Intel NetStructure 7110/7115 e-Commerce Accelerator
Version
 Copyright
Trademarks
 Table of Contents
 Theory of Operation
 Scenarios
 Remote Management
 Alarms and Monitoring
 Troubleshooting Appendix a Front Panel
 List of Figures
 Xii
 Introduction
About this User Guide
 New in This Release
Remote Management
 Who Should Use this Book
Before You Begin
 How to Use this Book
 Glossary defines terms appearing in this User Guide
Page
 Installation and Initial Configuration
 Installing the 7110/7115 Free- Standing or in a Rack
Rack Installation
 Free-Standing Installation
Network Connections
 Network and Server LEDs
Admin Terminal Connection
Status Check
Inline LED
 HyperTerminal§ Paste Operations
 Server and Network LEDs
Troubleshooting
Continuing Configuration
 Single Server Acceleration
Theory of Operation
Security
 7110/7115 in Single Server Configuration
Multiple Servers
 Working with Internet Traffic Management ITM Devices
Positioning 7110/7115 between ITM Device and Client Network
 Spilling and Throttling
Positioning 7110/7115 between ITM Device and Server
Scalability and Cascading
 Keys and Certificates
Availability
 Cutting and Pasting with HyperTerminal§
 Create a Certificate Signing Request
Procedure
Create a key Type the create key command at the prompt
Intel 7115 create sign
 Asciix Enter
Certificate REQUEST----- lines
Intel 7115 export sign mywebserver
 Typically, the CSR will look something like this
Enter
 Apache Interface to Open SSL§ modssl
Save the configuration when the server has been mapped
Exporting a Key/Certificate from a Server
 Apache SSL§
 Intel 7115 import key mywebserver
Stronghold§
Importing into the 7110/7115
 Save the configuration when the server has been mapped
 Create a key as follows
Enter the create cert command with the keyID
Creating a new Key/Certificate on the 7110/7115
Intel 7115 create cert mywebserver
 Global Site Certificates
Overview
 Intel 7115 import cert keyID
Global Site Certificate Paste Procedure
Example
 A P T E R Redirection Clients and Unsupported Ciphers
Intel 7115 set redirect
 Intel 7115 show redirect
Client Authentication
To disable a redirect URL for a mapping
Intel 7115 set redirect 2 none Intel 7115 show redirect
 Next, import the client CA certificate for Map ID
Intel 7115 import clientca
 Generate a certificate signing request
Creating a Client CA Certificate using OpenSSL§
Generate the client CA certificate
 Automapping
SSL Processing
Mapping
 Deleting automapping entries
Automapping with user-specified key and certificate
Automapping with multiple port combinations
Manual mapping
 Use the show block command to verify
Combining automapping and manual mapping
 Use show block to verify
Subnet IP, Specific Port
All IPs, Specific Port
 Intel 7115 delete block
Use the show block command to confirm the block
Delete a Block
 Failure Conditions, Fail-safe, and Fail-through
 Scenarios
 Syntax
 Scenario 1-Single Server
Procedure for Scenario
Manual Configuration
 Intel 7115delete map 1 Intel 7115list maps
 This scenario shows how to configure two or more servers
Scenario 2-Multiple Servers
 ID KeyID
 Scenario 3-Multiple 7110/ 7115s, Cascaded
Assumptions
 Intel 7115 export config
Multiple Cascaded 7110/7115s
 After verification y or refusal n, the prompt reappears
Save the configuration
Intel 7115 import config
 To reverse this process
Intel 7115set egressmac none
 Command Reference
Online Help
 Command Line Prompt
Command Line Interface
User Authentication
Abbreviation to Uniqueness
 A P T E R Command Line Interface
 Moving the Insertion Point
Input Editing Commands
Command History
 Cut and Paste
 Command Summary
 Inline List
Command Command Options Import
Nic Password Reboot
 Command Command Options Set
 Command Command Options Show
 Status
Setsnmp
Showsnmp
Ttychar
 Status Command
Command Reference
Help Commands
 Delete key
SSL Commands
Command Description Create key
Import key
 List keys
Command Description Export key
Show key
 Import cert
Command Description Create cert
Delete cert
Export cert
 Displays all certificates
Command Description Show cert
Display the expanded certificate including PEM format
Set ciphers
 Show clientca
Command Description Set redirect
Show redirect
 Create sign
Command Description Import clientca
Delete clientca
 Show sign keyID
Command Description Delete sign
Export sign
 Display the default certificate creation information
Command Description Set defcert
Issuer e-mail address. You can change all, some or none
Field
 Set clienttmo
Command Description Set kstrength
Show kstrength
Show clienttmo
 Client request is rejected
Command Description Set servertmo
Displays the currently specified server timeout value
Show servertmo
 Delete block
Port Mapping Commands
Command Definition Create block
Show block
 Show permit
Command Definition Create permit
Delete permit
 Show map
Command Definition Create map
Delete map mapID
List maps
 Inline
Operational Commands
Command Description Bypass
 Command Description Set spill
Show spill
 Maxremotesessions
Remote Management Commands
Command Description Set ip
 Set telnetport
Command Description Set telnet
Show telnet
 Show ssh
Command Description Show telnetport
Set ssh
Set sshport
 Setsnmp snmpinfo
Command Description Setsnmp snmp
Showsnmp snmp
 Delete Snmp community strings
CommandDescription
Snmpcommunity
 List trapcommunity
Command Description Setsnmp trapauthen
Trapcommunity
 Delete trapcommunity Delete Snmp trap community strings
Intel 7115 delete trapcommunity
 Show alarms
Alarms and Monitoring Commands
Command Description Set alarms
Set rscwindow
 Set utlhighwater
Command Description Show rscwindow
Set utlwindow
 Show utlhighwater
Command Description Set utllowwater
Show utlwindow
Show utllowwater
 CommandDescription Show ovlwindow
Intel 7115 show ovlwindow
 Display current volatile configuration settings
Configuration Commands
Command Description Show config
 Intel 7115 show config default Default configuration
 Config default
Command Description Config compare
Config reset
Config save
 Import config
Command Description Export config
Configuration specifics are displayed
Import a configuration file paste, xmodem, uudecode
 List system
Command Description Import upgrade
Import patch
 Command Description Factorydefault
Returns to factory configuration settings
 Show info
Administration Commands
Command Description Password
Set date
 Show ether
Command Description Set egressmac
Set ether
Set idleto
 Set prompt
Command Description Set more
Nic
Set serial
 Command Description
Logging Commands
Command Description Show serial
Exit
 All deletes all logs
Command Description Delete log
Delete saved log/trace files from /flash/logs
List logs
 Remote Management
Overview
 Remote Management CLI Commands
Limitations
 A P T E R Overview
 Remote Telnet Sessions
Local Serial Console
 To display the Telnet port
Remote Console, Telnet
Changing the Telnet Port
Unix-prompttelnet
 Remote SSh Sessions
To verify Telnet disable
Enable remote SSh sessions
Disabling Telnet
 Remote Console, SSh
Unix-promptssh -1 admin
Passwordpassword
Changing the SSh Port
 Disabling SSh
To verify SSh disable
Intel 7115 set ssh disable
To display the SSh port
 Standards Compliance
Intel MIB Tree
 Management Information Base-II MIB-II Intel Enterprise MIBs
Where to find MIB Files
Supported MIBs
Ceo-header.my
 Enterprise Private MIB Summary
Following is a summary of the 7110/7115 private MIB
Page
 Snmp
 ThrottlesPerSec Number of throttles per second
 Snmp
 Private Traps in ssl-appliance-mib.my
Trap Summary
Standard Snmp Traps
 Enabling Snmp
Intel 7115 setsnmp snmp enable Intel 7115 showsnmp snmp
Intel 7115 setsnmp snmp disable Intel 7115 showsnmp snmp
 Specifying Snmp Information
Intel 7115 showsnmp snmpinfo
 Community String
Intel 7115 delete snmpcommunity
 Use CLI commands, setsnmp trapcommunity, list
Trap Community String
 Access Control
Page
 Alarms Monitoring
 CLI commands for alarm configuration are
Set alarms All, esc, rsc, utl, ovl, nls None Show alarms
 Alarm Modifiers and Messages
Alarm Types
ESC Encryption Status Change Alarm
For example
 RSC Refused SSL Connections
RSC Alarm CLI Commands
To set Overload Alarm time window
Extended Data
 This alarm monitors three utilization threshold values
UTL Utilization Threshold Alarm
To display Overload Alarm time window
Intel 7115 set rscwindow Intel 7115 show rscwindow
 To set Utilization Threshold Alarm high-water value
UTL Alarm CLI commands
To set Utilization Threshold Alarm time window
To set Utilization Threshold Alarm low-water value
 Intel 7115 set ovlwindow seconds Range
OVL Overload Alarm
OVL Alarm CLI Commands
Intel 7115 set ovlwindow Intel 7115 show ovlwindow
 Alarm Logging
NLS Network Link Status Alarm
 Intel 7115 status
 Respend Inline
 Ip 10.1.11.34 netmask
 Example, status alarms command
Intel 7115 status alarms
 Monitoring Reports
Report Configuration
Monitoring
Monitor report format
 Monitoring Reports CLI Commands
Intel 7115 set monitoringfields
 Intel 7115 set monitoring enable Intel 7115 show monitoring
Intel 7115 show monitoringfields
Page
 Software Updates
 Intel 7115 import upgrade
Using Windows§ HyperTerminal§
Press y for yes at the Continue with upgrade? prompt
 Command import patch
Connect the serial cable to the 7110/7115 auxiliary console
 To send the uuencoded file use the ~ command
Intel 7115import upgrade
 Intel 7115import patch
Page
 Troubleshooting
 Intel 7115 set clienttmo
 Error message Intermediate
See Global Site Certificates
 Then use the nic command to force
Error message Server
Settings
Different media
 Front Panel
LEDs
 Front Panel LEDs
Buttons and Switches
Press to physically force bypass mode bypass 7110/7115
Processing
 See Appendix B, Failure
Overload
 Connectors
 Enable 7110/7115 processing
Failure/Bypass Modes
 Fail-through Switch Security Level
Bypass Button
 P E N D I X B Fail-through Switch Security Level
Page
 Supported Ciphers
Cipher Strength
 SSL Version Level
 RC4-64 SSLv2
RC2 SSLv2
RC2128
RC464
Page
 Regulatory Information
Taiwan Class a EMI Statement
 Vcci Statement
FCC Part 15 Compliance Statement
 Canada Compliance Statement Industry Canada
CE Compliance Statement
 Cispr 22 Statement
Vcci Class a Japan Australia
 Avertissement
 Warnung
 Advertencias
 Wichtige Sicherheitshinweise
 Wichtige Sicherheitshinweise
Page
 Terms and Conditions and Software License
END User Terms and Conditions of Sale and Software License
Page
 P E N D I X E
Page
 Year warranty
 Process of being installed
 Export Law Regulations
Page
 Glossary
 Glossary-2
 Glossary-3
 Glossary-4
 North America only
Support Services
Worldwide Access to Technical Support
Japan only
 Support-2
 Intel NetStructure 7110/7115 e-Commerce Accelerator User
 Support-4
 Index
 D E
 Index-3
 Index-4