Manuals
/
Nokia
/
Cell Phone
/
Cell Phone
Nokia
IPSO 4.0
manual
Nokia Network Voyager For Ipso Reference Guide
Models:
IPSO 4.0
1
1
510
510
Download
510 pages
5.58 Kb
1
2
3
4
5
6
7
8
<
>
Troubleshooting
Install
Error messages
Password
Preference Default
Configuring RIP Timers
Interface Status Indicators
Cluster Administrator Users
Configuring System Functions
Managing Security and Access
Page 1
Image 1
Nokia Network Voyager
for IPSO 4.0
Reference Guide
Part No. N451818001 Rev A
Published October 2005
Page 2
Page 1
Image 1
Page 2
Contents
Nokia Network Voyager For Ipso Reference Guide
Restricted Rights Legend
Nokia Network Voyager for Ipso 4.0 Reference Guide
Https//support.nokia.com Tac.support@nokia.com
Nokia Network Voyager for Ipso 4.0 Reference Guide
Contents
Nokia Network Voyager Ipso 4.0 Reference Guide
Configuring System Functions
Nokia Network Voyager Ipso 4.0 Reference Guide
Virtual Router Redundancy Protocol Vrrp
Configuring Clustering
Nokia Network Voyager Ipso 4.0 Reference Guide
Configuring IPv6
Configuring Snmp
Managing Security and Access
Configuring Routing
Nokia Network Voyager Ipso 4.0 Reference Guide
Nokia Network Voyager Ipso 4.0 Reference Guide
Configuring Traffic Management
Monitoring System Configuration and Hardware
Configuring Router Services
Index
About the Nokia Network Voyager Reference Guide
About the Nokia Network Voyager Reference Guide
Text Conventions
Conventions This Guide Uses
Text Conventions
Convention Description
Menu Items
Related Documentation
Nokia Network Voyager for Ipso 4.0 Reference Guide
Software Overview
Logging Off
Logging In to Network Voyager
To open Nokia Network Voyager
To log in with exclusive configuration lock
Obtaining a Configuration Lock
To log in without exclusive configuration lock
To override a configuration lock
Navigating in Network Voyager
Accessing Documentation and Help
Reloading Pages
To clear the memory and disk cache
To open a new window to view help
Nokia support site https//support.nokia.com
To view the asset management summary
Viewing Hardware and Software Information for Your System
Interface Overview
Configuring Interfaces
IP2250 Management Ports
Configuring Network Devices
Type Prefix
Physical Interface Logical Interface
Configuring IP Addresses
Interface Status
Interface Status Indicators
Configuring Tunnel Interfaces
Indicator Description
Physical Interface Configuration Parameters
Configuring Ethernet Interfaces
Ethernet Interfaces
Parameter Description
Link Aggregation
To configure an Ethernet interface
Configuring Switches for Link Aggregation
Managing Link Aggregation Using Snmp
Link Aggregation on the IP2250
Static Link Aggregation
Firewall Synchronization Traffic
Production Traffic ADP I/O Ports Only
Configuring the Remaining Management Ports
Physical Interface Configuration
Configuring Link Aggregation
To set up link aggregation in Network Voyager
To physically configure the interfaces you will aggregate
To configure link aggregation groups
Group Configuration
Gigabit Ethernet Interfaces
Logical Configuration
Deleting Aggregation Groups
Gigabit Ethernet Interface Parameters
MTU
To configure a Gigabit Ethernet interface
To configure PPPoE
Configuring PPPoE
Point-to-Point Over Ethernet
Nokia Network Voyager for Ipso 4.0 Reference Guide
To delete configuration profiles
To change configuration profiles
To create PPPoE logical interfaces
To delete PPPoE logical interfaces
Virtual LAN Interfaces
Configuring MSS Clamping
To delete a Vlan Interface
To configure a Vlan Interface
To define the maximum number of VLANs
Vlan Example Topology
Fddi Interfaces
To configure an Fddi Interface
To change the IP address of an Fddi interface
To change the duplex setting of an Fddi interface
Isdn Interfaces
To configure an Isdn physical interface
To configure an Isdn logical interface to place calls
Nokia Network Voyager for Ipso 4.0 Reference Guide
Nokia Network Voyager for Ipso 4.0 Reference Guide
To configure an Isdn interface to receive calls
To add an incoming number
Configuring Calling Line-Identification Screening
To remove an incoming number
To configure an interface to place and receive calls
Dial-on-Demand Routing DDR Lists
To delete a DDR list
To create a DDR list
To add a new rule to a DDR list
To modify a rule
Example DDR List
To apply or remove a DDR list to/from an interface
Isdn Network Configuration Example
To configure the IP650 to handle an incoming call
To configure the IP330 to place an outgoing call
Sample Call Traces
Trace for connecting a call from the Nokia IP330 is
Logging
Isdn Troubleshooting
To set level of messages logged
To view the message log
To trace Isdn traffic using tcpdump
Troubleshooting Cause Codes
Tracing
Isdn Cause Code Fields
Isdn Cause Values
Cause Cause Description Diagnostics
Cause Values
See Isdn Cause Values table
Information-element identifiers is missing
Value Description
Isdn Bearer-Capable Values
Token Ring Interfaces
To configure a Token Ring interface
To change a Token Ring interface
To deactivate a Token Ring interface
Token Ring Example
Fddi
Point-to-Point Link over ATM
To configure an ATM interface
To change the VPI/VCI of an ATM interface
To change the IP MTU of an ATM interface
To change the IP Address of an ATM interface
Fddi
ATM Example
To configure an ATM logical IP subnet LIS interface
To configure the ATM interface on Nokia Platform a
IP over ATM IPoA
To change the VPI/VCIs of an ATM LIS Interface
To change the IP Address of an ATM LIS interface
ATM
IPoA Example
Serial V.35 and X.21 Interfaces
To configure a serial interface for Cisco Hdlc
To configure a Serial Interface for PPP
To configure a serial interface for frame relay
Nokia Network Voyager for Ipso 4.0 Reference Guide
Serial Interface Example
To configure a T1 Interface for Cisco Hdlc
To configure the serial interface on Nokia Platform a
T1with Built-In CSU/DSU Interfaces
Nokia Network Voyager for Ipso 4.0 Reference Guide
To configure a T1 Interface for PPP
Nokia Network Voyager for Ipso 4.0 Reference Guide
To configure a T1 interface for frame relay
Nokia Network Voyager for Ipso 4.0 Reference Guide
T1 Interface Example
To configure the serial interface on Nokia Platform a
E1 with Built-In CSU/DSU Interfaces
To configure an E1 interface for Cisco Hdlc
Nokia Network Voyager for Ipso 4.0 Reference Guide
To configure an E1 interface for PPP
Nokia Network Voyager for Ipso 4.0 Reference Guide
100
To configure an E1 interface for frame relay
Nokia Network Voyager for Ipso 4.0 Reference Guide 101
102
Hssi Interfaces
To configure an Hssi interface for Cisco Hdlc
Nokia Network Voyager for Ipso 4.0 Reference Guide 103
104
To configure an Hssi interface for PPP
Nokia Network Voyager for Ipso 4.0 Reference Guide 105
To configure an Hssi interface for frame relay
106
To configure an unnumbered interface
Configuring Unnumbered Interfaces
Unnumbered Interfaces
Nokia Network Voyager for Ipso 4.0 Reference Guide 107
108
To change an unnumbered interface to a numbered interface
Nokia Network Voyager for Ipso 4.0 Reference Guide 109
To configure a static route over an unnumbered interface
Ospf over Unnumbered Interfaces Using Virtual Links
Configuring Ospf over Unnumbered Interface
110
To change the keepalive interval for Cisco Hdlc
Cisco Hdlc Protocol
Nokia Network Voyager for Ipso 4.0 Reference Guide 111
To change the IP address in Cisco Hdlc
Point-to-Point Protocol
To change the keepalive interval in PPP
112
To change the IP address in PPP
To change the keepalive maximum failures in PPP
Nokia Network Voyager for Ipso 4.0 Reference Guide 113
To change the keepalive interval in frame relay
Frame Relay Protocol
To change the Dlci in frame relay
114
To change the interface type in frame relay
To change the LMI parameters in frame relay
Nokia Network Voyager for Ipso 4.0 Reference Guide 115
To change the IP address in frame relay
To change the active status monitor setting in frame relay
To remove a frame relay interface
116
To add an IP Address to a Loopback Interface
Loopback Interfaces
To change the IP Address of a loopback interface
Nokia Network Voyager for Ipso 4.0 Reference Guide 117
GRE Tunnels
Configuring GRE Tunnels
To create a GRE tunnel
118
Nokia Network Voyager for Ipso 4.0 Reference Guide 119
120
To change IP TOS value of a GRE tunnel
Nokia Network Voyager for Ipso 4.0 Reference Guide 121
GRE Tunnel Example
HA GRE Tunnel Example
High Availability GRE Tunnels
122
Nokia Network Voyager for Ipso 4.0 Reference Guide 123
124
To create a Dvmrp tunnel
Dvmrp Tunnels
Nokia Network Voyager for Ipso 4.0 Reference Guide 125
To change the local or remote addresses of a Dvmrp tunnel
Dvmrp Tunnel Example
126
Nokia Network Voyager for Ipso 4.0 Reference Guide 127
To change ARP global parameters
ARP Table Entries
128
To add a proxy ARP entry
To add a static ARP entry
Nokia Network Voyager for Ipso 4.0 Reference Guide 129
Configuring ARP for ATM Interfaces
To delete a static ATM ARP entry
To add a static ATM ARP entry
To view and delete dynamic ATM ARP entries
Nokia Network Voyager for Ipso 4.0 Reference Guide 131
Limitations
Transparent Mode
132
Nokia Network Voyager for Ipso 4.0 Reference Guide 133
Transparent Mode Processing Details
134
Configuring Transparent Mode in VPN Environments
Nokia Network Voyager for Ipso 4.0 Reference Guide 135
Example of Transparent Mode
136
Configuring Transparent Mode
To create a transparent mode group
Creating and Deleting Transparent Mode Groups
To delete a transparent mode group
Nokia Network Voyager for Ipso 4.0 Reference Guide 137
To enable or disable a transparent mode group
Enabling or Disabling a Transparent Mode Group
138
Transparent Mode and Check Point NGX
Monitoring Transparent Mode Groups
Enabling or Disabling Vrrp for a Transparent Mode Group
Configuring Antispoofing
Unnumbered VTIs
Virtual Tunnel Interfaces Fwvpn for Route-Based VPN
Routing Traffic through the VTI
140
Nokia Network Voyager for Ipso 4.0 Reference Guide 141
Vrrp Support
Creating Virtual Tunnel Interfaces
To create a virtual tunnel interface
To create the VPN community
Nokia Network Voyager for Ipso 4.0 Reference Guide 143
144
To create the virtual tunnel interface
Nokia Network Voyager for Ipso 4.0 Reference Guide 145
Configuring Dhcp
Dhcp Client Configuration
Configuring Dhcp Client Interfaces
To configure the Dhcp client interface
To enable the Dhcp client process
To configure the Dhcp server process
Configuring the Dhcp Server
Nokia Network Voyager for Ipso 4.0 Reference Guide 147
To enable the Dhcp server process
Dhcp Server Configuration
148
To disable the Dhcp server process
Changing Dhcp Service
To change the Dhcp service
Adding Dhcp Address Pools
Enabling or Disabling Dhcp Address Pools
To enable and existing IP address pool
Assigning a Fixed-IP Address to a Client
To assign a fixed-IP address to a client
Nokia Network Voyager for Ipso 4.0 Reference Guide 151
Creating Dhcp Client Templates
152
Configuring Dynamic Domain Name System Zones
Configuring Dynamic Domain Name System Service
To configure Dynamic Domain Name System Ddns
Nokia Network Voyager for Ipso 4.0 Reference Guide 153
Configuring Disk Mirroring
Configuring the Domain Name Service
To configure DNS
To create a mirror set
To delete a mirror set
Using an Optional Disk Flash-Based Systems Only
Nokia Network Voyager for Ipso 4.0 Reference Guide 155
To configure the system to store log files on the PC card
To install and configure PC card flash memory
Mail Relay
To remove an optional disk
To configure failure notification
Configuring Mail Relay
To configure mail relay for your firewall
System Failure Notification
Sending Mail
Setting the System Time
To send mail from the firewall
158
To set system time once
Configuring Host Addresses
To add a static host entry
Nokia Network Voyager for Ipso 4.0 Reference Guide 159
Configuring Logging on Disk-Based Systems
Configuring System Logging
Accepting Log Messages
Logging to a Remote System
To send syslog messages to a remote system
Configuring Logging on Flash-Based Systems
Nokia Network Voyager for Ipso 4.0 Reference Guide 161
162
Configuring Logging to Remote Log Servers
Configuring Logging to an Optional Disk
Configuring Audit Logs
Nokia Network Voyager for Ipso 4.0 Reference Guide 163
164
To set the system configuration audit log
Nokia Network Voyager for Ipso 4.0 Reference Guide 165
Remote Core Dump Server on Flash-Based Systems
Changing the Hostname
Managing Configuration Sets
To change the hostname
166
To switch a currently active database
To create a factory default configuration file
To delete unwanted configuration database files
Scheduling Jobs
To delete scheduled jobs
Backing Up and Restoring Files
168
To create a backup file manually
Creating Backup Files
To delete local backup files
Nokia Network Voyager for Ipso 4.0 Reference Guide 169
Configuring Automatic Transfers
Transferring Backup Files
To configure scheduled backups
To cancel a regularly scheduled backup
To manually transfer archive files to a remote server
Transferring Backup Files Manually
Nokia Network Voyager for Ipso 4.0 Reference Guide 171
To restore files
Restoring Files from Locally Stored Backup Files
172
Changing Current Image
Managing Nokia Ipso Images
Deleting Images
To select a new current image
To delete an Nokia Ipso image
Installing New Images
174
To test an image before activating it
Testing a New Image
Nokia Network Voyager for Ipso 4.0 Reference Guide 175
Upgrading Nokia Ipso Images for a Cluster
Rebooting a Cluster
Downgrading Nokia Ipso Images
176
Nokia Network Voyager for Ipso 4.0 Reference Guide 177
Configuring Monitor Reports
Managing Packages
Installing and Enabling Packages
Restrictions for Flash-Based Platforms
Monitor Report Parameters
Nokia Network Voyager for Ipso 4.0 Reference Guide 179
To install a package
Tuning the TCP/IP Stack
Advanced System Tuning
To enable or disable a package
To delete a package
To set the TCP MSS
Router Alert IP Option
Nokia Network Voyager for Ipso 4.0 Reference Guide 181
182
How Vrrp Works
Vrrp Overview
Nokia Network Voyager for Ipso 4.0 Reference Guide 183
184
Simple Vrrp Configuration
Vrrp Configuration with Simultaneous Backup
Vrrp Configuration with Internal and External VRIDs
Understanding Monitored-Circuit Vrrp
Configuring Vrrp
186
Priority
Selecting Configuration Parameters
Nokia Network Voyager for Ipso 4.0 Reference Guide 187
Hello Interval
Authentication
188
Priority Delta
Backup Address
Nokia Network Voyager for Ipso 4.0 Reference Guide 189
190
Vmac Mode
Vrrp Configuration Parameters
Global Vrrp Settings
Before you Begin
Nokia Network Voyager for Ipso 4.0 Reference Guide 191
192
Configuring Monitored-Circuit Vrrp
Nokia Network Voyager for Ipso 4.0 Reference Guide 193
To add a virtual router
To change the configuration of an existing virtual router
Configuring Monitored-Circuit Vrrp using the Full Method
To delete a virtual router
194
Nokia Network Voyager for Ipso 4.0 Reference Guide 195
Additional Vrrp Parameters Used in Full Method
To add or back up a virtual router using VRRPv2
Configuring VRRPv2
196
Nokia Network Voyager for Ipso 4.0 Reference Guide 197
Configuring Check Point NGX for Vrrp
198
Configure settings under the 3rd party configuration tab
Configuration Rule for Check Point NGX FP1
Configuring Vrrp Rules for Check Point NGX
Nokia Network Voyager for Ipso 4.0 Reference Guide 199
Configuring Rules if You Are Using Ospf or Dvmrp
Configuration Rules for Check Point NGX FP2 and Later
Source Destination Service Action
200
Monitoring Vrrp
CLI commands for Vrrp
Link Aggregation IP2250 Systems Only
State
Stats
Location
202
General Configuration Considerations
Troubleshooting Vrrp
To enable or disable Monitor Firewall state
To enable traces for Vrrp
Firewall Policies
Access Control Lists
204
Monitored-Circuit Vrrp in Switched Environments
Switched Environments
VRRPv2 in Switched Environments
Nokia Network Voyager for Ipso 4.0 Reference Guide 205
206
IP Clustering Description
Using Flash-Based Platforms
Nokia Network Voyager for Ipso 4.0 Reference Guide 207
208
Example Cluster
Nokia Network Voyager for Ipso 4.0 Reference Guide 209
Cluster Management
210
Cluster Terminology
Nokia Network Voyager for Ipso 4.0 Reference Guide 211
Cluster member a cluster node that is not the master
212
Clustering Modes
Nokia Network Voyager for Ipso 4.0 Reference Guide 213
Network Environment
Considerations for Clustering
214
Nokia Network Voyager for Ipso 4.0 Reference Guide 215
Other Considerations
216
Clustering IP2250 Platforms
Nokia Network Voyager for Ipso 4.0 Reference Guide 217
Upgrading Ipso in a Cluster
Upgrading from Ipso 3.7 or Later
For All Upgrades
Upgrading from Ipso
218
Nokia Network Voyager for Ipso 4.0 Reference Guide 219
Enabling Cluster Management
Configuration Overview
Creating and Configuring a Cluster
To create and configure a cluster
Creating a Cluster
Configuring the Work Assignment Method
Selecting the Cluster Mode
Nokia Network Voyager for Ipso 4.0 Reference Guide 221
To include an interface in the cluster
Configuring an Interface
222
Supporting Non-Check Point Gateways and Clients
Configuring Firewall Monitoring
Nokia Network Voyager for Ipso 4.0 Reference Guide 223
Using IP Pools
Configuring VPN Tunnels
224
Nokia Network Voyager for Ipso 4.0 Reference Guide 225
Using IP Pools When Only Check Point Gateways Are Involved
Configuring IP pools in Cluster Voyager
Configuring Join-Time Shared Features
226
What if Settings Conflict?
What is Sharable?
Nokia Network Voyager for Ipso 4.0 Reference Guide 227
228
Configuring Features for Sharing
Making the Cluster Active
Adding a Node to a Cluster
After You Create a Cluster
Nokia Network Voyager for Ipso 4.0 Reference Guide 229
230
Recommended Procedure
Joining a System to a Cluster
Managing a Cluster
Nokia Network Voyager for Ipso 4.0 Reference Guide 231
To start Cluster Voyager
Using Cluster Voyager
232
Cluster Administrator Users
If You Forget the cadmin Password
Nokia Network Voyager for Ipso 4.0 Reference Guide 233
Configuring the Performance Rating
Configuring the Failure Interval
Monitoring a Cluster
234
Nokia Network Voyager for Ipso 4.0 Reference Guide 235
Managing Join-Time Shared Features
236
Installing Ipso Images
Nokia Network Voyager for Ipso 4.0 Reference Guide 237
238
Removing a Node from a Cluster
Deleting a Cluster Configuration
Changing Cluster Interface Configurations
Synchronizing the Time on Cluster Nodes
Assigning the Time Zone
NTP Server Outside the Cluster
Configuring NTP
240
Using the Master Node as the NTP Server
Configuring NGX for Clustering
Nokia Network Voyager for Ipso 4.0 Reference Guide 241
242
Nokia Network Voyager for Ipso 4.0 Reference Guide 243
Clustering Example Three Nodes
244
Configuring the Cluster in Voyager
Nokia Network Voyager for Ipso 4.0 Reference Guide 245
Configuring the Internal and External Routers
246
Clustering Example With Non-Check Point VPN
Nokia Network Voyager for Ipso 4.0 Reference Guide 247
248
Nokia Network Voyager for Ipso 4.0 Reference Guide 249
Snmp Overview
Source Function
250
UDP-MIB
Nokia Network Voyager for Ipso 4.0 Reference Guide 251
252
Snmp Proxy Support for Check Point MIB
Using cpsnmpstart
Using the Check Point MIB
Nokia Network Voyager for Ipso 4.0 Reference Guide 253
Enabling Snmp and Selecting the Version
To enable or disable Snmp
254
Setting an Agent Address
Configuring the System for Snmp
To set an Snmp agent address
Nokia Network Voyager for Ipso 4.0 Reference Guide 255
Types of Snmp Traps
Configuring Traps
256
Type of Trap Description
Nokia Network Voyager for Ipso 4.0 Reference Guide 257
258
Setting the Trap PDU Agent Address
Configuring Trap Receivers
Enabling or Disabling Trap Types
Configuring Location and Contact Information
Interpreting Error Messages
To configure location and contact information
Error status code Meaning
Nokia Network Voyager for Ipso 4.0 Reference Guide 261
GetRequest
Variable-bindings Element Description
Value Field Set Description
GetNextRequest
Configuring SNMPv3
GetBulkRequest
262
Managing Snmp Users
Request Messages
Security Related Options Used in Request Messages
Nokia Network Voyager for Ipso 4.0 Reference Guide 263
264
To add an Snmp user
Nokia Network Voyager for Ipso 4.0 Reference Guide 265
To delete a USM user
266
Nokia Network Voyager for Ipso 4.0 Reference Guide 267
IPv6 Overview
Interfaces
To configure IPv6 logical interfaces
268
To configure neighbor discovery
To disable IPv6 on an interface
To delete an IPv6 address
Nokia Network Voyager for Ipso 4.0 Reference Guide 269
To configure IPv6 in IPv4 tunnels
Configuring IPv6 in IPv4 Tunnels
IPv6 and IPv4 Compatibility
270
Configuring IPv6 over IPv4
Configuring IPv6 to IPv4
To configure IPv6 to IPv4
To configure IPv6 over IPv4
Configuring an IPv6 Default or Static Route
Configuring IPv4 in IPv6 Tunnels
To configure IPv4 in IPv6 tunnels
To configure an IPv6 default or static route
Configuring OSPFv3
Routing Configuration
Configuring RIPng
Creating IPv6 Aggregate Routes
Redistributing Static Routes into RIPng
Creating Redistributed Routes
Redistributing Aggregate Routes in RIPng
274
Router Discovery
Configuring ICMPv6 Router Discovery
Redistributing Interface Routes into RIPng
Nokia Network Voyager for Ipso 4.0 Reference Guide 275
276
Vrrp for IPv6
Configuring Vrrp for IPv6
Nokia Network Voyager for Ipso 4.0 Reference Guide 277
278
Creating a Virtual Router for an IPv6 Interface Using VRRPv3
Nokia Network Voyager for Ipso 4.0 Reference Guide 279
To set the virtual MAC address
Setting a Virtual MAC Address for a Virtual Router
280
Removing a Virtual Router in VRRPv3
Changing the IP Address List of a Virtual Router in VRRPv3
Nokia Network Voyager for Ipso 4.0 Reference Guide 281
282
Creating a Virtual Router in Monitored Circuit Mode for IPv6
Nokia Network Voyager for Ipso 4.0 Reference Guide 283
284
Traffic Management
To enable FTP, TFTP, or Telnet access
Security and Access Configuration
Nokia Network Voyager for Ipso 4.0 Reference Guide 285
286
To change the current user’s password
Managing Passwords
Nokia Network Voyager for Ipso 4.0 Reference Guide 287
Managing User Accounts
To change another user’s password
288
User Account Attributes
Adding and Deleting Users
Nokia Network Voyager for Ipso 4.0 Reference Guide 289
Attribute Description
To add a user
Managing and Using S/Key
To remove a user
290
To configure S/Key
Using S/Key
To use the S/Key
Nokia Network Voyager for Ipso 4.0 Reference Guide 291
Managing Groups
To disable S/Key
Disabling S/Key
292
To add or edit a group
Role-Based Administration
Nokia Network Voyager for Ipso 4.0 Reference Guide 293
To add or edit a role
Managing Roles
294
To assign roles and access mechanisms to users
Assigning Roles and Access Mechanisms to Users
To delete a role
Nokia Network Voyager for Ipso 4.0 Reference Guide 295
296
Creating Cluster Administrator Users
Network Access Configuration Options
Configuring Network Access and Services
Network Services
Service Description
To enable network access options and services
Configuring a Modem on COM2, COM3, or COM4
Modem Configuration Parameters
298
Nokia Network Voyager for Ipso 4.0 Reference Guide 299
To configure a modem on COM2, COM3, or COM4
Country Codes for Ositech Five of Clubs Card
Configuring Nokia Network Voyager Access
Country Codes for Ositech Five of Clubs Card II
300
To configure Web access for Nokia Network Voyager
Configuring Basic Nokia Network Voyager Options
Nokia Network Voyager for Ipso 4.0 Reference Guide 301
Generating an SSL/TLS Certificate and Keys
Generating and Installing SSL/TLS Certificates
To generate a certificate and its associated private key
302
To install the certificate and its associated private key
Installing the SSL/TLS Certificate
Nokia Network Voyager for Ipso 4.0 Reference Guide 303
Secure Shell SSH
Troubleshooting SSL/TLS Configuration
304
To configure SSH
Initial SSH Configuration
Nokia Network Voyager for Ipso 4.0 Reference Guide 305
To configure advanced options
Configuring Advanced Options for SSH
306
Nokia Network Voyager for Ipso 4.0 Reference Guide 307
308
Configuring Secure Shell Authorized Keys
To configure key pairs
To configure authorized keys
Changing Secure Shell Key Pairs
Nokia Network Voyager for Ipso 4.0 Reference Guide 309
To manage user identities
Managing User RSA and DSA Identities
310
Tunneling Http Over SSH
Network Voyager Session Management
To tunnel Http over SSH
Nokia Network Voyager for Ipso 4.0 Reference Guide 311
To enable or disable session management
Configuring Session Timeouts
To set the session timeout interval
Enabling Enabling or Disabling Session Management
Creating an AAA Configuration
Authentication, Authorization, and Accounting AAA
To create an AAA configuration
Nokia Network Voyager for Ipso 4.0 Reference Guide 313
Creating a Service Profile
Creating a Service Module Entry
Creating an Authentication Profile
Nokia Network Voyager for Ipso 4.0 Reference Guide 315
Authentication Profile Types
Type Module Description
To create an account profile
Creating an Accounting Profile
316
317
Profile Controls
Creating a Service Module Example
318
Control Description
Service Auth. Mgmt Acct. Mgmt Session Mgmt
Configuring Radius
Nokia Network Voyager for Ipso 4.0 Reference Guide 319
320
Nokia Network Voyager for Ipso 4.0 Reference Guide 321
Configuring TACACS+
To delete an authentication server
Deleting an AAA Authentication Server Configuration
322
Changing the Service Profile
Changing an AAA Configuration
To change an AAA configuration
To add an authentication profile
Service Authentication Management
Creating a Stacked Service Module
324
Changing an Authentication Profile Configuration
Changing a Service Module Configuration
To add an accounting profile
To add a session profile
Changing a Session Profile Configuration
Changing an Accounting Profile Configuration
326
Deleting an Item in a Service Profile Entry
Deleting an AAA Configuration
To delete an AAA configuration
Encryption Acceleration
IPSec Tunnels Ipso Implementation
To enable the card for a Check Point VPN
Enabling Encryption Accelerator Cards
Monitoring Cryptographic Acceleration
Nokia Network Voyager for Ipso 4.0 Reference Guide 329
Transport and Tunnel Modes
Protocol Negotiation and Key Management
Building VPN on ESP
330
Nokia Network Voyager for Ipso 4.0 Reference Guide 331
IPSec Implementation in Ipso
Using PKI
IPSec RFCs
332
Nokia Network Voyager for Ipso 4.0 Reference Guide 333
Miscellaneous Tunnel Requirements
IPSec Parameters
Phase 1 Configuration
Platform Support
334
To chose IPv4 or IPv6 general configuration pages
Choosing IPv4 or IPv6 General Configuration
Creating an IPSec Policy
Nokia Network Voyager for Ipso 4.0 Reference Guide 335
Trusted CA Certificates
Proposal and Filters
To select a trusted CA certificate
336
Nokia Network Voyager for Ipso 4.0 Reference Guide 337
Device Certificates
338
To enroll and install a device certificate
Nokia Network Voyager for Ipso 4.0 Reference Guide 339
Advanced IPSec
To complete creating an IPSec policy
Putting It All Together
340
To create an IPSec tunnel rule
Creating an IPSec Tunnel Rule
Nokia Network Voyager for Ipso 4.0 Reference Guide 341
To create a transport rule
Transport Rule
342
Nokia Network Voyager for Ipso 4.0 Reference Guide 343
IPSec Tunnel Rule Example
To configure Nokia Platform
344
Nokia Network Voyager for Ipso 4.0 Reference Guide 345
To configure Nokia Platform 1 Ipso
Configure Nokia Platform
IPSec Transport Rule Example
346
Nokia Network Voyager for Ipso 4.0 Reference Guide 347
Removing an IPSec Tunnel
Configure PC1
To remove an IPSec tunnel
348
To set TCP flag combinations
Miscellaneous Security Settings
Nokia Network Voyager for Ipso 4.0 Reference Guide 349
350
Routing Protocols
Routing Overview
Nokia Network Voyager for Ipso 4.0 Reference Guide 351
352
RIP
Nokia Network Voyager for Ipso 4.0 Reference Guide 353
Route Maps
354
Types of Areas
High Availability Support for Ospf
Area Border Routers
Nokia Network Voyager for Ipso 4.0 Reference Guide 355
Clustering
Configuring Ospf
356
Ospf Area Configuration Parameters
Configuring Ospf Areas and Global Settings
Stub Area Parameters
Nokia Network Voyager for Ipso 4.0 Reference Guide 357
358
Nssa Not So Stubby Area Parameters
To configure Ospf
Configuring Virtual Links
To configure a virtual link
Nokia Network Voyager for Ipso 4.0 Reference Guide 359
360
Configuring Global Settings
Nokia Network Voyager for Ipso 4.0 Reference Guide 361
Global Settings for Ospf
Configuration Parameters for Ospf Interfaces
Configuring Ospf Interfaces
362
Nokia Network Voyager for Ipso 4.0 Reference Guide 363
To configure an Ospf interface
364
Configuring Ospf Example
Nokia Network Voyager for Ipso 4.0 Reference Guide 365
Network Mask
Auto Summarization
Virtual IP Address Support for Vrrp
366
To configure RIP
Configuring RIP
RIP 1 Configuration Options Available from Network Voyager
Nokia Network Voyager for Ipso 4.0 Reference Guide 367
368
Configuring RIP Timers
RIP Example
Configuring Auto-Summarization
Enabling RIP 1 on an Interface
Nokia Network Voyager for Ipso 4.0 Reference Guide 369
370
Enabling RIP 2 on an Interface
PIM Support for IP Clustering
Configuring Virtual IP Support for Vrrp
PIM Dense-Mode
Nokia Network Voyager for Ipso 4.0 Reference Guide 371
372
PIM Sparse-Mode
Configuring Check Point VPN-1 Pro/Express
Configuring Dense-Mode PIM
PIM and Check Point SecureXL
Nokia Network Voyager for Ipso 4.0 Reference Guide 373
374
Disabling PIM
Nokia Network Voyager for Ipso 4.0 Reference Guide 375
Setting Advanced Options for Dense-Mode PIM Optional
376
Configuring Sparse-Mode PIM
Nokia Network Voyager for Ipso 4.0 Reference Guide 377
Configuring High-Availability Mode
378
Nokia Network Voyager for Ipso 4.0 Reference Guide 379
380
Configuring a PIM-SM Static Rendezvous Point
Nokia Network Voyager for Ipso 4.0 Reference Guide 381
Setting Advanced Options for Sparse-Mode PIM Optional
382
Debugging PIM
Command Shows
Nokia Network Voyager for Ipso 4.0 Reference Guide 383
384
To log information about errors and events
Nokia Network Voyager for Ipso 4.0 Reference Guide 385
Igrp
386
Nokia Network Voyager for Ipso 4.0 Reference Guide 387
Generation of Exterior Routes
Aliased Interfaces
Configuring Igrp
Igrp Aggregation
388
Igrp Example
To enable Igrp on an interface
Nokia Network Voyager for Ipso 4.0 Reference Guide 389
390
Dvmrp
Configuring Dvmrp Timers
Configuring Dvmrp
Nokia Network Voyager for Ipso 4.0 Reference Guide 391
392
Igmp
Nokia Network Voyager for Ipso 4.0 Reference Guide 393
Configuring Igmp
394
Static Routes
To setting the rank for static routes
To configure a default or static route
Nokia Network Voyager for Ipso 4.0 Reference Guide 395
396
To add and configure many static routes at the same time
To create a static route non-default
To create a static default route
Adding and Managing Static Routes Example
Creating/Removing Static Routes
To disable a static route
Backup Static Routes
To create a backup static route
Route Aggregation
To remove aggregate routes
To create aggregate routes
Nokia Network Voyager for Ipso 4.0 Reference Guide 399
400
Route Aggregation Example
Route Rank
Preference Default
Rank Assignments
Nokia Network Voyager for Ipso 4.0 Reference Guide 401
To set route rank
Routing Protocol Rank Example
402
Support for BGP-4++
To configure the routing preferences
Nokia Network Voyager for Ipso 4.0 Reference Guide 403
BGP Path Attributes
BGP Sessions Internal and External
404
Path Attribute Definition
Nokia Network Voyager for Ipso 4.0 Reference Guide 405
BGP Interactions with IGPs
BGP Multi-Exit Discriminator
406
Redistributing Routes to BGP
Inbound BGP Route Filters
Communities
Nokia Network Voyager for Ipso 4.0 Reference Guide 407
408
Route Reflection
Community attribute Description
Nokia Network Voyager for Ipso 4.0 Reference Guide 409
Confederations
410
Ebgp Multihop Support
Route Dampening
TCP MD5 Authentication
Nokia Network Voyager for Ipso 4.0 Reference Guide 411
412
BGP Support for Virtual IP for Vrrp
BGP Memory Requirements
BGP Support for IP Clustering
Tables
Nokia Network Voyager for Ipso 4.0 Reference Guide 413
Example
Memory Size
414
BGP Neighbors Example
To configure Ibgp on Nokia Platform a
Nokia Network Voyager for Ipso 4.0 Reference Guide 415
To configure Ibgp on Nokia Platform C
To configure Ibgp on Nokia Platform B
416
To configure Ebgp on Nokia Platform C
To configure Ebgp on Nokia Platform a
To configure Ebgp on Nokia Platform D
Nokia Network Voyager for Ipso 4.0 Reference Guide 417
Path Filtering Based on Communities Example
To configuring Ebgp on Nokia Platform E
Verification
418
BGP Multi Exit Discriminator Example
To configure Default MED for Nokia Platform D
Nokia Network Voyager for Ipso 4.0 Reference Guide 419
420
To configure MED Values for all peers of AS200
Nokia Network Voyager for Ipso 4.0 Reference Guide 421
Changing the Local Preference Value Example
To configure the static routes required for an Ibgp session
To configure an Ibgp peer for Nokia Platform B
To set the local preference value for an Ibgp peer
422
BGP Confederation Example
Configuring Nokia Platform C
Nokia Network Voyager for Ipso 4.0 Reference Guide 423
424
Configuring Platform B
Nokia Network Voyager for Ipso 4.0 Reference Guide 425
Route Reflector Example
Configuring Platform B as Route Reflector
426
Configuring Platform D as Ibgp Peer of Platform B
Configuring Platform C as Ibgp Peer of Platform B
Nokia Network Voyager for Ipso 4.0 Reference Guide 427
Configuring Redistribution of BGP Routes on Platform B
Configuring BGP Route Inbound Policy on Platform B
BGP Community Example
428
Nokia Network Voyager for Ipso 4.0 Reference Guide 429
Follow the steps in the Redistributing Ospf to BGP Example
Configuring a Loopback Address on Platform B
Configuring a Loopback Address on Platform a
Configuring a Static Route on Platform a
Ebgp Load Balancing Example Scenario #1
Configuring an Ebgp Peer on Platform a
Configuring a Static Route on Platform B
Configuring an Ebgp Peer on Platform B
Nokia Network Voyager for Ipso 4.0 Reference Guide 431
Configuring Ospf on Platform B
Configuring Ospf on Platform a
Ebgp Load Balancing Example Scenario #2
432
Nokia Network Voyager for Ipso 4.0 Reference Guide 433
Adjusting BGP Timers Example
Configuring TCP MD5 Authentication on Nokia Platform a
TCP MD5 Authentication Example
Configuring BGP Route Redistribution on Nokia Platform B
434
BGP Route Dampening Example
Field Default value Units of measurement
Nokia Network Voyager for Ipso 4.0 Reference Guide 435
BGP-4++ Example
BGP Path Selection
436
Nokia Network Voyager for Ipso 4.0 Reference Guide 437
To configure configure a BGP4 session over IPv6 transport
438
Route Redistribution
Nokia Network Voyager for Ipso 4.0 Reference Guide 439
Redistributing Routes to RIP and Igrp
To configure BGP route redistribution on Nokia Platform D
BGP Route Redistribution Example
To redistribute a single route
Nokia Network Voyager for Ipso 4.0 Reference Guide 441
Redistributing RIP to Ospf Example
442
Nokia Network Voyager for Ipso 4.0 Reference Guide 443
Redistributing Ospf to BGP Example
To redistribute Ospf to BGP through Nokia Platform a
Redistributing Routes with Ospf
444
Inbound Route Filters
To configure IGP inbound filters
Nokia Network Voyager for Ipso 4.0 Reference Guide 445
446
BGP Route Inbound Policy Example
Nokia Network Voyager for Ipso 4.0 Reference Guide 447
Aspath Regular Expressions
BGP AS Path Filtering Example
448
Packet Filtering Description
Traffic Management Overview
Traffic Shaping Description
Nokia Network Voyager for Ipso 4.0 Reference Guide 449
Traffic Queuing Description
Configuring Access Control Lists
450
To apply or remove an ACL to or from an interface
To create or delete an ACL
Nokia Network Voyager for Ipso 4.0 Reference Guide 451
452
Configuring ACL Rules
To add a new rule to an ACL
Modifying a Rule
Nokia Network Voyager for Ipso 4.0 Reference Guide 453
454
ACL Rule Attributes
Nokia Network Voyager for Ipso 4.0 Reference Guide 455
Configuring Aggregation Classes
To associate an aggregation class with a rule
To create an Aggregation Class
456
Nokia Network Voyager for Ipso 4.0 Reference Guide 457
Configuring Queue Classes
To create or delete a queue class
To set or modify queue class configuration values
458
To associate a queue class with an interface
Configuring ATM QoS
Create a QoS descriptor
Nokia Network Voyager for Ipso 4.0 Reference Guide 459
To dissociate an ATM QoS Descriptor from an existing PVC
To delete an ATM QoS descriptor
460
Nokia Network Voyager for Ipso 4.0 Reference Guide 461
Configuring Common Open Policy Server
Configuring Security Parameters for a Cops Client ID
Configuring a Cops Client ID and Policy Decision Point
462
Nokia Network Voyager for Ipso 4.0 Reference Guide 463
Assigning Roles to Specific Interfaces
Activating and Deactivating the Cops Client
To disable and delete a Client ID
Deleting a Client ID
464
Nokia Network Voyager for Ipso 4.0 Reference Guide 465
Example Rate Shaping
466
Example Expedited Forwarding
Nokia Network Voyager for Ipso 4.0 Reference Guide 467
468
To test the configuration
Nokia Network Voyager for Ipso 4.0 Reference Guide 469
BOOTP/DHCP Relay
To enable Bootp relay on an Interface
Configuring BOOTP/DHCP Relay
Bootp configuration parameters
470
IP Broadcast helper configuration parameters
To disable Bootp relay on an interface
IP Broadcast Helper
Nokia Network Voyager for Ipso 4.0 Reference Guide 471
472
To configure IP broadcast helper
Router Discovery Overview
Configuring Router Discovery
Nokia Network Voyager for Ipso 4.0 Reference Guide 473
Router discover configuration parameters
To enable router discovery services
474
Network Time Protocol NTP
To disable router discovery services
Nokia Network Voyager for Ipso 4.0 Reference Guide 475
To configure NTP
Configuring NTP
476
Nokia Network Voyager for Ipso 4.0 Reference Guide 477
478
CPU-Memory Live Utilization
Viewing System Utilization Statistics
Nokia Network Voyager for Ipso 4.0 Reference Guide 479
Monitoring Process Utilization
Disk and Swap Space
480
Nokia Network Voyager for Ipso 4.0 Reference Guide 481
Ipso Process Management
Process Description
Reports
Generating Monitor Reports
482
Report Description
To display reports
Monitoring System Health
Nokia Network Voyager for Ipso 4.0 Reference Guide 483
484
Monitoring System Logs
Nokia Network Voyager for Ipso 4.0 Reference Guide 485
Viewing Cluster Status and Members
Viewing Routing Protocol Information
Displaying Route Settings
Displaying the Kernel Forwarding Table
486
Hardware Monitoring
Displaying Interface Settings
Nokia Network Voyager for Ipso 4.0 Reference Guide 487
Iclid Commands
Using the iclid Tool
To display routing daemon status using iclid
488
Nokia Network Voyager for Ipso 4.0 Reference Guide 489
490
Nokia Network Voyager for Ipso 4.0 Reference Guide 491
492
Nokia Network Voyager for Ipso 4.0 Reference Guide 493
494
Preventing Full Log Buffers and Related Console Messages
If you are using FireWall-1 NG
If you are using FireWall-1
Nokia Network Voyager for Ipso 4.0 Reference Guide 495
496
Nokia Network Voyager for Ipso 4.0 Reference Guide Index
Index
Bios
CPU
DSA
Http
Httpd
Managing
NGX
Nssa
RIP
RSA
TACACS+
Deleting virtual router
Index
Top
Page
Image
Contents