A
CCESS
G
ATEWAY
22
Introduction
As part of Nomadix’ commitment to provide outstanding carrier-class network management
capabilities to its family of public access gateways, we offer secure management through the
NSE’s standards-driven, peer-to-peer IPSec tunneling with strong data encryption. Establishing
the IPSec tunnel not only allows for the secure management of the Nomadix gateway using any
preferred management protocol, but also the secure management of third party devices (for
example, WLAN Access Points and 802.3 switches) on private subnets on the subscriber side
of the Nomadix gateway. See also,
“Defining IPSec Tunnel Settings” on page 188
.
Two subsequent events drive the secure management function of the Nomadix gateway and the
devices behind it:
1.
Establishing an IPSec tunnel to a centralized IPSec termination server (for example, Nortel
Contivity). As part of the session establishment process, key tunnel parameters are
exchanged (for example, Hash Algorithm, Security Association Lifetimes, etc.).
2.
The exchange of management traffic, either originating at the NOC or from the edge
device through the IPSec tunnel. Alternatively, AAA data such as RADIUS
Authentication and Accounting traffic can be sent through the IPSec tunnel. See also,
“RADIUS-driven Auto Configuration” on page 20
.
The advantage of using IPSec is that all types of management traffic are supported, including
the following typical examples:
ICMP - PING from NOC to edge devices
Telnet - Telnet from NOC to edge devices
Web Management - HTTP access from NOC to edge devices
SNMP
SNMP GET from NOC to subscriber-side device (for example, AP)
SNMP SET from NOC to subscriber-side device (for example, AP)
SNMP Trap from subscriber-side device (for example, AP) to NOC
Secure Socket Layer (SSL)
This feature allows for the creation of an end-to-end encrypted link between your NSE-
powered product and wireless clients by enabling the Internal Web Server (IWS) to display
pages under a secure link—important when transmitting AAA information in a wireless
network when using RADIUS.
SSL requires service providers to obtain digital certificates to create HTTPS pages.
Instructions for obtaining certificates are provided by Nomadix.
Содержание Access Gateway
Страница 1: ......
Страница 12: ...ACCESS GATEWAY xii ...
Страница 51: ...ACCESS GATEWAY Introduction 39 ...
Страница 84: ...ACCESS GATEWAY 72 Installing the Access Gateway ...
Страница 90: ...ACCESS GATEWAY 78 Installing the Access Gateway ...
Страница 95: ...ACCESS GATEWAY System Administration 83 ...
Страница 96: ...ACCESS GATEWAY 84 System Administration ...
Страница 146: ...ACCESS GATEWAY 134 System Administration ...
Страница 161: ...ACCESS GATEWAY System Administration 149 ...
Страница 185: ...ACCESS GATEWAY System Administration 173 ...
Страница 205: ...ACCESS GATEWAY System Administration 193 The Network Interfaces screen appears ...
Страница 275: ...ACCESS GATEWAY System Administration 263 5 Repeat Steps 1 3 for page 3 of 3 see following screen ...
Страница 310: ...ACCESS GATEWAY 298 The Subscriber Interface ...
Страница 376: ...This page intentionally left blank ACCESS GATEWAY 364 Troubleshooting ...
Страница 378: ...This page intentionally left blank ACCESS GATEWAY 366 ...