Nortel NN46110-602 manuel d'utilisation

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230

Aller à la page of

Un bon manuel d’utilisation

Les règles imposent au revendeur l'obligation de fournir à l'acheteur, avec des marchandises, le manuel d’utilisation Nortel NN46110-602. Le manque du manuel d’utilisation ou les informations incorrectes fournies au consommateur sont à la base d'une plainte pour non-conformité du dispositif avec le contrat. Conformément à la loi, l’inclusion du manuel d’utilisation sous une forme autre que le papier est autorisée, ce qui est souvent utilisé récemment, en incluant la forme graphique ou électronique du manuel Nortel NN46110-602 ou les vidéos d'instruction pour les utilisateurs. La condition est son caractère lisible et compréhensible.

Qu'est ce que le manuel d’utilisation?

Le mot vient du latin "Instructio", à savoir organiser. Ainsi, le manuel d’utilisation Nortel NN46110-602 décrit les étapes de la procédure. Le but du manuel d’utilisation est d’instruire, de faciliter le démarrage, l'utilisation de l'équipement ou l'exécution des actions spécifiques. Le manuel d’utilisation est une collection d'informations sur l'objet/service, une indice.

Malheureusement, peu d'utilisateurs prennent le temps de lire le manuel d’utilisation, et un bon manuel permet non seulement d’apprendre à connaître un certain nombre de fonctionnalités supplémentaires du dispositif acheté, mais aussi éviter la majorité des défaillances.

Donc, ce qui devrait contenir le manuel parfait?

Tout d'abord, le manuel d’utilisation Nortel NN46110-602 devrait contenir:
- informations sur les caractéristiques techniques du dispositif Nortel NN46110-602
- nom du fabricant et année de fabrication Nortel NN46110-602
- instructions d'utilisation, de réglage et d’entretien de l'équipement Nortel NN46110-602
- signes de sécurité et attestations confirmant la conformité avec les normes pertinentes

Pourquoi nous ne lisons pas les manuels d’utilisation?

Habituellement, cela est dû au manque de temps et de certitude quant à la fonctionnalité spécifique de l'équipement acheté. Malheureusement, la connexion et le démarrage Nortel NN46110-602 ne suffisent pas. Le manuel d’utilisation contient un certain nombre de lignes directrices concernant les fonctionnalités spécifiques, la sécurité, les méthodes d'entretien (même les moyens qui doivent être utilisés), les défauts possibles Nortel NN46110-602 et les moyens de résoudre des problèmes communs lors de l'utilisation. Enfin, le manuel contient les coordonnées du service Nortel en l'absence de l'efficacité des solutions proposées. Actuellement, les manuels d’utilisation sous la forme d'animations intéressantes et de vidéos pédagogiques qui sont meilleurs que la brochure, sont très populaires. Ce type de manuel permet à l'utilisateur de voir toute la vidéo d'instruction sans sauter les spécifications et les descriptions techniques compliquées Nortel NN46110-602, comme c’est le cas pour la version papier.

Pourquoi lire le manuel d’utilisation?

Tout d'abord, il contient la réponse sur la structure, les possibilités du dispositif Nortel NN46110-602, l'utilisation de divers accessoires et une gamme d'informations pour profiter pleinement de toutes les fonctionnalités et commodités.

Après un achat réussi de l’équipement/dispositif, prenez un moment pour vous familiariser avec toutes les parties du manuel d'utilisation Nortel NN46110-602. À l'heure actuelle, ils sont soigneusement préparés et traduits pour qu'ils soient non seulement compréhensibles pour les utilisateurs, mais pour qu’ils remplissent leur fonction de base de l'information et d’aide.

Table des matières du manuel d’utilisation

  • Page 1

    Version 7.00 Part No. NN4611 0-602 315900-E Rev 01 February 2007 Document status: Standard 600 Technology Park Drive Billerica, MA 01821-4130 Nor tel VPN Router T r oub leshooting[...]

  • Page 2

    2 NN46110-602 Copyright © 2007 Nortel Ne tworks. All rights reserved. The information in this document is subj ect to change without notice. The statements, config urations, technical data, and recommendations in this docume nt are believ ed to be accura te and reliable, but are presen ted without e xpress or implied warranty . Users must take ful[...]

  • Page 3

    3 Nortel VPN Router Tr oublesho oting Portions of the code in this softw are product may be Copyright © 1988, Re gents of the Univ er sity of California. All rights reserved . Redistribution and use in so urce and binary forms of such portions are permitted, pr ovided tha t the abov e copyright notice and this paragraph are dupl icated in all such[...]

  • Page 4

    4 NN46110-602 3. Limitation of Remedies. IN NO EVENT SHALL NOR TEL NETWORKS O R ITS A GENTS OR SUPPLIERS BE LIABLE FOR ANY OF THE FOLLO WING: a) DAMA GES B A SED ON ANY THIRD P AR TY CLAIM; b) LOS S OF , OR D AMAGE T O, CUSTOMER’S RECORDS, FILES OR D A T A; OR c) DIRECT , INDIRECT , SPECIAL, INCIDENT AL, PUNITIVE, OR CONSEQUENTIAL D AMA GES (INCL[...]

  • Page 5

    5 Nor tel VPN Router T roublesh ooting Contents Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Bef ore you begin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 T e xt conv e ntions . . . . . . . . . . . . . . . . . .[...]

  • Page 6

    6 Contents NN46110-602 Configuring SNMP traps t o send notification when an IP address pool reaches the configured threshold . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32 Chapter 2 Status and logging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 Sessions[...]

  • Page 7

    Contents 7 Nor tel VPN Router T roublesh ooting Using SFTP to transfer back up files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 Stopping th e transf er of b ack up files u sing SFTP . . . . . . . . . . . . . . . . . . . . . . 59 Disabling new logins . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . [...]

  • Page 8

    8 Contents NN46110-602 System pr oblems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96 Solving routin g problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98 Client address redistr ibution prob lems . . . . . . . . . . . . . . . . . . . . . .[...]

  • Page 9

    Contents 9 Nor tel VPN Router T roublesh ooting Viewing a pack et c apture out put file on a PC . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 Installing Ethereal software . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 Saving, downloading, and viewing PCAP files . . . . . . . . . . . . . . . . . . .[...]

  • Page 10

    10 Contents NN46110-602 Appendix B Using serial PPP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165 Establishing a serial PPP connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165 Setting up a Dial-Up Ne tworking connectio n . . . . . . . . . . . . . . . . . . . . . . [...]

  • Page 11

    Contents 11 Nor tel VPN Router T roublesh ooting IPX client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 223 Windows 95 and Win dows 98 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224 Windows NT . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . [...]

  • Page 12

    12 Contents NN46110-602[...]

  • Page 13

    13 Nor tel VPN Router T roublesh ooting Figures Figure 1 Admin > SN MP T raps window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Figure 2 Event logs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42 Figure 3 Capture an d display filters . . . . . . . . . . . . . . . . . [...]

  • Page 14

    14 Figures NN46110-602[...]

  • Page 15

    15 Nor tel VPN Router T roublesh ooting Ta b l e s T able 1 Field IDs for data collection records . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40 T able 2 T roubleshooting t ools . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71 T able 3 T rap categor ies . . . . . . . . . . . . . . . . . . . . . . . . [...]

  • Page 16

    16 Tables NN46110-602[...]

  • Page 17

    17 Nortel VPN Ro uter Trouble shooting Preface This guide prov ides information about ho w to manage and troubleshoot the Nortel VPN Router . Bef o re y ou begin This guide is for network managers wh o monitor and mainta in the Nortel VPN Router . This guide assumes that you ha ve e xperience with system administration and familiarity with netw ork[...]

  • Page 18

    18 Pref ace NN46110-602 braces ({}) Indicate required elements in syntax descriptions where there is more than one optio n. Y ou must ch oose only one of the options. Do no t type the braces when entering the command. Example: If the command syntax is ldap-server source {external | internal} , you must enter either ldap-server source external or ld[...]

  • Page 19

    Preface 19 Nortel VPN Router Tr oublesho oting Acr o n yms This guide uses the follo wing acronyms: vertical line ( | ) Separates choices for command keywords and arg uments. Enter only one of the cho ices. Do not type the vertical line when entering the command. Example: If the command syntax is terminal paging { off | on } , you enter either term[...]

  • Page 20

    20 Pref ace NN46110-602 L2TP Layer 2 T unneling Protocol LAN local area network LD AP Lightweight Directory Access Proto col N A T Network Address T ranslation OSI Open Systems Interconnection OSPF Open Shortest Path First P AP Passw ord Authentication Protocol PCAP packet capture PDN public data netw ork POP point of presence PPP Point-to-Point Pr[...]

  • Page 21

    Preface 21 Nortel VPN Router Tr oublesho oting Related publications For more information about the Nort el VPN Router , see the following publications: • Release notes pro vide the latest inform ation, including brief descriptions of the ne w features, problems f ixed in th is release, and kno wn problems and workarounds. • Nortel VPN Router Co[...]

  • Page 22

    22 Pref ace NN46110-602 Har d-copy tec hnical manuals Y ou can print selected technical manuals and release notes free, directly from the Internet. Go to www .nortelnetworks.com/documentation , find the product for which you need documentation, then lo cate the specif ic category and model or version for your har dware or software p roduct. Use Ado[...]

  • Page 23

    Preface 23 Nortel VPN Router Tr oublesho oting Getting help fr om the Nor tel W eb site The best way to get techni cal support for Nortel products is from the Nortel T echnical Support W eb site: www .nortel.com/support This site provides quick access to softw are, documentation, bulletins, and tools to address issues with Nortel prod ucts. From th[...]

  • Page 24

    24 Pref ace NN46110-602 Getting help thr ough a Nor t el distributor or reseller If you purchased a service contract for you r Nortel product from a distrib utor or authorized reseller , contact the technica l support staf f for that distrib u tor or reseller .[...]

  • Page 25

    25 Nortel VPN Ro uter Trouble shooting Ne w in this release The follo wing section details what is new in Nortel VPN Router T r oubleshooting for Release 7.0. Features See the follo wing sections for in formation about feature changes: • SNMP traps when an IP address pool reaches the configured threshold • Automatic backups • PCAP enhancement[...]

  • Page 26

    26 New in this release NN46110-602 A utomatic backups Y ou can no w back up a file or a directory , as well as trigger a backup, when a file changes. Previously , you could only back up system, configuration, and log files. Y ou can use either the graphical user interface (GUI) or the command line interface (CLI) to conf igure automated backup. Y o[...]

  • Page 27

    27 Nortel VPN Ro uter Trouble shooting Chapter 1 VPN Router administration This chapter introduces administrator se ttings, tools, system conf iguration, and f ile management. It also include s informat ion about SNMP traps. Administrator settings The VPN Router supports multiple administ rators. Y ou can assign dif ferent rights to allo w or prev [...]

  • Page 28

    28 Chapter 1 VPN Router ad ministration NN46110-602 Y ou use the Administrator Settin gs windo w to do the following: • change the primary ad ministrator user ID an d password • control the Administrator Idle T i meout Setting for all administrators • control the default language • control the serial port settings There is only one primary [...]

  • Page 29

    Chapter 1 VPN Router administration 29 Nortel VPN Router Tr oublesho oting Dynamic pass w ord T wo types of administra tiv e use rs exist on the VPN Router: • one super -user (Administrator) • as many administrati ve users as needed There is dynamic password support fo r administrati ve users only . The Administrator still requires a static pas[...]

  • Page 30

    30 Chapter 1 VPN Router ad ministration NN46110-602 The T race route tool measures a network ro und-trip delay . Messages are sent per hop and the w ait occurs between each message. If the address is unreachable, it uses the follo wing formula to determin e ho w long it takes for the T raceroute to time out. maximum hops (30) x the wait timeout (5)[...]

  • Page 31

    Chapter 1 VPN Router administration 31 Nortel VPN Router Tr oublesho oting Simple Netw ork Management Protocol (SNMP) Use the Admin > SNMP window to do the follo w ing: • designate the remote SNMP management stations that are authorized to send SNMP Gets to the VP N Router • enable specif ic MIBs SNMP counters meas ure pack et attributes bas[...]

  • Page 32

    32 Chapter 1 VPN Router ad ministration NN46110-602 The traps displayed on the group window s—in particular the Hardware T rap Conf iguration and the Service T rap Conf iguration windows—reflect the hardw are and software av ailable on your VPN Router. F o r examp le, if you ha ve a VPN Router with no W AN interface cards, the traps for W AN in[...]

  • Page 33

    Chapter 1 VPN Router administration 33 Nortel VPN Router Tr oublesho oting Figure 1 Admin > SNMP T raps windo w 2 Enter a host name o r IP address in the Ho st Name or IP Addr ess text box. 3 Enter a name in the Community Name te xt box. 4 Click Enable . 5 Click OK . 6 Under the Tr a p G r o u p s section on the SNMP T raps windo w , click Conf [...]

  • Page 34

    34 Chapter 1 VPN Router ad ministration NN46110-602 T o configure the amount: CES(config)# ip local pool ex hausted-amount <amount>[...]

  • Page 35

    35 Nortel VPN Ro uter Trouble shooting Chapter 2 Status and logg ing The Status windo ws sho w which users are logged on, their traff ic demands, and a summary of the VPN Router’ s hardware configurat ion, including a v ailable memory and disk space. The statu s windo ws include: • Sessions •R e p o r t s •S y s t e m • Health check • S[...]

  • Page 36

    36 Chapter 2 Status and logging NN46110-602 Most e vents are sent to the e vent log f irs t. Significant e vents from the e vent log are sent to the system log. (N ot all data that the system log sa ves comes from the e vent log.) From the system log, the VPN Router f ilters security entries for the security log and conf iguration entries fo r the [...]

  • Page 37

    Chapter 2 St atus and logging 37 Nortel VPN Router Tr oublesho oting If you ha ve multiple VPN Routers throughou t the world, use the Greenwich Mean T ime (GMT) standard to synchronize the v arious log files so that the timestamps are directly comparable. System The Status > System windo w shows the VPN Router’ s up time, software and hardware[...]

  • Page 38

    38 Chapter 2 Status and logging NN46110-602 Accounting The accounting log provides informatio n about user sessi ons. This log pro vides last and first names, user ID, tunnel ty pe, session start and end dates, and the number of packets and b ytes transferre d. Y ou can use most of these fields to search the log. Accounting recor ds Accounting reco[...]

  • Page 39

    Chapter 2 St atus and logging 39 Nortel VPN Router Tr oublesho oting The data collection system stores records in te xt-bas ed files stored in the system/ dclog subdirectory . The system stores the most recent 60 days of data. The system stores daily files, summary files, and summary history f iles. Ongoing administration tasks include monitoring t[...]

  • Page 40

    40 Chapter 2 Status and logging NN46110-602 • Summary file that al ways has exactly f i ve records containing summary data in a f ile called summary .dc. These values are used to gi ve historical graphs and reports about specif ic v alues. • Summary history file that contains rec o rds representing cumu lati ve daily data for the most recent 60[...]

  • Page 41

    Chapter 2 St atus and logging 41 Nortel VPN Router Tr oublesho oting Logs The VPN Router has se veral logs that prov ide dif ferent le vels of information. The logs are stored in te xt files and indicate what happened, when the e vent occu rred, and the IP address and user ID of the person causing the e vent. Event log The e vent log is a detailed [...]

  • Page 42

    42 Chapter 2 Status and logging NN46110-602 As the e vent log adds inform ation, the oldest entries are o verwritten. The e vent log retains the latest 2000 entries and dis cards old entries when it is refreshed. T o configure e vent logging: 1 Select Status > Even t Log . The Event Log wi ndow appears. (Figure 2) Figure 2 Ev ent logs 2 In the S[...]

  • Page 43

    Chapter 2 St atus and logging 43 Nortel VPN Router Tr oublesho oting Figure 3 Capture an d display filters 5 Y ou conf igure the capture f ilter and di splay filter using Entity-Subentity or Se verity . T o configure the capture f ilter or display fi lter: a Click Conf igure Captur e Entity or Configur e Display Entity . Figure 4 sho ws the Conf ig[...]

  • Page 44

    44 Chapter 2 Status and logging NN46110-602 Figure 4 Configure Display Entity b Select an Entity from the list. c Select a Subentity from the list. d Click Add to add the selected entity-s ubentity pair to the f ilter . e Click Accept to complete your changes to the filter . f Click Remove to delete a sel ected item from the list. g Click Conf igur[...]

  • Page 45

    Chapter 2 St atus and logging 45 Nortel VPN Router Tr oublesho oting System log The system log contains all system ev ents that are considered significant enough to be written to disk, including those disp layed in the conf iguration and security logs. Events that appear in the system log include: • LD AP acti vity • conf iguration acti vity ?[...]

  • Page 46

    46 Chapter 2 Status and logging NN46110-602 • communications with servers •L D A P • Remote Authentication Dial-In User Service (RADIUS) Configuration log The Conf iguration log records all conf iguration changes. For e xample, it tracks adding, modifying, or deleting the follo wing conf iguration parameters: • group or user profiles • LA[...]

  • Page 47

    47 Nortel VPN Ro uter Trouble shooting Chapter 3 Administrative tasks This chapter describes administrativ e task s that help you operate the VPN Router. These tasks provide details on scheduling backup s, upgrading the software image, saving conf iguration files, performing f ile maintenance, creating recov ery diskettes, and system shutdo wn. Shu[...]

  • Page 48

    48 Chapter 3 Administrative tasks NN46110-602 Reco ver y In the unlikely e vent that there is a hard disk crash, use the Reco very windo w to configure a reco very diskette to restore the software image and f ile system to the hard dri ve of the VPN Router. The recov ery diskette is included with your VPN Router. Y ou can also use this windo w to c[...]

  • Page 49

    Chapter 3 Administrative tasks 49 Nortel VPN Router Tr oublesho oting This supplies a minimal conf iguration u tility so that you can vie w the VPN Router from a W eb browser . 3 In the W eb bro wser , enter the management IP address of the VPN Rou ter. The Recov ery Diskette window appears, which you can use to: — restore the factory def ault co[...]

  • Page 50

    50 Chapter 3 Administrative tasks NN46110-602 • Select Restor e Factory Conf iguration , then cli ck Restor e to return the VPN Router to its original factory def ault co nfiguration. This erases da ta contained in flash memory and also in the configuration f ile. An online message specifies the result of the Factory Configuration reset action. ?[...]

  • Page 51

    Chapter 3 Administrative tasks 51 Nortel VPN Router Tr oublesho oting Y ou can use a ne w factory default softw a re image and f ile system to restore the VPN Router’ s hard disk. Specify the name or address and path of th e network f ile server ont o which the softwa re from the Nortel CD is installed. T o view the serial numb er when the VPN R [...]

  • Page 52

    52 Chapter 3 Administrative tasks NN46110-602 12 Click Synchr onize to immediately syn chronize the primary and second ary disks. Thereafter , the disks auto matically synchronize e very hour . 13 From the list, select the driv e on which you want to upgrade the system boot software. 14 If the system boot sect or is corrupted, click Upgrade to re w[...]

  • Page 53

    Chapter 3 Administrative tasks 53 Nortel VPN Router Tr oublesho oting Y ou must create a directory on the File T ransfer Protocol (FTP) or Secure File T ransfer Protocol (SFTP) server before running automatic backup. If you specify a path in the Admin > Auto backup windo w and the direct ory does not exist on the FTP or SFTP serv er , the automa[...]

  • Page 54

    54 Chapter 3 Administrative tasks NN46110-602 T o enable automatic backup when a file or a directory changes: 1 Select Admin > A uto Backup . The Automatic Backup window appears. (Figure 6) Figure 6 A utomatic ba ckup window 2 Click Enabled to enable the associated host backup file serv er . 3 Enter the backup f ile server host name or IP addres[...]

  • Page 55

    Chapter 3 Administrative tasks 55 Nortel VPN Router Tr oublesho oting 7 T o back up at certain interv als of time, click Interval and in the Interv al text box specify in hours the time peri od af ter which the system automatically backs up changed files. The minimum in terval is 1 hour , and the maximum is 8064 (336 days). The default is 5 hours. [...]

  • Page 56

    56 Chapter 3 Administrative tasks NN46110-602 Figure 7 Specific A utomatic Back up window 14 T o see the list of f iles for a directory , highlight the name of a d irectory and click Display . The f iles for that directory appear in the Files list. 15 T o select the f ile that you w ant to back up, highli ght the name of the f ile and click Select [...]

  • Page 57

    Chapter 3 Administrative tasks 57 Nortel VPN Router Tr oublesho oting 22 Click Backup to run the backup to each enabled server no w . This action also synchronizes the hard disk dri ves when there is more than one hard driv e in a de vice. Otherwise, the hard disk s synchronize automa tically ev ery 60 minutes. A ne w windo w appears with the backu[...]

  • Page 58

    58 Chapter 3 Administrative tasks NN46110-602 Backing up specific f iles and directories T o back up specific f iles and dire ctories, with the option to delete them after backup, e nter: exception backup advanced {1 | 2 | 3} {full | partial | specific [<file-path> ] [overwrite] [ delete]} For e xample, to set the target of the ex ception bac[...]

  • Page 59

    Chapter 3 Administrative tasks 59 Nortel VPN Router Tr oublesho oting Stopping the bac kup of changes to specific files or directories T o stop backing up the chan ges for specif ic files or directories for a particular server , ente r: no exception backup advanced {1 | 2 | 3} specific For e xample, to stop backing up files th at changed in backup [...]

  • Page 60

    60 Chapter 3 Administrative tasks NN46110-602 Disabling ne w logins Y ou can pre vent clients from connecting to the VPN Router without affecting the users currently connected b y using this feature to disable ne w logins. When ne w logins is disabled, no ne w IP se c connections are established. T o disable ne w logins: 1 Select Admin > Shutdo [...]

  • Page 61

    Chapter 3 Administrative tasks 61 Nortel VPN Router Tr oublesho oting • Nortel W eb site • your o wn FTP site if you previously do wnloaded the software from the Nortel FTP site • Nortel software CD If an FTP serv er does not use standard FTP por t numbers, you cannot use it to do wnload FTP servers for Nortel softw are . For more information[...]

  • Page 62

    62 Chapter 3 Administrative tasks NN46110-602 Before you upgrade your softwa re, use one of the follo wing methods to make sure there is enough av ailable disk space: • From the GUI, select Status > Statistics > File System . The last line lists the free space on the disk. • From the CLI, enter show status statistics system f ile-system .[...]

  • Page 63

    Chapter 3 Administrative tasks 63 Nortel VPN Router Tr oublesho oting 5 Ty p e 5 ( Create A User Control Tunnel (IPsec) Profile ). 6 Enter the user ID that you plan to use to log in remotely to the VPN Router . 7 Enter the password that you plan to use. 8 Enter the password ag ain. 9 When you are prompted for an IP addre ss, you can enter a static [...]

  • Page 64

    64 Chapter 3 Administrative tasks NN46110-602 b Click Backup to start the backup immediately . This sav es your entire hard dri ve, incl uding the LD AP and configuration f iles. Retrieving the ne w software For V ersion 4.80 and later , the VPN Ro uter release image is av ailable in a compressed .zip f ile so that each indi vidu al f ile does not [...]

  • Page 65

    Chapter 3 Administrative tasks 65 Nortel VPN Router Tr oublesho oting Figure 9 sho ws an example upgrade to V04_80.114 from server 192.32.250.64. The f ile V04_80.114.tar .gz must be located at the root of the FTP directory . Figure 9 FTP menu e xample When you FTP to the FTP serv er from another PC, you see the location of the file. D:ftp>ftp [...]

  • Page 66

    66 Chapter 3 Administrative tasks NN46110-602 • User ID: type the login ID required to gain access to the FTP server where the ne w VPN Router software is located. • Passw ord and Confirm Passw o rd: type the password (twice) that corresponds to the user ID you just entered. 4 After f illing in all the required fields, click Retriev e new versi[...]

  • Page 67

    Chapter 3 Administrative tasks 67 Nortel VPN Router Tr oublesho oting — Response Timeout f or RADI US Accounting Server — Exter nal RADIUS Accounting Serv er b Click OK . Applying the software After you start the apply p rocess, do not make any queri es on the VPN Router. Queries try to access f iles and can cause problems during the upgrade pr[...]

  • Page 68

    68 Chapter 3 Administrative tasks NN46110-602 6 Select a system shutdo wn type of None and cl ick OK . Y ou hav e su ccessfully upgraded yo ur switch.[...]

  • Page 69

    69 Nortel VPN Ro uter Trouble shooting Chapter 4 T r oubleshooting This chapter introduces the concepts and practices of advanced network configuration and troubleshooting fo r the Nortel VPN Router. Its purpo se is two-fold: to pro vide conf iguration details to consult when setting up or modifying the extranet, and to serv e as a res ource when d[...]

  • Page 70

    70 Chapter 4 Troub leshooting NN46110-602 T roubleshooting remote access problems typica lly starts at the client end when the remote user cannot establish a connection, loses a connection, or has dif ficulty bro wsing the network or printing. Wh en connecti vity problems occur and the source of the problem is unkno wn, it is usually best to follo [...]

  • Page 71

    Chapter 4 Troubleshooting 71 Nortel VPN Router Tr oublesho oting Microsoft Point-to-Point T unneling Pr oto col (PPTP) Dial-Up Ne tworking Monitor provides network statistics on device, connection, and network protocols that help monitor traf fic flo w and a ssess PPTP connection performance. For more information on the PPTP Dial-Up Networking Moni[...]

  • Page 72

    72 Chapter 4 Troub leshooting NN46110-602 Solving connectivity pr oblems This section lists man y of the common co nnecti vity problems that occur and their recommended so lutions. Problems, and some typ ical client user resp onses that can help with diagnosis, are categorized as follo ws: Modem and dial-up prob lems “I cannot bro wse the W eb or[...]

  • Page 73

    Chapter 4 Troubleshooting 73 Nortel VPN Router Tr oublesho oting 1 Confirm that the modem is attached and working properly by running a terminal emulation program at thei r remote workstation, such as, Hyperterminal*, and issuing the A T command. If the response is AT O K , the modem is operating correctly . 2 V erify that there is a PPP dial-up co[...]

  • Page 74

    74 Chapter 4 Troub leshooting NN46110-602 Remote host not responding Cause: This indicates that the VPN Router ne ver respon ded to the IPsec connection attempt or that User Datagram Protocol (UDP) port 500 is blocke d. Action: V erify that the VPN Router is accessible by pinging the host name or IP address that you f illed in the destin ation fiel[...]

  • Page 75

    Chapter 4 Troubleshooting 75 Nortel VPN Router Tr oublesho oting Action: V erify that the user name you entere d is correct and retype the password before trying t he connection ag ain. No pr oposal chosen Cause : The VPN Router you are connecting to is not configured to handle the authentication method conf igured un der the current connection p r[...]

  • Page 76

    76 Chapter 4 Troub leshooting NN46110-602 Action: Click Connect to re-establish the extranet connection. If this works, the connection was probably lost due to th e Idle T imeout conf igured on the VPN Router. If no data is transferred through the e xtranet connectio n for a long period of time, normally 15 minutes or more, th e VPN Router automati[...]

  • Page 77

    Chapter 4 Troubleshooting 77 Nortel VPN Router Tr oublesho oting Action: V a lidate that the VPN Client is conf igured with a DNS entry . For W indo w s NT 4.0, open a command prompt and enter ipconfig/all . V erify that a DNS server entry is listed. For W indow s 95, from the Start menu on the task bar , select Run and enter winipcfg . Select Nort[...]

  • Page 78

    78 Chapter 4 Troub leshooting NN46110-602 Cannot access W eb servers on the Internet afte r establishing a VPN Client connection Cause : For both PPTP and IPsec, this condition occurs as a result of all network traf fic passing through the corporate network. T ypically , fire walls and other security measures on the corporate network limit access t[...]

  • Page 79

    Chapter 4 Troubleshooting 79 Nortel VPN Router Tr oublesho oting Alternati vely , on NT 4.0, W indo ws 98, and W indows 95 , complete the follo wing steps to change your workst ation to be a member of a workgroup instead of a domain: 1 From the Start menu, select Settings > Contr ol P anel . In the Contr ol Panel , double-click Network . The Net[...]

  • Page 80

    80 Chapter 4 Troub leshooting NN46110-602 • Start from the top do wn to go in the opposite direction, looking at PPP first and worki ng do wn to the physical connection. An im portant point to remember when taking this approach is that at the higher protocol layers, there are more options to misconf igu re, but changing them is easier and general[...]

  • Page 81

    Chapter 4 Troubleshooting 81 Nortel VPN Router Tr oublesho oting Check the HDLC framing Assuming that the T1/V .35 interface is op erati ng correctly , use the follo wing steps to determine whether the HDLC layer is up and run ning properly , and to provide information for Nortel Customer Support for further diagnosis: 1 Check that there are no inp[...]

  • Page 82

    82 Chapter 4 Troub leshooting NN46110-602 4 If the PPP layer still does not come up, enable the interface deb ugger to generate large amounts of packet tr aces in the e vent log. Report this information to Nortel Customer Support for further diagnosis. Har dware encryption a ccelerator connectivity If the hardware encryption accelerator fails, all [...]

  • Page 83

    Chapter 4 Troubleshooting 83 Nortel VPN Router Tr oublesho oting • DHCP Server assigns IP addresses to clients • WINS Server provides a translation of the NetBIOS domain name to the IP address • DNS Serve r pro vides a tran slation of the IP Host name to the IP address • Master Bro wser is an elected host that maintains lists of all NetBIOS[...]

  • Page 84

    84 Chapter 4 Troub leshooting NN46110-602 The client system’ s NetBIOS name must be unique in the priv ate network to which the client is connecting. Do not us e the same name as your of fice d esktop machine or something like my computer . Uniqueness is required. What is the preferred wa y to access neighbors on the netwo rk? Microsoft recommend[...]

  • Page 85

    Chapter 4 Troubleshooting 85 Nortel VPN Router Tr oublesho oting The rene wal interv al gov erns ho w often a c lient must reregister its name with the WINS server . It begins trying at one-half of the rene wal interv al. The extinction interv al gove rns the length of time betwee n when a client name is released and when it becomes extinct. These [...]

  • Page 86

    86 Chapter 4 Troub leshooting NN46110-602 In the WINS mappings entry , enter a show database command. Note the entry for -__MSBR O WSE__. This is the machine that is actually the elected master bro wser , and it changes frequently . If this en try is pointing to an in v a lid machine, it can cause problems. Can I control which mac hi ne is the mast[...]

  • Page 87

    Chapter 4 Troubleshooting 87 Nortel VPN Router Tr oublesho oting T o specify a computer as the preferred master bro wser, set the parameter for IsDomainMasterBrowser to T rue or Y e s in the following re gistry path: HKEY_LOCAL_MACHINESystemC urrentControlSetServicesBrowser Parameters Unless the computer is configured as the preferred master [...]

  • Page 88

    88 Chapter 4 Troub leshooting NN46110-602 When 10.1.2.3 broad casts to find a network neighbor , it (incorrec tly) sends to 10.255.255.255. Normal rou ting functionality does not fo rw ard such a packet. The VPN Router finds the best match among its physical interfaces (10.1 in this case) and modif ies the broadcast to be corr ect for that interf a[...]

  • Page 89

    Chapter 4 Troubleshooting 89 Nortel VPN Router Tr oublesho oting After about 10 to 15 seco nds, NetBIOS g i ves up on the primary interf ace, mov es to the correct tunnel interface, and st arts to bro wse the Network Neighborhood. Wh y can't I bro wse another cl ient in a diff erent tunnel? Cause: If you are not using a WINS serv er, this is n[...]

  • Page 90

    90 Chapter 4 Troub leshooting NN46110-602 Y ou must create a connection def inition fo r your initial Internet link through your service provider . A separate connection defin ition is needed for creating the PPTP tunnel. A co mmon conf iguration problem ex perienced during initial PPTP setup is the failure to select the PPTP VPN adap ter (instead [...]

  • Page 91

    Chapter 4 Troubleshooting 91 Nortel VPN Router Tr oublesho oting My downloaded DNS server s for m y tunnel connection do not wo r k Cause: The Microsoft Windo ws 95/98 an d W indows NT operating systems attempt to ping ne w DNS servers before addi ng them to the current list of serv ers. Action: As a quick test, try to ping (with the tunnel connect[...]

  • Page 92

    92 Chapter 4 Troub leshooting NN46110-602 • Ho w to T rou bleshoot TCP/IP Connectivity with W indows NT • Remote Access Service (RAS) Error Code List for W indows NT 4.0 • RAS Error 720 When Dialing Out • T roubleshooting PPTP Connecti vity Issues in W indows NT 4.0 • PPTP Registry Entries • Connecting to Network Reso urces from Multiho[...]

  • Page 93

    Chapter 4 Troubleshooting 93 Nortel VPN Router Tr oublesho oting • For Acti veX Scripts, Ja v a, and Jav aSc ript*, you must enable both Acti veX and Jav a programs in Internet Explorer , and enable both Jav a and Jav aScript in Netscape Communicator for prop er VPN Router W eb management windo ws. These options are enabled b y default on both W [...]

  • Page 94

    94 Chapter 4 Troub leshooting NN46110-602 Clearing y our W eb br ow ser cac he when upgrading T o av oid problems when upgrading soft ware re vision le vels, Nort el recommends that you clear your bro wser cache and exit the bro ws er and all associated windo ws (such as mail and ne ws readers). See the following section for bro wser cache clearing[...]

  • Page 95

    Chapter 4 Troubleshooting 95 Nortel VPN Router Tr oublesho oting Document not found messa g e Cause: This message is returned when the HTTP ser ver ca nnot f ind the requested windo w . This can happen be cause the Jav a navigation index f ile is out of sy nch with the rest of the system. A corrupted or incorrectly cached inde x file can also cause[...]

  • Page 96

    96 Chapter 4 Troub leshooting NN46110-602 Action: Close help windo ws after vie wing them. Distorted backgr ound images Cause: In Nets cape versions prior to 4.0, where you c onfigured your W indows 95, W indo ws 98, or W indows NT system for 8-bit color (256 colors or less), images can ap pear distorte d in the na vigational area. Action: T o av o[...]

  • Page 97

    Chapter 4 Troubleshooting 97 Nortel VPN Router Tr oublesho oting Action: If necessary , remov e the front bezel as described in the installation guide, then push the bottom of the po wer supply in to reseat it. Cannot con vert from an intern al ad dress pool to an external DHCP server Cause: Y ou cannot con vert IP address distri b ution from an in[...]

  • Page 98

    98 Chapter 4 Troub leshooting NN46110-602 Action: Po wer-c ycle the system using the gr een po wer button on the back of the VPN Router. Solving r outing prob lems The following sections describe ro uting problems . Client address redistrib ution pr oblems The number of current Utunnel host user s can display more than the configur ed maxim um. Cau[...]

  • Page 99

    Chapter 4 Troubleshooting 99 Nortel VPN Router Tr oublesho oting Solving fire wall pr oblems An error occurred whil e par sing the policy Description: The polic y that you are attempting to view or edit cannot be opened because it does not conform to the required format. This is caused by an error in the LD AP database or a problem with the connect[...]

  • Page 100

    100 Chapter 4 Troubl eshooting NN46110-602 A uthorization failed. Please tr y again. Description: This error occurs when the wron g authentication credentials are entered. The user is re-prompted for creden tials until they are either correct or the user clicks Cancel. Action: No action required. Unable to communicate with the VPN Router Descriptio[...]

  • Page 101

    Chapter 4 Troublesho oting 101 Nortel VPN Router Tr oublesho oting Action: T o ensure that the most current data is loaded: 1 Close the current polic y , if opened. Sa ving is not permitted until this error is remedied. 2 From the polic y selection windo w , select All from the Refr esh menu. System files were not loaded pr operly Description: This[...]

  • Page 102

    102 Chapter 4 Troubl eshooting NN46110-602[...]

  • Page 103

    103 Nortel VPN Ro uter Trouble shooting Chapter 5 P acket capture Pack et capture (PCAP) is a troubleshooting tool that network administrators and customer support person nel use, in conjunc tion with other t ools such as statistics, logging, netwo rk analyzers, and testers, to remotely troubleshoot VPN Router and network problems. Packet capture i[...]

  • Page 104

    104 Cha pter 5 Pack et captur e NN46110-602 PCAP initially occurs to the RAM b u f fer . A low priority task writes the RAM bu ffer to di sk f iles, called the disk capture f iles. Alth ough you can set th e maximum size of this f ile, when the maximum file size is reached, PCAP can continue writing the captured data. Y ou specify the directory whe[...]

  • Page 105

    Chapter 5 Packet capt ure 105 Nortel VPN Router Tr oublesho oting • limit the traf fic that t he filters capture • automatically start and stop packet capture wi th triggers Security features Pa cket ca pture on the VPN Router p rovide s the follo wing features to enh ance security: • Pack et capture is disabled by default. Y ou can enable pa[...]

  • Page 106

    106 Cha pter 5 Pack et captur e NN46110-602 Capture types The VPN Router captures pack ets from the follo wing sources: • Physical interfaces, includi ng the following: — Asynchronous digital subscriber line (ADS L)/asynchronous transfer mode (A TM) — Fast Ethernet and Gigabit Et hernet, including traf fic that is not directed t o the VPN Rou[...]

  • Page 107

    Chapter 5 Packet capt ure 107 Nortel VPN Router Tr oublesho oting T unnel ca ptures sav ed to disk are encap sulated with raw IP encapsulation. When you con vert these f iles to file formats th at do not support ra w IP encapsulation (including Snif fer), L2 encapsulation is required. Y ou can conf igure a capture object for an ex isting tunnel or [...]

  • Page 108

    108 Cha pter 5 Pack et captur e NN46110-602 A global IP capture object captures pa ckets beginning from the IP header; no Layer 2 header is sav ed in the capture f ile. Because both encrypted and decrypted packets are captured, global IP pack et capture is useful in trou bleshooting certain VPN issues. Filters and trig g ers Y ou can apply existing[...]

  • Page 109

    Chapter 5 Packet capt ure 109 Nortel VPN Router Tr oublesho oting •A start trigg er causes the sy stem to w ait for a spec if ic pack et before it st arts saving pack ets to the capture bu f fer . •A stop trigger causes the system to stop saving traf fic in the capture b u f fer after a specific packet matching the st op trigger is enco untered[...]

  • Page 110

    110 Cha pter 5 Pack et captur e NN46110-602 Y ou can create ne w capture objects un til the maximum block size reaches 25 Mbyte. (The VPN Router do es not allo w you to reduce the maximum block size to less than 25 Mbyt e.) If you all ocate too much memory to pack et capture b uffers , you recei ve an error message suggesting a smaller buf fer size[...]

  • Page 111

    Chapter 5 Packet capt ure 111 Nortel VPN Router Tr oublesho oting • Delete a capture object or capture files when you n o longer need them to free up memory or disk space. • Do not run capture objects for physical interfaces or tunnels at the sa me time that you run th e global IP capture object (some p ackets are captured more than once). Enab[...]

  • Page 112

    112 Cha pter 5 Pack et captur e NN46110-602 6 Enter the administrator’ s user name and passw ord. Please enter the administrat or's user name: admin Please enter the administrat or's password: ***** The serial main menu appears. Main Menu: System is currently in NORMAL mode. 1) Interfaces 2) Administrator 3) Default Private Route Men u [...]

  • Page 113

    Chapter 5 Packet capt ure 113 Nortel VPN Router Tr oublesho oting 10 If you want, you can now change the VPN Router administrator p assword. CES# configure terminal Enter configuration commands , one per line. End with Ctrl/z. CES(config)# adminname <admin_name> password <new_p assword> CES(config)# exit CES# After you enable packet cap[...]

  • Page 114

    114 Cha pter 5 Pack et captur e NN46110-602 Fo r example , enter: CES(capture-ethernet) #filepath /ideX/ system/log Setting the size of the RAM buff er T o set the RAM buf fer size, from CLI Capture Conf iguration Mode enter: buffersize < size > where size is the size of the RAM buf fer . Fo r example , enter: CES(capture-ethernet) #buffersiz[...]

  • Page 115

    Chapter 5 Packet capt ure 115 Nortel VPN Router Tr oublesho oting Fo r example , enter: CES(capture-ethernet) #maxfiles 99 Saving captured data T o set the PCAP capture mode to loss or no loss, from CLI Capture Configuration Mode enter: capture-all or No capture-all Fo r example , enter: CES(capture-ethernet) #capture-all Configuring and running pa[...]

  • Page 116

    116 Cha pter 5 Pack et captur e NN46110-602 For e xample, enter the following command: CES# capture add test1 ? atm ATM interfac e capture bri Bri interf ace capture dial Dial inter face capture FastEthernet Fast Ether net interface capture GigabitEthernet Gigabit Et hernet interface capture global Global RAW IP capture serial Serial int erface cap[...]

  • Page 117

    Chapter 5 Packet capt ure 117 Nortel VPN Router Tr oublesho oting T o conf igure a capture object: 1 Navigate to Captur e Configurati on m o d e b y e n t e r i n g t h e capture command with the object name. CES# capture ether0 CES(capture-ethernet)# The resulting prompt sho ws the type of capture object (physical interface, tunnel, or glob al IP)[...]

  • Page 118

    118 Cha pter 5 Pack et captur e NN46110-602 T unnel capture parameters Capture objects for tunnels ha ve se ve ral unique parameters. The follo wing example creates a tunnel object called bot1 , na vigates to Capture Conf iguration mode, and displays the co mmands for tunnel obje cts. The commands in bold are the commands that are av ailable only f[...]

  • Page 119

    Chapter 5 Packet capt ure 119 Nortel VPN Router Tr oublesho oting Global IP parameters The conf igurable parameters for the global IP capture object are the same as the parameters av ailable for physical interf ace objects. The follo wing example creates a global capture object called raw i p , navigates to Capture Configuration mode, and displays [...]

  • Page 120

    120 Cha pter 5 Pack et captur e NN46110-602 In the follo wing example, the sho w capture command is run with no object name to display a list of all the captu re objects configured on the VPN Router. CES# show capture Name Type S ize Buffer use Count State bot1 TUNNEL 1 048576 0% 0 EMPTY ether0 ETHERNET 1 048576 7% 984 STOPPED rawip1 GLOBAL 1 04857[...]

  • Page 121

    Chapter 5 Packet capt ure 121 Nortel VPN Router Tr oublesho oting Sample pac ket captu re configurations This section provides sample conf igura tions and the commands us ed to create them. Interface capture object usin g a filter and direction In the follo wing example, yo u co nfigure a capture object called test-f ilter-in on Fast Ethernet inter[...]

  • Page 122

    122 Cha pter 5 Pack et captur e NN46110-602 T o vie w the status of the runni ng capture object, as well as its conf iguration, use the show capture command. (In this e xample, 20 frames are captured in the buff e r.) CES# show capture test-filter-in Capture state: RUNNING Capture buffer size: 1048576 Capture type: ETHERNET Capturing on interface: [...]

  • Page 123

    Chapter 5 Packet capt ure 123 Nortel VPN Router Tr oublesho oting T o create and use this capture object, you run commands like the ones i llustrated in this example. These commands do the follo wing: 1 Create a capture object called test-trigger on Fast Ether net interface 0/1 . 2 Enter Capture Conf iguration mode for the object. 3 Set the start t[...]

  • Page 124

    124 Cha pter 5 Pack et captur e NN46110-602 After T elnet traff ic activ ates the stop trigger , the show capture command resembles the follo wing example. The Captur e state field no w shows that the capture wa s stopped b y the stop trigg er . CES# show capture test-trigger Capture state: STOPPED by stop trigger Capture buffer size: 1048576 Captu[...]

  • Page 125

    Chapter 5 Packet capt ure 125 Nortel VPN Router Tr oublesho oting 4 Exit Captur e Conf iguration mode. 5 Start the capture. CES# capture add test-remote-ip tunnel CES# capture test-remote-ip CES(capture-tunnel)# remoteip 192.168.1 00.1 CES(capture-tunnel)# exit CES# capture test-remote-ip start CES# T o stop the capture and sav e the buf fer conten[...]

  • Page 126

    126 Cha pter 5 Pack et captur e NN46110-602 3 Click ether eal-setup- n.nn.n .exe . 4 Click a do wnload site and save the ex ecutable file on your hard dri ve. 5 Double-click the ex ecutable file to install Eth ere al software in the c:Pro gram FilesEthereal directory . 6 After you install the softw are, click the Ether eal application to open the[...]

  • Page 127

    Chapter 5 Packet capt ure 127 Nortel VPN Router Tr oublesho oting 6 Enter the password that you entered wh en you enabled packet capture (see “Enabling packet capture on a VPN Router” on page 111 ). 7 From the open Ethereal window , disable Enable network name r esolution . If this parameter is enabled, a larg e PCAP f ile takes a long time to [...]

  • Page 128

    128 Cha pter 5 Pack et captur e NN46110-602 T1 frame relay capture: editcap -F ngsniffer d:pcapfr.cap frelay.syc 5 From Sniffer Pr o , open the .enc file or the .syc file to vie w the trace. For a global IP trace or tunnel trace, you must perform an extra step on Snif fer Pro because only Layer 3 traf f i c is recorded in the PCAP capture. 6 Befo[...]

  • Page 129

    Chapter 5 Packet capt ure 129 Nortel VPN Router Tr oublesho oting T o delete a pack et capture object: 1 Display all conf igured capture objects on the VPN Router to locate the object or objects that you w ant to delete. CES# show capture Name Type Siz e Buffer use Count State test-fast ETHERNET 104 8576 0% 10 STOPPED test-filter-in ETHERNET 104 85[...]

  • Page 130

    130 Cha pter 5 Pack et captur e NN46110-602[...]

  • Page 131

    131 Nortel VPN Ro uter Trouble shooting Appendix A MIB suppor t The VPN Router supports the management information base (MIB) for use with network mana gement protocols in TCP/IP-based Intern ets and TCP/IPX-based networks. T he VPN Router supports SNMP Gets only . It does not support SNMP Sets. Nortel also pro vides proprietary MIBs for the VPN Ro[...]

  • Page 132

    132 Appendix A MIB support NN46110-602 RFC 1724—RIP V ersion 2 MIB Extension The VPN Router supports RFC 1724, R IP V ersion 2 MIB Extension . As stated in the introduction to the RFC, the RFC “d efines a portion of the Management Information Base (MIB) for use with netw ork management protocols in TCP/ IP-based internets. In particular , it de[...]

  • Page 133

    Appendix A MIB support 13 3 Nortel VPN Router Tr oublesho oting RFC 2787—VRRP MIB The VPN Router supports RFC 2787, Def initions of Manag ed Objects for the V irtual Router Redundancy Pr otocol . As stated in the introduction, RFC 2787 “def ines an extension to th e Management Information Base (MIB) for use with SNMP-based netw ork management. [...]

  • Page 134

    134 Appendix A MIB support NN46110-602 RFC 1573—IanaIfT ype MIB This MIB contains the enumerations for rfc2233 ifT able.ifT ype. These enumerations describe the v arious types of interfaces that ifT able can support. RFC 2233—If MIB This MIB is the latest e volution of rfc12 13 Interf aces group, plus se veral ne w objects. RFC 2571—Snmp-Fram[...]

  • Page 135

    Appendix A MIB support 13 5 Nortel VPN Router Tr oublesho oting — hrNetworkT able — hrPrinterT able — hrDiskStorageT able hrDiskStorageCapacity — hrPartit ionT able hrPartitionSize — hrFST able hrFSLastFullBackupDate hrFSLastParti alBackupDate • hrSWRun Group hrSWRun • hrSWRunPerf Group hrSWRunPerf • hrSWRunT able — hrSWRunIndex ?[...]

  • Page 136

    136 Appendix A MIB support NN46110-602 RFC2863 Interface MIB ( 64 bit counter s suppor t) The support for the following entries w as a dded in the interface table: ifHCInOctets, ifHCInUcastPkts, ifHCOu tOctets and ifHCOutUcastPkts. These counters already existed and were ex tended from Coun ter32 to Counter64. VPN Router MIB This MIB contains VPN R[...]

  • Page 137

    Appendix A MIB support 13 7 Nortel VPN Router Tr oublesho oting cestraps.mib—Nor tel pr oprietary MIB This section lists the cont ents of the cestraps.mib, the Nortel MIB for the VPN Router. -- Trap #5005 -------------- ------------------- -- Each Trap contains the Trap OID as well as the follo wing OIDs: -- SeverityLevel -- System Name -- System[...]

  • Page 138

    138 Appendix A MIB support NN46110-602 -- The second means packets were dropp ed due to a detected spoofed address -- The third should never happen, but means the status has been set to a bogus value. " ::= {serviceCESTrapInfo 6} antiSpoofingStatusTrap TRAP- TYPE ENTERPRISE serviceCESTrapInfo VARIABLES { severityLevel, antiSpoofingS tatus, sys[...]

  • Page 139

    Appendix A MIB support 13 9 Nortel VPN Router Tr oublesho oting ne w o ak.mib This section provides the contents of the ne woak.mib, which def ines the newoak enterprise ID, the contivity object identif ier , and the sysObjectIDs for ea ch VPN Router model. -- This MIB module uses the extended OBJECT-TYPE macro as -- defined in [9], and the TRAP-TY[...]

  • Page 140

    140 Appendix A MIB support NN46110-602 Har dware-related traps hardwareTrapInfo OBJECT IDEN TIFIER ::= {ContivitySnmpTraps 1} -- Trap #1001 hardDisk1Status OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Hard Disk Numbe r 1 Status." ::= {hardwareTrapInfo 1} -- Trap #1002 hardDisk0Status OBJECT-TYPE SYNTAX D[...]

  • Page 141

    Appendix A MIB support 14 1 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "Status of the f irst CPU fan." ::= {hardwareTrapInfo 6} -- Trap #1007 fanTwoStatus OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of the s econd CPU fan." ::= {hardwareTrapInfo 7}[...]

  • Page 142

    142 Appendix A MIB support NN46110-602 ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.5VA power." ::= {hardwareTrapInfo 12} -- Trap #10013 twoDotFiveVB OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of 2.5VB power." ::= {hardwareTrapInfo 13} -- Trap #10014 twelveVoltsPositive O[...]

  • Page 143

    Appendix A MIB support 14 3 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "The chassis int rusion sensor indicates that the unit has been opened." ::= {hardwareTrapInfo 18} -- Trap #10019 dualPowerSupply OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of the r[...]

  • Page 144

    144 Appendix A MIB support NN46110-602 Server-related traps serverTrapInfo OBJECT IDENTI FIER ::= {ContivitySnmpTraps 2} -- Trap #3001 radiusAcctServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of Exter nal Radius Accounting Server." ::= {serverTrapInfo 1} -- Trap #3002 backupServer OBJECT-TYPE[...]

  • Page 145

    Appendix A MIB support 14 5 Nortel VPN Router Tr oublesho oting ACCESS read-only STATUS mandatory DESCRIPTION "Status of DNS Server." ::= {serverTrapInfo 6} -- Trap #3007 SNMPServer OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Status of SNMP Server." ::= {serverTrapInfo 7} -- Trap #3008 IPAddre[...]

  • Page 146

    146 Appendix A MIB support NN46110-602 Software-related traps softwareTrapInfo OBJECT IDEN TIFIER ::= {ContivitySnmpTraps 3} -- Trap #5001 NetBuffers OBJECT-TYPE SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Network buffer usage." ::= {softwareTrapInfo 1} -- Trap #5002 fireWall OBJECT-TYPE SYNTAX DisplayString ACCESS[...]

  • Page 147

    Appendix A MIB support 14 7 Nortel VPN Router Tr oublesho oting Intrusion-related traps intrusionTrapInfo OBJECT IDE NTIFIER ::= {ContivitySnmpTraps 5} -- Trap #201 securityIntrusion OBJECT-TYP E SYNTAX DisplayString ACCESS read-only STATUS mandatory DESCRIPTION "Login Security Intrusion." ::= {intrusionTrapInfo 1} System-related traps --[...]

  • Page 148

    148 Appendix A MIB support NN46110-602 Inf o rmation passed with e very trap SeverityLevel OBJECT-TYPE SYNTAX INTEGER { fatal(1), major(2), minor(3), informational(4), insignificant(5), reversal(6) } ACCESS read-only STATUS mandatory DESCRIPTION "Severity of spe cific trap." ::= {ContivitySnmpTraps 7} systemName OBJECT-TYPE SYNTAX Display[...]

  • Page 149

    Appendix A MIB support 14 9 Nortel VPN Router Tr oublesho oting Ta b l e 3 provides trap categori es and explanations. T able 3 T rap categ ories Hard ware 1.3.6.1.4.1.2505.1.1.0.1001 hardDisk 1StatusTrap 1.3.6.1.4.1.2505.1.1.0.1002 hardDisk 0StatusTrap 1.3.6.1.4.1.2505.1.1.0.1003 memoryUs ageTrap 1.3.6.1.4.1.2505.1.1.0.1004 lanCardS tatusTrap 1.3.[...]

  • Page 150

    150 Appendix A MIB support NN46110-602 Ta b l e 4 provides descriptions for the VPN Router traps. Server 1.3.6.1.4.1.2505.1.2.0.3007 snmpServ erTrap 1.3.6.1.4.1.2505.1.2.0.3008 ipAddres sPoolTrap 1.3.6.1.4.1.2505.1.2.0.3009 extLDAPS erverTrap 1.3.6.1.4.1.2505.1.2.0.30010 radiusAu thServerTrap 1.3.6.1.4.1.2505.1.2.0.30011 certific ateServerTrap Soft[...]

  • Page 151

    Appendix A MIB support 15 1 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.1009 f iv eV olts P osStatu sT rap Status of the +5 V ol t power . Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10010 five V oltsMinusT rap Status of -5 V olt pow er . Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10011 threeV oltsP ositiv eT rap Status of +3 V olt [...]

  • Page 152

    152 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10020 t1 W ANStatusT rap St atus of T1 W AN card(s); P ossible v a lues f or W anic: Aler t: Inv alid Device X. W ar ning: Device W anicX disab led. Aler t: Device W anicX down. W ar ning: Device W anicX not initialized. W ar ning: Device W anicX PPP negotiating. Aler t: De[...]

  • Page 153

    Appendix A MIB support 15 3 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10022 hw AccelT rap Status of hardware accelerator card. P ossible V alues: Inv alid hardware accelerator unit %d. Unknown hardware accelerator unit %d. Health y: Bulk Accelerator in slot %d: Unit %d Status 1— AT TA C H E D . W ar ning: Bulk Acce [...]

  • Page 154

    154 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10024 v90W AN StatusT rap Status of V .90 Interface card. P ossible V alues: Please note that X corresponds to the unit number of the card. Aler t: V .90 Inv alid index X. Disabled: De vice IntModem-X disabled. Health y: Device IntModem-X: PPP is UP . Aler t: Device IntMode[...]

  • Page 155

    Appendix A MIB support 15 5 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.1.0.10026 serUar tStatusT rap Status of Serial (COM) por t/ interface . P ossible V alues: Please note that X corresponds to the unit number of the serial interface . Aler t: COM por t Inv alid index X Health y: De vice COMX is set fo r Serial Menu. Dis[...]

  • Page 156

    156 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.2.0.3005 loadBala nci ngSer verT rap Status of Load Balancing Ser v er . Proprieta r y 1.3.6.1.4.1.2505.1.2.0.3006 dnsSer ve rT rap Status of DNS Server . Proprieta r y 1.3.6.1.4.1.2505.1.2.0.3007 snmpSer v erT rap Status of SNMP Ser v er . Proprieta r y 1.3.6.1.4.1.2505.1.2.0.[...]

  • Page 157

    Appendix A MIB support 15 7 Nortel VPN Router Tr oublesho oting Proprieta r y 1.3.6.1.4.1.2505.1.2.0.30014 dhcpSer verT rap Status of DHCP Ser ver . P ossible V alues: Disabled: DHCP Server is Disabled. Aler t: DHCP Ser v er is NO T configured. Aler t: DHCP Ser v er is configured and operational, Usi ng backup config. Aler t: No IP Address av ai la[...]

  • Page 158

    158 Appendix A MIB support NN46110-602 Proprieta r y 1.3.6.1.4.1.2505.1.3.0.5007 sslV pnStatusT rap Status of SSL-VPN Accelerator . P ossible V alu es: Disabled: Disabled—The unit is administratively disab led. Disabled: HW not installed— There is no SSL-VPN Accelerator installed. W ar ning : Initializa tion in progress—The unit is being inti[...]

  • Page 159

    Appendix A MIB support 15 9 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending proto col entity recogni zes a f ailure in one of the communication links represen ted in the agent's configuration. V arbind list: ifInde x—ifInde x of the interface . ifAdminStatus—ifAdminStatus [...]

  • Page 160

    160 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending proto col entity recogni zes that one of the communicati on links represented in the agent's configuration is up . V arbind list: ifInde x—ifInde x of the interface . ifAdminStatus—ifAdminStatus of the interf ace. ifOperStatus[...]

  • Page 161

    Appendix A MIB support 16 1 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure n aut henticationF ailure trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message that is not properly au thenticated. The snmpEnableA uthenT raps object indicates wh ether this trap is generated. s[...]

  • Page 162

    162 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending proto col entity recogni zes a f ailure in one of the communication links represen ted in the agent's configuration. V arbind list: ifInde x—ifInde x of the interface . ifAdminStatus—ifAdminStatus of the interf ace. ifOper[...]

  • Page 163

    Appendix A MIB support 16 3 Nortel VPN Router Tr oublesho oting Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending proto col entity recogni zes that one of the communicati on links represented in the agent's configuration is up . V arbind list: ifInde x—ifInde x of the interface ifAdminStatus—ifAdminStatus of the i[...]

  • Page 164

    164 Appendix A MIB support NN46110-602 Standard 1.3.6.1.2.1.11.0.5 authenticationF ailure An aut henticationF ailu re trap signifies that the SNMPv2 entity , acting in an agent role, received a protocol message that is not properly au thenticated. The snmpEnableA uthenT raps object indicates whether this trap is generated. snmpA uthenOperation-ces [...]

  • Page 165

    165 Nortel VPN Ro uter Trouble shooting Appendix B Using serial PPP Y ou use Serial Point-to-Poin t Protocol (PPP) to manage the VPN Router from a remote location using PPP and the serial interface. If the VPN Router becomes unreachable ov er the Internet, you can s till dial up and mana ge it through the serial interface menu. W ith this feature, [...]

  • Page 166

    166 Appendix B Using serial PPP NN46110-602 Setting up a Dial-Up Netw orking connection T o establish a Serial PPP connection us ing a Microsoft Dial-Up Netw orking connection from the client system: 1 Double-click My Computer . 2 Double-click the Microsoft Di al-Up Networking icon . 3 Set the COM port baud rate on the client system so that it is c[...]

  • Page 167

    Appendix B Using serial PPP 167 Nortel VPN Router Tr oublesho oting Setting up the modem The follo wing procedure assumes that you are using a 3Com/US Robotics 5 6K x2 modem. It describes how to set up a modem to co mmunicate with the VPN Router using a dial-up network ing connection. Ta b l e 5 lists the DIP switch settings. Setting up the VPN Rou[...]

  • Page 168

    168 Appendix B Using serial PPP NN46110-602 to access all management services (HTTP , T elnet, FTP , SNMP) through the W eb interface. Once you establis h a session through PPP , the serial interface acts as a pri vate W AN interface with an internal IP address (0.0.1.35). • Auto detect—automatically detects whether the co nnected de vice is us[...]

  • Page 169

    Appendix B Using serial PPP 169 Nortel VPN Router Tr oublesho oting Dialing in to the VPN Router Use the standard dial-up networking pr ocedure to connect to the VPN Router. After connecting, you can then manage th e VPN Router using either T elnet (for the command line interface) or the browser -based G UI. Use the VPN Router’ s management IP ad[...]

  • Page 170

    170 Appendix B Using serial PPP NN46110-602 Cause: Y ou were dialed in and managing the VPN Router remotely using PPP and you changed the baud rate and applied it, bu t no w you cannot manage the VPN Router. Action: T o manage the VPN Router, disconnect the dial-up connection and try to re-establish it. This gi ves the modem a chan ce to rene gotia[...]

  • Page 171

    Appendix B Using serial PPP 171 Nortel VPN Router Tr oublesho oting Action: Make sure that the modem that is connec ted to the VPN Router has hardware flo w control enable d. PPP option settings The follo wing settings describe the VP N Router’ s behavior when ne gotiating serial PPP . For IP: • IP Address ne gotiation is enabled. • The VPN R[...]

  • Page 172

    172 Appendix B Using serial PPP NN46110-602[...]

  • Page 173

    173 Nortel VPN Ro uter Trouble shooting Appendix C System messages System forwarding (syslog) uses the syst em logging daemon (syslogd) to forw ard information from the VPN Router system log to dif ferent host machines. This appendix provides a listing of possib le syslog messages that the VPN Router can write to a remote system. A description and [...]

  • Page 174

    174 Appendix C System messages NN46110-602 tCer t: Shutdown complete Description: This informational message indica tes that the task responsible for certificate maintenance is shut do wn. This is usually part of the normal system shutdo wn. Action: No action required. tCer t: task creation failed Description: The task responsible for X.509 certifi[...]

  • Page 175

    Appendix C System messages 175 Nortel VPN Router Tr oublesho oting 2 Manually verify the tunnel-related ce rtif icate fingerprints. Perform this procedure any time you suspect tamp ering. ISAKMP messages ISAKMP [ 13 ] No pr oposal chosen in message from xxx (a.b.c.d) In many cases, a Session:IPsec message precedes the ISAKMP message. If the Session[...]

  • Page 176

    176 Appendix C System messages NN46110-602 Action: Make sure the PFS settings on both sides match. Either enable PFS on the remote side, or disable PFS locally . ISAKMP [ 13 ] Err or notification (No pr oposal chosen) received from xxx (a.b.c.d) Description: The proposal made by the local VPN Router is reject ed by a VPN Client. This usually indica[...]

  • Page 177

    Appendix C System messages 177 Nortel VPN Router Tr oublesho oting ISAKMP [ 13 ] Error notification (A uthent ication failure) received from xxx (a.b.c.d) Description: A VPN Client attempted to connect , b ut the user supplied the wrong password. Action: Make sure that the user and the VPN Router ha ve the same password. Description: A remote branc[...]

  • Page 178

    178 Appendix C System messages NN46110-602 ISAKMP [ 13 ] In v alid ID informat ion in message fr om xxx (a.b.c.d) Description: One side of the connection is conf igured to support dynamic routing while the other side is con figured for static routing. Bran ch of fice is xxx . Action: Conf igure both sides to us e the same routing type. Description:[...]

  • Page 179

    Appendix C System messages 179 Nortel VPN Router Tr oublesho oting Action: Remov e the existing static route or change the route for the remote network to be a sub set or superset of the static route. SSL messages Checking c hain: in valid parent cert, xxx Description: The gi ven certif icate in the chain is not v alid. This indicates that the cert[...]

  • Page 180

    180 Appendix C System messages NN46110-602 No matching trusted CA certs Description: None of the certificates in the ch ain are truste d CA certificates. Y ou can recei ve this message if the CA certif ic at e is not installed or is not marked as trusted on the VPN Router. Action: Make sure the CA certif icate is insta lled and that the certificate[...]

  • Page 181

    Appendix C System messages 181 Nortel VPN Router Tr oublesho oting Action: Make sure the b ackup f ile has an 8.3 f ile name. LDIF file: could not restore xxx Description: The internal LD A P server database cannot be restored from the specif ied LDIF file. This indicat es that the LDIF fil e does not exist. Action: Choose an LDIF f ile that curren[...]

  • Page 182

    182 Appendix C System messages NN46110-602 CaA uthSer verCollection: authenticate xxx cer t [xxx] in valid signature b y [xxx] - xxx Description: The certif icate passed in with th e authentication request does not ha ve a v alid signature, based on the CA certificate conf igured on the VPN Router. This indicates either an incorrect certificat e at[...]

  • Page 183

    Appendix C System messages 183 Nortel VPN Router Tr oublesho oting Action: Start the LD AP se rver , or change the external LD AP server conf iguration to make it accessible. Security: store ne w system subnet mask xxx failed— xxx Description: The system subnet mask cannot be stored in the VPN Router conf iguration LD AP entry . This can in dicat[...]

  • Page 184

    184 Appendix C System messages NN46110-602 Action: Start the LD AP se rver , or change the external LD AP server conf iguration to make it accessible. Err or deleting entry [xxx]—xxx Description: An er ror occurred while deleting an LD AP entry . This indicates that the LD AP server is not accessible. Action: Start the LD AP se rver , or change t[...]

  • Page 185

    Appendix C System messages 185 Nortel VPN Router Tr oublesho oting xxx xxx being referenced b y xxx Description: The LD AP entry is referenced by another LD AP entry (for example, a f ilter set referenced b y a User Group or Branch Of fice Connection). Action: Remov e all references to the LD AP entry in question, then delete the entry . Session: x[...]

  • Page 186

    186 Appendix C System messages NN46110-602 Session: xxx[xxx]:xxx xxx auth method not allowed Description: The authentication method of the in coming request is not allo wed in the group that th e session is bound to . The session is bound to a g roup by one of the follo wing: • the group that the user’ s account is in (in LD AP) • RADIUS def [...]

  • Page 187

    Appendix C System messages 187 Nortel VPN Router Tr oublesho oting Session: xxx[xxx] : xxx IP address assignment failed Description: An address cannot be assigned to the session. This occurs if the static address for the session is in use or if the address po ol is exh austed. Action: Expand the numb er of addresses in the pool, or change the stati[...]

  • Page 188

    188 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx account not allowed now Description: The session request is outside the permitted hours of access. Action: Change the Access Hours setting assigned to the group on the Profiles > Groups > Edit > Connecti vity window . Session: xxx[xxx] : xxx authentication failed using xxx [...]

  • Page 189

    Appendix C System messages 189 Nortel VPN Router Tr oublesho oting Session: xxx[xxx] : xxx in valid pass w ord —master admin authentication failed Description: The primary administrator passw o rd is in valid. This results from using the wrong passw ord or from making a mistake while ty ping the password. Action: Make sure you are using the corre[...]

  • Page 190

    190 Appendix C System messages NN46110-602 Session: xxx[xxx] : xxx pool address [xxx] already in use Description: The returned static pool address is currently is use. This error occurs if another tunnel is using this address through a static address conf iguration or another address pool. The error also occurs if a static host rout e using this ad[...]

  • Page 191

    Appendix C System messages 191 Nortel VPN Router Tr oublesho oting RADIUS accounting messages RADIUS: Cannot send ac counting request to < ser ver-name >, possibl y due to DNS translation failure Description: This message indicates a conn ection failure. Whi le sending a request, an error occurred du e to a socket creation probl em. This usua[...]

  • Page 192

    192 Appendix C System messages NN46110-602 RADIUS: network soc ket failure with < ser ver-name >, recvfr om err or: < err or > Description: This message indicates a connection failure. An error occurred while receiving the response. Action: Retry authentic ation attempt and v erify that RADIUS serv er packets are properly formed. RADIUS[...]

  • Page 193

    Appendix C System messages 193 Nortel VPN Router Tr oublesho oting Action: Retry authentic ation attempt and v erify that RADIUS serv er packets are properly formed. Unsuppor ted response type (< numb e r >) received from server Description: This message indicates that an in v alid response was recei ved. The response packet type is not one o[...]

  • Page 194

    194 Appendix C System messages NN46110-602 RADIUS authentication messages RADIUS: Cannot sen d request to < ser ver-name >, possib ly due to DNS translation failure Description: This message indicates a conn ection failure. Whi le sending a request, an error occurred du e to a socket creation probl em. This usually indicates a DNS resolution [...]

  • Page 195

    Appendix C System messages 195 Nortel VPN Router Tr oublesho oting RADIUS: < server-name > server timed out authenticating < user-name > Description: This message indicates a connec tion failure. The connection timed out while waiting for a response. Action: V erify the follo wing: • RADIUS serv er’ s IP address and port number are [...]

  • Page 196

    196 Appendix C System messages NN46110-602 RADIUS: < server-name > sent in v alid response packet f or < user-name > Description: This message indicates that an in v alid response was recei ved. The length of the response packet is not equal to the number of bytes recei ved. Action: Retry authentic ation attempt and v erify that RADIUS [...]

  • Page 197

    Appendix C System messages 197 Nortel VPN Router Tr oublesho oting Action: V erify that the shared secrets match. RADIUS: < server-name > sent pac ket with in valid response authenticator f or < user -name > Description: This message indicates that an in v alid response was recei ved. The computed authenticator does not match the v alue[...]

  • Page 198

    198 Appendix C System messages NN46110-602 RADIUS: < user-name > access DENIED b y ser ver < server-name > Description: This message indicates that a v a lid access-reject response was recei ved. Action: No action required. Response OK Description: This message indicates that a valid access-accept response was recei ved. Action: No acti[...]

  • Page 199

    Appendix C System messages 199 Nortel VPN Router Tr oublesho oting Action: No action required. Closing OSPF-RTM connection Description: OSPF closed the R TM connection, wh ich occurs if the administrator disables OSPF from Routing > OSPF window . Action: No action required. Ospf_Global.State changed from ENABLED to DISABLED b y user 'admin&[...]

  • Page 200

    200 Appendix C System messages NN46110-602 Can not accept x.x. x.x as router id Description: OSPF can not accept the gi ven router ID in the Routing > OSPF windo w . Action: Y ou must chan ge router ID in the Routing > OSPF window . In va lid router IDs are 127.0.0.1 and 0.0.0.0. LoadOspfAreas F ailed Description: OSPF failed to load all area[...]

  • Page 201

    Appendix C System messages 201 Nortel VPN Router Tr oublesho oting VR xxx : Star ting xxx as Bac kup for xxx Description: Logged when starting as a backup for an address. The parameters are: • The VRID of this VR • The reason for starting, either because it was enabled or the interface went up • The IP addre ss Action: No action required. VR [...]

  • Page 202

    202 Appendix C System messages NN46110-602 Unable to get conf iguration for VR xxx Description: This is an error e vent that is lo gged when VRRP is enabled bu t the common configuration parameters are mi ssing. These are the items set in the Routing > VRRP windo w . Action: No action required. RIP xxx : RIP Enabled Description: Logged when RIP [...]

  • Page 203

    Appendix C System messages 203 Nortel VPN Router Tr oublesho oting RIP xxx : Circuit xxx deleted Description: Logged when the RIP circuit is de leted. The parameter stands for circuit ID. Action: No action required. RIP xxx : Unable to register with UDP Description: Logged when you can not re gister with UDP protocol. Action: No action required. RI[...]

  • Page 204

    204 Appendix C System messages NN46110-602 RIP xxx : Unable to spa wn timer task xxx fo r R I P Description: Logged when RIP fails to spaw n the timer task. The parameter stands for the name of the task. Action: No action required. RIP xxx : cid xxx mismatched auth passw ord fr om xxx Description: Logged when RIP authentication fa ils while recei v[...]

  • Page 205

    Appendix C System messages 205 Nortel VPN Router Tr oublesho oting Interface [ nnn ] replaced, deleting fr om config Description: This indicates the card type specif ied in the configurat ion file does not match the card currently in the sl ot. The interface is deleted from the conf iguration. This ap plies when the replaced card has more ports tha[...]

  • Page 206

    206 Appendix C System messages NN46110-602[...]

  • Page 207

    207 Nortel VPN Ro uter Trouble shooting Appendix D Configuring f or interoperability This chapter e xplains the requirements and p rocedures for setting up dif ferent vendor hardw are or software to intero perate with the VPN Router. Y ou can use these instructions to establish encrypted tunnels to and from the VPN Router with the noted v endors. T[...]

  • Page 208

    208 Appendix D Config uring for in teroperability NN46110-602 Figure 11 VPN Router and Cisco 2514 netw or k topolog y[...]

  • Page 209

    Appendix D Configurin g for interoperability 209 Nortel VPN Router Tr oublesho oting The follo wing is a show config command: Cisco2514# show config Using 1088 out of 32762 byte s version 11.3 no service password-encryption hostname Cisco2514 enable secret 5 $1$aSJB$Xz/o 4I4IqCY.FT2RH372/1 enable password password ! crypto isakmp policy 1 hash md5 [...]

  • Page 210

    210 Appendix D Config uring for in teroperability NN46110-602 dialer-list 1 protocol ipx p ermit snmp-server community public RO line con 0 line aux 0 line vty 0 4 password terminal login end Configuring the VPN Router f or Cisco interoperability T o configure the VPN Router for Cisco interoperability: 1 Select to Pr of iles > Networks and click[...]

  • Page 211

    Appendix D Configurin g for interoperability 211 Nortel VPN Router Tr oublesho oting Configuring the SafeNet/Soft-PK Security P olicy Database Editor , V er sion 1.0s T o set up the VPN Router to establish encrypted tunnel connections with the IRE Soft-PK Security Policy Client as illustrated in Figure 12 , configure the windo ws as described on fo[...]

  • Page 212

    212 Appendix D Config uring for in teroperability NN46110-602 Connecting to IRE SafeNET/So ft-PK Security P olicy Client T o set up the VPN Router to establish encrypted tunnel connections with the IRE SafeNet/Soft-PK Security Polic y Client, do the follo wing: 1 Open the SafeNet/Soft-PK Secu rity Polic y Client, and click File: New . The follo win[...]

  • Page 213

    Appendix D Configurin g for interoperability 213 Nortel VPN Router Tr oublesho oting • 8.1.10.42 The SafeNet/Soft PX Security Po lic y Editor dialog box appears. 6 Click My Identity to conf igure the SafeNet clie nt, and select the following: • Select Certificate: None •I D T y p e : IP Address • Port: All 7 Click Pr e-Shared K ey . The Pre[...]

  • Page 214

    214 Appendix D Config uring for in teroperability NN46110-602 The SafeNet/Soft-PK Security Po lic y Editor dialog box appears. 10 From Security Policy: Select Phase 1 Negotiation Mode , click Main Mode . 11 Click Enable Replay Detection . 12 On the A uthentication (Phase 1), Proposal 1, A uthentication window , enable the following:[...]

  • Page 215

    Appendix D Configurin g for interoperability 215 Nortel VPN Router Tr oublesho oting • Authentication Method: Pr e-Shar ed key • Encrypt Alg: DES •H a s h A l g : MD5 •S A L i f e : Seconds and 3000 (Seconds) • K ey Group: Diffie-Hellman Gr oup 1 13 On the Key Exchange (Phase 2), Pr opo sal 1 windo w , enable the following: • Encapsulat[...]

  • Page 216

    216 Appendix D Config uring for in teroperability NN46110-602 9 For some v e ndors, if you want to turn off V endor ID and/or P erfect F orward Secrecy (PFS) , do that on the Prof iles > Groups > IPsec: Conf igure windo w . Thir d-par ty c lient installation The VPN Router supports third-party IPsec clien ts and includes supp ort for the foll[...]

  • Page 217

    Appendix D Configurin g for interoperability 217 Nortel VPN Router Tr oublesho oting Considerations f or usin g third- par ty c lients There are sev eral considerations regarding the use of third-party clients with VPN Router: • Client Dynamic Addressing—M any th ird-party clients no w support the Aggressi ve mode method o f establis hing a sec[...]

  • Page 218

    218 Appendix D Config uring for in teroperability NN46110-602 • Load Balancing—T raditional load balancers often do not work with the IPsec protocol because of the security featur es on individual packets and separate ke y management and data channels. The VPN Router has built-in load balancing features for IPsec client term inations that allow[...]

  • Page 219

    Appendix D Configurin g for interoperability 219 Nortel VPN Router Tr oublesho oting (are correctly decrypted, and authenti cated) are accepted; other packets are dropped. If an y attempt is made to chan ge the station address of the client, the tunnel is automatically closed. Third-part y clients do no t necessarily have this security . • T ight[...]

  • Page 220

    220 Appendix D Config uring for in teroperability NN46110-602 then select a default server certif icate from the list. Y ou configure servers from the System > Certif icates windo w . 7 Select Prof iles > Branch Off ice , click Edit , scroll do wn to the IPsec section and click Conf igure . The Bran ch Of fice windo w appears. 8 Select the en[...]

  • Page 221

    Appendix D Configurin g for interoperability 221 Nortel VPN Router Tr oublesho oting Figure 13 Split tunneling e xample T o configure the VPN Router as a user tunnel: 1 Select Prof iles > Gr oups and click Add . Enter a group name of up to 64 characters (spaces are pe rmitted); for example, Research and De velopment. 2 Click Edit ne xt to the na[...]

  • Page 222

    222 Appendix D Config uring for in teroperability NN46110-602 6 Selections in the Encryption field s are dependent on the type of encryption that your third-p arty client supports. 7 Enable Perfect F orw ard Secrecy (PFS) . PFS ensures that if one ke y is compromised, subsequent ke ys are not compromised. 8 In the F o rced Logoff dialog box, specif[...]

  • Page 223

    Appendix D Configurin g for interoperability 223 Nortel VPN Router Tr oublesho oting Network addresses fo rm the basis of the IPX internetwork addressing scheme for sending packets between netw ork segm ents. Every network segment of an internetwork is assigned a unique netw ork address by which routers forward packets to their f inal destination n[...]

  • Page 224

    224 Appendix D Config uring for in teroperability NN46110-602 Windows 95 and Windo ws 98 When running W indows 95 or W i ndows 98, load the intraNetW are* client, which is a v ailable from the No vell W eb site: http://www.novell.com Windows NT Y ou can use either the NetW are client that is alrea dy on W indo ws NT systems or the No vell int raNet[...]

  • Page 225

    Appendix D Configurin g for interoperability 225 Nortel VPN Router Tr oublesho oting Figure 14 IPX topolog y Note: The pri v ate LAN can also carry IP and IPX traf fic simultaneously . The IP addresses are no t sho wn in this figure.[...]

  • Page 226

    226 Appendix D Config uring for in teroperability NN46110-602[...]

  • Page 227

    Nortel VPN Ro uter Trouble shooting 227 Inde x A accounting data 40 records 38, 39 accounting log 38 acti ve sessions 96 Acti veX Scripts 93 administrato r settings 28 administrator privileges 27 authentication fai led 74 B background images 96 backups 52 branch of fice error messages 178 bro wser error messages 94 bro wsing delays 93 C certifi cat[...]

  • Page 228

    228 Ind ex NN46110-602 SSL 179 e v ent log 35, 41 External DHCP server 97 extinction interval 84 timeout 84 Extranet Access client monitor 70 connection problems 73 F factory default 49 configuration 50 f ile managemen t 30 G general problems over vi ew 7 0 solving 92 H hard driv e, refo rmatting 51 hardware health check 37 hardware error messages [...]

  • Page 229

    Index 229 Nortel VPN Router Tr oublesho oting modem hardware errors 82 MS-DOS naming con vention 97 multiple Help windows 95 N NetBEUI 77, 83 NetBIOS 77, 83, 84, 88 Netscape Communicator 92 netstats command 71 NetW are client 224 Network Neighborhood 84 ne woak.mib 139 Nortel Networks MIB 31 Nov ell intraNetW are client 224 P Partial Backup 50 perf[...]

  • Page 230

    230 Ind ex NN46110-602 RADIUS accounting 191 RADIUS authentication 194 routing 198 security 181 SSL 179 T T1/V .35 interface 80 technical publications 22 text con ventions 17 tools ARP 30 ping 29 traceroute 30 tracert command 71 traps hardware 140 information for all 147, 148 intrusion-related 147 login-related 146 server -related 144 software-rela[...]