40 Engineering guidelines

LAN configuration

ICB customers should select one of the following alternatives for BUI access:

users and administrators access the ICB from the global internet (the new capability of MICB Release 3)

users and administrators access the ICB from the customer LAN/intranet only (existing MICB Release 2 capability)

Global internet access

Global internet access requires careful configuration of security elements. Figure 6 shows a sample configuration.

Figure 6

Global internet access example

 

World Wide

 

 

 

Web

 

 

Firewall

 

 

 

 

ICB BUI

 

 

 

Green and

 

 

 

Red LAN

 

 

ICB BUI

ICB4

 

 

connection

 

 

 

 

 

ICB BUI

 

 

 

C-LAN

E-LAN

 

 

10/100 Base-T or 100 Base-T

10/100 Base-T

 

 

 

Router

 

 

 

 

ICB

4

 

 

(s)

 

 

card

 

 

 

 

PBX E-LAN

 

 

 

connection

 

 

ICB BUI

ICB BUI

IPE Module

 

 

G100277

In typical configurations, the firewall does not allow any kind of access from the World Wide Web into the C-LAN. Only access from the C-LAN

hosts to the World Wide Web is allowed (for example, HTTP and FTP).

553-3001-358/555-4001-135 Standard 02.00 July 2006

Page 40
Image 40
Nortel Networks 553-3001-358, 555-4001-135 manual LAN configuration, Global internet access example