EasyManua.ls Logo

Nortel BCM50a User Manual

Nortel BCM50a
315 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
BCM50a
BCM50a Integrated Router
Document Number: N0115791
Document Version: 1.0
Date: September 2006
BCM50a Integrated Router Configuration —
Advanced

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Nortel BCM50a and is the answer not in the manual?

Nortel BCM50a Specifications

General IconGeneral
ModelBCM50a
Maximum Users50
Max number of IP Trunks8
VoIP SupportYes
Maximum Stations50
Maximum Trunks12
Product TypeBusiness Communication Manager
Integrated ApplicationsVoicemail, Call Center
Power SupplyAC
Ports8 digital station ports, 4 analog line ports

Summary

Chapter 1 Getting to know your BCM50a Integrated Router

Preface

Introduction to the guide's purpose and scope, including text conventions and related publications.

Introducing the BCM50a Integrated Router

Introduces the BCM50a Integrated Router as a secure gateway and outlines its key features.

Physical features

Discusses ADSL2+ support for high transmission speeds and lists supported ADSL standards.

Networking compatibility

States compatibility with major ADSL Digital Subscriber Line Access Multiplexer (DSLAM) providers.

Multiplexing

Explains support for VC-based and LLC-based multiplexing methods.

Encapsulation

Details supported encapsulation methods like PPPoA, RFC 1483, and PPP over Ethernet.

Four-Port switch

Describes the integrated switch functionality for connecting multiple devices to the LAN.

Autosensing 10/100 Mb/s Ethernet LAN

Describes automatic adjustment of LAN interfaces for crossover or straight-through Ethernet cables.

Time and date

Explains how to set the router's time and date, manually or from an external server.

Reset button

Details the function of the reset button for restoring factory defaults.

IPSec VPN capability

Describes establishing secure Virtual Private Network tunnels using IPSec for encrypted internet communication.

Nortel Contivity Client Termination

States support for VPN connections using Nortel Contivity VPN Client software.

Certificates

Explains the use of digital certificates for user authentication and public key exchange.

SSH

Describes the use of SSH (Secure Shell) for secure communication between hosts.

HTTPS

Explains HTTPS for secure web GUI access to the router using SSL.

Firewall

Details the stateful inspection firewall with DoS protection, TCP/UDP inspection, and real-time alerts.

Brute force password guessing protection

Describes a mechanism to deter password guessing attacks by enforcing wait times after incorrect attempts.

Content filtering

Explains blocking web features, proxies, and specific URLs using keyword features and time periods.

Packet filtering

Describes blocking unwanted traffic entering or leaving the network using packet filtering mechanisms.

Universal Plug and Play (UPnP)

Explains how UPnP-enabled devices can dynamically join a network and convey capabilities.

Call scheduling

Describes configuring time periods to restrict and allow access for users on remote nodes.

PPPoE

Explains PPPoE's role in high-speed data network access via a dial-up interface.

Dynamic DNS support

Describes using Dynamic DNS for static host name aliases for dynamic IP addresses.

IP Multicast

Explains the use of IP multicast for delivering packets to groups of hosts using IGMP.

IP Alias

Describes partitioning a physical network into logical networks over the same Ethernet interface.

Central Network Management

Explains how network administrators can manage the router remotely for configuration and upgrades.

SNMP

Describes SNMP for exchanging management information between network devices using TCP/IP.

Network Address Translation (NAT)

Explains translating multiple IP addresses within one network to different IP addresses in another.

Traffic Redirect

Details forwarding WAN traffic to a backup gateway when the primary connection fails.

Port Forwarding

Explains forwarding incoming service requests to a specific server on the local network.

DHCP (Dynamic Host Configuration Protocol)

Describes DHCP for clients obtaining TCP/IP configuration and the router's DHCP server capability.

Full network management

Mentions the web configurator and SMT interface for managing and configuring the router.

Logging and tracing

Lists logging and tracing functions, including message logging, packet tracing, and syslog support.

Upgrade BCM50a Integrated Router Firmware

Explains how to upgrade the router's firmware manually through the WebGUI.

Embedded FTP and TFTP Servers

Describes embedded FTP and TFTP servers for firmware upgrades and configuration backups.

Secure broadband internet access and VPN

Details broadband internet access via ADSL, IP address sharing, firewall, and VPN capabilities.

Chapter 2 Introducing the SMT

Introduction to the SMT

Explains accessing the System Management Terminal (SMT) and its menu overview.

Initial screen

Describes the router's internal tests and line initialization upon startup.

Logging on to the SMT

Details the process of logging into the SMT interface using username and password.

Navigating the SMT interface

Explains how to navigate the SMT interface for router configuration using menus and commands.

Main menu

Describes the BCM50a Integrated Router Main Menu displayed after logging into the SMT.

Changing the system password

Provides steps to change the administrator password for the BCM50a Integrated Router.

SMT menus at a glance

Provides a visual overview of the SMT menu structure and navigation flow.

SMT menu 1 - general setup

Guides users through filling in the required fields in the General Setup screen.

Configuring dynamic DNS

Explains how to configure Dynamic DNS settings by enabling the feature and filling in service provider details.

Chapter 3 WAN Setup

Introduction to WAN setup

Introduces the process of configuring the WAN port settings using Menu 2.

WAN setup

Guides users to access Menu 2 from the main menu to configure WAN settings.

Traffic redirect setup

Explains how to configure parameters for traffic redirection to a backup gateway using Menu 2.2.

Chapter 4 LAN setup

Introduction to LAN setup

Introduces the configuration of the BCM50a Integrated Router for LAN connections using Menu 3.

Accessing the LAN menus

Guides users to access the LAN configuration menus by selecting Menu 3 from the main menu.

LAN port filter setup

Describes specifying filter sets to apply to LAN traffic for blocking packets and enhancing security.

TCP/IP and DHCP ethernet setup menu

Details configuring TCP/IP and DHCP settings for the Ethernet interface via Menu 3.2.

IP Alias Setup

Explains how to configure IP Alias to create multiple logical LAN interfaces through a single Ethernet interface.

Chapter 5 Internet access

Internet access configuration

Guides users on entering Internet Access information using Menu 4, requiring ISP account details.

Basic setup complete

Confirms successful setup and initial connection to the network and internet.

Chapter 6 Remote Node setup

Introduction to Remote Node setup

Describes configuring protocol-independent parameters for a remote node required for calls to a remote gateway.

Outgoing Authentication Protocol

Discusses employing the strongest possible authentication protocols for secure remote connections.

Nailed-Up Connection

Explains a dial-up connection that remains always up, regardless of traffic demand, at potential higher costs.

Remote Node profile

Guides the configuration of a remote node's profile by selecting and editing its settings in Menu 11.1.

Encapsulation and Multiplexing scenarios

Discusses choosing encapsulation and multiplexing methods based on ISP requirements and LAN-to-LAN needs.

Edit IP/Bridge

Details the steps to edit TCP/IP parameters for a remote node's network layer options in Menu 11.3.

Remote Node filter

Explains configuring filter sets to apply to traffic between a remote node and the router to prevent unwanted call triggers.

Editing ATM Layer Options

Guides on editing ATM Layer Options for remote nodes, with versions depending on multiplexing and PPP encapsulation choices.

Advance Setup Options

Details accessing advanced setup options, particularly when PPPoE is selected in the Encapsulation field.

Chapter 7 IP Static Route Setup

IP Static Route Setup

Guides on configuring static routes with the BCM50a Integrated Router using Menu 12.

Chapter 8 Dial-in User Setup

Dial-in User Setup

Explains creating user accounts for local authentication without a RADIUS server.

Chapter 9 Network Address Translation (NAT)

Using NAT

Discusses configuring NAT and firewall rules to allow traffic forwarding from WAN to BCM50a Integrated Router.

SUA (Single User Account) Versus NAT

Explains SUA as a subset of NAT with Many-to-One and Server mapping types.

Applying NAT

Guides on applying NAT via menus 4 or 11.3 for Internet access and remote node configuration.

NAT setup

Details creating mapping tables to assign global addresses to LAN computers using address mapping sets.

Address Mapping Sets

Guides on accessing Menu 15.1 to configure address mapping sets for NAT.

SUA Address Mapping Set

Describes accessing the SUA Address Mapping Set screen (Figure 34) where fields cannot be changed.

Ordering your rules

Emphasizes the importance of rule order for packet processing and action selection in NAT.

General NAT examples

Provides examples of NAT configuration scenarios, including internet access only.

Example 2: Internet access with an inside server

Illustrates configuring internet access with an inside server using SUA Only set and Menu 15.2.

Example 3: Multiple public IP addresses with inside servers

Demonstrates mapping multiple public IP addresses to inside servers for FTP, web, and mail services.

Chapter 10 Introducing the firewall

Using SMT menus

Guides on accessing Menu 21 for Filter Set and Firewall Configuration.

Activating the firewall

Explains how to activate the firewall using Menu 21.2 to protect against DoS attacks.

Chapter 11 Filter configuration

Introduction to filters

Introduces filters used for deciding packet passage, call initiation, and their subdivision into device and protocol filters.

Filter Structure

Explains filter sets consisting of multiple rules, system limits, and application to ports.

Configuring a Filter Set

Provides a procedure to configure a new filter set, starting with menu 21.

Configuring a Filter Rule

Guides on configuring a filter rule by typing its number in the Filter Rules Summary menu.

Configuring a TCP/IP Filter Rule

Explains how to create TCP/IP filter rules based on IP and upper-layer protocol fields.

Configuring a Generic Filter Rule

Describes configuring generic filter rules to filter non-IP packets by treating them as byte streams.

Example Filter

Demonstrates blocking outside users from accessing the router via Telnet using a filter example.

Filter Types and NAT

Discusses the two classes of filter rules: Generic Filter (Device) and Protocol Filter (TCP/IP).

Firewall Versus Filters

Refers to Chapter 10 for firewall configuration and compares filtering, NAT, and firewall functions.

Applying a Filter

Shows where to apply filters after designing them, noting pre-configured filters for NetBIOS, Telnet, FTP, and HTTP.

Applying LAN Filters

Explains applying LAN traffic filter sets to block packets, reduce traffic, and prevent security breaches via menu 3.1.

Applying Remote Node Filters

Guides on applying filter sets to remote nodes via menu 11.1.4, including call filter sets for PPPoE/PPPoA.

Chapter 12 SNMP Configuration

SNMP Configuration

Explains how to configure SNMP settings using Menu 22, noting it requires TCP/IP configuration.

SNMP Traps

Lists events that trigger SNMP traps sent to the SNMP manager, such as system startup or authentication failures.

Chapter 13 System security

System security

Outlines configuring system password, external RADIUS server, and 802.1x authentication.

System password

Guides on changing the system password and the importance of not forgetting it.

Configuring external RADIUS server

Details the steps to configure external RADIUS server settings for authentication and accounting.

Chapter 14 System information and diagnosis

Introduction to System Status

Introduces diagnostic tools for maintaining the router, including system status, port status, and log capabilities.

System Status

Explains how to access System Status to view firmware version, port status, and packet statistics.

System information and console port speed

Describes how to choose different console port speeds and access system information.

System Information

Explains how to obtain system information, including routing protocol, Ethernet address, and IP address.

Console port speed

Details changing the console port speed through Menu 24.2.2.

Log and trace

Explains the syslog facility for message logging and trace function for viewing call-triggering packets.

Syslog logging

Describes using the syslog facility to log CDR and system messages to a syslog server, with configuration options.

Packet triggered

Explains packet triggered log messages and their formats.

Filter log

Provides the format for filter log messages, explaining source, destination, and protocol details.

PPP log

Describes the PPP log message format and examples of PPP connection status messages.

Firewall log

Explains the format of firewall log messages, including source, destination, protocol, and action details.

Call-Triggering packet

Describes how call-triggering packets are displayed and their equivalent hex format information.

WAN DHCP

Explains enabling DHCP on LAN or WAN, and using WAN Release/Renewal fields in Menu 24.4.

Chapter 15 Firmware and configuration file maintenance

Filename conventions

Explains the naming conventions for configuration files (*.rom) and system firmware (*.bin) files.

Backup configuration

Guides on backing up the router's configuration to a computer using FTP, emphasizing its speed and recommendation.

Using the FTP command from the command line

Provides step-by-step instructions for using FTP commands to back up configuration files from the router.

Example of FTP commands from the command line

Shows a sample FTP session demonstrating commands for file transfer, including get and put.

GUI-based FTP clients

Describes general commands commonly found in GUI-based FTP clients for file management.

TFTP and FTP over WAN Management Limitations

Lists conditions under which TFTP, FTP, and Telnet over WAN do not function correctly.

Backup configuration using TFTP

Explains using TFTP for uploading and downloading firmware and configuration files, recommending LAN use.

Restore configuration

Guides on restoring a previously saved configuration, warning about overwriting the current settings.

Restore Using FTP

Explains using FTP as the preferred method for restoring configurations due to its speed.

Uploading Firmware and Configuration Files

Details how to upload firmware and configuration files, referencing procedures for restore and upload menus.

Firmware file upload

Describes using FTP as the preferred method for uploading firmware and configuration files via Telnet.

Configuration file upload

Explains accessing menu 24.7.2 via Telnet for uploading system configuration files using FTP.

FTP file upload command from the DOS prompt example

Provides an example of FTP file upload commands executed from a DOS prompt.

TFTP file upload

Explains using TFTP for uploading firmware and configuration files over LAN, with notes on Telnet and CI mode requirements.

TFTP upload command example

Shows an example TFTP command for uploading firmware files, explaining parameters like host and transfer mode.

Chapter 16 System Maintenance menus 8 to 10

Command Interpreter mode

Introduces the Command Interpreter (CI) for low-level setup and diagnostics, accessible via SMT menu 24.8.

Command syntax

Explains the syntax rules for commands, including keywords, required/optional fields, and symbols.

Command usage

Guides on finding and using commands, including help, full commands, and exiting to the SMT.

Call control support

Describes call control functions like budget management and call history, applicable for PPPoE/PPPoA.

Budget management

Explains budget management statistics for outgoing calls and how to configure call time limits.

Call History

Describes accessing call history to view information about past incoming and outgoing calls.

Time and Date setting

Explains setting the router's time and date manually or from an external server via Menu 24.10.

Resetting the Time

Details the three instances when the router automatically resets its time.

Chapter 17 Remote Management

Remote Management

Explains determining which services and protocols can access the router's interface from remote locations.

Remote Management Limitations

Lists conditions under which remote management may not function, such as filter rules or service disabling.

Chapter 18 Call scheduling

Introduction

Introduces call scheduling feature for managing remote nodes, dictating call times and duration.

Appendix A Setting up your computer IP address

Windows 95/98/Me

Guides on configuring TCP/IP settings for Windows 95/98/Me by accessing network configuration.

Installing components

Explains installing necessary network components like adapter, TCP/IP protocol, and Client for Microsoft Networks.

Configuring

Details configuring TCP/IP properties by setting IP address, subnet mask, and DNS information.

Windows 2000/NT/XP

Guides on accessing network connections and control panel for TCP/IP configuration in Windows 2000/NT/XP.

Macintosh OS 8/9

Provides instructions for configuring TCP/IP settings on Macintosh OS 8/9 via the Control Panel.

Verifying Settings

Checks TCP/IP properties in the TCP/IP Control Panel window.

Macintosh OS X

Explains configuring TCP/IP settings for Macintosh OS X by accessing System Preferences and Network settings.

Verifying settings

Checks TCP/IP properties in the Network window.

Appendix B Triangle Route

The Ideal Setup

Illustrates an ideal network topology where the router acts as a secure gateway between LAN and Internet.

The Triangle Route Problem

Explains the triangle route problem occurring with multiple internet connections and alternate gateways on the LAN.

IP aliasing

Describes using IP aliasing to partition networks into logical sections and act as a gateway for each.

Appendix C Importing certificates

Import BCM50a Integrated Router certificates into Netscape Navigator

Guides on importing router certificates into Netscape Navigator to trust the server certificate.

Importing the BCM50a Integrated Router Certificate into Internet Explorer

Explains importing certificates into Internet Explorer to trust the router's self-signed or CA-issued certificate.

Enrolling and Importing SSL Client Certificates

Details the requirement for SSL clients to have certificates when 'Authenticate Client Certificates' is enabled.

Installing the CA’s certificate

Guides on installing a Certificate Authority's trusted certificate to produce a recognized security certificate.

Installing your personal certificates

Explains the process of installing personal certificates provided by a CA, requiring a password.

Using a certificate when accessing the BCM50a Integrated Router example

Provides a procedure to access the BCM50a Integrated Router via HTTPS using client certificates.

Appendix D PPPoE

PPPoE in action

Explains PPPoE's role in establishing PPP sessions over Ethernet for ADSL connections to DSLAMs.

Benefits of PPPoE

Lists benefits of PPPoE, including a familiar dial-up interface and reduced burden on carriers.

Traditional dial-up scenario

Depicts a typical hardware configuration using PCs with traditional dial-up networking.

How PPPoE works

Explains the PPPoE driver, Ethernet framing, and L2TP tunneling between Access Concentrator and ISP.

BCM50a Integrated Router as a PPPoE client

Describes how PCs on the LAN see only Ethernet when the router acts as a PPPoE client, simplifying administration.

Appendix E Hardware specifications

Cable pin assignments

Illustrates Ethernet cable pin assignments for both straight-through and crossover connections.

Appendix F IP subnetting

IP addressing

Explains how routers route data packets based on network numbers and host IDs.

IP classes

Categorizes IP addresses into classes (A, B, C, D) based on the first octet's value and bit structure.

Subnet masks

Defines subnet masks and their use in determining network and host ID bits using logical AND operations.

Subnetting

Explains subnetting by ignoring class arrangements and converting host ID bits to network number bits.

Example: two subnets

Illustrates creating two separate networks from a class C address by borrowing one host ID bit.

Example: four subnets

Shows how to divide a class C address space into four subnets by borrowing two host ID bits.

Example: eight subnets

Demonstrates creating eight subnets using a 27-bit mask and provides last-octet values for class C IP addresses.

Subnetting with Class A and Class B networks.

Explains how subnet masks determine network and host ID bits for Class A and Class B addresses.

Appendix G Command Interpreter

Command Syntax

Explains the syntax rules for commands, including keywords, required/optional fields, and symbols.

Command usage

Guides on finding and using commands, including help, full commands, and exiting to the SMT.

Sys commands

Lists and describes system commands preceded by 'sys', such as 'stdio' and 'hostname'.

Ethernet Commands

Lists and describes Ethernet commands that must be preceded by 'ether', like 'config' and 'status'.

IP commands

Lists and describes IP commands preceded by 'ip', such as 'address', 'alias', and 'ping'.

IPSec commands

Lists and describes IP Sec commands preceded by 'ipsec', covering debug, timer, and policy configuration.

WAN Commands

Lists and describes WAN commands, including ADSL, ATM, and hwsar functions, preceded by 'wan'.

Sys firewall commands

Lists and describes system firewall commands, preceded by 'sys firewall', for managing ACLs, logs, and DoS protection.

Bandwidth management commands

Lists and describes bandwidth management commands preceded by 'bm', covering interface, class, and filter configurations.

Certificates commands

Lists and describes certificate commands, including creating, importing, exporting, and verifying certificates.

Appendix H NetBIOS filter commands

Introduction

Introduces NetBIOS packets used for LAN communication and explains how to configure NetBIOS filters.

Display NetBIOS filter settings

Shows how to display current NetBIOS filter modes and their default settings using the 'sys filter netbios disp' command.

NetBIOS filter configuration

Explains configuring NetBIOS filters for LAN/WAN traffic, IPSec packets, and call initiation using 'sys filter netbios config'.

Example commands

Demonstrates configuring NetBIOS filters for various traffic types and call initiation scenarios.

Appendix I Enhanced DHCP option commands

Enhanced DHCP option commands introduction

Introduces enhanced DHCP features for adding site-specific options to DHCP server offer messages.

Specifying the Nortel BCM50 IP address

Details the syntax for assigning a specific IP address to the Nortel BCM50 via DHCP.

Nortel BCM50 DHCP server options

Explains using commands to add site-specific options to DHCP server offer messages for Nortel devices.

BCM50 DHCP server settings

Describes syntax for configuring BCM50 DHCP server modes and IP address ranges.

BCM50 IP sets override setting

Explains the command to configure Nortel BCM50 DHCP server settings and override default IP assignment behavior.

Nortel i2004 IP phone options

Describes adding site-specific options to DHCP messages for Nortel i2004 IP telephones.

VoIP server settings assignment

Details the syntax for assigning VoIP server information, including IP address and port, to IP telephones.

VLAN ID assignment

Explains assigning VLAN IDs to IP telephones using DHCP, specifying interface and VLAN ID details.

Nortel WLAN handsets 2210 & 2211 phone options

Mentions WLAN handsets require similar options to IP phones, with additional site-specific options.

TFTP server IP address assignment

Describes assigning a TFTP server IP address to WLAN handsets via DHCP.

WLAN IP Telephony Manager IP Address Assignment

Explains assigning a WLAN Telephony Manager IP address to WLAN handsets using DHCP option 151.

Appendix J Log descriptions

Log descriptions

Introduces appendix providing descriptions of various log messages generated by the router.

System error logs

Lists and describes system error log messages.

System maintenance logs

Lists and describes system maintenance log messages.

UPnP logs

Describes UPnP log messages indicating packets passing through the firewall.

Content filtering logs

Lists and describes content filtering log messages for URL access and blocking.

Attack logs

Lists and describes firewall attack log messages, including TCP, UDP, ICMP, and IP spoofing attacks.

Access logs

Lists and describes access log messages related to firewall policies and rule matches.

VPN/IPSec logs

Guides on viewing IPSec and IKE connection logs using menu 27, showing typical logs from a VPN initiator.

Example VPN initiator IPSec log

Displays a typical log from the VPN connection initiator, detailing the IPSec negotiation process.

VPN responder IPSec log

Shows a typical log from the VPN connection peer, including log index, date/time, and messages.

Configuring what you want the BCM50a Integrated Router to log

Explains using 'sys logs load' and 'sys logs category' commands to configure logging settings.

Displaying logs

Guides on showing all logs or specific log settings using 'sys logs display' and 'sys logs category display' commands.

Log command example

Demonstrates setting up access logs and alerts recording and viewing the results using command-line commands.

Appendix K Brute force password guessing protection

Brute force password guessing protection

Describes commands for enabling, disabling, and configuring the mechanism to prevent brute-force password guessing.

Related product manuals