IBM 1G User Manual - Contents

Manual is about: IBM Security Network Active Bypass

Summary of 1G

  • Page 1

    Ibm security 1g network active bypass user guide.

  • Page 2

    Copyright statement © copyright ibm corporation 2009, 2014. U.S. Government users restricted rights — use, duplication, or disclosure restricted by gsa adp schedule contract with ibm corp. Publication date: april 2014.

  • Page 3: Contents

    Contents homologation statement - regulation notice. . . . . . . . . . . . . . . . V safety, environmental, and electronic emissions notices . . . . . . . . . . Vii about this publication . . . . . . . Xvii contacting ibm support . . . . . . . . . Xviii chapter 1. Introducing the network active bypa...

  • Page 4

    Iv 1g network active bypass: user guide.

  • Page 5

    Homologation statement - regulation notice this product is not intended to be connected directly or indirectly by any means whatsoever to interfaces of public telecommunications networks. © copyright ibm corp. 2009, 2014 v.

  • Page 6

    Vi 1g network active bypass: user guide.

  • Page 7

    Safety, environmental, and electronic emissions notices safety notices may be printed throughout this guide. Danger notices warn you of conditions or procedures that can result in death or severe personal injury. Caution notices warn you of conditions or procedures that can cause personal injury tha...

  • Page 8

    When working on or around the system, observe the following precautions: electrical voltage and current from power, telephone, and communication cables are hazardous. To avoid a shock hazard: v connect power to this unit only with the ibm ® provided power cord. Do not use the ibm provided power cord...

  • Page 9

    Caution: the battery contains lithium. To avoid possible explosion, do not burn or charge the battery. Do not: v throw or immerse into water v heat to more than 100°c (212°f) v repair or disassemble exchange only with the ibm approved part. Recycle or discard the battery as instructed by local regul...

  • Page 10

    Product safety labels one or more of the following safety labels may apply to this product. Danger hazardous voltage, current, or energy levels are present inside any component that has this label attached. Do not open any cover or barrier that contains this label. (l001) danger multiple power cords...

  • Page 11

    Laser compliance all lasers are certified in the u.S. To conform to the requirements of dhhs 21 cfr subchapter j for class 1 laser products. Outside the u.S., they are certified to be in compliance with iec 60825 as a class 1 laser product. Consult the label on each part for laser certification numb...

  • Page 12

    Remarque : cette marque s'applique uniquement aux pays de l'union européenne et à la norvge. L'etiquette du systme respecte la directive européenne 2002/96/ec en matire de déchets des equipements electriques et electroniques (deee), qui détermine les dispositions de retour et de recyclage applicable...

  • Page 13

    Le recyclage des batteries et accumulateurs usés. Cette étiquette est appliquée sur diverses batteries pour indiquer que la batterie ne doit pas être mise au rebut mais plutôt récupérée en fin de cycle de vie selon cette norme. In accordance with the european directive 2006/66/ec, batteries and accu...

  • Page 14

    This class a digital apparatus complies with canadian ices-003. Avis de conformité aux normes du minist?re des communications du canada cet appareil numérique de las classe a est conform à la norme nmb-003 du canada. European union (eu) electromagnetic compatibility directive this product is in conf...

  • Page 15

    Zulassungsbescheinigung laut dem deutschen gesetz über die elektromagnetische verträglichkeit von geräten (emvg) vom 18. September 1998 (bzw. Der emc eg richtlinie 89/336) für geräte der klasse a. Dieses gerät ist berechtigt, in Übereinstimmung mit dem deutschen emvg das egkonformitätszeichen - ce -...

  • Page 16

    Xvi 1g network active bypass: user guide.

  • Page 17: About This Publication

    About this publication this guide is designed to help you connect to and configure your network active bypass unit. Scope this guide includes basic information and the required procedures for connecting the network active bypass unit to your network and for configuring basic settings. Audience this ...

  • Page 18

    Contacting ibm support ibm support provides assistance with product defects, answers faqs, and helps users resolve problems with the product. Before you begin before you contact ibm support, search for an answer or a solution by using other options first: v see the support portfolio topic in the sof...

  • Page 19

    Chapter 1. Introducing the network active bypass unit the network active bypass unit is an external device that uses active bypass functions to ensure that network traffic continues to flow if the appliance fails or loses power. The network active bypass unit provides seamless failover, extensive ma...

  • Page 20

    V configuration of the number of link losses before activating bypass v configuration of the number of heartbeats before disabling bypass secured web management the network active bypass unit provides a secured web management interface that includes the following items: v extensive cli interface v s...

  • Page 21

    About the unit familiarize yourself with the features of the network active bypass unit before you add the unit to your network. Front panel diagram the following figure illustrates the front panel of the network active bypass unit. Note: segments are arranged right-to-left, in the following order: ...

  • Page 22

    Basic operation this topic describes the basic operating principles of the network active bypass unit. Typical deployment the following diagram shows how the data is transferred from the network to the network ips through the network active bypass unit, and highlights the associated functions handle...

  • Page 23

    Switching mode description bypass bypass mode channels ethernet frames from the public network to port n1 (network in). Data is routed through a closed loop from port n1 (network in) to port n2 (network out) and bypasses the network ips appliance so that frames go directly from the public network to...

  • Page 24

    Operation modes the network active bypass unit uses the following operation modes: operation mode description 0: normal active bypass (default mode) if the bypass unit receives heartbeat signals within the timeout period, the switching mode remains or is changed to active switching mode. If the bypa...

  • Page 25

    Chapter 2. Setting up the network active bypass unit this chapter contains information you need to connect and configure the network active bypass unit. Configuring and deploying the network active bypass unit this topic contains detailed steps for configuring and deploying the network active bypass...

  • Page 26

    Placing the network active bypass unit and the network ips appliances procedure 1. Decide where to place the network active bypass unit and the network ips appliances. 2. Add the network active bypass unit and the network ips appliances to the rack. 3. Connect the cable to the network ips appliances...

  • Page 27

    Setting up e-mail notification about this task configure e-mail notification to receive a status e-mail when the state of the network active bypass unit changes. You must set up e-mail notification before you configure your segments. Setting up segments procedure 1. In the management interface, sele...

  • Page 28

    10 1g network active bypass: user guide.

  • Page 29: Management Interface

    Chapter 3. Configuring the network active bypass unit in the management interface you can use either the management interface or the command line interface to set most of the configuration options for the network active bypass unit. This chapter lists the configuration options available through the ...

  • Page 30

    Accessing the management interface you can manage and monitor the network active bypass unit from any web browser. Prerequisite make sure that the ethernet management port for the network active bypass unit is connected to the local network or to the host computer. Default management port ip address...

  • Page 31

    Monitoring the status of the network active bypass unit this topic provides information about using the management interface to monitor the status of the network active bypass unit. Checking overall status the status page is the first page you see when you log in to the management interface. Use the...

  • Page 32

    Managing settings for the network active bypass unit use the management interface to view or change settings for the network active bypass unit. Setting up segment configurations procedure 1. In the management interface, select the segment configuration page. 2. Complete the fields for each of the f...

  • Page 33

    Field description operation mode specifies the operation mode of the network active bypass unit: v 0: normal active bypass (default mode) - if the network active bypass unit receives heartbeat signals within the timeout period, the switching mode remains or is changed to active switching mode. If th...

  • Page 34

    Configuring management port settings procedure use the management port page to configure ip settings for the management port. Field description ip address ip address of the management port default: 192.168.0.111 network mask ip address of the network or subnet mask default: 255.255.255.0 gateway ip ...

  • Page 35

    Field description subject subject to be displayed in the subject line of the outgoing e-mail message example: “proventia nab status report” configuring snmp traps about this task the network active bypass unit provides an snmp trap function that can send messages to a trap server when the segment st...

  • Page 36

    Synchronizing time and setting time zones procedure use the ntp setting page to enable the network time protocol (ntp) to synchronize the network active bypass unit time with a network time server. Use the time setting page to set the time zone for the network active bypass unit. Set the values as d...

  • Page 37

    Backing up or restoring settings procedure use the backup/restore page to make a backup file or to return the network active bypass unit to its default settings. Complete the fields as indicated in the following table. Field description backup saves a copy of current settings on the network active b...

  • Page 38

    Restarting the network active bypass unit about this task use the restart page to restart the network active bypass unit. Configuring remote authentication about this task use the remote authentication page to configure settings for the tacacs+ protocol. The tacacs+ (terminal access controller acces...

  • Page 39

    Chapter 4. Configuring the network active bypass unit using the command line interface you can use either the management interface or the command line interface to set most of the configuration options for the network active bypass unit. This chapter lists the command line parameters, and describes ...

  • Page 40

    Field description user type the user name note: the default user is admin. Password type the password note: the default user is admin. Note: you can change the password through the command line interface or through the management interface. Syntax for command line parameters this topic outlines the ...

  • Page 41

    Command line parameters this topic lists the command line parameters available for the network active bypass unit. The parameters are divided into the following categories: v management port v communication v e-mail notification v snmp v operational use parameters with care use these command line pa...

  • Page 42

    Parameter description dhcp dhcp client dhcp: set this parameter to dhcp to enable the dhcp client on the network active bypass unit management port. Static: set this parameter to static to disable the dhcp client on the network active bypass unit management port host host name for the unit this para...

  • Page 43

    Parameter description email_to list of e-mail addresses to which the notification should be sent snmp parameters the parameters in the following table control the sending of snmp traps. Parameter description snmp enables or disables the snmp function v 0: disables snmp function v 1: enables snmp fun...

  • Page 44

    Parameter description op_mode default operation mode for the network active bypass unit v 0: normal active bypass if heartbeat is received, system will be inline. V 1: normal active inline if heartbeat is received, system will be in bypass. V 2: manual active v 3: manual active bypass v 4: manual pa...

  • Page 45

    Parameter description tacacs_secret tacacs+ secret default: none tacacs_server ip number of tacacs+ server tacacs_service tacacs+ service default: all chapter 4. Configuring the network active bypass unit using the command line interface 27.

  • Page 46

    28 1g network active bypass: user guide.

  • Page 47: Notices

    Notices this information was developed for products and services offered in the u.S.A. Ibm may not offer the products, services, or features discussed in this document in other countries. Consult your local ibm representative for information on the products and services currently available in your a...

  • Page 48

    Licensees of this program who wish to have information about it for the purpose of enabling: (i) the exchange of information between independently created programs and other programs (including this one) and (ii) the mutual use of the information which has been exchanged, should contact: ibm corpora...

  • Page 49: Index

    Index b backup/restore 19 c command line interface accessing 21 parameters 23 command line syntax 22 e e-mail notification 16 f firmware update 19 i ibm security support portal xviii technical support xviii troubleshooting xviii m management interface 11 management port settings 16 p package content...

  • Page 50

    32 1g network active bypass: user guide.

  • Page 52

    Printed in usa.