Nortel Secure Network Access Switch 4050 User Guide
Copyright Nortel Networks Limited 2005. All rights reserved
320818-A
Nortel Secure Network Access Switch 4050 User Guide
Licensing
General
Contents
Managing the network access devices
Contents
Configuring the domain
Configuring groups and profiles
Configuring authentication 233
TunnelGuard SRS Builder
Managing system users and groups
Customizing the portal and user logon
Setting the portal display language using the CLI
Configuring system settings
Adding a host interface
Managing certificates
Configuring Snmp
Maintaining and managing the system
Upgrading or reinstalling the software
Appendix a CLI reference
Troubleshooting 837
Appendix C Supported MIBs
Appendix H Software licensing information Index
Contents 320818-A
Preface
Connect the switch to the network
Before you begin
Preface
Text conventions
Bold text
Plain Courier text
Related information
Publications
Example Set Trap Monitor Filters
How to get help
Online
Preface
Nortel SNA solution
This chapter includes the following topics
Elements of the Nsna solution
Supported users
Overview
Role of the Nortel Snas
Nortel Snas 4050 functions
Nortel SNA VLANs and filters
Groups and profiles
Authentication methods
TunnelGuard host integrity check
Communication channels
About SSH
Communication channels in the Nortel SNA network
Nortel Snas 4050 clusters
RSA DSA
One-armed and two-armed configurations
One-armed configuration
Two-armed configuration
Nortel SNA configuration and management tools
Illustrates a two-armed configuration
Nortel Snas 4050 configuration roadmap
Configure the network Dhcp server
Overview
Overview
Overview
Overview
Overview 320818-A
Chapter Initial setup
Initial setup
About the IP addresses
Management IP address
Portal Virtual IP address
Login admin Password admin
Initial setup
Log on using the following username and password
Real IP address
Setup Menu displays
Select the option for a new installation
Enter port number for the management interface
Enter network mask 255.255.255.0 mask
Enter Vlan tag id or zero for no Vlan
Setup a two armed configuration yes/no no
Enter default gateway IP address or blank to skip
Enter IP address for this machine on traffic interface
Specify the MIP for this device or cluster
Enter port number for the traffic interface
Enter a timezone or select select timezone
Specify the DNS server, if applicable
Configure the time settings
Specify the NTP server, if applicable
Enter NTP server address or blank to skip IPaddr
Change the admin user password, if desired
Specify the pVIP of the Nortel Snas 4050 device
Specify a name for the Nortel Snas 4050 domain
Create http to https redirect server no
Settings created by the quick setup wizard
Adding a Nortel Snas 4050 device to a cluster
Extended profile details
Before you begin
Joining a cluster
Select the option to join an existing cluster
Enter network mask 255.255.255.0 mask
Enter the existing admin user password password
Specify the MIP of the existing cluster
Setup successful Login
Next steps
Applying and saving the configuration
Cfg/dump
Applying and saving the configuration using the CLI
Applying and saving the configuration using the Srem
Cfg/ptcfg
Apply and Commit buttons
Initial setup 320818-A
Chapter Managing the network access devices
Managing the network access devices
Managing network access devices using the CLI
Roadmap of domain commands
Reset
Specify the IP address of the network access device
Adding a network access device using the CLI
Using the quick switch setup wizard
Cfg/domain 1/quick
Go to on
Nsna communication port5000
Red vlan id of Switch Vlan ID
To continue, go to on
Manually adding a switch
Switch menu displays
Cfg/domain #/switch switch ID
Deleting a network access device using the CLI
Cfg/domain #/switch #/dis Cfg/domain #/switch #/delete
Configuring the network access devices using the CLI
Switch menu includes the following options
Cfg/domain #/switch switch ID followed by
Ip IPaddr
Followed by
Mapping the VLANs using the CLI
Cfg/domain #/switch #/vlan
Dis Delete
Cfg/domain #/switch #/vlan/list
Domain vlan or Switch vlan menu displays
Cfg/domain #/switch #/vlan followed by
Add name Vlan ID
Managing SSH keys using the CLI
Nsnas SSH key menu displays
Generating SSH keys for the domain using the CLI
For an Ethernet Routing Switch 5510, 5520, or
Cfg/domain #/sshkey
Cfg/domain #/switch #/sshkey/export
Nsnas SSH key menu includes the following options
Cfg/domain #/sshkey followed by
Shows sample output for the /cfg/domain #/sshkey command
Main# /cfg/domain 1/sshkey
Cfg/domain #/switch #/sshkey
Cfg/domain #/switch #/sshkey followed by
Cfg/domain#1/sshkey/export command to
Cfg/domain #/switch #/hlthchk
Reimporting the network access device SSH key using the CLI
Monitoring switch health using the CLI
Enter Apply to apply the change immediately
HealthCheck menu includes the following options
Cfg/domain #/switch #/hlthchk followed by
Cfg/domain #/switch #/dis
Deadcnt count
To add a network access device, use the following steps
Managing network access devices using the Srem
Adding a network access device using the Srem
Cfg/domain #/switch #/ena
Add a Switch
Add a Switch fields
Deleting a network access device using the Srem
Configuring the network access devices using the Srem
Switch Configuration screen appears see Figure
Switch Configuration screen 320818-A
Switch Configuration fields
Mapping the VLANs using the Srem
You can perform the Vlan mapping in two ways
Mapping VLANs by domain
Domain VLANs screen
Click Add Add a new Vlan dialog box appears see Figure
Adding VLANs to a domain
To add VLANs to a domain, complete the following steps
Add a new Vlan fields
Removing VLANs from a domain
Mapping VLANs by switch
Switch VLANs screen
Adding VLANs to a switch
To add VLANs to a switch, complete the following steps
Managing SSH keys using the Srem
Removing VLANs from a switch
Managing the network access devices
Managing the network access devices
Generating SSH keys for the domain using the Srem
Key Generation screen appears see Figure
Exporting SSH keys for the domain using the Srem
Switch SSH Key fields
Export Key screen appears see Figure
Click Apply on the toolbar to begin the export process
Export Key fields
Managing SSH keys for Nortel SNA communication using
Switch SSH Key screen appears see Figure
Reimporting the network access device SSH key using the Srem
Click Delete Switch SSH Key
Monitoring switch health using the Srem
Switch SSH Key screen appears see on
Click Import SSH from Switch
Health Check screen appears see Figure
Health Check screen 320818-A
Viewing a connected client list using the Srem
Connected Clients fields
Managing the network access devices
Switch Configuration screen
Chapter Configuring the domain
Configuring the domain using the CLI
Configuring the domain
Cfg/domain
Logging traffic with syslog messages
Captive portal Portal look and feel Linksets
Details onoff
You can create a domain in two ways
Creating a domain using the CLI
Manually creating a domain using the CLI
Cfg/domain domain ID
320818-A
Using the Nortel Snas 4050 domain quick setup wizard
Main# /cfg/domain
Cfg/quick
Specify the certificate to be used by the portal server
Main# cfg/quick
Configuring the domain
Do you require chain certificates yes/no no
Do you want to configure a switch? yes/no no
Specify whether the SSL server uses chain certificates
Do you want an http to https redirect server yes/no no
Do you want to create a tunnelguard test user? yes/no yes
Configuring the domain
Deleting a domain using the CLI
To delete a domain, use the following command
Cfg/domain #/del
Cfg/domain domain ID followed by
Configuring domain parameters using the CLI
To configure the domain, use the following command
Pvips IPaddr
Httpredir
Cfg/domain #/aaa/tg
Configuring the TunnelGuard check using the CLI
TG menu displays TG menu includes the following options
Cfg/domain #/aaa/tg followed by
Cfg/domain #/aaa/tg/status-quo
Using the quick TunnelGuard setup wizard in the CLI
Cfg/domain #/aaa/tg/quick
Server 1001 menu displays
Configuring the SSL server using the CLI
TunnelGuard quick setup wizard creates a default SRS rule
Main# /cfg/domain #/aaa/tg/quick
Cfg/domain #/server followed by
Tracing SSL traffic using the CLI
Server 1001 menu includes the following options
Interface ID
Output mode
Ssldump
Tcpdump
Cfg/domain #/adv/interface command
Cfg/domain #/server/trace followed by
Ping host
Dnslookup host
Configuring SSL settings using the CLI
SSL Settings menu displays
Traceroute host
Cert certificate
SSL Settings menu includes the following options
Cfg/domain #/server/ssl followed by
Index
Yes
Cachain certificate
Index list
Cfg/domain #/server/ssl/protocol
Configuring traffic log settings using the CLI
Ena Dis
Cfg/domain #/server/adv/traflog
Traffic Log Settings menu displays
Traffic Log Settings menu includes the following options
Cfg/domain #/server/adv/traflog followed by
Cfg/domain #/httpredir followed by
Configuring Http redirect using the CLI
Cfg/domain #/httpredir
Redir onoff
Cfg/domain #/adv
Configuring advanced settings using the CLI
Cfg/sys/host #/interface command see
Cfg/domain #/adv followed by
Configuring Radius accounting using the CLI
Cfg/domain #/aaa/radacct
Managing Radius accounting servers using the CLI
Radius Accounting Servers menu displays
Cfg/domain #/aaa/radacct followed by
Cfg/domain #/aaa/radacct/servers followed by
VPN Attribute menu displays
NSNAS-Portal-ID
Cfg/domain #/aaa/radacct/vpnattribu
Cfg/domain #/aaa/radacct/vpnattribu followed by
Configuring the domain using the Srem
VPN Attribute menu includes the following options
Vendorid
Creating a domain using the Srem
Manually creating a domain using the Srem
Secure Access Domain Table screen 320818-A
Add a Secure Access Domain
Add a Secure Access Domain fields
Using the Srem Domain Quick Wizard
Configuring the domain
Domain Quick Wizard General Settings fields
Click Domain Quick Wizard
Click Next
Domain Quick Wizard Certificate
Domain Quick Wizard Certificate fields
Organization name and do not use any of the following
Domain Quick Wizard Certificate Chain
Domain Quick Wizard Certificate Chain fields
Domain Quick Wizard Server dialog box appears see Figure
Domain Quick Wizard Server fields
Domain Quick Wizard Switch dialog box appears see Figure
Domain Quick Wizard Switch fields
Domain Quick Wizard Tunnel Guard dialog box appears see
Domain Quick Wizard Tunnel Guard fields
Deleting a domain using the Srem
To delete a domain, perform the following steps
Configuring domain parameters using the Srem
To configure a domain, perform the following steps
Domain Configuration fields
Additional domain configuration in the Srem
Domain domain Configuration screen
Additional domain configuration tabs
Additional domain tree components
Component Description
Configuring the TunnelGuard check using the Srem
TunnelGuard Configuration screen appears see Figure
TunnelGuard Configuration fields
Groups using the Srem on
Using the TunnelGuard Quick Setup in the Srem
TunnelGuard Quick Setup screen appears see Figure
TunnelGuard Quick Setup fields
Configuring the SSL server using the Srem
Server Configuration screen 320818-A
Server Configuration fields
Configuring SSL settings using the Srem
Server SSL Settings screen 320818-A
Server SSL Settings fields
ALL@STRENGTH
Configuring traffic log settings using the Srem
Configuring the domain Server SSL Settings fields
Traffic Log Syslog Settings screen appears see Figure
Traffic Log Syslog Settings fields
Configuring Http redirect using the Srem
Tracing SSL traffic using the Srem
Http Redirect screen 320818-A
Configuring Radius accounting using the Srem
Http Redirect fields
Configuring Nortel Snas 4050-specific attributes using
Radius accounting Configuration screen appears see Figure
Managing Radius accounting servers using the Srem
Adding a Radius accounting server using the Srem
Radius accounting Configuration fields
Radius Accounting Servers screen appears see Figure
Radius Accounting Servers screen
Moving a Radius accounting server using the Srem
Radius Accounting Server fields
Deleting a Radius accounting server using the Srem
Configuring the domain 320818-A
Chapter Configuring groups and profiles
Groups
Configuring groups and profiles
Overview
This section includes the following topics
Default group
Linksets
TunnelGuard SRS rule
Extended profiles
Configuring groups and extended profiles using the CLI
Create the SRS rules see TunnelGuard SRS Builder on
Roadmap of group and profile commands
Configuring groups using the CLI
To create and configure a group, use the following command
Cfg/domain 1/aaa/group group ID
Cfg/domain 1/aaa/group # followed by
Restrict
Extend profile ID
Tgsrs SRS rule name
Comment comment
Main# /cfg/domain 1/AAA/group
Configuring client filters using the CLI
Cfg/domain 1/aaa/filter filter ID
Client Filter menu includes the following options
Cfg/domain 1/aaa/filter filter ID followed by
Tg truefalseignore
Configuring extended profiles using the CLI
Main# /cfg/domain 1/AAA/filter
Cfg/domain 1/aaa/group group IDgroup name/extend
Filter name
Extended Profile menu includes the following options
Cfg/domain 1/aaa/group #/extend # followed by
Vlan name
Main# cfg/domain 1/aaa/group 2/extend
Cfg/domain 1/aaa/group #/extend #
Linkset Del
Extended Profile 1# ../extend 2/filter tgfailed/vlan Yellow
Cfg/domain 1/aaa/group #/extend #/linkset
Mapping linksets to a group or profile using the CLI
Cfg/domain 1/aaa/group #/linkset
Cfg/domain 1/aaa/group #/extend #/linkset followed by
Main# cfg/domain 1/aaa/group 1/linkset
Linksets# add example2
Linksets# insert 2 example3
Configuring groups using the Srem
Configuring groups and extended profiles using the Srem
Creating a default group using the CLI
This section contains the following topics
Using the guide for creating groups
Click a Guide to Create a Group on the toolbar
Adding a group
Groups screen 320818-A
Click Add Add a Group dialog box appears see Figure
Add a Group fields
To configure a group, perform the following steps
Group Configuration screen appears see Figure
Modifying a group
Configuring client filters using the Srem
Group Configuration fields
Adding a client filter
Client Filters screen appears see Figure
Click Add Add a Client Filter dialog box appears see Figure
Add a Client Filter fields Sheet 1
Check using the Srem on
To configure a client filter, perform the following steps
Client filter Configuration screen appears see Figure
Modifying a client filter
Client Filters configuration fields
Configuring extended profiles using the Srem
Adding an extended profile
Extended Profiles screen appears see Figure
Add an Extended Profile screen
Add an Extended Profile fields
Extended profiles Configuration screen appears see Figure
Modifying an extended profile
Mapping linksets to a group or profile using the Srem
Extended Profile Configuration fields
Mapping linksets to a group
Linksets screen for a group
Adding linksets to a group
To add a linkset to a group, perform the following steps
Add a Linkset fields
Removing linksets from a group
Reordering linksets in a group
Mapping linksets to a profile
Linksets screen for an extended profile
Adding linksets to an extended profile
Removing linksets from an extended profile
Reordering linksets in an extended profile
Creating a default group using the Srem
AAA Configuration screen 320818-A
AAA Configuration fields
Configuring groups and profiles 320818-A
Chapter Configuring authentication
Configuring authentication
Before you begin
Configuring authentication using the CLI
Roadmap of authentication commands
Cfg/domain 1/aaa
Command
Configuring authentication methods using the CLI
Cfg/domain 1/aaa/auth auth ID
Cfg/domain 1/aaa/auth auth ID followed by
Radiusldaplocal
Display
Local accesses the Local database menu
Cfg/domain 1/aaa/auth #/adv followed by
Configuring Radius authentication using the CLI
Cfg/domain 1/aaa/auth #/adv
Groupauth auth IDs
Adding the Radius authentication method using the CLI
You can perform the following configuration tasks
Configuring authentication
Modifying Radius configuration settings using the CLI
Main# /cfg/domain 1/aaa/auth
Cfg/domain 1/aaa/auth #/radius
Cfg/domain 1/aaa/auth #/radius followed by
Type
Radius servers menu displays
Managing Radius authentication servers using the CLI
Timeout interval
Sessiontim
Radius servers menu includes the following options
Cfg/domain 1/aaa/auth #/radius/servers followed by
Configuring Ldap authentication using the CLI
Configuring session timeout using the CLI
Cfg/domain 1/aaa/auth #/radius/sessiontim
Adding the Ldap authentication method using the CLI
Configuring authentication
Modifying Ldap configuration settings using the CLI
Cfg/domain 1/aaa/auth #/ldap
Ldap menu displays Ldap menu includes the following options
Cfg/domain 1/aaa/auth #/ldap followed by
Do not use the isdbinddn and isdbindpas
Userattr names
SAMAccountName=bill . The user’s login
Isdbindpas password
Ou=Users, dc=example, dc=com .
Enaldaps truefalse
Enauserpre truefalse
Activedire
Managing Ldap authentication servers using the CLI
Cfg/domain 1/aaa/auth #/ldap/servers
Removes the specified Ldap server from the current
Managing Ldap macros using the CLI
Cfg/domain 1/aaa/auth #/ldap/ldapmacro
Cfg/domain 1/aaa/auth #/ldap/ldapmacro followed by
Prefix suffix
Add variable name
Ldap attribute
Variable name
Active Directory Settings menu displays
Managing Active Directory passwords using the CLI
Set the Active Directory settings using
Cfg/domain 1/aaa/auth #/ldap/activedire command
Configuring local database authentication using the CLI
Configuring authentication
Authentication menu commands local database
Local database menu displays
Managing the local database using the CLI
You can add users to the database in two ways
Cfg/domain 1/aaa/auth #/local
Cfg/domain 1/aaa/auth #/local followed by
Cur group command
Local database menu includes the following options
TAB or use the /cfg/domain 1/aaa
Import protocol
Server filename key
Specifying authentication fallback order using the CLI
Export protocol
Cfg/domain 1/aaa/authorder auth ID,auth ID
Main# /cfg/domain 1/aaa/authorder
Configuring authentication using the Srem
Configuring authentication methods using the Srem
Authentication Server Table appears see Figure
Configuring Radius authentication using the Srem
Add an Authentication Server Radius 320818-A
Adding the Radius method and server
Modifying Radius configuration
Add an Authentication Server Radius fields
Modifying Radius method settings
Configuration 320818-A
Configuration fields
Modifying Radius configuration settings
Radius Configuration screen appears see Figure
Radius Configuration fields
Configuring authentication Radius Configuration fields
Managing additional Radius servers
Adding a Radius server
Add a Radius Server fields
Configuring authentication Add a Radius Server fields
Reordering additional Radius servers
Removing a Radius server
Configuring Ldap authentication using the Srem
Next steps
Add an Authentication Server Ldap fields
Adding the Ldap method and server
Modifying Ldap configuration
Modifying Ldap method settings
Configuration fields
Modifying Ldap configuration settings
Ldap Configuration screen appears see Figure
Ldap Configuration fields
Ou=Users, dc=example, dc=com. The user
Cn=Users, dc=example, dc=com
Configuring authentication Ldap Configuration fields
Active Directory, on
Managing additional Ldap servers
Adding an Ldap server
Click Apply
Add an Ldap Server fields
Reordering additional Ldap servers
Removing an Ldap server
Managing Ldap macros
Ldap Macros
Adding Ldap macros
Add an Ldap Macro fields
Reordering Ldap macros
Removing Ldap macros
Configuring local database authentication using the Srem
Populate the database see Populating the database on
Adding the Local method
Add an Authentication Server Local fields
Database on
You can populate the Local database in two ways
Populating the database
Adding users to the local database
Local Users screen appears see Figure
Click Add Add a Local User dialog box appears see Figure
Add a Local User fields
Configuring authentication
Importing a database
Import Local User Database 320818-A
Modifying Local database configuration
Import Local User Database fields
Modifying Local method settings
Modifying local users
Local Users screen appears see on
Local Users Configuration 320818-A
Modifying local user passwords
Local Users Configuration fields
Select the Local User Configuration tab
Local Users Local User Configuration 320818-A
Local Users Local User Configuration fields
Exporting the database
Export Local User Database 320818-A
Export Local User Database fields
Specifying authentication fallback order using the Srem
Authentication Server Order
Saving authentication settings
Chapter TunnelGuard SRS Builder
TunnelGuard SRS Builder
Configuring SRS rules
TunnelGuard user interface
\tunnelguard\tg.txt
Software Definition menu
Menu commands
File menu
Describes important items from the File menu
Software Definition Entry menu
Software Definition Entry menu items Sheet 1
Describes important items from the TunnelGuard Rule menu
TunnelGuard Rule menu
Tool menu
Describes important items from the Tool menu
SRS definition toolbar
SRS Definition toolbar item descriptions
Software Definition Available SRS list
SRS Components table
SRS Components table items
Customizing a component
WINNT%\xxx.dll
SRS Rule toolbar
Memory snapshot
TunnelGuard Rule Definition screen
Memory snapshot item descriptions
Available Expression list
SRS Rule list
SRS Rule Expression Constructor
Rule Expression Constructor
Managing TunnelGuard rules and expressions
Creating a software definition
Adding entries to a software definition
Selecting modules or files from running processes
Create New Memory Module SRS window
For more information, see Making API calls on
Selecting file on disk
Select the TunnelGuard Rule Definition tab
Create New on Disk SRS Entry window
Creating logical expressions
Click the TunnelGuard Rule Definition tab
TunnelGuard Rule Definition tab
Click the Form TunnelGuard Rule Expression button
Available Expressions screen
New SRS Rule window
TunnelGuard Rule Name screen
Registry-based rules
Registry-only SRS entry
Describes supported operands for integer values
Supported integer operands
Constructs for string based regular expressions Sheet 1
String regular expression Description
Creating a registry entry
Registry-based File/Module
Enter the Key Value Data Expression
TunnelGuard SRS Builder Registry Entry
Manually creating SRS entries
Manually creating an OnDisk file entry
Create new OnDisk SRS Entry
Manually creating a Memory Module entry
Create New Memory Module SRS Entry page opens see on
Create new Memory Module SRS entry
File age check
Adding comments
Adding a TunnelGuard rule comment
TunnelGuard SRS Builder Date/Time Range
Deleting SRS rules and their components
Adding a software definition comment
Deleting a TunnelGuard rule
Deleting a software definition
Deleting a software definition entry
Deleting an expression
TunnelGuard support for API calls
Making API calls
TunnelGuard SRS Builder 320818-A
Chapter Managing system users and groups
User rights and group membership
Managing system users and groups
Group membership and user rights
Managing system users and groups using the CLI
Roadmap of system user management commands
Cfg/sys/user
Managing user accounts and passwords using the CLI
User menu displays User menu includes the following options
Cfg/sys/user followed by
Del username
Add username
Managing user settings using the CLI
Edit username
Caphrase
Password confirm User password
Managing user groups using the CLI
Password user
Cfg/sys/user/edit username
This section includes the following detailed examples
CLI configuration examples
Adding a new user
Cfg/sys/user/edit username/groups
Access the User Menu
Main# /cfg/sys/user
User# edit certadmin
Apply the changes
Verify and apply the changes
User# edit admin
Changing a user’s group assignment
Changing passwords
Changing your own password
Changing another user’s password
Type the password command to initialize the password change
Deleting a user
Managing system users and groups using the Srem
Managing user accounts using the Srem
To manage users, choose from one of the following tasks
User Table
Adding new user accounts
Click Add Add a User dialog box appears see Figure
Removing existing user accounts
To remove an existing user, perform the following steps
Add a User fields
Setting password expiry using the Srem
Password Setting 320818-A
Password Settings fields
Changing your password using the Srem
Change Your Password 320818-A
Only the admin user can change the passwords of other users
Changing another user’s password using the Srem
Click Change Password
Change Your Password fields
Change User Password 320818-A
Setting the certificate export passphrase using the Srem
Change User Password fields
Set Certificate Export PassPhrase screen appears see Figure
Set Certificate Export PassPhrase 320818-A
Managing user groups using the Srem
Click Set Pass Phrase
Set Certificate Export PassPhrase fields
Adding a user group
Choose from the following tasks to manage users groups
To add a new user group, perform the following steps
Removing a user group
Click Add Add a User Group dialog box appears see Figure
Add a User Group fields
Managing system users and groups
Chapter Customizing the portal and user logon
Captive portal and Exclude List
Customizing the portal and user logon
Exclude List
Allowed regular expressions and escape sequences
String Usage Expressions
Portal display
Portal look and feel
Default appearance
Colors
Common colors, with hexadecimal codes Sheet 1
Color Hexadecimal code
Language localization
Content-Type text/plain charset=iso-8859-1/n
Linksets and links
Autorun linksets
Planning the linksets
Macros
Automatic redirection to internal sites
Examples of redirection URLs and links
Examples of redirection URLs and link text Sheet 1
Managing the end user experience
Automatic JRE upload
Customizing the portal and logon using the CLI
Roadmap of portal and logon configuration commands
Windows domain logon script
Number
Color2 code
DNS Exclude menu displays
Configuring the captive portal using the CLI
Configuring the Exclude List using the CLI
Cfg/domain 1/dnscapt
Changing the portal language using the CLI
DNS Exclude menu includes the following options
Cfg/domain 1/dnscapt/exclude followed by
Configuring language support using the CLI
Language Support menu displays
Cfg/lang
Cfg/lang followed by
Cfg/lang/import command
Language Support menu includes the following options
Server filename
Cfg/domain 1/portal/lang followed by
Setting the portal display language using the CLI
Cfg/domain 1/portal/lang
Cfg/domain 1/portal/lang/list
Cfg/domain 1/portal
Configuring the portal display using the CLI
Restore
Cfg/domain 1/portal followed by
Logintext text
Redirect URL
Linkcols columns
Linktext text
Linkurl onoff
Linkwidth width
Changing the portal colors using the CLI
Portal Colors menu displays
Cfg/domain 1/portal/colors
Cfg/domain 1/portal/content
Configuring custom content using the CLI
Portal Custom Content menu displays
Portal Colors menu includes the following options
Tftpftpscpsftp. The default is tftp
Portal Custom Content menu includes the following options
Cfg/domain 1/portal/content followed by
Available
Configuring linksets using the CLI
Cfg/domain 1/linkset linkset ID
Text text
Linkset menu includes the following options
Cfg/domain 1/linkset linkset ID followed by
Autorun truefalse
Configuring links using the CLI
Cfg/domain 1/linkset linkset ID/link index
Link menu includes the following options
Cfg/domain 1/linkset linkset ID/link index followed by
Move new index
Cfg/domain 1/linkset linkset ID/link index/ external/quick
Configuring external link settings using the CLI
Configuring FTP link settings using the CLI
Cfg/domain 1/linkset linkset ID/link index/ ftp/quick
Customizing the portal and logon using the Srem
Configuring the captive portal using the Srem
Enabling DNS capture
DNS Capture screen includes the following components
DNS Capture fields
Configuring the DNS Exclude List using the Srem
Click Add Entry appears in the DNS Exclude List
Add DNS Domain fields
Changing the portal language using the Srem
Languages sub-tabs appear see Figure
Configuring language support using the Srem
Select the System Language tab
Choose from one of the following tasks
To view custom languages, use the following procedure
Viewing predefined languages
Viewing and removing custom languages
Importing and exporting language definitions
Click the Import/Export Definition tab
Import/Export Definition screen appears see Figure
Import/Export Definition fields
Setting the portal display language using the Srem
Configuring the portal display using the Srem
Language fields
Configuring content
Portal Configuration tab appears see Figure
Portal Configuration fields
Sites, see on
Importing banners
Import Banner screen 320818-A
Import Banner fields
Changing the portal colors using the Srem
Color Settings screen 320818-A
Color Settings fields
Configuring custom content using the Srem
Viewing basic information about custom content
Basics screen appears see Figure
Basics fields
Importing custom content
To import custom content, perform the following steps
Import Content screen appears see Figure
Import Content fields
Exporting custom content
To export custom content, perform the following steps
Export Content screen appears see Figure
Configuring linksets using the Srem
Export Content fields
Creating a linkset
To create a linkset, perform the following steps
Portal Links screen appears see Figure
Click Add Add a Linkset dialog box appears see Figure
Add a Linkset
Linkset Configuration screen appears see Figure
Modifying a linkset
To modify a linkset, perform the following steps
Linkset Configuration fields
See Linksets and links on
Configuring links using the Srem
Creating an external link using the Srem
To create an external link, perform the following steps
Links screen appears see Figure
Click Add Add a Portal Link dialog box appears see Figure
Add a Portal Link fields
Creating an FTP link using the Srem
To create an FTP link, perform the following steps
Add a Portal Link FTP
Add a Portal Link FTP fields
Modifying external link settings using the Srem
External link Configuration screen appears see Figure
To modify a link, perform the following steps
External link Configuration fields
Reordering links using the Srem on
Modifying FTP link settings using the Srem
FTP link Configuration screen appears see Figure
Reordering links using the Srem
FTP link Configuration fields
Re Order Links screen appears see Figure
Re Order Links fields
Customizing the portal and user logon 320818-A
Chapter Configuring system settings
Configuring system settings
Configuring the cluster using the CLI
Cfg/sys
Roadmap of system commands
Parameter
Health interval
Show
Configuring system settings using the CLI
Cfg/sys followed by
Rsa server ID
Cfg/domain #/server/trace/tcpdump
Configuring the Nortel Snas 4050 host using the CLI
Cfg/domain #/server/trace/ssldump
Cfg/sys/host host ID
/cfg/sys/host #/interface #
Cluster Host menu includes the following options
Cfg/sys/host host ID followed by
Interface number
Hwplatform
Ports
Ports = 1,23
Halt
Reboot
Cfg/sys/cur command
Cfg/sys/host #/delete
Cfg/sys/host host ID/interface interface ID
Configuring host interfaces using the CLI
Viewing host information
Cfg/sys/host #/interface interface ID
Mode
Cfg/sys/host #/interface interface ID followed by
Vlanid tag
Failovertrunking
Cfg/sys/routes
Configuring static routes using the CLI
Primary port
Cfg/sys/host host ID/routes
Add IPaddr mask
Configuring host ports using the CLI
Cfg/sys/host #/interface #/routes followed by
Gateway
Cfg/sys/host #/port port followed by
Managing interface ports using the CLI
Host Port menu includes the following options
Cfg/sys/host #/interface interface ID/ports
Cfg/sys/accesslist
Configuring the Access List using the CLI
Cfg/sys/host #/ports command see
Interface Ports menu includes the following options
Date and Time menu displays
Configuring date and time settings using the CLI
Cfg/sys/accesslist followed by
Add IPaddr mask
NTP Servers menu displays
Managing NTP servers
Date and Time menu includes the following options
Cfg/sys/time followed by
Cfg/sys/time/ntp followed by
Configuring DNS servers and settings using the CLI
NTP Servers menu includes the following options
Cfg/sys/dns
Ttl ttl
Retransmit interval
Count count
Health interval
Managing DNS servers
Cfg/sys/dns/servers
Cfg/sys/dns/servers followed by
Move index number new index number
Configuring RSA servers using the CLI
RSA Servers menu displays Switch Software Release
Cfg/sys/rsa
Syslog Servers menu displays
Configuring syslog servers using the CLI
RSA Servers menu includes the following options
Cfg/sys/rsa followed by
Facility
Syslog Servers menu includes the following options
Cfg/sys/syslog followed by
Syslog.conf under Unix
Cfg/sys/adm
Configuring administrative settings using the CLI
Administrative Applications menu displays
Cfg/sys/adm followed by
Auth
Srsadmin
Audit
Telnet onoff
Cfg/sys/adm/srsadmin
Enabling TunnelGuard SRS administration using the CLI
Configuring Nortel Snas 4050 host SSH keys using the CLI
Cfg/sys/adm/srsadmin followed by
Draft-ietf-secsh-publickeyfile
Cfg/sys/adm/sshkeys
Cfg/sys/adm/sshkeys followed by
Knownhosts
SSH Known Host Keys menu includes the following options
Managing known hosts SSH keys using the CLI
SSH Known Host Keys menu displays
Cfg/sys/adm/sshkeys/knownhosts
Configuring Radius auditing using the CLI
About Radius auditing
About the vendor-specific attributes
NSNAS-SSL-Audit-Trail
Configuring Radius auditing
Map this string to the Vendor-Type value
Cfg/sys/adm/audit
Radius Audit Servers menu includes the following options
Managing Radius audit servers using the CLI
Radius Audit Servers menu displays
Cfg/sys/adm/audit/servers
Adds a Radius audit server to the configuration. You
Configuring authentication of system users using the CLI
Cfg/sys/adm/auth
Radius Authentication Servers menu displays
Fallback onoff
Cfg/sys/adm/auth/servers
Cfg/sys/adm/auth/servers followed by
Configuring the cluster using the Srem
Configuring system settings using the Srem
Select the System Configuration tab
System Configuration screen appears see Figure
Configuring a Nortel Snas 4050 host using the Srem
System Configuration fields
Hosts
Viewing and configuring TCP/IP properties
Host
Viewing and installing host licenses
Host fields
Viewing global licenses for all hosts
Describes the Global Licenses fields
Global Licenses fields
Viewing per domain licenses for all hosts
Describes the Per Domain Licenses fields
Per Domain Licenses fields
Viewing installed licenses for a particular host
Installing a license for a particular host
Install New License
Configuring host interfaces using the Srem
To continue, choose one of the following procedures
Select the System Hosts host Interfaces tab
Adding a host interface
To create a host interface, perform the following steps
Add an Interface fields
Configuring system settings Add an Interface fields
Click Apply New interface appears in the Interfaces table
Configuring an existing host interface
Interface fields
Link is transferred back to the primary port
Configuring static routes using the Srem
Removing a host interface
To delete a host interface, perform the following steps
Viewing static routes for a cluster
IP Routes
Viewing static routes for a host
Routes
Viewing static routes for an interface
Managing static routes
Adding a static route
Add Route fields
Removing a static route
Configuring host ports using the Srem
Ports
Port
Port fields
Managing interface ports using the Srem
Adding interface ports
Removing interface ports
Add a Port fields
Configuring the access list using the Srem
Select the System Access List tab
Adding an access list entry
Access List Table appears see Figure
Access List Table appears see on Click Add
Removing an Access List entry
Add Access Host dialog box appears see Figure
Add Access Host fields
Managing date and time settings using the Srem
Date & Time
Configuring the date and time settings
Select the System Date & Time tab
Date & Time fields
Adding an NTP server
Select the System Date and Time tab
Add NTP Server fields
Removing an NTP server
Configuring DNS settings using the Srem
Select the System DNS Client Settings tab
DNS Client Settings screen appears see Figure
DNS Client Settings fields
Configuring servers using the Srem
Managing syslog servers
Click Add Add Syslog Server dialog box appears see Figure
Adding a new syslog server
From this screen, complete the following tasks as necessary
Add Syslog Server fields
Reordering a new syslog server
Removing an existing syslog server
Adding a DNS server on Removing an existing DNS server on
Adding a DNS server
Select the System Servers DNS Servers tab
Add DNS Server fields
Removing an existing DNS server
Managing RSA servers
RSA Server Table
Select the System Servers RSA Server Table tab
To configure RSA servers, perform the following steps
Adding an RSA server
Add RSA Server fields
Removing an existing RSA server
Removing the RSA node secret
Describes the RSA Server fields
RSA Server fields
Importing sdconf.rec
Click Remove Secret Node
Select an RSA server from the RSA Server Table
Select the Import sdconf.rec tab
Import sdconf.rec screen appears see Figure
Configuring administrative settings using the Srem
Import sdconf.rec fields
Configuring SRS control settings using the Srem
Configuring Nortel Snas 4050 host SSH keys using
Select from one of the following tasks
Add SSH Key fields
Showing SSH keys
Show SSH Keys
Configuring system settings
Managing Nortel Snas 4050 and known host SSH keys
Click Generate SSH Keys
SSH Keys Hosts field
Adding an SSH key for a known host using the Srem
Add SSH Key
Managing Radius audit settings using the Srem
About the vendor-specific attributes
Configuring Radius auditing
Configuring Radius audit settings using the Srem
Radius audit Configuration
Describes the Add Audit Configuration fields
Add Audit Configuration fields
Managing Radius audit servers using the Srem
Select from the following tasks to manage the audit servers
Adding a new Audit Server
Click Add Add Audit Server dialog box appears see Figure
Add Audit Server fields
Removing an existing Radius audit server
Managing Radius authentication of system users using
Configuring Radius authentication of system users using
Radius Authentication Configuration fields
Managing Radius authentication servers using the Srem
Radius Server Table appears see Figure
Adding a Radius authentication server
Add Radius Server fields
Removing an existing Radius server
Configuring system settings 320818-A
Chapter Managing certificates
Managing certificates
Key and certificate formats
Supported key and certificate formats Sheet 1
320818-A
Installing certificates and keys
Creating certificates
Saving or exporting certificates and keys
Updating certificates
Managing private keys and certificates using the CLI
Roadmap of certificate management commands
Managing and viewing certificates and keys using the CLI
Cfg/cert cert id
Cfg/cert cert ID followed by
/cfg/cert #/show command
Generating and submitting a CSR using the CLI
Cert #/export command
Phrase
Cfg/cert #/request
CSR information
IPip-address
Emailemail-address
Email Address tester@dummyssltesting.com
Generating a CSR
Save the CSR to a file
Adding a certificate to the Nortel Snas 4050 using the CLI
Lines
Entire contents of the key, including
Add the certificate Enter the following command
Cfg/cert #/cert
Adding a certificate by pasting
Certificate added Certificate 2# apply
Adding a private key to the Nortel Snas 4050 using the CLI
Add the private key Enter the following command
Cfg/cert #/key
Adding a private key by pasting
Cfg/cert #/import
Certificate and key import information
Admin@hostname.isd
Anonymous
Displaying or saving a certificate and key using the CLI
Cfg/cert #/display
Copy the private key, certificate, or both, as required
Displaying a private key and certificate
Cfg/cert #/export
Certificate and key export information
About the formats, see Key and certificate formats on
Generating a test certificate using the CLI
Cfg/cert #/test
Managing private keys and certificates using the Srem
Viewing certificates using the Srem
Certificates screen
Select the Certificates Certificates tab
Creating a certificate using the Srem
To create a certificate, perform the following steps
Add a Certificate Component fields
Managing certificates
Generating and submitting a CSR using the Srem
To generate a CSR, perform the following steps
CA Request fields
Importing a certificate or key using the Srem
Import Certificate screen 320818-A
Displaying or saving a certificate and key using the Srem
Import Certificate fields
Display Certificate screen 320818-A
Display Certificates fields
Export Certificate screen 320818-A
Export Certificate fields
Viewing certificate information using the Srem
Viewing configuration details
Configuration screen appears see Figure
Describes the certificate Configuration fields
Certificate Configuration fields
Managing certificates Certificate Configuration fields
Viewing general information
Info screen appears see Figure
Describes the Info fields
Info fields
Viewing certificate subject settings
Managing certificates Info fields
Subject screen appears see Figure
Describes the Subject fields
Subject fields
Managing certificates Subject fields
Chapter Configuring Snmp
Configuring Snmp using the CLI
Configuring Snmp
Cfg/sys/adm/snmp
Roadmap of Snmp commands
Configuring Snmp settings using the CLI
Snmp menu displays Snmp menu includes the following options
Configuring the Snmp v2 MIB using the CLI
SNMPv2-MIBmenu displays
Cfg/sys/adm/snmp/snmpv2-mib
Cfg/sys/adm/snmp/snmpv2-mib followed by
Configuring the Snmp community using the CLI
SNMPv2-MIBmenu includes the following options
Cfg/sys/adm/snmp/community
Configuring SNMPv3 users using the CLI
Cfg/sys/adm/snmp/users user ID
Md5 Sha
Des Aes
Snmp User menu includes the following options
Cfg/sys/adm/snmp/users user ID followed by
Configuring Snmp notification targets using the CLI
Notification Target menu displays
Cfg/sys/adm/snmp/target target ID
Event menu displays
Configuring Snmp events using the CLI
Notification Target menu includes the following options
Version v1v2cv3
Options -b name
Event menu includes the following options
Cfg/sys/adm/snmp/event followed by
OID op value
Options -t name
OID value
Event
Comment name
Options -x name
OID
Notification
Configuring Snmp settings using the Srem
This section contains information about the following topics
Configuring Snmp using the Srem
To configure SNMP, perform the following steps
Snmp Configuration fields
Sonmp
Configuring Snmp targets using the Srem
Adding Snmp targets
To add an Snmp target, perform the following steps
Snmp Target Table appears see Figure
Click Add Add Snmp Target dialog box appears see Figure
Add Snmp Target 320818-A
Snmp Target fields
Target Settings screen appears see Figure
Managing Snmp targets
To manage Snmp targets, perform the following steps
Removing Snmp targets
Configuring SNMPv3 users using the Srem
Adding SNMPv3 users
To add an SNMPv3 user, perform the following steps
SNMPv3 User Table appears see Figure
Click Add Add SNMPv3 User dialog box appears see Figure
Add SNMPv3 User 320818-A
Add SNMPv3 User fields
User Settings screen appears see Figure
Managing SNMPv3 users
User Settings fields Sheet 1
Configuring Snmp User Settings fields Sheet 2
Removing SNMPv3 users
Configuring Snmp events using the Srem
Managing monitor events
To manage monitor events, select from the following tasks
Adding monitor events
To add monitor events, perform the following steps
Viewing configuration details of monitor events
Add a Monitor fields
Removing monitor events
Boolean monitors
To delete a monitor event, perform the following steps
Add a Monitor Boolean
Boolean monitor fields Sheet 1
Configuring Snmp Boolean monitor fields Sheet 2
Threshold monitors
Threshold monitor fields
Existence monitors
Existence monitor fields Sheet 1
Managing notification events
Existence monitor fields Sheet 2
Adding notification events
To add notification events, perform the following steps
Notification Table screen appears see Figure
Add a Notification Event
Add a Notification Event fields
Removing notification events
To delete a notification event, perform the following steps
659
Info
Roadmap of information and statistics commands
Viewing system information and performance statistics
Stats
Viewing system information using the CLI
Information menu displays
Information menu includes the following options
Info followed by
Domain ID
Kick domain ID
Switchid
Info/mac command
Username
Mac MACaddr
Info/ip command
Switch ID
Username-prefix
Local
Ethernet
Info/events
Viewing alarm events using the CLI
To view active alarms, use the following command
Info/events followed by
To view and download log files, use the following command
Viewing log files using the CLI
Viewing AAA statistics using the CLI
Logs menu displays Logs menu includes the following options
Total
Stats/aaa
Stats/aaa followed by
Isdhost host ID
Main# stats/aaa/dump
Viewing all statistics using the CLI
Viewing local information using the Srem
Stats/dump
Information screen appears see Figure
Describes the Information fields
Information fields
Viewing cluster information using the Srem
Viewing the controller list using the Srem
Describes the Controller List fields
Controller List fields
Viewing Sonmp topology information using the Srem
Describes the Sonmp State fields
Sonmp State fields
Viewing switch distribution using the Srem
Viewing port information using the Srem
Describes the Switch Distribution fields
Switch Distribution fields
Describes the Port Information fields
Port Information fields Sheet 1
Viewing license information using the Srem
Viewing global license information
Nortel Snas 4050, SSL is the only type of license
Viewing license information for a domain
Viewing session details using the Srem
Viewing active sessions using the Srem
Sessions screen
Describes the Sessions parameters
Sessions parameters
Viewing details for a particular session
Session Properties screen
Ending active user sessions
Describes the Session Properties parameters
Click KickOut
KickOut User fields
Viewing the number of active sessions using the Srem
Describes the Number of Sessions fields
Number of Sessions fields
Viewing alarms using the Srem
Viewing active alarms using the Srem
Active Alarms screen 320818-A
Describes the Active Alarms fields
Active Alarms fields
Downloading alarms using the Srem
Download Alarms screen 320818-A
Managing log files using the Srem
Describes the Download Alarms fields
Download Alarms fields
Viewing the log list using the Srem
Logs screen
Downloading log files using the Srem
Describes the Download fields
Download fields Sheet 1
Viewing AAA statistics using the Srem
Viewing AAA statistics for a host
Hosts table
License tab opens see on
Viewing License statistics
For a description of the fields, seeTable
License statistics Sheet 1
Viewing Radius statistics
Radius statistics 320818-A
Radius statistics
Viewing Local database statistics
Local DB statistics Sheet 1
Viewing Ldap statistics
Ldap statistics
Viewing AAA statistics for the domain
Statistics table
Select one of the following tasks
Viewing License statistics
For the Nortel Snas 4050, SSL is the only type of license
For a description of the fields, see Table
Viewing Radius Statistics Sheet 1
320818-A
Viewing Local database statistics
Logging Accepted Rejected
Viewing Ldap Statistics Sheet 1
Viewing Ethernet statistics using the Srem
Ethernet Interface table
Viewing Rx statistics
For a description of the fields seeTable
Viewing Rx statistics Sheet 1
Rx Frames Displays number of errors due to malformed packets
Viewing Tx statistics
Viewing Tx Statistics Sheet 1
Information, see Configuring host ports using the Srem
Page
Chapter Maintaining and managing the system
Managing and maintaining the system using the CLI
Maintaining and managing the system
Maint
Roadmap of maintenance and boot commands
Boot
Performing maintenance using the CLI
Maintenance menu displays
Maintenance menu includes the following options
Dumplogs protocol server filename all-isds?
Maint followed by
All-isds?
Mode
Starttrace tags
Domain ID output
Stoptrace
Backing up or restoring the configuration using the CLI
Cfg/dump passphrase
Ptcfg protocol
Configuration menu backup and restore commands
Cfg
Server filename passphrase
Passphrase
Cfg followed by
Gtcfg protocol
Dump passphrase
Boot followed by
Managing Nortel Snas 4050 devices using the CLI
Boot menu displays Boot menu includes the following options
Software
Cfg/sys/host #/delete command
Cfg/sys/host #/reboot command instead
Cfg/sys/host #/delete command see
Boot/software
Software Management menu includes the following options
Boot/software followed by
Activate command
Activate version
Upgradecomplete.pkg
Managing and maintaining the system using the Srem
Performing maintenance using the Srem
Ftp 10.0.0.1 pub/SSL-5.1.1
Dumping logs and status information using the Srem
Dumps
Starting and stopping a trace using the Srem
Click Dump
Dump fields
To start or stop a trace, perform the following steps
Start/Stop Trace fields
Checking configuration using the Srem
Click Check Configuration
Backing up or restoring the configuration using the Srem
Backup & Restore 320818-A
Backup & Restore fields
If you later restore the configuration, the Certificate
Managing software versions using the Srem
Image List
Describes the Image List fields
Following tasks are available from this screen
Image List fields
Select the System Boot Image List tab
Viewing details of the active software image
Activating a software image
Downloading images using the Srem
Removing an inactive software image
Maintaining and managing the system
Rebooting or deleting a Nortel Snas 4050 device using
Download Image fields
Reboot/Delete ISD Options
Downloading files using the Srem
File Download screen appears see Figure
Describes the File Download fields
File Download fields
Running Nortel Snas 4050 diagnostics using the Srem
Maintaining and managing the system File Download fields
Describes the Diagnostics fields
Diagnostics fields
Maintaining and managing the system 320818-A
Chapter Upgrading or reinstalling the software
Upgrading the Nortel Snas
Performing minor and major release upgrades
Upgrading or reinstalling the software
Downloading the software image using the CLI
Enter the host name or IP address of the server
Activating the software upgrade package
Admin@hostname/IP.isd
Nsnas
At the Software Management# prompt, enter
Log in again and verify the new software version
Reinstalling the software
Before you begin
Upgrading or reinstalling the software
Reinstalling the software from an external file server
Booting Login
Restarting Restarting system
Alteon WebSystems, Inc
Reinstalling the software from a CD
When the installation is complete, remove the CD and reboot
Run install-nsnas isd4050
Upgrading or reinstalling the software 320818-A
Chapter Command Line Interface
Connecting to the Nortel Snas
Command Line Interface
Establishing a console connection
Procedure
Console configuration parameters
Requirements
Enabling and restricting Telnet access
Establishing a Telnet connection
Establishing a connection using SSH
Enabling and restricting SSH access
Running Telnet
Running an SSH client
Accessing the Nortel Snas 4050 cluster
For more information, see How to get help on
User access levels
CLI Main Menu or Setup
Command line history and editing
Idle timeout
Command Line Interface
On page 780 illustrates the network configuration
Scenario
Configuration example
Network devices Sheet 1
Summarizes the VLANs for the Ethernet Routing Switch
Configuration example Network devices Sheet 2
VLANs for the Ethernet Routing Switch
Configure the network DNS server
Steps
Configure the network Dhcp server
Create a new Dhcp scope see Figure
Naming the new Dhcp scope 320818-A
Specify the IP address range for the Dhcp scope see Figure
Choosing to configure additional options 320818-A
Enter the IP address of the default gateway see Figure
Enter the IP address of the DNS server see Figure
Specifying the DNS server
Configure the network core router
Shows the Dhcp scopes created for use in this example
Configure the Ethernet Routing Switch 8300 using the CLI
Steps
Configuring the Red, Yellow, and Green VLANs
Configuring the Nortel Snas 4050 pVIP subnet
Configuring the VoIP VLANs
Enabling SSH
Enabling Nsna globally
Configuring the Nsna uplink filter
Configuring the Nsna ports
Add the uplink port
Configure the Ethernet Routing Switch
Setting the switch IP address
5510-48Tconfig#nsna nsnas 10.40.40.0/24
Configuring SSH
5510-48Tconfig# ssh
5510-48Tconfig#nsna vlan 240 color voip
5510-48Tconfig-if#exit
Configure the Nortel Snas
Configuring the login domain controller filters
5510-48Tconfig#nsna enable
Performing initial setup
10.40.40.1
Enter a password for the admin user
Completing initial setup
Enable SRS administration
Main# cfg/sys/adm/srsadmin/ena
Group 1# /cfg/domain 1/aaa/tg/quick
Adding the network access devices
Main# cfg/domain 1/sshkey/generate
TG#../group 1/tgsrs srs-rule-test
Import the public SSH key from the switch
Adding the Ethernet Routing Switch
Add the switch manually
Main# cfg/domain 1/switch 1 Creating Switch
Main# cfg/domain 1/switch 1/vlan/add yellow
Use the quick switch wizard
Main# cfg/domain 1/switch 2/sshkey/import
Switch Vlan# ../../vlan/add yellow
Switch 2# apply Changes applied successfully
Enabling the network access devices
Main# cfg/domain 1/switch 1/ena Switch 1# ../switch 2/ena
Domain Vlan# apply Changes applied successfully
Configuration example 320818-A
Appendix a CLI reference
Using the CLI
Global commands
Quit
Paste
Exit
Netstat
Command line history and editing
Command line history and editing options Sheet 2
Command stacking
You can use the following CLI command shortcuts
CLI shortcuts
NTP Servers# ../../dns/servers
Command abbreviation
Tab completion
Main# cfg/sys/time/ntp/list Main# c/sy/t/n/l
Using a submenu name as a command argument
Configuration# cur sys
IP addresses
Using slashes and spaces in commands
IP address and network mask formats
Network masks
Variables
Variables
CLI command reference
CLI Main Menu
Appendix a CLI reference
Certs
Information menu commands Sheet 1
Information menu
Sys
Statistics menu
Cfg/cert cert ID Name name
Configuration menu
Configuration menu commands Sheet 1
Cert
Auth #/adv Secondauth auth ID
Cfg/domain Name name
Auth ID Radiusldaplocal
Auth ID for Ldap
Auth #/ldap/activedire Truefalse
Cfg/domain #/aaa Servers
Auth #/ldap Searchbase
Expiredgro Group
Passwd user name
Auth #/local Password group
Cfg/domain #/aaa Add user name
Auth #/radius Vendorid vendor ID
Auth #/radius Vendortype vendor
Profile ID Access rule Number Linkset Del
Cfg/domain #/aaa Vendorid vendor ID
Type Ena Dis Cfg/domain #/aaa
Radacct Vpnattribu
Group #/extend # Del index number
Group #/linkset Del index number
Ena Dis Cfg/domain #/aaa List
Heartbeat interval
Cfg/domain #/aaa/tg Quick
Recheck interval
Cfg/domain #/adv Interface interface
Linkset ID Text text
Restore
Cfg/domain #/linkset Name name
Linkset #/link index Text text
Colors Color2 code
Content Server filename
Cfg/domain #/portal Color1 code
Lang Charset
Protocol
Cfg/domain #/server Sysloghost IPaddr
Adv/traflog Udpport port
Ssl2ssl3ssl23tls1
Switch #/dis
Cfg/domain #/switch Name name
Switch ID Type ERS8300ERS5500
Switch #/ena
Cfg/gtcfg protocol
Cfg/domain #/vlan Add name Vlan ID
Passphrase
Passphrase Cfg/lang Import protocol
Cfg/sys/adm Snmp
Cfg/sys/accesslist List
Add IPaddr mask
Sonmp onoff
Cfg/sys/adm/snmp Ena
Cfg/sys/adm/auth List
Shared secret
Versions v1v2cv3
Cfg/sys/adm/snmp Addmonitor
Snmpv2-mib SnmpEnable
Disabledenabled Cfg/sys/adm/snmp Ip IPaddr
Event Options -b name
Dis Cfg/sys/adm/sshkeys Generate
Cfg/sys/adm/snmp Name name
Users user ID Seclevel
Knownhosts
Interface #/ports Del port
Mode fullhalf Cfg/sys/host #/routes
Cfg/sys/dns/servers List
Add port Cfg/sys/host # List
SysLocatio
Cfg/sys/host Ip IPaddr
Host ID SysName name
Cfg/sys/rsa Rsaname name
Password confirm
Add IPaddr Cfg/sys/user Password old
Password new
Username Password user
Boot Software
Boot menu
Boot menu commands
Reboot Delete Boot/software Cur
Maint Dumplogs protocol
Maintenance menu
Maintenance menu commands
All-isds?
Chapter Troubleshooting
Troubleshooting tips
Enable Telnet or SSH access
Cannot connect to the Nortel Snas 4050 using Telnet or
Verify the current configuration
Check the Access List
Check the IP address configuration
# /cfg/cur sys
Cannot add the Nortel Snas 4050 to a cluster
Cannot contact the MIP
Add Interface 1 IP addresses and the MIP to the Access List
Main# /cfg/sys/accesslist/add
Enter network address IP address Enter netmask network mask
Nortel Snas 4050 stops responding
Telnet or SSH connection to the MIP
Console connection
Operator user password
User password is lost
Administrator user password
Root user password
User fails to connect to the Nortel Snas 4050 domain
Boot user password
Trace tools
Main# maint/starttrace
Sample output for the trace command
Tag Description Sample output
System diagnostics
Installed certificates
Network diagnostics
Main# /stats/dump
Cluster Host 1# cur
Main# /cfg/sys/cur
Main# /info/ethernet
Active alarms and the events log file
Error log files
Troubleshooting
Appendix B Syslog messages
Syslog messages by message type
Operating system OS messages
Lists the Emerg operating system messages
Lists the operating system Critical messages
Operating system messages Error
System Control Process messages
Lists the operating system Emerg messages
Lists the System Control Process Info messages
About alarm messages
Alarm severity and syslog level correspondence
System control process messages Info
System Control Process messages Alarm
Alarm
System Control Process messages Event
Audit/ena command
About event messages
With /cfg/sys/cur
Traffic Processing Subsystem messages
Lists the Traffic Processing Error messages
Traffic Processing messages Error Sheet 1
Lists the Traffic Processing Critical messages
Css error reason
Traffic Processing messages Warning
Traffic Processing messages Error Sheet 3
Lists the Traffic Processing Warning messages
Domain #/server/portal
Start-up messages
Lists the Traffic Processing Info messages
Traffic Processing messages Info
AAA subsystem messages
Lists the AAA Error messages
AAA messages Error
Lists the Start-up Info messages
AAA messages Info Sheet 1
Log value Message Category Contains
Nsnas subsystem messages
There are two categories of Nsnas subsystem messages
AAA messages Info Sheet 2
Lists the Nsnas Info messages
Lists the Nsnas Error messages
Nsnas Error
Nsnas Info Sheet 1
Nsnas Info Sheet 2
Syslog messages in alphabetical order
Lists the syslog messages in alphabetical order
Syslog messages in alphabetical order Sheet 1
Sys/adm/audit/ena command
Error Nsnas
Syslog messages in alphabetical order Sheet 3
Info AAA
Error AAA
Syslog messages in alphabetical order Sheet 5
Authenticate is set to off
Cfg/domain #/server/portal
Syslog messages in alphabetical order Sheet 7
Root filesystem repaired
Syslog messages in alphabetical order Sheet 9
Unable to use the certificate for
Supported MIBs
Following MIBs are supported by the Nortel Snas
Appendix C Supported MIBs
ANAifType-MIB
SNMPv2-MIB
Supported MIBs Sheet 1
Supported MIBs Sheet 2
ALTEON-ISD-SSL-MIB
CLI, using the /cfg/sys/adm/snmp/target command
Appendix C Supported MIBs Supported MIBs Sheet 3
Describes the traps supported by the Nortel Snas
Use the CLI command /cfg/sys/adm/snmp/snmpv2-mib
Supported traps
Supported traps
Appendix C Supported MIBs 320818-A
Appendix D Supported ciphers
Supported ciphers
Appendix D Supported ciphers
Install All Administrative Tools Windows 2000 Server
Register the Schema Management dll Windows Server
Click Start and select Run
Nortel Secure Network Access Switch 4050 User Guide
Permit write operations to the schema Windows 2000 Server
Create a shortcut to the console window
Select a Title for the Program page displays
Nortel Secure Network Access Switch 4050 User Guide
Create the new class
Add isdUserPrefs attribute to nortelSSLOffload class
Add the nortelSSLOffload Class to the User Class
320818-A
Appendix F Configuring Dhcp to auto-configure IP Phones
Configuring IP Phone auto-configuration
Appendix F Configuring Dhcp to auto-configure IP Phones
Creating the Dhcp options
Dhcp Management Console
Predefined Options and Values dialog box opens see Figure
Click Add Option Type dialog box opens see on
Option Type dialog box
Option Type dialog box field values for Vlan Information
Scope Options dialog box displays see Figure
Scope Options dialog box
Call Server Information string parameter values
Setting up the IP Phone
Vlan ID Information string parameter values
Page
Configuring the logon script
Create the logon script see Creating a logon script on
Using Windows, open a plain text editor, such as Notepad
Creating a logon script
Creating the script as a batch file
Assigning the logon script
Creating the script as a VBScript file
Double-clickDefault Domain Policy
Right-click the Default Domain Policy and select Edit
On the Group Policy tab, click Open
Appendix H Software licensing information
GNU General Public License
Appendix H Software licensing information
Appendix H Software licensing information
Appendix H Software licensing information
Apache Software License, Version
Bouncy Castle license
Symbols
Index
Index
Index
DNS
Index
Local authentication database Add users
Cannot contact
Index
See also SRS rule
SSL
Index
Index