Instruction/ maintenance manual of the product 3050 Nortel Networks
Go to page of 15
Nortel Networks VPN Gateway 3050 RSA SecurID Ready Implementation Guide Last Modified: March 14, 2008 Partner Information Product Information Partner Name Nortel Networks Web Site www.nortelnetworks.com Product Name VPN Gateway 3050 Version & Platform 7.
Solution Summary The Nortel Networks VPN Gateway 3050 is a remote access se curity solution t hat extends the reach of enterprise applications a nd resources to remote employees, partn ers, and customers.
Product Requirement s Partner Product Requirements: Nor t el VPN Gateway 3050 Firmware Version 7.0.1.0 Hardware Platform Platform Required Patches VPN 3050, ASA 310, ASA 410, ASA 310 FIPS N/A Additional Software Requirements Application A dditional Patches Internet Explorer 5.
Agent Host Configuration Important: “Agent Hos t” and “Aut hentication Agent” are synony mous. “Agent Host” is a term used w ith the RSA Authentication Manager 6.x servers and below . RSA Authentication Manager 7.1 uses th e term “Authentica tion Agent”.
Partner Authentication Agent Configuration Before You Begin This section provides instruction s for int egrating t he partners’ product with RSA Secu rID Authentication. This document is not intended to su gge st optimum installations or configuratio n s.
Creating and Configuring a RSA SecurID or RADIUS User Group 1. From the admin console, expand VPN Gateways and click Add to add a VPN Gateway. 2. Click Create VPN . 3. Now click on the VPN Gateway you just creat ed and click on Groups . 4. Click on the button Add New Group .
Configure the RSA Server record 1. Open the Management Interf ace (MIP) of the Nortel VPN Gate way us ing a web browser. Authenticate with administrative user account and select the Config tab. 2. From the SSL-VPN admin menu select Administration > RSA Serv ers item.
Configuring the RADIUS Authentication Servers 6. From the admin console, select VPN Gateways > Authentication . 7. Click Ad d . 8. Enter information for the Authentication Server su ch as Name and Displ a y Name. The Authentication Mechanism will be RADIU S .
Configuring RADIUS Auth entication Servers for Administrative Access 1. From the admin console, select Administration > RADIUS . 2. Click Ad d . 3. Enter information for the RADIUS Authenticat ion Server. 4. Click update . 5. Enable authentication b y selecting en abled for RADIUS Authentic atio n Status.
Testing the configuration 1. Open a web browser and point to the portal a ddress. 2. For user credentials enter a SecurID userna me and Passc ode. 3. From the Login Service list select your RSA SecurID or RSA RADIUS challenge group. 4. Click Login to authenticate and enter the Portal Server.
Certification Checklist Date Tested: September 26, 2007 Certification Environment Product Name Version Information Operating System RSA A uthentication Manager 6.
Certification Checklist For RSA Authentication Manager 7.x Date Tested: March 14, 2008 Certification Environment Product Name Version Information Operating System RSA Authentication Man ager 7.1 Windows 2003 RSA RADIUS Server 7.1 Windows 2003 VPN Gateway 3050 7.
Known Issues PIN Rejection: When a PIN is rejected by the Authenticati on Man ager Se rver the user is questioned by the client to try a different PIN but the program flow is not intuitive. 1. The user first authenticates using either Token or Pass word.
Administration Logon. NEW-PIN mode does not work via the admin consol e. The use r is pro mpted to create or accept a PIN but the PIN never gets sent to the server and the user gets re directe d to a blank web page.
Appendix Delete Node Secret 1. Navigate to Config > Adminis tration > RSA Servers and click on the link for t he RSA Authentic atio n Server Label you created. 2. Click the button labeled Remo ve Node Secret . Remove sdconf.rec and sdstatus.12 1.
An important point after buying a device Nortel Networks 3050 (or even before the purchase) is to read its user manual. We should do this for several simple reasons:
If you have not bought Nortel Networks 3050 yet, this is a good time to familiarize yourself with the basic data on the product. First of all view first pages of the manual, you can find above. You should find there the most important technical data Nortel Networks 3050 - thus you can check whether the hardware meets your expectations. When delving into next pages of the user manual, Nortel Networks 3050 you will learn all the available features of the product, as well as information on its operation. The information that you get Nortel Networks 3050 will certainly help you make a decision on the purchase.
If you already are a holder of Nortel Networks 3050, but have not read the manual yet, you should do it for the reasons described above. You will learn then if you properly used the available features, and whether you have not made any mistakes, which can shorten the lifetime Nortel Networks 3050.
However, one of the most important roles played by the user manual is to help in solving problems with Nortel Networks 3050. Almost always you will find there Troubleshooting, which are the most frequently occurring failures and malfunctions of the device Nortel Networks 3050 along with tips on how to solve them. Even if you fail to solve the problem, the manual will show you a further procedure – contact to the customer service center or the nearest service center