
A
CCESS
G
ATEWAY
Introduction
20
Two subsequent events drive the secure management function of the Nomadix gateway and the devices
behind it:
1.
Establishing an IPSec tunnel to a centralized IPSec termination server (for example, Nortel Contivity). As
part of the session establishment process, key tunnel parameters are exchanged (for example, Hash
Algorithm, Security Association Lifetimes, etc.).
2.
The exchange of management traffic, originating either at the NOC or from the edge device through the
IPSec tunnel. Alternatively, AAA data such as RADIUS Authentication and Accounting traffic can be
sent through the IPSec tunnel. See also
on page 18.
The advantage of using IPSec is that all types of management traffic are supported, including the following
typical examples:
ICMP - PING from NOC to edge devices
Telnet - Telnet from NOC to edge devices
Web Management - HTTP access from NOC to edge devices
SNMP
SNMP GET from NOC to subscriber-side device (for example, AP)
SNMP SET from NOC to subscriber-side device (for example, AP)
SNMP Trap from subscriber-side device (for example, AP) to NOC
Secure Socket Layer (SSL)
This feature allows for the creation of an end-to-end encrypted link between your NSE- powered product and
wireless clients by enabling the Internal Web Server (IWS) to display pages under a secure link—important
when transmitting AAA information in a wireless network when using RADIUS.
SSL requires service providers to obtain digital certificates to create HTTPS pages. Instructions for obtaining
certificates are provided by Nomadix.
Secure XML API
XML (Extensible Markup Language) is used by the subscriber management module for user administration.
The XML interface allows the NSE to accept and process XML commands from an external source. XML
commands are sent over the network to your NSE-powered product which executes the commands, and
returns data to the system that initiated the command request. XML enables solution providers to customize
and enhance their product installations.
This feature allows the operator to use Nomadix' popular XML API using the built-in SSL certificate
functionality in the NSE so that parameters passed between the Gateway and the centralized Web server are
secured via SSL.
f you plan to implement XML for external billing, please contact technical
support for the XML specification of your product. Refer to Contact
Information on page 268.
Session Rate Limiting (SRL)
Session Rate Limiting (SRL) significantly reduces the risk of “Denial of Service” attacks by allowing
administrators to limit the number sessions any one user can take over a given time period and, if necessary,
then block malicious users.
Содержание AG 2300
Страница 1: ......
Страница 184: ...ACCESS GATEWAY 172 System Administration...
Страница 294: ...ACCESS GATEWAY 282 Glossary of Terms...