Page 71 / 210 Scroll up to view Page 66 - 70
NetVanta 2000 Series System Manual
Section 4, User Interface Guide
61200361L1-1E
© 2002 ADTRAN, Inc.
71
S
OURCE
A
DDRESS
- Drop down menu allows you to configure the source IP address of the outbound
network traffic for which this VPN policy will provide security. Mostly, this address will be from your
corporate network address space. All entries in the IP Address Table appear in this drop down menu. You
can choose one of these, or select
O
THER
option from this menu and define the source IP address/subnet in
the immediately following text boxes.
A
NY
option in this menu represents all valid IP addresses in the
Internet address space.
D
ESTINATION
A
DDRESS
- Drop down menu allows you to configure the destination IP address of the
outbound network traffic for which this VPN policy will provide security. Mostly, this address will be from
remote site's corporate network address space. All entries in the IP Address Table appear in this drop down
menu. You can choose one of these, or select
O
THER
option from this menu and define the destination IP
address/subnet in the immediately following text boxes.
A
NY
option in this menu represents all valid IP
addresses in the Internet address space.
S
OURCE
P
ORT
- Drop down menu allows you select the source port value for this VPN policy selector. All
entries in the Services table appear in this menu. You can choose one from these, or select
O
THER
option
and define the Source Port in the immediately following text box.
A
NY
option in this menu indicates the
complete port range i.e. 1 to 65535.
D
ESTINATION
P
ORT
- Drop down menu allows you select the destination port value for this VPN policy
selector. All entries in the Services table appear in this menu. You can choose one from these, or select
O
THER
option and define the Destination Port in the immediately following text box.
A
NY
option in this
menu indicates the complete port range (i.e., 1 to 65535).
> P
OLICIES
> VPN > C
ERTIFICATES
The NetVanta 2000 series supports the use of both RSA and DSS Signature Algorithm Certificates. The
NetVanta 2000 series provides the capability to generate self-certificate requests, and maintains a listing of
private keys (certificate requests) that currently have no public key (self-certificate assigned by the
Certificate Authority).
Always contact your Certificate Authority (VeriSign, Entrust, etc.) before generating your self-certificate
request. The parameters configured in your request must match what the Certificate Authority requires for
you to receive your self-certificate. Once the request is generated, follow your Certificate Authority’s
guidelines for supplying them with your request. Many Certificate Authorities allow e-mail requests, but
some do not.
> P
OLICIES
> VPN > C
ERTIFICATES
> S
ELF
C
ERTIFICATE
The NetVanta 2000 series provides the capability to generate self certificate requests in PEM (Privacy
Enhanced Mail) format for either RSA or DSS signature algorithms. Refer to DLP-017,
Generating a
Self-Certificate Request
for more details.
> P
OLICIES
> VPN > C
ERTIFICATES
> CA C
ERTIFICATE
The NetVanta 2000 series supports loading Certificate Authority certificates in PEM (Privacy Enhanced
Mail) format for either RSA or DSS signature algorithms. Refer to DLP-018,
Uploading a CA Certificate
to the NetVanta
for more details.
Page 72 / 210
Section 4, User Interface Guide
NetVanta 2000 Series System Manual
72
© 2002 ADTRAN, Inc.
61200361L1-1E
> P
OLICIES
> VPN > C
ERTIFICATES
> P
RIVATE
K
EY
W
ITHOUT
P
UBLIC
K
EY
The NetVanta 2000 series provides the capability to generate self certificate requests in PEM (Privacy
Enhanced Mail) format for either RSA or DSS signature algorithms. Refer to DLP-017,
Generating a
Self-Certificate Request
for more details. The NetVanta 2000 series tracks all self certificate generated
requests and maintains them in the Private Key Without Public Key until the corresponding self certificate
is loaded into the unit.
> P
OLICIES
> VPN > C
ERTIFICATES
> CRL
The NetVanta 2000 series supports loading Certificate Revocation Lists obtained from Certificate
Authorities. Upload the CRL by clicking the
B
ROWSE
button to find the Certificate Authority’s CRL file,
then click the
U
PLOAD
button to make it active in the NetVanta 2000 series system.
> M
ONITOR
This section discusses the monitoring capabilities of NetVanta 2000 series including access policy and
association database statistics, user session information, and NetVanta 2000 series access records. The
NetVanta 2000 series monitor configuration parameters are displayed by clicking on the
M
ONITOR
menu on
the Administration Console.
> M
ONITOR
> P
OLICY
S
TATISTICS
The Policy Statistics page is displayed by clicking on
P
OLICY
S
TATISTICS
found in the menu list.
> M
ONITOR
> P
OLICY
S
TATISTICS
> A
CCESS
P
OLICY
S
TATISTICS
The Access Policy Statistics page displays static and dynamic policy allocation attempts, policy allocation
failures, and policy request successes and failures. This table shows the policy statistics for the current
hour, previous hour, and a daily total.
> M
ONITOR
> P
OLICY
S
TATISTICS
> A
SSOCIATION
D
ATABASE
S
TATISTICS
The Association Database Statistics page displays association memory statistics as well as broadcast,
connection, security association (SA), and other security and traffic-related statistics. Using the same
format as the Access Policy Statistics display, it shows the association database statistics for current hour,
previous hour, and a daily total.
> M
ONITOR
> U
SER
A
CCOUNTING
The User Accounting page provides remote user session statistics. This includes
U
SER
N
AME
,
L
OGIN
T
IME
,
L
OGOUT
T
IME
,
B
YTES
transferred
I
N
and
O
UT
, and the user's
S
OURCE
IP
address. These fields summarize a
remote user's session. Effective network administrators will have a sense of normal activity on the network
making it easier to spot abnormal activity or behavior. The User Accounting page is displayed by clicking
on User Accounting found in the menu list.
> M
ONITOR
> A
CCESS
L
OG
The Access Log page is displayed by clicking on
A
CCESS
L
OG
found in the menu list. The Log Window
shows all event log messages that have not been exported by NetVanta 2000 series.
Page 73 / 210
NetVanta 2000 Series System Manual
Section 4, User Interface Guide
61200361L1-1E
© 2002 ADTRAN, Inc.
73
The NetVanta 2000 series log queue can be cleared by clicking on the
C
LEAR
L
OG
button found in the Log
Window dialog box.
Messages in the log queue when it is cleared are permanently lost.
Page 74 / 210
Section 4, User Interface Guide
NetVanta 2000 Series System Manual
74
© 2002 ADTRAN, Inc.
61200361L1-1E
Page 75 / 210
61200361L1-1E
© 2002 ADTRAN, Inc.
75
DETAIL LEVEL PROCEDURES
Connecting to the Netvanta 2000 Series
.........................................................................................
DLP-001
Changing the Admin Password in the NetVanta
.............................................................................
DLP-002
Saving the Current Settings of the NetVanta
...................................................................................
DLP-003
Setting the Time and Date in the NetVANTA
..................................................................................
DLP-004
Configuring the LAN Interface IP Address
.......................................................................................
DLP-005
Configuring the WAN Interface Using Dynamic or Static IP Addressing
.........................................
DLP-006
Configuring the WAN Interface For PPPoE Addressing
..................................................................
DLP-007
Upgrading the Firmware of the NetVanta 2000 series
....................................................................
DLP-008
Saving the Current Configuration of the NetVanta
..........................................................................
DLP-009
Loading a Saved Configuration into the NetVanta
..........................................................................
DLP-010
Adding a Default Route to the NetVanta Route Table
.....................................................................
DLP-011
Configuring the LAN Interface DHCP Server
..................................................................................
DLP-012
Defining a User Group in the NetVanta
...........................................................................................
DLP-013
Adding a User to the Users Component Table
................................................................................
DLP-014
Using the IP Address Component Table
.........................................................................................
DLP-015
Adding a Service to the Services Component Table
.......................................................................
DLP-016
Generating a Self-Certificate Request
.............................................................................................
DLP-017
Uploading a CA Certificate to the NetVanta
....................................................................................
DLP-018
Uploading a Self-Certificate to the NetVanta
...................................................................................
DLP-019
Reviewing the Various Keys of the NetVanta
..................................................................................
DLP-020
Restoring the NetVanta to Factory Defaults
....................................................................................
DLP-021
Viewing the DHCP Info Table
..........................................................................................................
DLP-022

Rate

4 / 5 based on 1 vote.

Popular Adtran Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top