Summary of the content on the page No. 1
Nokia Network Voyager
for IPSO 4.0
Reference Guide
Part No. N451818001 Rev A
Published October 2005
Summary of the content on the page No. 2
COPYRIGHT ©2005 Nokia. All rights reserved. Rights reserved under the copyright laws of the United States. RESTRICTED RIGHTS LEGEND Use, duplication, or disclosure by the United States Government is subject to restrictions as set forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013. Notwithstanding any other license agreement that may pertain to, or accompany the delivery of, this computer software, the rights of the United States
Summary of the content on the page No. 3
Fax 1-650-691-2170 Mail Nokia Inc. Address 313 Fairchild Drive Mountain View, California 94043-2215 USA Regional Contact Information Americas Nokia Inc. Tel: 1-877-997-9199 313 Fairchild Drive Outside USA and Canada: +1 512-437-7089 Mountain View, CA 94043-2215 email: info.ipnetworking_americas@nokia.com USA Europe, Nokia House, Summit Avenue Tel: UK: +44 161 601 8908 Middle East, Southwood, Farnborough Tel: France: +33 170 708 166 and Africa Hampshire GU14 ONG UK email: info.ipnetworking_emea@
Summary of the content on the page No. 4
4 Nokia Network Voyager for IPSO 4.0 Reference Guide
Summary of the content on the page No. 5
Contents About the Nokia Network Voyager Reference Guide . . . . . . . . .19 Conventions This Guide Uses . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 Notices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 Text Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21 Menu Items . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 Related Documentation . . . . . . . . . . . .
Summary of the content on the page No. 6
Configuring Tunnel Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . 33 Ethernet Interfaces. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 Configuring Ethernet Interfaces. . . . . . . . . . . . . . . . . . . . . . . . . . 34 Link Aggregation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35 Managing Link Aggregation Using SNMP. . . . . . . . . . . . . . . . . . 36 Configuring Switches for Link Aggregation . . . . . . .
Summary of the content on the page No. 7
Configuring Unnumbered Interfaces . . . . . . . . . . . . . . . . . . . . . 107 Configuring OSPF over Unnumbered Interface . . . . . . . . . . . . 110 OSPF over Unnumbered Interfaces Using Virtual Links . . . . . . 110 Cisco HDLC Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111 Point-to-Point Protocol . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112 Frame Relay Protocol. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Summary of the content on the page No. 8
Changing DHCP Service. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149 Adding DHCP Address Pools . . . . . . . . . . . . . . . . . . . . . . . . . . 149 Enabling or Disabling DHCP Address Pools. . . . . . . . . . . . . . . 150 Assigning a Fixed-IP Address to a Client . . . . . . . . . . . . . . . . . 150 Creating DHCP Client Templates . . . . . . . . . . . . . . . . . . . . . . . 151 Configuring Dynamic Domain Name System Service. . . . . . . . 153 Configuring the Domain Name
Summary of the content on the page No. 9
Downgrading Nokia IPSO Images. . . . . . . . . . . . . . . . . . . . . . . 176 Configuring Monitor Reports . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177 Managing Packages. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 178 Installing and Enabling Packages . . . . . . . . . . . . . . . . . . . . . . . 178 Advanced System Tuning . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 180 Tuning the TCP/IP Stack. . . . . . . . . . . . . . . . . . . . . .
Summary of the content on the page No. 10
Cluster Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 210 Clustering Modes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 212 Considerations for Clustering . . . . . . . . . . . . . . . . . . . . . . . . . . 214 If You Do Not Use a Dedicated Primary Cluster Protocol Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 Upgrading IPSO in a Cluster . . . . . . . . . . . . . . . . . . . . . . . . . . . . 217 For
Summary of the content on the page No. 11
6 Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249 SNMP Overview. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 249 SNMP Proxy Support for Check Point MIB . . . . . . . . . . . . . . . . . 252 Using the Check Point MIB . . . . . . . . . . . . . . . . . . . . . . . . . . . . 253 Using cpsnmp_start. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 253 Enabling SNMP and Selecting the Version . . . . . . . . .
Summary of the content on the page No. 12
Using VRRPv3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278 Creating a Virtual Router to Back Up Another VRRP Router Addresses Using VRRPv3 . . . . . . . . . . . . . . . . . . . . . 278 Monitoring the Firewall State. . . . . . . . . . . . . . . . . . . . . . . . . . . 279 Setting a Virtual MAC Address for a Virtual Router. . . . . . . . . . 280 Changing the IP Address List of a Virtual Router in VRRPv3 . . 281 Removing a Virtual Router in VRRPv3 . . . . . . . .
Summary of the content on the page No. 13
Configuring Secure Shell Authorized Keys . . . . . . . . . . . . . . . . 308 Changing Secure Shell Key Pairs . . . . . . . . . . . . . . . . . . . . . . . 309 Managing User RSA and DSA Identities. . . . . . . . . . . . . . . . . . 310 Tunneling HTTP Over SSH . . . . . . . . . . . . . . . . . . . . . . . . . . . . 311 Network Voyager Session Management . . . . . . . . . . . . . . . . . . . 311 Enabling Enabling or Disabling Session Management . . . . . . . 312 Configuring Session Timeouts .
Summary of the content on the page No. 14
Routing Protocols . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351 Route Maps. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 353 OSPF . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 353 Types of Areas . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 354 Area Border Routers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 355 High Availability Support
Summary of the content on the page No. 15
Configuring IGRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 388 DVMRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 390 Configuring DVMRP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 391 Configuring DVMRP Timers . . . . . . . . . . . . . . . . . . . . . . . . . . . 391 IGMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 392 Configuring IGMP . . . . . . . . .
Summary of the content on the page No. 16
BGP Multi Exit Discriminator Example . . . . . . . . . . . . . . . . . . . 419 Changing the Local Preference Value Example . . . . . . . . . . . . 421 BGP Confederation Example . . . . . . . . . . . . . . . . . . . . . . . . . . 423 Route Reflector Example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 426 BGP Community Example. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 428 EBGP Load Balancing Example: Scenario #1 . . . . . . . . . . . . . 430 EBGP Load Balancing E
Summary of the content on the page No. 17
Configuring a COPS Client ID and Policy Decision Point . . . . . 462 Configuring Security Parameters for a COPS Client ID . . . . . . 462 Assigning Roles to Specific Interfaces . . . . . . . . . . . . . . . . . . . 463 Activating and Deactivating the COPS Client . . . . . . . . . . . . . . 464 Changing the Client ID Associated with Specific Diffserv Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 464 Deleting a Client ID . . . . . . . . . . . . . . .
Summary of the content on the page No. 18
Displaying Interface Settings. . . . . . . . . . . . . . . . . . . . . . . . . . . 487 Hardware Monitoring . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 487 Using the iclid Tool. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 iclid Commands. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 488 Preventing Full Log Buffers and Related Console Messages . . . 494 Index . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Summary of the content on the page No. 19
About the Nokia Network Voyager Reference Guide This guide provides information about how to configure and monitor Nokia IPSO systems. This guide provides conceptual information about system features and instructions on how to perform tasks using Nokia Network Voyager, the Web-based interface for IPSO. All of the tasks that you perform with Network Voyager you can also perform with the command-line interface (CLI), allowing you to choose the interface you are most comfortable with. For in
Summary of the content on the page No. 20
About the Nokia Network Voyager Reference Guide the hostname . It also describes how to save configuration sets, schedule jobs, backup and restore files, manage and upgrade system images, reboot the system, manage packages, and advanced system tuning. Chapter 4, “Virtual Router Redundancy Protocol (VRRP)” describes how to provides dynamic failover of IP addresses using VRRP. Chapter 5, “Configuring Clustering” describes how to provide fault tolerance and dynamic load balancing using cluste