![](/images/backgrounds/154478/bg5.png)
5
2 TheContivityExtranet4600Switch
TheNortelNetworksContivityExtranetSwitch4600(referredtoasthemodule,or
Switchinthisdocument)providesascalable,secure,manageableremoteaccessserver
thatmeetsFIPS140-1level2requirementsforamultiple-chipstandalonemodule.The
followingsectionsdescribehowtheSwitchaddressesFIPS140-1requirements.
2.1 CryptographicModule
TheContivityExtranetSwitchcombinesremoteaccessprotocols,security,
authentication,authorization,andencryptiontechnologiesinasinglesolution.
Figure1–TheContivityExtranet4600Switch
TheSwitchcansupportupto5000simultaneoususersessions,allowingeachuserto
exerciseavarietyofsecureservices.TheSwitchsupportsanumberofsecurenetwork-
layeranddata-link-layerprotocolsincludingInternetProtocolSecurity(IPSec),Point-to-
PointTunnelingProtocol(PPTP),LayerTwoTunnelingProtocol(L2TP),andLayerTwo
Forwarding(L2F).ThearchitecturefortheSwitchisuser-centric,whereanindividual
userorgroupofuserscanbeassociatedwithasetofattributesthatprovidecustomaccess
totheExtranet.Ineffect,youcancreateapersonalizedextranetbasedonthespecific
needsofauserorgroup.TheuniqueQualityofService(QoS)featuresincludecall
administrationandpacketforwardingpriorities,andsupportforResourceReSerVation
Protocol(RSVP).
2.2 ModuleInterfaces
TheinterfacesfortheSwitcharelocatedontherearpanelasshowninFigure2.