Page 11 / 210 Scroll up to view Page 6 - 10
61200361L1-1E
© 2002 ADTRAN, Inc.
11
SYSTEM DESCRIPTION
C
ONTENTS
System Overview
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Features and Benefits
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Physical Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13
Firewall Features. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13
Address Translation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13
IPSec Tunnel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13
Administration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
13
DHCP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14
PPPoE. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14
Routing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
14
Page 12 / 210
Section 1, System Description
NetVanta 2000 Series System Manual
12
© 2002 ADTRAN, Inc.
61200361L1-1E
1.
SYSTEM OVERVIEW
The NetVanta 2000 series of VPN products include small to mid-range IPSec compliant gateways
providing all the necessary components required to secure an integrated VPN solution. Used primarily for
remote access and site-to-multisite connectivity, the NetVanta 2050 and NetVanta 2100 targets the
corporate branch office, the small office/home office (SOHO), as well as business-to-business
applications. As a branch office or mid-size host security gateway, the NetVanta 2300 provides the same
features as the NetVanta 2100 with an added DMZ port for public server access. For networks supporting a
large VPN network, the NetVanta 2400 is available to provide all necessary host site gateway functionality.
The NetVanta 2000 series provides several key security and data management features such as IPSec VPN
tunneling, stateful inspection firewall (providing cyber assault protection), authenticated remote user
access, and Network Address Translation. Adhering to IPSec standards (established and maintained by the
IETF) enables the NetVanta 2000 series to be interoperable with many other IPSec compliant gateways,
allowing for a multi-vendor VPN solution.
On a public infrastructure like the Internet, security is of the utmost importance. The NetVanta 2000 series
protect the corporate network against attacks with a built in firewall and provides data security through
encryption, authentication and key exchange. The NetVanta 2000 series employ a stateful inspection
firewall that protects an organization's network from common cyber attacks including TCP syn-flooding,
IP spoofing, ICMP redirect, land attacks, ping-of-death, and IP reassembly problems.
For encryption, the NetVanta 2000 series encrypt the data being sent out onto the network, using either the
Data Encryption Standard (DES) or 3DES encryption algorithms. Data integrity is ensured using MD5 or
SHA1 as it is transported across the public infrastructure. In addition, Internet Key Exchange (IKE) can be
used for user authentication supporting public and private keys or digital certificates, assuring that the
proper VPN tunnel is established and that the tunnel has not been redirected or compromised.
NetVanta 2000 series are Internet Protocol Security (IPSec) compliant devices that supports both ESP and
AH protocols and provides secure communication over potentially unsecure network components. Acting
as a security gateway, the NetVanta 2050 and 2100 can provide up to 10 private encryption communication
tunnels through the Internet with remote locations while the larger scale NetVanta 2300 offers support for
up to 100 private encryption tunnels. For networks requiring more than 100 tunnels, the NetVanta 2400
provides 1000 private encryption tunnels. The NetVanta 2000 series can also hide IP addresses from the
external world by performing Network Address Translation (NAT). The internal router allows multiple
users to share a VPN connection and can also direct incoming IP traffic.
A remote NetVanta 2000 series can easily be configured and managed using a standard web browser.
NetVanta 2000 series also have built-in alert and logging mechanisms for messaging and mail services.
This enables the unit to warn administrators about activities that are going on in the network by logging
them into a Syslog server or sending an email to the administrator.
Unlike a software implemented VPN solution, which depends on local CPU and memory performance to
implement encryption, the NetVanta 2000 series are standalone, hardware platforms that off-load the CPU
intensive encryption process. 3DES encryption significantly impacts CPU performance, possibly slowing
all the local processes on the computer. Since the NetVanta 2000 series offers dedicated processing
platforms to drive the encryption process, local computer performance is unaffected.
Page 13 / 210
NetVanta 2000 Series System Manual
Section 1, System Description
61200361L1-1E
© 2002 ADTRAN, Inc.
13
2.
FEATURES AND BENEFITS
The NetVanta 2000 series provide granular control over network access that includes maximum security,
data authenticity and privacy, and significant ease of use. The major features of the NetVanta 2000 series
are described below.
Physical Interfaces
WAN:
RJ-45 10/100 Auto-sensing ethernet interface
LAN:
RJ-45 10/100 Auto-sensing ethernet interface
Serial Port: RS-232 for off-net configuration (NetVanta 2300 Only)
DMZ:
RJ-45 10/100 Auto-sensing ethernet interface
Firewall Features
Stateful inspection firewall
Application content filtering
Cyber assault protection
HTTP relay
Address Translation
Basic NAT (1:1)
NAPT (Many:1)
Reverse NAT (translation of an inbound session’s destination IP address)
IPSec Tunnel
Encapsulating Security Payload (ESP)
Authentication Header (AH)
Manual key management or automatic key management using Internet Key Exchange (IKE)
X.509 certificate support
MD5-HMAC 128-bit authentication algorithm
SHA1-HMAC 160-bit authentication algorithm
DES-CBC 56-bit encryption
3DES-CBC 168-bit encryption
Administration
Web-based management
Syslog logging in WELF format
E-mail alerts (SMTP)
User and group access control policies based on time-of-day
User accounting policy statistics
Page 14 / 210
Section 1, System Description
NetVanta 2000 Series System Manual
14
© 2002 ADTRAN, Inc.
61200361L1-1E
DHCP
Server (to manage IP addresses on local network)
Client (to acquire the WAN-side IP address from service provider)
PPPoE
Client (to acquire the WAN-side IP address from service provider)
Routing
TCP/IP
Static routes
RIP (V1 and V2)
RIP with Authentication
Page 15 / 210
61200361L1-1E
© 2002 ADTRAN, Inc.
15
ENGINEERING GUIDELINES
C
ONTENTS
Equipment Dimensions
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Power Requirements
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Reviewing the front Panel Design . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Front Panel LEDs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
17
Reviewing the Rear Panel Design . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
LAN Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
19
WAN Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
19
DMZ Connection (NetVanta 2300 Only) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
20
COM1 Interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
21
Power Connection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
21
At-A-Glance Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
F
IGURES
Figure 1.
NetVanta 2000 series Front Panel Layout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
16
Figure 2.
NetVanta 2300 Front Panel Layout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
17
Figure 3.
NetVanta 2000 series Rear Panel Layout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
18
Figure 4.
NetVanta 2300 Rear Panel Layout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
19
T
ABLES
Table 1.
NetVanta 2000 series Front Panel Description . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Table 2.
NetVanta 2000 series LEDs
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Table 3.
LAN Pinout
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Table 5.
DMZ Pinout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Table 4.
WAN Pinout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
Table 6.
DB-9 Connector Pinout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Table 7.
Specifications
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22

Rate

4 / 5 based on 1 vote.

Popular Adtran Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top