, band-
width guarantees plus reduce per flow traffic jitter as
required by the application. 

Configurable Security Profiles—Built-in IP address and IP
port filtering, ACLs and DoS attack detection creates a
comprehensive security environment.

Enhanced IP Services—DNS resolver and relay,
NAT/NAPT, dynamic DNS, and DHCP server, eases inte-
gration.

SNMP/HTTP Management—Easily manage the IPLink
VPN Routers via a simple web browser interface.

S P E C I F I C AT I O N S

WAN Ethernet port

:

10/100Base-T (RJ-45 connector); auto-
negotiating; half/full duplex operation
with automatic MDI/MDI-X

LAN Ethernet Ports

: One

10/100BaseT port (RJ-45 connector);
auto-negotiating; half or full duplex oper-
ation with automatic MDI/MDI-X plus
One 10BaseT (RJ-45 connector); half or
full duplex with automatic MDI/MDI-X

Management:

CLI via Telnet; TFTP

for software upgrade and configuration
upload; SNMPv1; HTTP/web browser

Protocols

: IP (RFC 741), TCP (RFC

793), UDP (RFC 768), ICMP & ICMP
Redirect (RFC 792), ARP (RFC 826). IP
Router with RIPv1 (RFC 1058), RIPv2
(RFC 2453), programmable static routes.
Integrated DHCP Server (RFC 2131), DNS
Relay (RFC 1631), IEEE 802.1p VLAN
Tagging, NAT/NAPT (RFC 1631/2391)

Security

: IPsec including AH and ESP.

DES, 3DES, and AES encryption. Access
Control Lists (ACLs). IP port and address
filtering both by source and destination.
DoS Detection. Password protected sys-

tem management with a username/pass-

word for console and virtual terminal.

Power Supplies

: External univer-

sal 90–260 VAC input or 48 VDC input.

(Optional Internal universal 90–260

VAC input.)

Compliance: 

CE Mark; Safety:

UL60950-1, CSA 22.2 6095001,

IEC/EN60950-1. Universal AC units are

US NRTL Listed; EMC Emissions: FCC Part

15 Class A; EN55022 Class A; EMC

Immunity: EN55024

Environment:

Temp.: 0–40°C

(32–104°F); Humidity: 5–80% non-

condensing

Dimensions:

7.3W x 1.6H x 6.1D in.

(18.5H x 4.1W x 15.5D cm)

Weight:

30.5 oz./500g (models with

internal power); 24.4 oz./400g (models

with external power; no power supply)

Typical application

WAN

DMZ

LAN

PC

PC

iPhone

2823 IPLink

IP PBX

WWW

WWW, DNS

Server

No public access
to Private LAN

Summary of Contents for ACC-S02

Page 1: ...d PPP Bridge Control Protocol Auto Learning and Aging Supports 4096 MAC Address Public Access Private Access Edge Product Line Ethernet Ports Integrated WAN Interfaces Model Description Pg 1 4 1 1 1 1 1 1 1 1 or 4 port switch 2 2 2 2 Gigabit Ethernet 2 Gigabit Ethernet Up to 11 1 T1 E1 2 T1 E1 1 E1 1 T1 V 35 X 21 V 35 X 21 V 24 RS 232 1 Ethernet 1 T1 E1 V 35 X 21 2 4 T1 E1 Inverse Multiplexer 2 4 ...

Page 2: ...V1 V2 OSPFv2 v3 RIPng PPP with BCP IPCP Multi Link PPP Packet filtering firewall PPTP VPN L2TP VLAN IPsec VPN NAT NAPT VLAN p Q Tunneling port wholesaling with L2TP IP filtering MAC filtering 2802 2805 SOHO Enterprise Secure VPN Ethernet Appliances 2823 Managed DMZ Secure VPN WAN Access Device 2803 Integrated T1 E1 VPN WAN Access Device 2835 Integrated V 35 VPN WAN Access Device 2821 Integrated X ...

Page 3: ...ed on Ethernet port and voice switched to second T1 E1 port Manage encrypted voice video and data flows over IP to create secure building ingress points Service provider based Internet Access and IPsec VPN service overlay for remote branch connectivity Use existing broadband and T1 E1 Internet access networks to create secure private networks with firewalls using strong VPN encryption Create a ser...

Page 4: ...interfaces If you have an existing leased line or a TDM network carrying legacy TDM data and you want to add some IP con nectivity between locations the Model 2620 is right for you The Model 2620 is a multi port T1 E1 WAN Router that supports TDM drop and insert between both T1 E1 ports and the on board IP Ethernet Ports With full routing functionality the 2620 allows users to leverage existing le...

Page 5: ... complement to any MxU DSLAM installation If you have multiple remote locations to manage the 2884 provides an ideal companion to any out of band network management solution Equipped with VLAN and RIP support the 2884 is adept at providing the con nectivity required to manage and monitor remote locations The 2884 series is a channelized multi port access bridge router that sup ports up to 124 remo...

Page 6: ...n point to terminate your services the 2800 series is right for you By establish ing differential Quality of Service metrics for voice data and video services the 2800 series allows the Carrier to manage and control IP service flows across IP networks to the customer premise With the abil ity to encrypt and decrypt as well as perform tagging and prioritization of any IP flow voice data video and p...

Page 7: ...Routers take it one step further and integrate qual ity of service QoS to optimize business traffic flows allow ing dual use business and leisure of broadband connections without impacting the quality of business communications IPLink VPN Routers implement a comprehensive security environment It all starts with IPSec By supporting ESP as well as AH IPLink VPN Routers provide data integrity authent...

Page 8: ... man agement platform F E A T U R E S B E N E F I T S Triple Port Power DMZ Use to configure the 3rd 10 100 Ethernet port as a physical and logical DMZ to keep traffic off the local network VPN Tunnels Standard IPsec with AH and ESP ensures maximum protection when traversing unsecured net works Strong Encryption DES 3DES and AES offer standards based encryption algorithms from 56 to 256 bits QoS C...

Page 9: ...ase of use with powerful data routing to make shared Internet connectivity simple and easy With NAT support the IPLink router offers convenient and economical operation by using a single IP address while the integrated DHCP server automates IP address assignment for connected LAN computers Security is standard with built in firewall and violation alerting features that protect the net work from wo...

Page 10: ...the WAN interface you need in industry standard connectors PPP and Frame Relay Versatile WAN options enable deployment into any network Use routed IP or Bridged Ethernet for transparent networking Bridge passes VLAN tagged frames no VLAN tagging within the 2635 2621 NAT NAPT Firewall DHCP Powerful routing features make shared Internet connectivity simple and secure 10 100 Ethernet with MDI X Easil...

Page 11: ...ll traffic flows as well as key multimedia features such as prioritization of voice video and data traffic IP multicast and IGMP and embedded VoIP gateway VPN routers enable the secure communication of remote offices home offices and mobile users across insecure IP net works such as the Internet IPLink VPN Routers take it one step further and integrate quality of service QoS to opti mize business ...

Page 12: ...ality of service QoS to optimize business traffic flows plus include a serial port to eliminate the need for external converters IPLink VPN Routers implement a comprehensive security environment It all starts with IPSec By supporting ESP as well as AH IPLink VPN Routers provide data integrity authentication anti replay and data confidentiality to any traffic flow DES 3DES and AES provide standard ...

Page 13: ...AN Terminate nx64 data Frame Relay or PPP encapsulated IP traffic on channelized interfaces Enhanced IP Services DNS relay NAT NAPT DHCP server and relay make it easy to offer any service Firewall with Standard DoS Filtering Built in IP address and IP port filtering intrusion detection and blacklisting capabilities make firewall services a snap Integrated TDM IP Routers IPLink 2620 Link up effortl...

Page 14: ...port Channelized T1 E1 Support up to 124 PPP sessions with up to 4 channelized T1 E1 ports ML PPP Expands Bandwidth Bind any number of chan nels or T1 E1 ports to create up to an 8 Mbps WAN link Dual Gigabit Ethernet Ports With Dual 10 100 1000 auto MDI ports easily connect to any LAN infrastructure Per Flow QoS Traffic rates are set through ACLs that shape and police VLAN and IP traffic Stateful ...

Page 15: ...LAN tagging and priority VLAN tagged traffic that is received on any of the Gigabit Ethernet inter faces is transparently transported over the WAN to the matching Inverse Mux on the other side The VLAN priority bits are inspected and the QoS of the individual Ethernet frames are preserved end to end The Multi Megabit Inverse Mux likewise supports VLAN tagging of Ethernet traffic ACLs allow Layer 3...

Page 16: ...n RFC 2865 2868 Accounting RFC 2866 2867 SPECIFICATIONS Routing RIPv1 RFC 1058 RIPv2 RFC 2453 OSPFv2 RFC 2328 VLSM RFC 1878 T1 E1 Ports Software configurable T1 AMI B8ZS line coding or E1 HDB3 AMI line coding G 703 G 704 G 723 IP Services ARP RFC0826 Proxy ARP RFC1027 ICMP RFC0950 RFC1256 NTPv3 RFC1305 IGMP IGMPv2 RFC2236 DiffServ RFC2474 NAT RFC 1631 2663 2766 2993 PAP RFC 1332 CHAP RFC 1334 1994...

Reviews: