Manuale d’uso / di manutenzione del prodotto 2+ del fabbricante Compatible Systems
Vai alla pagina of 75
IntraPort 2 and Intr aPort 2+ VPN Access Server Administrator ’ s Guide Compatib le Syst ems Corpor ation 4730 W al n ut S treet Suite 1 02 Boulde r , Colorado 803 01 303- 444- 9532 800- 356- 0283 http://www .
IntraPort 2 and In traPort 2+ VPN Access Server Administrator’ s Guid e, Ve r s i o n 1 . 5 Copyri ght © 1999, C ompatible Systems C orporation All rights reserved. IntraPort, RISC Rou ter, Micro Router and Comp ati- V iew are trademarks of Compatible System s Corporation.
i Chapter 1 - Introduction 1 A BOU T THE I NTRA P ORT 2/2+ VPN A CCESS S ERV ER 1 A N OTE A BOUT R EMOTE C LIENT C ONNEC TIONS 1 I NTRA P ORT 2/2+ VPN A CC ESS S ERVER I NSTA LLATI ON O VERVI EW 1 Cha.
ii Chapter 6 - Basic Configuration Gu id e 19 S ETUP O PTIONS 19 Diagra m of Dual- Ether net Setup 20 Diagra m of Sing le-Eth erne t Set up 21 C ONFIGURATION U SING C OMPATI V IEW 22 VPN Client Tunnel.
iii Appendix B - Connector and Cable Pin Outs 58 Pin Outs fo r DB-25 Ma le to DB-25 Female RS-23 2 Data & Consol e Cable 58 Appendix C - Securi ty Dynamics ACE/Server Information 59 Appendix D - L.
iv.
Cha pter 1 - I n tr odu ctio n 1 Chapter 1 - Introduction About the IntraPort 2/2+ VPN Access Server Congratul ations on y our purchas e of the Intr aPort 2 or I ntraPort 2+ VPN Access Server. These VPN Access Servers pro vide secure Internet-based remo te access and site-to-site connections .
2 Cha pter 1 - In tr odu ctio n In shor t, the installation steps are: 1. Install the IntraPo rt 2 or I ntraPort 2+ har dware on your Ethernet LAN and connect one or both of the 10/100 twisted-pair Ethernet interfaces to a Fast Ethernet or Ethernet h ub.
Cha pter 1 - I n tr odu ctio n 3 Alternate Protocols an d Security Parameters This part of the manual lists configuratio n parameters that must be set in order to use the In traP ort 2/2+ VP N Access Serv er with pro tocol s other than TCP/IP , and when u sing additional security p arameters such as SecurID and RADIUS.
..
Chapter 2 - Getting St arted 5 Chapter 2 - Getting Started A Few Notes Please Read the Manuals The manuals included with your IntraPort 2/2+ VPN Access Server contain v ery importan t information about the pr oduct and V irtual Private Netwo rking in gener al.
6 Chapter 2 - Getting St arted questions via e-mail to s upport@compa tible.com. Compatible Systems ’ phone number is listed on the front of this g uide.
Chapter 2 - Getting St arted 7 Ethernet Conne ction Requirements The server ’ s Ethernet interfaces di rectly support full or half duplex 100BaseTx or 10BaseT twisted-p air Ethernet.
..
Chapter 3 - Network Installatio n 9 Chapter 3 - Network Installation Figure 1. IntraPor t 2/2+ VP N Acces s Server Back Pa nel This secti on of the manu al describes ho w to connect the IntraPort 2/2+ VPN Access Server to your Ethernet network. In summary , the steps for installation are: 1.
10 Chapter 3 - Network Installation The other op tion is to set up the server behind your Internet access router/firewall using Ethernet 0 only . In this scenario, Ethernet 1 is not used and shou ld not be plugged in to anyth ing.
Chapter 4 - CompatiVie w Software Installation 11 Chapter 4 - CompatiView Software Installation All of the products in the Com pat ible S ystems networking fam ily , including all IntraPor t servers, RISC Router and MicroRouter models, can be managed from a single m anagement plat form called CompatiV iew .
v Note: T o choo se t h e acti ve t rans po rt pr ot ocol o n a W indows mach ine which has both IPX and IP insta lled, s elect “Options” from the Databas e menu and cli ck the Genera l tab. Th en select the ap pr o- priate r adio bu tton under “T r ansport.
Chapter 4 - CompatiVie w Software Installation 13 two mos t common IPX f rame types upon start up (802.2 and 802.3 (raw)). If C ompatiV iew has the IPX/SPX protocol selected as its trans- port, it wil.
..
Chapter 5 - Comm and Line Management 15 Chapter 5 - Command Line Management The command line interface allows you to configure and mon itor the server in-b and via T elnet or out-of-band with a term inal connected to the server ’ s Console interface.
Temporaril y Reconfig uring a Host for Co mmand Lin e Manage ment Y o u can temporarily reconf igure an IP host in order to s et the server ’ s IP parameters to allow in-band T elnet access.
Chapter 5 - Comm and Line Management 17 command line interf ace, do the following: A. Use th e config ur e command and set the IP Addr es s , Sub- netMask , and IPBroa dcast keyw ords in the IP Ethernet 0 s ection. B. Use the save co mmand to save the changes to the dev ice ’ s Flash ROM.
..
Chapter 6 - Basic Configurat ion Guide 19 Chapter 6 - Basic Configuration Guide This chapter prov ides a step-by-step ou tline of the minimum required parameters which must be co nfigured int o the device for proper opera- tion.
20 Chapter 6 - Basic Configuration Guid e Diagram of Dua l-Ethernet Setup Figure 2. Diagram of Dual-Eth er net Set up.
Chapter 6 - Basic Configurat ion Guide 21 Diagram of Sing le -Et hernet Setu p Figure 3. D iagram o f Single E thernet S etup.
22 Chapter 6 - Basic Configuration Guid e Configuration Using CompatiView This section provides a list of parameter s th at m us t be entere d into a server for proper operati on using CompatiV iew , Co mpatible Systems ’ management software.
Chapter 6 - Basic Configurat ion Guide 23 2. Set basic IP parameter s for Ethernet 0. Du al Eth ernet Singl e Ethernet TCP/IP Rou ting: Ether net 0 To access this dialog box, select TCP/IP Routing under Ethernet 0 in the Device View. A. Click the IP Routing radio butt on.
24 Chapter 6 - Basic Configuration Guid e 3. (Dual Ethernet ) Set basic IP paramet ers for Ethernet 1. TCP/IP Rou ting: Ether net 1 T o access this dialog box, s elect TCP/IP Routing under Ether net 1 in the Device V iew . A. Click the IP On radio but ton.
Chapter 6 - Basic Configurat ion Guide 25 4. Set an IP Gateway for Et hernet 0. IP Stati c Routes T o access the IP St atic Routes dialog box, select IP S tatic Routes under Global in the Device V iew . A. Click the Add... butt on. The S tatic Route dialog box w ill appear: Dual Et hernet St atic R oute S ingle E thernet St atic Route B.
26 Chapter 6 - Basic Configuration Guid e Leave all other parameters at their defaul t settings for basic configurat ion, or refer to the CompatiV iew Management Soft- w a re Re f e re n c e G u i d e for more advanced configuration s et- tings.
Chapter 6 - Basic Configurat ion Guide 27 5. Set an IPSec Gateway. IPSec Gate way T o access this dialog box, s elect IPSec Gateway under Global in the Device V iew . A. For dual Ethernet setups, the IPSec Gateway is the equ ivalent of a default gateway for the IPSec interface (Ethernet 1).
28 Chapter 6 - Basic Configuration Guid e 6. Set an IKE Policy. There are two ph ases to the IKE negotiation. During Phase 1 negotia- tion, the IntraPort and C lient must authenticate each o ther . Th e IKE Policy di alog box cont rols t his P hase 1 n e go tiati on .
Chapter 6 - Basic Configurat ion Guide 29 7. Set up VPN Group Configur ations. VPN Group Configu ration: G eneral T ab T o access this dialog box, s elect VPN Group Configuration in the Device V iew . A. Cli ck on the New ... butt on. B. Enter a New VPN Group Config Name (e.
30 Chapter 6 - Basic Configuration Guid e without receiving any traf fic from a client belonging to this VP N Group Confi guration w ithout ending the tunnel sessio n. • Set the Minimu m Clien t V ersion or keep the de fault value. This places a limit on the VPN Client Software ver- sion numb er which wi ll be allowed to connect.
Chapter 6 - Basic Configurat ion Guide 31 IKE Conf igurat ion Transform List The default settings of MD5 for Authentication and DES for Encryption are adequate for mos t setups. Click OK . • In the IKE Key Manag ement d ialo g bo x, yo u may click on the PFS checkbox to add additional security param e ter s durin g tunnel sessions.
32 Chapter 6 - Basic Configuration Guid e Dual Ethe rnet VPN Group C onfiguration : IP Con nection T ab Single Ethernet VPN Gro up Configu ration: IP Connecti on T ab F . On the IP Conn ection T ab: • Enter the St a r t I P A d d r e s s . This specifies the first IP address to be assigned to clien t sessions under this co nfig- uration.
Chapter 6 - Basic Configurat ion Guide 33 same network as Eth ernet 0 or a subinterf ace thereof). Also, they cannot conflict with thos e used for any other VPN Groups.
34 Chapter 6 - Basic Configuration Guid e VPN G roup Confi guration : IPX Connection T ab H. If you will be tunneling IPX traffic, click the IPX Connection Ta b . • Enter an IPX network number in t he S tart IPX Network edit box. This IPX network number is the first IPX address assi gned to an incoming Cl ient tunnel session.
Chapter 6 - Basic Configurat ion Guide 35 8. Set up VPN Users. If you are using a RADIUS server for user authen tication, you will need to set up VPN users on that se rver .
36 Chapter 6 - Basic Configuration Guid e sent. This secret is used for VPN us ing IKE Key Manag ement. The same secret mus t also be entered into the VPN Client for the tunnel sessio n to be successful. v Note: STEP/ST AMP is Compatible System ’ s pr oprietary tunn el nego- tiation pr otocol .
Chapter 6 - Basic Configurat ion Guide 37 Configu ring the S erve r for LAN-to -LAN Tunne ls This section configures VPN tu nnel parameters and defi nes a virtual por t for LAN-to-LAN tunn el traffic.
38 Chapter 6 - Basic Configuration Guid e C. I f you a re us ing both E thern et po rts, t hen the Bin d T o interface should be set to Ethernet 1. For si ngle Ethernet setups, it should be Ethern et 0. This specifies which interf ace on this device will act as the end point for the tunnels defin ed by this configuration.
Chapter 6 - Basic Configurat ion Guide 39 will only initiate tu nnel establish ment atte mpts and w ill not resp on d to t h em. If Respond is selected, this T unnel Partner will use IKE, but will only re spond to tun nel establishmen t attempts and wi ll not initiate them.
40 Chapter 6 - Basic Configuration Guid e 4. Save the configu ration to a file and download to th e device. A. From the File menu choose Save T o > File. This will bring up a file sav e dialog box . Name the device configuration fi le, making su re that yo u asso ciate the file nam e with the Intr aPort 2/2+ and can find the file later .
Chapter 6 - Basic Configurat ion Guide 41 Basic Configuration Using Co mmand Line This section briefly discus ses th e major parameters that must be s e t in order to use the IntraPort 2/2+ VPN Access.
42 Chapter 6 - Basic Configuration Guid e 2. Set basic IP parameter s for Ethernet 0. This will be the internal TCP/IP address ing inform ation you have assigned to the I ntraPort 2/2+ Use configure and set the IP A ddress , SubnetMas k , and IPBroadc ast keyword s in the IP Ethernet 0 section.
Chapter 6 - Basic Configurat ion Guide 43 4. Set an IP Gateway for Et hernet 0. For dual Ethernet setu ps, this is th e internal T CP/I P addr ess of your firewa ll or proxy , whichever is applicable . For single Eth ernet setups , this is the interna l TCP/IP address of your upstream In ternet access/firewalling router .
44 Chapter 6 - Basic Configuration Guid e 5. Set an IPSec Gateway. For dual Ethernet setup s, the IPSec Gateway is the equivalent of a default gateway for the IPSec interface (Ethernet 1). Enter the TCP/IP address of the upst ream or Intern et router for your netw ork.
Chapter 6 - Basic Configurat ion Guide 45 7. Set up VPN Group Configur ations. This is w here tunnelin g profiles for a group of one or more I ntraPort 2/2+ u ser s a re de f ine d.
46 Chapter 6 - Basic Configuration Guid e Ethernet example, 1 92.168.233.0/2 4), all traff ic from a client going to the internal network will b e tunneled through the IntraPort 2/2+. This is the most common configuration . There can be multiple entries, inclu ding individual addresses (i.
Chapter 6 - Basic Configurat ion Guide 47 8. Set up VPN Users. Users are added to the configuration by entering a few unique parame- ters, and each is assigned to a VPN Group Configu ration, co nfigu red in the previous step. Use edit config to s et th e pa ram eter s in the VP N Use r s section.
48 Chapter 6 - Basic Configuration Guid e Configu ring the S erve r for LAN-to -LAN Tunne ls This section configures VPN tu nnel parameters and defi nes a virtual por t for LAN-to-LAN tunn el traffic.
Chapter 6 - Basic Configurat ion Guide 49 If Ma nual is specified, this T unnel Partner will not use IKE, and the tu nnel ’ s encr yption and authentication par ameters must be manually set i n the Manual Key Management dialog box, which is not desc ribed here.
50 Chapter 7 - Alternate Protocols an d Security Parameters Chapter 7 - Alternate Protocols and Security Parameters This chapter briefly discusses the configuratio n of th e Intr aPo rt 2/2+ VPN Access Server for App leT alk and IPX, and with RADIUS and SecurID authentication server s.
Chapter 7 - Alternate P rotocols and Security Pa rameters 51 AppleTalk Protoco l Required for AppleTalk Generally , there ar e no required ch anges from th e shipping Et hernet configuration for AppleT alk. The Ethernet interface will autoconfig ure to use AppleT alk Phase 2, and will adapt to conditions on the Ethernet.
52 Chapter 7 - Alternate Protocols an d Security Parameters RADIUS Server User Authe ntication Settings In order f or client authentication and accounting to be done on a RADIUS server , the RADIUS server must be configured with fo ur pieces of data for each user .
Chapter 7 - Alternate P rotocols and Security Pa rameters 53 attribute setting s will r equire that you enter users in the Users text file. See the user manual for your server for mor e information on exporting, editing and importin g the Users text file.
54 Chapter 7 - Alternate Protocols an d Security Parameters Setti ng the Int raP o r t for an ACE/S erver Just a few basic s ettings are required fo r the IntraPort to com municate with an ACE/Server .
Chapter 7 - Alternate P rotocols and Security Pa rameters 55 Saving a Configuration File to Flash ROM Once a configur ation is complete, you can save it to the router ’ s Fl a s h ROM. Until saved, all change s are made in a separa te buf fer and the serve r ’ s interfaces co ntinue to run as befo re the changes were mad e.
..
Appendix A - Shipp ing Defaults 57 Appendix A - Shipping Defaults Ethernet Interfaces Default Pass word • letmein IP Defaults • Ether net 0 is on • Addr ess : 19 8.
58 Appendix B - Connector and Cable Pin Outs Appendix B - Connector and Cable Pin Outs Pin Outs for DB-25 Male to DB-25 Female RS-232 Data & Console Cable The cable supplied with the IntraPor t 2/2+ VPN Access Server is 25 conduct ors connected st raight through .
Appendix C - Security Dynamics ACE/Server Infor mation 59 Appendix C - Security Dynamics ACE/Server Information ACE/Server s oftware and SecurID tokens can be purchas ed directly from Security Dyn amics T echnologies, Inc. Use the fo llowing informa- tion to contact Security Dynamics fo r more information: Security Dynamics T echnologies, Inc.
..
Appendix D - LED Patterns an d Test Switch Settings 61 Appendix D - LED Patterns and Test Switch Settings IntraPort 2/2+ VPN Ac cess Server s LED Patterns Ethernet Back Panel Indicators LEDs The Intra.
62 Appendix D - LED Patterns and Test Switch Settings IntraPort 2 Connections/Users LEDs IntraPort 2+ Connections/Users LEDs Connections/Users LED User Range 11 - 5 66 - 1 1 12 12 - 17 18 18 - 23 24 2.
Appendix D - LED Patterns an d Test Switch Settings 63 IntraPort 2 Special Indicators IntraPort 2+ Special Indica tors IntraPort 2/2+ VPN Ac cess Server Switch Settings v Note: Settings marked with an a sterisk may era se your Flash R OM. Please do not u se these settings wi thout first cont acting Com patible Systems T echnical Support.
..
Appendix E - Downloading Software From Compatible Systems 65 Appendix E - Downloading Software From Compatible Systems The latest versions of operating sof twar e for all Compatib le Systems products are available at our W eb site. The latest ver sion of CompatiV iew management s oftware is als o available.
..
Appendix F - T erms and Conditions 67 Appendix F - Terms and Condition s Compatible S ys tem s Corporation (Com patible Systems) offers to sell only on the condition that Cu sto mer ’ s acceptance is expres sly limited to Compat- ible Systems ’ terms and condit ions of sale.
THE W ARRANTIES SET FOR TH IN THESE TERMS AND CONDI- TIONS ARE IN LIE U OF ALL OTHER W ARRANTIES, EXPRESSED OR IMPLIED. WITHOUT LIMIT A TION ON THE GENERALITY OF THE FOREGOING SENTENCE, COMP A TIBLE SYSTEMS EXPRESSL Y DISCLAIMS AND EXCLUDES ALL IMPLIED W ARRANTIES OF MERCHANTIBILITY AND OF FITNESS (GENERALL Y OR FOR A P AR TICULAR PURPOSE).
Appendix F - T erms and Conditions 69 appropriate, of the s ubsequent purchaser). I N NO EVENT SHALL COM- P A TIBLE SYSTEMS BE LIABLE FOR ANY SPECIAL, CONSEQUEN- TIAL, OR INCIDENT AL DAMAGES ARISING O.
Un punto importante, dopo l’acquisto del dispositivo (o anche prima di acquisto) è quello di leggere il manuale. Dobbiamo farlo per diversi motivi semplici:
Se non hai ancora comprato il Compatible Systems 2+ è un buon momento per familiarizzare con i dati di base del prodotto. Prime consultare le pagine iniziali del manuale d’uso, che si trova al di sopra. Dovresti trovare lì i dati tecnici più importanti del Compatible Systems 2+ - in questo modo è possibile verificare se l’apparecchio soddisfa le tue esigenze. Esplorando le pagine segenti del manuali d’uso Compatible Systems 2+ imparerai tutte le caratteristiche del prodotto e le informazioni sul suo funzionamento. Le informazioni sul Compatible Systems 2+ ti aiuteranno sicuramente a prendere una decisione relativa all’acquisto.
In una situazione in cui hai già il Compatible Systems 2+, ma non hai ancora letto il manuale d’uso, dovresti farlo per le ragioni sopra descritte. Saprai quindi se hai correttamente usato le funzioni disponibili, e se hai commesso errori che possono ridurre la durata di vita del Compatible Systems 2+.
Tuttavia, uno dei ruoli più importanti per l’utente svolti dal manuale d’uso è quello di aiutare a risolvere i problemi con il Compatible Systems 2+. Quasi sempre, ci troverai Troubleshooting, cioè i guasti più frequenti e malfunzionamenti del dispositivo Compatible Systems 2+ insieme con le istruzioni su come risolverli. Anche se non si riesci a risolvere il problema, il manuale d’uso ti mostrerà il percorso di ulteriori procedimenti – il contatto con il centro servizio clienti o il servizio più vicino.