Especificações Técnicas
Roteadores VPN Contivity Nortel Modelos 600, 1010, 1050, 1100, 1750, 2700 e 5000
Serviços de roteamento IP
• RIPv1, v2, Open Shortest Path First (OSPFv2), Border Gateway Protocol (BGP-4)
• 802.1Q VLAN routing
• Policy-based routing (next hop traffic filters)
• Virtual Router Redundancy Protocol (VRRP)
• Data Link Switching (DLSw); SNA encapsulation within IP
• Dynamic Routing over IPSec (RFC 3884)
Protocolos de “tunelamento” VPN
• IPSec, incluindo authentication header (AH), encapsulating security protocol (ES) e Internet key exchange (IKE)
• Point-to-point tunneling protocol (PPTP), incluindo compressão e encriptação
• Layer 2 Tunneling Protocol (L2TP), incluindo L2TP/IPSec
• Secure Sockets Layer (SSL) v2.0, 3.0 e Transport Layer Security (TLS) com SSL VPN Module
Encriptação
• Data Encryption Standard (DES)
• Triple DES (3DES) using 3 independent 56-bit keys; 168-bit key length (effective strength of 128 bits)
• Advanced Encryption Standard (AES); 128-bit e 256-bit versions
• RC4
Serviços de autenticação de usuários
• X.509 Digital Certificates e Smart Cards (suporte para grande maioria dos fabricantes e MS-CAPI)
• Remote authentication dial-in user services (RADIUS)
• Hard e soft token support (e.g., SecureID and AXENT)
• User name, password e NT Domain Login
• Interno ou externo lightweight directory access protocol (LDAP)
Serviços e protocolos WAN
• Point-to-Point Protocol (PPP); incluindo PPP over Ethernet (PPPoE)
• Frame Relay (incluindo FRF.9 compression e FRF.12 fragmentation)
• ADSL (G.DMT, G.Lite, ANSI T1.413) com suporte a PPP e PPPoE sobre ATM
• Dial-on-demand e serviço dial back-up via integral V.90 modem ou ISDN
Gerenciamento de Bandwidth - QoS
• Configuração dos parâmetros de bandwidth para Usuários e group-level
• Priorização de filas
• DiffServ (Differentiated Services) com code point marking
• 802.1 p/DSCP (Differentiated Services Code Point) mapping
• Multi-level Random Early Detection (MRED)
• Resource Reservation Protocol (RSVP)
Facilidades amigáveis de VoIP
• Secure IPSec transport of VoIP traffic
• SIP Application Layer Gateway (ALG) para NAT e stateful firewall
• Cone NAT (for Nortel Unistim protocol) com NAT “hairpinning”
• FRF.12 fragmentation
• Differentiated Services (DSCP) marking/mapping, incluindo DSCP marking através do VPN Client Nortel
Compressão de dados
• IPComp (RFC 3173) para encriptação e non-encrypted traffic
• FRF.9 Frame Relay compression
Contas
• Event, system, security e configuration logging
• Interno e externo RADIUS accounting
• Automatic archiving para external system
Gerenciamento
• Nortel VPN Router Multi-Element Manager provides multi-box provisioning para até 2,500 VPN Router devices
• Configuração completa de Web browser-based HTML
• Nortel Command Line Interface
• SSH para secure device configuration; SFTP client para secure back-up das configurações e dos logs
• Utilitário de simples instalação dos remote VPN Router set-up
• SNMP monitoração e alertas
• 3 níveis de acesso administrativo; gerenciamento role-based para separação dos service provider e dos end-user
Stateful firewall
• Multi-layers stateful packet inspection que suporta 100 protocolos de aplicação de rede, incluindo TCP, UDP, FTP, HTTP, H.323, RealAudio, Java e ActiveX
• Defense against major “hacker” attacks, incluindo DOS, SYN flood, Smurf, Ping, Spoofing, Fraggle e ICMP unreachable
• Extensive e customizáveis opções de login
• NAT, Proxy e end-user authentication
• Ilimitados usuários de firewall e políticas de tunelamento e tráfego de non-tunneled
Client VPN Nortel
• IPSec (com DES, 3DES e AES encriptação)
• Microsoft Windows 2000, XP e Vista-based clients
• Macintosh, Unix/Linux, Sun-Solaris e Windows Mobile (Pocket PC 2003) via licenças de software
Segurança endpoint
• Tunnel Guard enforces corporate security policies sobre endpoint PCs através de verificação por anti-virus, personal firewall ou qualquer outra aplicação de software ( patches) antes da conexão VPN
SSL VPN
• Support para até 1000 sessões seguras Web browser (com SSL VPN Module)
• Acesso através de Microsoft Internet Explorer, Netscape Navigator e browser Mozilla
• Acesso universal através de porta com IPSec ou SSL single sign-on pelos end-users
• Autenticação via RADIUS, LDAP, X.509 certificates
• Auto-logoff e cache-cleaning dos arquivos e históricos
Certifications
• ICSA (International Computer Security Association) 1.0d certification (IPSec)
• FIPS 140-2 (Federal Information Processing Standard for Security) suporte sobre VPN Router 600, 1750, 2700 e 5000; FIPS compliancy kit opcional
• Virtual Private Network Consortium (VPNC) Basic Conformance Testing (IPSec)
Licenças de software opcionais (para as linhas do VPN Router 1000, 2000 e 5000)
• Nortel VPN Router Stateful Firewall
• Nortel VPN Router Advanced Routing (OSPF, VRRP, bandwidth management)
• Nortel VPN Premium Routing (Advanced Routing plus BGP-4)
• Nortel VPN Client for MAC and UNIX
• Nortel VPN Router VPN Tunnel Upgrades (from 5 to max tunnels) available for Nortel VPN Router 1000 series, 1750 and 2700 models
• Nortel VPN Router Data Link Switching (DLSw
|