background image

LANCOM

 OAP-321-3G

Scope of features: as of LCOS version 8.5x

URL blocker

Filtering of unwanted URLs based on DNS hitlists and wildcard filters. Extended functionality with Content Filter Option

Password protection

Password- protected configuration access can be set for each interface

Alerts

Alerts via e- mail, SNMP- Traps and SYSLOG

Authentication mechanisms

EAP- TLS, EAP- TTLS, PEAP, MS- CHAP, MS- CHAPv2 as EAP authentication mechanisms, PAP, CHAP, MS- CHAP and MS- CHAPv2 
as PPP authentication mechanisms

Network protection

Network protection via site verification by GPS positioning, device stops operating if ist location is changed.

WLAN protocol filters

Limitation of the allowed transfer protocols, source and target addresses on the WLAN interface

IP redirect

Fixed redirection of any packet received over the WLAN interface to a dedicated target address

High availability / redundancy

VRRP

VRRP (Virtual Router Redundancy Protocol) for backup in case of failure of a device or remote station. Enables passive standby 
groups or reciprocal backup between multiple active devices including load balancing and user definable backup priorities

FirmSafe

For completely safe software upgrades thanks to two stored firmware versions, incl. test mode for firmware updates

UMTS backup

In case of failure of the main connection, a backup connection is established over the internal UMTS modem; automatic return 
to the main connection

Load balancing

Static and dynamic load balancing over up to 2 WAN connections. Channel bundling with Multilink PPP (if supported by network 
operator)

VPN redundancy

Backup of VPN connections across different hierarchy levels, e.g. in case of failure of a central VPN concentrator and re- routing 
to multiple distributed remote sites. Any number of VPN remote sites can be defined (the tunnel limit applies only to active 
connections). Up to 32 alternative remote stations, each with its own routing tag, can be defined per VPN connection. Automatic 
selection may be sequential, or dependant on the last connection, or random (VPN load balancing)

Line monitoring

Line monitoring with LCP echo monitoring, dead- peer detection and up to 4 addresses for end- to- end monitoring with ICMP 
polling

VPN

IPSec over HTTPS

Enables IPsec VPN based on TCP (at port 443 like HTTPS) which can go through firewalls in networks where e. g. port 500 for 
IKE is blocked. Suitable for client- to- site connections (with LANCOM Advanced VPN Client 2.22 or later) and site- to- site 
connections (LANCOM VPN gateways or routers with LCOS 8.0 or later). IPSec over HTTPS is based on the NCP VPN Path Finder 
technology

Number of VPN tunnels

5 IPSec connections active simultaneously (25 with VPN- 25 Option), unlimited configurable connections. Configuration of all 
remote sites via one configuration entry when using the RAS user template or Proadaptive VPN. Max. total sum of concurrently 
active IPSec and PPTP tunnels: 5 (25 with VPN 25 Option) 

Hardware accelerator

Integrated hardware accelerator for 3DES/AES encryption and decryption

Realtime clock

Integrated buffered realtime clock to save the date and time during power failure. Assures timely validation of certificates in any 
case

Random number generator

Generates real random numbers in hardware, e. g. for improved key generation for certificates immediately after switching- on

1- Click- VPN Client assistant

One click function in LANconfig to create VPN client connections, incl. automatic profile creation for the LANCOM Advanced 
VPN Client

1- Click- VPN Site- to- Site

Creation of VPN connections between LANCOM routers via drag and drop in LANconfig

IKE

IPSec key exchange with Preshared Key or certificate

Certificates

X.509 digital multi- level certificate support, compatible with Microsoft Server / Enterprise Server and OpenSSL, upload of 
PKCS#12 files via HTTPS interface and LANconfig. Simultaneous support of multiple certification authorities with the 
management of up to nine parallel certificate hierarchies as containers (VPN- 1 to VPN- 9). Simplified addressing of individual 
certificates by the hierarchy's container name (VPN- 1 to VPN- 9). Wildcards for certificate checks of parts of the identity in the 
subject. Secure Key Storage protects a private key (PKCS#12) from theft

Certificate rollout

Automatic creation, rollout and renewal of certificates via SCEP (Simple Certificate Enrollment Protocol) per certificate hierarchy

Certificate revocation lists (CRL)

CRL retrieval via HTTP per certificate hierarchy

OCSP Client

Check X.509 certifications by using OCSP (Online Certificate Status Protocol) in real time as an alternative to CRLs

XAUTH

XAUTH client for registering LANCOM routers and access points at XAUTH servers incl. IKE- config mode. XAUTH server enables 
clients to register via XAUTH at LANCOM routers. Connection of the XAUTH server to RADIUS servers provides the central 
authentication of VPN- access with user name and password. Authentication of VPN- client access via XAUTH and RADIUS 
connection additionally by OTP token

RAS user template

Configuration of all VPN client connections in IKE ConfigMode via a single configuration entry

Proadaptive VPN

Automated configuration and dynamic creation of all necessary VPN and routing entries based on a default entry for site- to-
site connections. Propagation of dynamically learned routes via RIPv2 if required

Algorithms

3DES (168 bit), AES (128, 192 or 256 bit), Blowfish (128 bit), RSA (128 or - 448 bit) and CAST (128 bit). OpenSSL implementation 
with FIPS- 140 certified algorithms. MD- 5 or SHA- 1 hashes

NAT- Traversal

NAT- Traversal (NAT- T) support for VPN over routes without VPN passthrough

IPCOMP

VPN data compression based on LZS or Deflate compression for higher IPSec throughput 

Security

Содержание OAP-321-3G

Страница 1: ...cations via HSPA UMTS EDGE GPRS GPS positioning secures the device even for mobile applications IP 66 housing and extended temperature range from 33 to 70 VPN site to site connectivity with 5 simultan...

Страница 2: ...e LANCOM OAP 321 3G with its 5 simultaneous IPSec channels and high security encryption by 3 DES or AES provides optimal security for VPN connections Thanks to IPSec over HTTPS based on the NCP VPN Pa...

Страница 3: ...double tagging Multi SSID Simultaneous use of up to 8 independent WLAN networks per WLAN interface IGMP snooping Support for Internet Group Management Protocol IGMP in the WLAN bridge for WLAN SSIDs a...

Страница 4: ...n of a WLAN profile max 8 with individual access parameters depending on signal strength or priority UMTS modem Supported standards UMTS HSPA HSPA with up to 21 Mbps HSUPA with up to 5 76 Mbps Edge an...

Страница 5: ...emote sites via one configuration entry when using the RAS user template or Proadaptive VPN Max total sum of concurrently active IPSec and PPTP tunnels 5 25 with VPN 25 Option Hardware accelerator Int...

Страница 6: ...gory or domain or a combination of both Optional notification of the administrator in case of overrides Black whitelist Lists that are manually configured to explicitly allow whitelist or block blackl...

Страница 7: ...default LAN port configurable as WAN port WAN port 10 100 Mbps default WAN port configurable as LAN port External antenna connectors Four N connectors for external LANCOM AirLancer Extender antennas o...

Страница 8: ...s other devices from a LANCOM device with an interface to the target subnet if the LANCOM device can be reached at its command line interface TFTP HTTP S client For downloading firmware and configurat...

Страница 9: ...ter LANCOM Content Filter 25 user 1 year subscription LANCOM Content Filter LANCOM Content Filter 100 user 1 year subscription LANCOM Content Filter LANCOM Content Filter 10 user 3 year subscription L...

Страница 10: ...d 5 GHz to be integrated between Access Point and antenna item no 61553 Surge arrestor LAN cable AirLancer Extender SA LAN surge arrestor LAN cable item no 61213 Documentation LANCOM LCOS Reference Ma...

Отзывы: