background image

 670-100-102

Issue 2

March 2004

Avaya SG5, SG5X, and SG200
Security Gateway 
Hardware Installation Guide

Summary of Contents for SG200

Page 1: ...670 100 102 Issue 2 March 2004 Avaya SG5 SG5X and SG200 Security Gateway Hardware Installation Guide ...

Page 2: ...hat includes telephone numbers for the International Centers of Excellence Providing Telecommunications Security Telecommunications security of voice data and or video communications is the prevention of any type of intrusion to that is either unauthorized or malicious access to or use of your company s telecommunications equipment by some party Your company s telecommunications equipment includes...

Page 3: ... CISPR 22 1997 and EN55022 1998 Information Technology Equipment Immunity Characteristics Limits and Methods of Measurement CISPR 24 1997 and EN55024 1998 including Electrostatic Discharge ESD IEC 61000 4 2 Radiated Immunity IEC 61000 4 3 Electrical Fast Transient IEC 61000 4 4 Lightning Effects IEC 61000 4 5 Conducted Immunity IEC 61000 4 6 Mains Frequency Magnetic Field IEC 61000 4 8 Voltage Dip...

Page 4: ...sic Rate Interface BRI and CTR4 Primary Rate Interface PRI and subsets thereof in CTR12 and CTR13 as applicable Copies of these Declarations of Conformity DoCs can be obtained by contacting your local sales representative and are available on the following Web site http www avaya com support Japan This is a Class A product based on the standard of the Voluntary Control Council for Interference by ...

Page 5: ... ports 13 Chapter 2 Installing the security gateway 15 General requirements 15 Environmental requirements 15 Power considerations 16 Equipment required 16 System requirements 16 Installing the security gateway 17 Chapter 3 Setting up the security gateway for configuration 23 Service provider provisioning 24 Power on self test 24 Connecting to the private port of the security gateway 25 Performing ...

Page 6: ...X SG200 Security Gateway Hardware Installation Guide Appendix A Specifications Physical specifications 29 Environmental specifications 30 Electrical specifications 30 Compliance specifications 31 Additional features 32 Index 33 ...

Page 7: ...w to install and preconfigure these devices It is recommended that you read the entire installation guide before installing the security gateway Contacting technical support Technical support is available to registered users of the Avaya security gateway products Domestic support Toll free phone support 866 462 8292 24x7 Email vpnsupport avaya com Web http support avaya com International support F...

Page 8: ...Installation Guide Documentation The security gateway documentation includes both the Hardware Installation Guide and the Security Gateway Configuration Guide for VPNos You can down load these guides from http support avaya com Navigate to Product Documentation VPN and Security ...

Page 9: ...ty threats The SG5X and the VSU200 are functionally identical to the SG5 but the VSU5X includes an integrated 7 port Ethernet switch The VSU200 introduces a cardbus PCMCIA expansion slot for future functionality routing capabilities and firewall enhancements that can be managed from a central site location Like other platforms in the Avaya VPN family the security gateway adds encryption authentica...

Page 10: ...city is assured by using MD5 or SHA 1 hashing algorithms to reject altered or forged packets All security mechanisms employed by the security gateway conform to IPsec standards in order to provide interoperability and broaden the use of VPN technology The security gateway also contains a powerful IP packet filtering engine to provide extensive filtering capabilities essential when you have a full ...

Page 11: ...VPNs and remote access users This greatly minimizes the necessary configuration of your workstations and IP devices The security gateway s web based user interface features a quick setup wizard designed to capture essential configuration information for easy initial setup Provisions are also made to access the web based interface remotely over the Internet if desired Where central management of yo...

Page 12: ...onents Figure 2 displays the back panel components on each of the security gateways Figure 2 Back panel components Ethernet Ports Status Indicators Private Port Public Port Connector DC Power Reset Switch Access Public Port Private Ports SG5 SG200 SG5X Private Port Console Port Interface Expansion Card Slot ...

Page 13: ... and 7 10 100BASE T Ethernet ports on the private interface The SG200 includes two 10 100BASE T Ethernet ports that includes a public and private interface port RS 232 console port and a PC Card Netgear PCMCIA expansion port The status indication of the LEDs on the Ethernet ports are shown in Figure 2 Table 1 Network zones Media type SG5 SG5X SG200 Ethernet0 Public Public Public Ethernet1 Private ...

Page 14: ...14 Introduction March 2004 Avaya SG5 SG5X SG200 Security Gateway Hardware Installation Guide ...

Page 15: ...The security gateway is intended for use in a normal home office environment For more extreme conditions verify that temperature humidity and power conditions meet the specifications indicated in Table 2 Additional security gateway specifications are included in Appendix A Table 2 Environmental requirements Item Operating Specification Temperature 32 to 104 F 0 to 40 C Relative Humidity 5 90 non c...

Page 16: ... carton should contain System requirements Before you begin the installation process confirm the following items are available on your local network A router DSL cable or ISDN modem providing connectivity to a WAN such as the Internet 10 100BASE T Ethernet hub router or switch providing connectivity to a LAN CAT 3 4 or 5 UTP cable to interconnect router VSU and hub s A Java enabled JDK 1 1 8 or la...

Page 17: ...the security gateway 17 Avaya SG5 SG5X SG200 Security Gateway Hardware Installation Guide Installing the security gateway Figure 3 shows a typical network using the SG5 security gateway Figure 3 Typical SG5 installation SG5 ...

Page 18: ...alling the security gateway March 2004 Avaya SG5 SG5X SG200 Security Gateway Hardware Installation Guide Figure 4 shows a typical network using the SG5X security gateway Figure 4 Typical SG5X installation SG5X ...

Page 19: ...4 Installing the security gateway 19 Avaya SG5 SG5X SG200 Security Gateway Hardware Installation Guide Figure 5 shows a typical network using the SG200 security gateway Figure 5 Typical SG200 installation SG200 ...

Page 20: ...re 6 Security gateway rear panel connectors Connect Cable between the SG5 5X Public Port and the DSL Cable Modem Connect Cable between the SG5 5X Private Port and Hub or Workstation Connect Cable between the SG200 Public Port and the DSL Cable Modem Connect Cable between the SG200 Private Port and Hub or Workstation ...

Page 21: ...d Ethernet cable connect the VSU public port to your DSL or cable modem 2 Connect the private port of the SG5 security gateway to your hub or in the case of a single user to your workstation s Ethernet LAN connector For the SG5X security gateway connect the private port to your workstations or IP devices on your LAN If you re attaching IP telephones connect them to the private ports as well 3 Conn...

Page 22: ...22 Installing the security gateway March 2004 Avaya SG5 SG5X SG200 Security Gateway Hardware Installation Guide ...

Page 23: ...2 The security gateway setup consists of two basic steps Establishing connectivity between the workstations or IP devices on your local network with the security gateway s Private Port s Setting up the security gateway s Public Port to reach the Internet When the security gateway is initially installed and connected to your local LAN it is provisioned with a default IP address for the DHCP server ...

Page 24: ...he time the call is made The actual available bandwidth may vary significantly depending on the time of day the number of simultaneous users and also differs from ISP to ISP If the SG5X deployment is in a business environment such as a small office a Service Level Agreement SLA with the service provider can ensure business quality VoIP connections Up to eight IP telephones can be connected behind ...

Page 25: ...ick Setup collects and preconfigures the essential information required to remotely configure and manage the security gateway Note If the security gateway is to be configured and managed locally see the Security Gateway Configuration Guide for the VPNos to perform a comprehensive device configuration The Quick Setup wizard collects the necessary information to communicate with the remote VPNmanage...

Page 26: ...ty alert message The security gateway Login window is displayed Figure 8 Security gateway login screen 3 Enter the User name root and the Password enter password Click Log In 4 The first time you connect to the security gateway two sequential pop up messages appear over the main screen The first is a password change alert that advises you to change the factory default password Change the default p...

Page 27: ... static addressing on the public port click the Static Addressing radio button and enter your IP address network mask and default route information DHCP If you plan to use DHCP the public port automatically obtains its address from a DHCP server This method is typical for cable modem connections 7 Depending on the IP config mode selected complete the fields that populate the dialog For Static ente...

Page 28: ...uired to send updates from VPNmanager 9 In the Date Time area enter the date time and time zone A 24 hour clock is used For example 13 00 00 is equivalent to 1 00 PM 10 Click Save and then click Log Out from the main page to log of the Web interface NOTE When you use Log out you are prompted to save any unsaved changes before exiting If you close your browser unsaved changes are lost You now have ...

Page 29: ...r SG5 SG5X SG200 Dimensions 6 0 W x 5 0 D x 1 5 H 15 24 x 12 7 x 3 82cm 7 75 W x 6 5 D x 1 9 H 19 6 x 16 5 x 4 8 cm 7 75 W x 6 5 D x 2 5 H 19 6 x 16 5 x 6 4 cm Weight 10 ounces 283 5 grams 16 ounces 497 grams 16 ounces 497 grams LAN Interface One 10 100BASE T Ethernet port Seven 10 100BASE T Ethernet ports Two 10 100BASE T Ethernet ports Management Interfaces One 10 100BASE T Ethernet port One 10 ...

Page 30: ... non serviceable part Table 4 Environmental specifications Parameter Operating Specification Temperature 32 104 F 0 40 C Relative Humidity 5 90 non condensing Altitude 0 12 000 feet 0 3 660 meters Table 5 Electrical specifications Parameter SG5 SG5X SG200 AC Adapter Voltage 90 264 VAC 90 264 VAC 90 264 VAC Input Frequency 50 60 Hz 50 60 Hz 50 60 Hz AC input current 2 3A max 100 240VAC 2 3A max 100...

Page 31: ...et Protocol RFC 2402IP Authentication Header RFC 2403The Use of HMAC MD5 96 within ESP and AH RFC 2404The Use of HMAC SHA 1 96 within ESP and AH RFC 2405The ESP DES CBC Cipher Algorithm with Explicit IV RFC 2406 IP Encapsulating Security Payload RFC 2407Internet IP Security Domain of Interpretation for ISAKMP RFC 2408Internet Security Association and Key Management ISAKMP RFC 2409Internet Key Exch...

Page 32: ... 1 RFC 2104 Key Management IKE Internet Key Exchange RFC 2409 Digital Certificates The security gateway uses X 509v3 digital certificates for network management with SSL Network Address Translation Supports static and port mapping System Management Remote configuration via Java based VPNmanager configuration traffic secured through SSL Local configuration via Web based interface Remote configurati...

Page 33: ...cification 32 environmental requirements 15 environmental specification 30 equipment provided by Avaya 16 provided by customer 16 Ethernet ports 13 I IPSec standards 10 K key management specification 32 L LAN connections 21 log out 28 Login 26 N network zones table by security gateway 13 P Password 26 phone support 7 physical specification 29 plug and play installation 11 POST error codes 24 Power...

Page 34: ...ications 29 authentication 32 compliance 31 electrical 30 encryption 32 environmental 30 key management 32 physical 29 software upgrades 32 standards electromagnetic compatibility 3 System Requirements 16 T technical support 7 triple DES 10 W world wide web support 7 Z zones network type of 13 ...

Reviews: