background image

Section 1, System Description

NetVanta 2000 Series System Manual

12

© 2002 ADTRAN, Inc.

61200361L1-1E

1.

SYSTEM OVERVIEW

The NetVanta 2000 series of VPN products include small to mid-range IPSec compliant gateways 
providing all the necessary components required to secure an integrated VPN solution. Used primarily for 
remote access and site-to-multisite connectivity, the NetVanta 2050 and NetVanta 2100 targets the 
corporate branch office, the small office/home office (SOHO), as well as business-to-business 
applications. As a branch office or mid-size host security gateway, the NetVanta 2300 provides the same 
features as the NetVanta 2100 with an added DMZ port for public server access. For networks supporting a 
large VPN network, the NetVanta 2400 is available to provide all necessary host site gateway functionality. 
The NetVanta 2000 series provides several key security and data management features such as IPSec VPN 
tunneling, stateful inspection firewall (providing cyber assault protection), authenticated remote user 
access, and Network Address Translation. Adhering to IPSec standards (established and maintained by the 
IETF) enables the NetVanta 2000 series to be interoperable with many other IPSec compliant gateways, 
allowing for a multi-vendor VPN solution.

On a public infrastructure like the Internet, security is of the utmost importance. The NetVanta 2000 series 
protect the corporate network against attacks with a built in firewall and provides data security through 
encryption, authentication and key exchange. The NetVanta 2000 series employ a stateful inspection 
firewall that protects an organization's network from common cyber attacks including TCP syn-flooding, 
IP spoofing, ICMP redirect, land attacks, ping-of-death, and IP reassembly problems.

For encryption, the NetVanta 2000 series encrypt the data being sent out onto the network, using either the 
Data Encryption Standard (DES) or 3DES encryption algorithms. Data integrity is ensured using MD5 or 
SHA1 as it is transported across the public infrastructure. In addition, Internet Key Exchange (IKE) can be 
used for user authentication supporting public and private keys or digital certificates, assuring that the 
proper VPN tunnel is established and that the tunnel has not been redirected or compromised.

NetVanta 2000 series are Internet Protocol Security (IPSec) compliant devices that supports both ESP and 
AH protocols and provides secure communication over potentially unsecure network components. Acting 
as a security gateway, the NetVanta 2050 and 2100 can provide up to 10 private encryption communication 
tunnels through the Internet with remote locations while the larger scale NetVanta 2300 offers support for 
up to 100 private encryption tunnels. For networks requiring more than 100 tunnels, the NetVanta 2400 
provides 1000 private encryption tunnels. The NetVanta 2000 series can also hide IP addresses from the 
external world by performing Network Address Translation (NAT). The internal router allows multiple 
users to share a VPN connection and can also direct incoming IP traffic.

A remote NetVanta 2000 series can easily be configured and managed using a standard web browser. 
NetVanta 2000 series also have built-in alert and logging mechanisms for messaging and mail services. 
This enables the unit to warn administrators about activities that are going on in the network by logging 
them into a Syslog server or sending an email to the administrator.

Unlike a software implemented VPN solution, which depends on local CPU and memory performance to 
implement encryption, the NetVanta 2000 series are standalone, hardware platforms that off-load the CPU 
intensive encryption process. 3DES encryption significantly impacts CPU performance, possibly slowing 
all the local processes on the computer. Since the NetVanta 2000 series offers dedicated processing 
platforms to drive the encryption process, local computer performance is unaffected.

Содержание 1200361L1

Страница 1: ...NETVANTA 2000 SERIES System Manual 1200362L1 NetVanta 2050 System 1200361L1 NetVanta 2100 System 1200366L1 NetVanta 2300 System 1200367L1 NetVanta 2400 System 61200361L1 1E May 2002 ...

Страница 2: ...is manual are current as of the date of publication ADTRAN reserves the right to change the contents without prior notice In no event will ADTRAN be liable for any special incidental or consequential damages or for commercial losses even if ADTRAN has been advised thereof as a result of issue of this publication 901 Explorer Boulevard P O Box 140000 Huntsville AL 35814 4000 Phone 256 963 8000 2001...

Страница 3: ...Guidelines Provides information to assist network designers with incorporating the NetVanta 2000 series system into their networks Section 3 Network Turnup Procedure Provides step by step instructions on how to install the NetVanta 2000 series unit determine the parameters for the system install the network and option modules and power up the system Section 4 User Interface Guide A reference guide...

Страница 4: ...e during an electrical storm There is a remote risk of shock from lightning 3 Do not use the telephone to report a gas leak in the vicinity of the leak 4 Use only the power cord power supply and or batteries indicated in the manual Do not dispose of batteries in a fire They may explode Check with local codes for special disposal instructions Save These Important Safety Instructions Notes provide a...

Страница 5: ... harmful interference in which case the user will be required to correct the interference at his own expense Canadian Emissions Requirements This digital apparatus does not exceed the Class A limits for radio noise emissions from digital apparatus as set out in the interference causing equipment standard entitled Digital Apparatus ICES 003 of the Department of Communications Cet appareil numérique...

Страница 6: ...service in some situations Repairs to certified equipment should be made by an authorized Canadian maintenance facility designated by the supplier Any repairs or alterations made by the user to this equipment or equipment malfunctions may give the telecommunications company cause to request the user to disconnect the equipment Users should ensure for their own protection that the electrical ground...

Страница 7: ...ace any equipment to a condition as warranted Customer is entitled to a full refund of the purchase price upon return of the equipment to ADTRAN This warranty applies only to the original purchaser and is not transferable without ADTRAN s express written permission This warranty becomes null and void if Customer modifies or alters the equipment in any way other than as specifically authorized by A...

Страница 8: ... equipment currently in house or possible fees associated with repair Identify the RMA number clearly on the package below address and return to the following address Pre Sales Inquiries and Applications Support Your reseller should serve as the first point of contact for support If additional pre sales support is needed the ADTRAN Support web site provides a variety of support services such as a ...

Страница 9: ...s multiple types and levels of installation and maintenance services which allow you to choose the kind of assistance you need This support is available at For questions call the ACES Help Desk Training The Enterprise Network EN Technical Training Department offers training on our most popular products These courses include overviews on product features and functions while covering applications of...

Страница 10: ...NetVanta 2000 Series System Manual 2001 ADTRAN Inc ...

Страница 11: ...02 ADTRAN Inc 11 SYSTEM DESCRIPTION CONTENTS System Overview 12 Features and Benefits 13 Physical Interfaces 13 Firewall Features 13 Address Translation 13 IPSec Tunnel 13 Administration 13 DHCP 14 PPPoE 14 Routing 14 ...

Страница 12: ...either the Data Encryption Standard DES or 3DES encryption algorithms Data integrity is ensured using MD5 or SHA1 as it is transported across the public infrastructure In addition Internet Key Exchange IKE can be used for user authentication supporting public and private keys or digital certificates assuring that the proper VPN tunnel is established and that the tunnel has not been redirected or c...

Страница 13: ...ensing ethernet interface Firewall Features Stateful inspection firewall Application content filtering Cyber assault protection HTTP relay Address Translation Basic NAT 1 1 NAPT Many 1 Reverse NAT translation of an inbound session s destination IP address IPSec Tunnel Encapsulating Security Payload ESP Authentication Header AH Manual key management or automatic key management using Internet Key Ex...

Страница 14: ...TRAN Inc 61200361L1 1E DHCP Server to manage IP addresses on local network Client to acquire the WAN side IP address from service provider PPPoE Client to acquire the WAN side IP address from service provider Routing TCP IP Static routes RIP V1 and V2 RIP with Authentication ...

Страница 15: ...erface 21 Power Connection 21 At A Glance Specifications 22 FIGURES Figure 1 NetVanta 2000 series Front Panel Layout 16 Figure 2 NetVanta 2300 Front Panel Layout 17 Figure 3 NetVanta 2000 series Rear Panel Layout 18 Figure 4 NetVanta 2300 Rear Panel Layout 19 TABLES Table 1 NetVanta 2000 series Front Panel Description 17 Table 2 NetVanta 2000 series LEDs 17 Table 3 LAN Pinout 19 Table 5 DMZ Pinout...

Страница 16: ...POWER REQUIREMENTS NetVanta 2050 and 2100 The NetVanta 2000 series has a maximum power consumption of 9W and a maximum current draw of 800mA NetVanta 2300 and 2400 The NetVanta 2300 has a maximum power consumption of 11W and a maximum current draw of 0 2A 3 REVIEWING THE FRONT PANEL DESIGN NetVanta 2050 The NetVanta 2100 front panel monitors operation by providing status LEDs for both the LAN and ...

Страница 17: ...fic The front panel is shown in Figure 3 Figure 3 NetVanta 2300 Front Panel Layout NetVanta 2400 The NetVanta 2300 front panel monitors operation by providing status LEDs for the LAN WAN and DMZ interfaces as well as VPN tunnels and traffic Additionally a LCD display provides quick glance access to the LAN IP parameters IP address and subnet mask The front panel is shown in Figure 4 Figure 4 NetVa...

Страница 18: ...received by the NetVanta LAN LNK 2300 2400 Only Indicates active physical link on the LAN port WAN TD Indicates WAN traffic transmitted by the NetVanta WAN RD Indicates WAN traffic received by the NetVanta WAN LNK 2300 2400 Only Indicates active physical link on the WAN port Table 2 NetVanta 2000 series LEDs For these LEDs This color light Indicates that PWR Red solid The unit has power and is in ...

Страница 19: ...lashes with VPN data received by the NetVanta 2000 series LAN TD Green blink Flashes with data transmitted on the LAN interface LAN RD Green blink Flashes with data received on the LAN interface LAN LNK 2300 2400 Only Green solid Unit has active physical connection on the LAN interface WAN TD Green blink Flashes with data transmitted on the WAN interface WAN RD Green blink Flashes with data receiv...

Страница 20: ...ta 2400 Rear Panel Layout LAN Interface The NetVanta 2000 series provides a standard 10 100BaseT Ethernet interface for connection to the local corporate network Connect the LAN interface to a hub located on your local corporate network A DHCP Server is enabled on the LAN interface by default References to the LAN interface include LAN CORP and Eth0 The LAN connection follows and Table 3 shows the...

Отзывы: