background image

 670-100-101

Issue 1

June 2003

Avaya™ SG203 and SG208
Security Gateway 
Hardware Installation Guide

Summary of Contents for SG208

Page 1: ...670 100 101 Issue 1 June 2003 Avaya SG203 and SG208 Security Gateway Hardware Installation Guide ...

Page 2: ...quipment that could be accessed via this Avaya product that is networked equipment An outside party is anyone who is not a corporate employee agent subcontractor or is not working on your company s behalf Whereas a malicious party is anyone including someone who may be otherwise authorized who accesses your telecommunications equipment with either malicious or mischievous intent Such intrusions ma...

Page 3: ...oltage Dips and Variations IEC 61000 4 11 Powerline Harmonics IEC 61000 3 2 Voltage Fluctuations and Flicker IEC 61000 3 3 Federal Communications Commission Statement Part 15 Canadian Department of Communications DOC Interference Information This Class A digital apparatus complies with Canadian ICES 003 Cet appareil numérique de la classe A est conforme à la norme NMB 003 du Canada This equipment ...

Page 4: ...cable Copies of these Declarations of Conformity DoCs can be obtained by contacting your local sales representative and are available on the following Web site http www avaya com support Japan This is a Class A product based on the standard of the Voluntary Control Council for Interference by Information Technology Equipment VCCI If this equipment is used in a domestic environment radio disturbanc...

Page 5: ... SG208 Security Gateway 15 Site requirements 15 Environmental requirements 15 Site power considerations 15 Equipment requirements 16 Physical installation 16 Required tools 17 Safety recommendations 17 Desktop 17 Rackmount 18 Overview of front panel 19 Console port 19 Multi interface ports 20 Connecting the SG203 SG208 security gateway to the network 20 Chapter 3 Setting up the security gateway fo...

Page 6: ...6 Avaya SG203 SG208 Security Gateway Hardware Installation Guide ...

Page 7: ...y Contacting Technical Support Technical support is available to registered users of the Avaya security gateway products Domestic support Toll free phone support 866 462 8292 24x7 Email vpnsupport avaya com Web http www support avaya com International support For regional support numbers go to http www avayanetwork com site GSO defaut htm Documentation The security gateway documentation includes b...

Page 8: ...8 Preface Issue 1 June 2003 Avaya SG203 SG208 Security Gateway Hardware Installation Guide ...

Page 9: ...way devices They are designed to provide the high capacity scalability and reliability required by your networks for IPSec firewall services in one unit or multiple units for enterprise headquarter locations requiring a rack mountable device The security gateway is easy to configure and can either be managed locally from the Web interface or remotely using Avaya VPNmanager ...

Page 10: ...ork The security gateway sits behind an edge router and has auto detecting ethernet interfaces on the public and private ports The security gateway s primary function is to perform IPSec and firewall security services to protect enterprise networks and to secure data being sent over shared IP networks The security gateway establishes an Internet Key Exchange IKE protocol session with its IPSec pee...

Page 11: ...algorithms and keys powerful enough for the most sensitive business communications to provide data stream privacy It supports DES and Triple DES and AES encryption as well as the ISAKMP key management standard Table 1 Additional features Parameter Specification Encryption DES Triple DES and AES hardware encryption DES uses a 56 bit key Triple DES uses three 56 bit independent keys for an effective...

Page 12: ...he additional packet overhead imposes a performance penalty in return for security The extra bytes tend to lengthen packets and reduce the throughput measured in packets per second The overhead depends on the IPSec policy and could be up to 63 bytes Table 2 SG203 208 performance specifications Plug and Play installation The auto sensing interfaces of the security gateway enables installation into ...

Page 13: ...redentials The quick set up guides the network administrator through the minimal network configuration Hardware components Each of the major components are shown in Figure 2 and Figure 3 Figure 2 Front panel Figure 3 Back panel Expansion slot Public port Private port Console RS 232 port Multi interface ports Ethernet activity indicator Ethernet0 Ethernet1 Ethernet2 3 Expansion slot Power and On Of...

Page 14: ...t3 are software configurable and can be used for fail over DMZ or other functions Each Ethernet port has status indication LEDs that show whether the link is active Parameter SG203 SG208 Dimensions 17 W x 18 5 D x 1 75 H 46 9cm x 43 1cm x 4 4cm 17 W x 18 5 D x 1 75 H 46 9cm x 43 1cm x 4 4cm Weight 17 pounds 7 7 Kilograms 17 pounds 7 7 Kilograms LAN Interface Four 10 100 Base T Ethernet Four 10 100...

Page 15: ...ation and operation of the security gateway Ensure that your site is properly prepared before beginning installation Environmental requirements The security gateway devices are intended for use in a normal office environment For more extreme conditions verify that temperature humidity and power conditions meet the following specifications Temperature range 32 to 104 F 0 to 40 C Relative humidity 5...

Page 16: ...talled with a Java enabled JDK1 1 8 or later 128 bit encryption capable browser either Internet Explorer 5 5 or later or Netscape 6 2 or later Physical installation The security gateway can be placed on a desktop or mounted in a rack It is easy to install and requires a screwdriver for rack mounted devices Voltage 100 240 VAC Input frequency 47 63 Hz AC input current 3 5 Amps 1 ea Security Gateway...

Page 17: ...ter installation Keep the ventilation gratings clear of any blockages Do not rest equipment in excess of 10 pounds on top of the chassis Disconnect all power before mounting or unmounting a unit from an equipment rack Never assume power is disconnected from a circuit always check Circuit Breaker 15A Warning WARNING This product relies on the building s installation for short circuit overcurrent pr...

Page 18: ...ation Enclosed racks must have adequate ventilation Ensure that the rack is not overly congested because each unit generates heat An enclosed rack should have louvered sides and a fan to provide cooling air When mounting a chassis in an open rack ensure that the rack frame does not block the ventilation grates If the chassis is installed on slides check the position of the chassis when it is seate...

Page 19: ...tion from an asynchronous ASCII terminal or a PC running terminal emulation software The connection requires a null modem cable which is supplied The communication settings for a device interfacing with the console port are provided in Table 5 Table 5 Terminal settings Public port Private port Ethernet port Status Indicators Console port Multi interface ports Expansion slot Parameter Setting Baud ...

Page 20: ...le when connecting to a router and uses a straight through cable when connecting to a hub or switch The SG208 can use any type of cable crossover or straight through when connecting to a hub switch or router NOTE To realize maximum performance when operating at the 1000 Base T rate it is necessary to use CAT5e cables shipped with the device Standard CAT5 cables are not rated for full Gigabit data ...

Page 21: ...1 Connect one end of the Cat5e cable to the public port Ethernet1 on the security gateway Connect the other end to the router s Ethernet port ethernet connector on the DSL or the cable modem For the SG203 use the crossover cable Figure 6 See Multi interface ports on page 20 about using Cat5e cables Public Network DSU CSU Router SG203 Private LAN Crossover Cable DSU CSU Router SG208 Private LAN ...

Page 22: ...ort Ethernet0 on the security gateway Connect the other end to the LAN hub or switch Note A crossover cable is required if the SG203 security gateway is connected directly to a workstation 3 Connect the power cable to the security gateway and then plug it in to an AC outlet 4 Power on the security gateway and proceed to Chapter 3 Setting up the security gateway for configuration The following are ...

Page 23: ...he instructions provided in Chapter 2 Installing SG203 and SG208 Security Gateway The security gateway quick setup consists of two basic steps 1 Establishing connectivity between a workstation or IP device on your local network with the security gateway s private port 2 Setting up the security gateway s public port to reach the Internet Through the Web interface you can assign a static IP address ...

Page 24: ...on Guide for the VPNos to perform a comprehensive device configuration The Quick Setup wizard collects the necessary information to communicate with the remote VPNmanager application through the security gateway s public port The following information is required to complete the quick setup The type of addressing to be used on the security gateway s public port either Static IP Addressing Dynamic ...

Page 25: ...ord Click Log In when it is highlighted 4 The first time you connect to the security gateway two sequential pop up messages appear over the main screen The first is a password change alert that advises you to change the factory default password Change the default password to a secure password 5 The next alert message indicates that the security gateway has not yet been configured Click OK to launc...

Page 26: ... the Static Addressing radio button and enter your IP address network mask and default route information DHCP If you plan to use DHCP the public port automatically obtains its address from a DHCP server This method is typical for cable modem connections PPPoE This method is typically used with DSL connections Click the PPPoE radio button and enter your PPPoE user name and password 7 Depending on t...

Page 27: ... 1 00 PM 10 Click Save and then click Log Out from the main page to log of the Web interface NOTE When you use Log out you are prompted to save any unsaved changes before exiting If you close your browser unsaved changes are lost You now have entered enough information to allow the security gateway to be accessed over the Internet The remaining configuration process can be completed remotely using...

Page 28: ...28 Setting up the security gateway for configuration Issue 1 June 2003 Avaya SG203 SG208 Security Gateway Hardware Installation Guide ...

Page 29: ...ngs 22 DES 11 documentation 7 E electrical specifications 16 electromagnetic compatibility standards 3 email support 7 encryption specification 11 environmental requirements 15 equipment provided by Avaya 16 provided by customer 16 H hardware components 13 humidity specification 15 I installation desktop 16 rackmount 16 IPSec standards 11 L log out 27 P password 25 performance 12 performance speci...

Page 30: ... safety recommendations 17 security 11 SHA1 11 specifications authentication 11 encryption 11 key management 11 standards electromagnetic compatibility 3 T technical support 7 temperature range 15 tools rackmount 17 triple DES 11 U user authentication 11 W warranty 2 world wide web support 7 ...

Reviews: