Page 316 / 342 Scroll up to view Page 311 - 315
16
Using Managed Services
316
Nokia IP45 Security Platform User’s Guide v4.0
To use Nokia Horizon Manager to access and manage your IP45 security platform
from the GUI:
1.
Choose Setup from the main menu, and choose Management.
2.
Choose IP Address Range next to SSH, and specify the IP address of Nokia Horizon
Manager.
3.
Click Apply.
To use Nokia Horizon Manager Interface to access and manage your IP45 security
platform:
1.
Click Devices in the main menu and choose Create Devices to create an IP45 device.
2.
Click Nokia Small Office Series Platform - IP45 for device type.
3.
In the Device text box, type the Device Name (IP45) or the IP address.
4.
Click Yes for Use Secure connection.
5.
Type the device login and password.
6.
Click OK at the bottom of the menu.Your IP45 device is created.
For more details see
Nokia Horizon Manager User Guide
.
Check Point SmartCenter LSM
Check Point SmartCenter Large Scale Manager (LSM) allows you to manage many Check Point
Remote Office/Branch Office (ROBO) gateways from a single SmartCenter Server. The Check
Point LSM concept is based on Gateway Profiles, which are defined in the standard Check Point
SmartDashboard. Each Gateway Profile represents many ROBO gateways.
For additional information on installing and configuring LSM, see
Check Point SmartCenter
LSM documentation.
To configure NG AI and IP45 for site-to-site by using LSM profiles on the IP45
Side
1.
Connect the IP45 to the SmartCenter.
±
Click Services on the main menu and choose Connect.
±
Specify the IP address of Check Point LSM, and click Next.
±
Type the Gateway ID and registration key as defined in VPN-1 Edge/Embedded ROBO
gateway, and click Next to continue.
±
After successful connection, the Confirmation window opens giving a list of services to
which you have subscribed.
Page 317 / 342
Check Point SmartCenter LSM
Nokia IP45 Security Platform User’s Guide v4.0
317
2.
Open http://my.firewall and verify the following before you proceed:
a.
Enterprise site was added to the VPN site page.
b.
The LSM profile object certificate was synchronized to the device.
c.
Topology was loaded to the device. This should be verified from
http://my.firewall/vpntopo.html.
3.
You can verify that the tunnel is open by sending packets from the IP45 to the VPN-1
gateway.
To configure NG AI and the Nokia IP45 security platform for site-to-site by using
LSM profiles on Check Point
1.
Enable LSM: in the command prompt, type LSMenabler on, and reset the FW services.
2.
Open SmartDashboard and define a new VPN-1 edge embedded ROBO profile.
3.
Name the LSM profile, and click OK.
4.
Click Save on SmartDashboard and close.Open SmartLSM.
5.
Define a new VPN-1 edge embedded gateway, and select the LSM profile you defined.
Make sure to choose the correct HA type (IP45).
6.
Open SD again, and define a Star Community.
Place VPN-1 GW in the Central Gateway, and the LSM profile in the Satellite Gateway.
7.
Define a new UDP service on ports to 9281-9282, and name it SW.
8.
Place the SW service in the excluded services of the Star Community you defined.
9.
Create the rule base, or policy used for managing your device.
10.
Install the policy.
Page 318 / 342
16
Using Managed Services
318
Nokia IP45 Security Platform User’s Guide v4.0
Page 319 / 342
Nokia IP45 Security Platform User’s Guide v4.0
319
17
Troubleshooting
This chapter provides troubleshooting tips, problems your Nokia IP45 security platform might
encounter, and solutions for them and includes the following topics:
±
Debugging
±
Configuring Debugging Levels
±
Frequently Asked Questions
±
Resetting the IP45 Security Platform to Factory Defaults
±
Failsafe Mode
±
Running Diagnostics
±
Using Packet Sniffer
Debugging
Debugging commands serves as a troubleshooting tool for advanced customers and support
engineers by displaying feature-specific information to the enabling console and optionally to
the log file. You can configure debug levels by using CLI, for the following features:
±
DDNS
±
Dial-up
±
HA
±
Kernel-bgp
The performance of the device does not get affected even if debugging is disabled. But when
debugging is enabled for many features, it can affect the primary firewall and VPN task of the
Nokia IP45. Debugging should be enabled judiciously and for brief periods.
The debugging commands enable debugging messages based on customer-defined criteria of
feature and level.
Configuring Debugging Levels
Use the following commands to configure DDNS debugging levels:
set debug ddns level<0-9>
Page 320 / 342
17
Troubleshooting
320
Nokia IP45 Security Platform User’s Guide v4.0
Use the following commands to configure dial-up debugging levels:
set debug dialup level<0-9>
Use the following commands to configure HA debugging levels:
set debug ha level<0-9>
Use the following commands to configure kernel-bgp debugging levels
set debug kernel-bgp level<0-9>
Viewing Debugging Levels
Use the following commands to view debugging levels:
show debug <ddns | dialup | ha | kernel bgp>
For more information about debug commands, see the
Nokia IP45 Security Platform CLI
Reference Guide Version 4.0
Frequently Asked Questions
Please list the modems that are supported.
The following modems are supported:
±
Analog modem 56 Kbps (DTE speed: up to 115200)
±
ISDN TA (using PPP) 64 Kbps (DTE speed: up to 230400)
±
ISDN TA (using MLPPP) 128 Kbps (DTE speed: up to 460800)
I cannot access the Internet. What should I do?
Check for the following:
±
Check if the PWR LED is active. If not, check the power connection to the IP45.
±
Check if the WAN LED is on. If not check the network cable to the modem and make sure
the modem is turned on.
±
Check if the LAN LED for the port that your computer uses is on. If not, check if the
network cable linking your computer to the IP45 is connected properly.
±
Use your web browser to go to http://my.firewall and check whether
connected
appears on
the status bar. Make sure that the IP45 network settings are configured according to your
service center directions.
±
Check your TCP/IP configuration according to Chapter 2
.
±
If the firewall level is set to High, try setting it to Medium or Low.
±
If Web filtering or email antivirus scanning are on, try turning them off.
±
Erase all your block rules through the security menu.
±
Check with your ISP for possible service outage.

Rate

3.5 / 5 based on 2 votes.

Popular Nokia Models

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top