6
Alcatel-Lucent Security Management Server SECURITY, VPN, AND QoS MANAGEMENT SOLUTION The Alcatel-Lucent Security Management Server software brings you advanced carrier-grade IP services management at a low total cost of ownership (TCO). Teamed with Alcatel-Lucent award-winning VPN Firewall Brick™ security appliance portfolio and the Alcatel-Lucent IPSec Client, the Alcatel-Lucent Security Management Server lets you rapidly provision and manage high-return services for thousands of users in a single console. It integrates firewall, VPN, QoS, VLAN, VoIP and virtual firewall policy management; provides industry-leading scalability and availability; delivers robust monitoring, logs and reports; and provides flexible deployment options — all without the costly additional modules or recurring license fees that competitive products require. Applications • Advanced security services • VPN services for site-to-site and remote access • Bandwidth management capabilities • VoIP security • Secure data center Web and application hosting • Storage network security solution • Mobile data security • Packet data gateway and packet data interworking functions for fixed mobile convergence/Wi-Fi VPN and VoIP/data security • Managed security services • Unlicensed mobile access (UMA) and IP multimedia subsystem (IMS) security FEATURES BENEFITS • One management solution including remote management • Single platform provides centralized, comprehensive management of all IP services with real-time monitoring, robust logging and customized reporting • Low operating costs • Secure remote management reduces need for network reconfigurations, truck rolls, or on-site support; VLAN, virtual firewall, and QoS support included at no extra charge • Management efficiencies cut staffing and administrative expenses • Cost-saving growth • Easily migrate from basic to advanced security, VPN, and QoS services • Simple, economical licensing model • No ongoing license fees or add-ons required for complete security management • Native high availability and carrier class reliability • Assures business continuity through native high availability with carrier-class reliability, and virtually impenetrable to hacker attacks

Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Embed Size (px)

Citation preview

Page 1: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Alcatel-Lucent Security Management ServerS E C U R I T Y , V P N , A N D Q o S M A N A G E M E N T S O L U T I O N

The Alcatel-Lucent Security Management Server software brings you advanced carrier-grade IP services

management at a low total cost of ownership (TCO). Teamed with Alcatel-Lucent award-winning VPN

Firewall Brick™ security appliance portfolio and the Alcatel-Lucent IPSec Client, the Alcatel-Lucent Security

Management Server lets you rapidly provision and manage high-return services for thousands of users in a

single console. It integrates firewall, VPN, QoS, VLAN, VoIP and virtual firewall policy management; provides

industry-leading scalability and availability; delivers robust monitoring, logs and reports; and provides flexible

deployment options — all without the costly additional modules or recurring license fees that competitive

products require.

Applications

• Advancedsecurityservices

• VPNservicesforsite-to-siteandremoteaccess

• Bandwidthmanagementcapabilities

• VoIPsecurity

• SecuredatacenterWebandapplicationhosting

• Storagenetworksecuritysolution

• Mobiledatasecurity

• Packetdatagatewayandpacketdatainterworkingfunctionsforfixedmobileconvergence/Wi-FiVPNandVoIP/datasecurity

• Managedsecurityservices

• Unlicensedmobileaccess(UMA)andIPmultimediasubsystem(IMS)security

FEATURES BENEFITS

•Onemanagementsolutionincluding remote management

•Singleplatformprovidescentralized,comprehensivemanagement of all IP services with real-time monitoring,robustloggingandcustomizedreporting

•Lowoperatingcosts •Secureremotemanagementreducesneedfornetwork reconfigurations, truck rolls, or on-site support; VLAN, virtual firewall, and QoS support included at no extra charge

•Managementefficienciescutstaffingandadministrative expenses

•Cost-savinggrowth •Easilymigratefrombasictoadvancedsecurity, VPN, and QoS services

•Simple,economicallicensingmodel •Noongoinglicensefeesoradd-onsrequiredforcomplete security management

•Nativehighavailabilityandcarrier class reliability

•Assuresbusinesscontinuitythroughnative high availability with carrier-class reliability, and virtually impenetrable to hacker attacks

Page 2: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Alcatel-Lucent Security Management Server | Data Sheet2

Complete, cost-effective solutions for network security, VPN, VoIP, service-quality assurance and moreTheAlcatel-LucentVPNFirewallBrickportfoliooffersabroadrangeofenterpriseandcarrier-classsecuritysolutionstoprotectcorporateandserviceprovidernetworksdeliveringmission-criticalIPapplicationstoheadquarteremployees,branchoffices,tradingpartners,roadwarriorsandcustomers.Alcatel-LucentVPNFirewallBricksolutionshelpstretchITbudgetswithsuperbprice/performanceandlowtotalcostofownership.Leadingedgetechnologywithtimesaving,work-savingfeatureshelpmaximizeITstaffresources.Plusampleflexibility,availabilityandscalabilitysimplifydeploymentandmanagementofdiverseapplicationsincluding:

• Advancedsecurityservices

• VPNservicesforsite-to-siteandremoteaccess

• Bandwidthmanagementcapabilities

• SecuredatacenterWebandapplicationhosting

• Storagenetworksecuresolution

• Mobiledatasecurity

• Packetdatagatewayandpacketdatainterworkingfunctionsfordual-modewireless/Wi-FiVPNandVoIP/datasecurity

TheAlcatel-LucentVPNFirewallBrickportfolioformsauniquethreetiersecurityarchitectureandincludes:

• VPN Firewall Brick security appliances –Securityappliancesthatintegrateapplicationlayerinspection,firewallfunctionalitywithadvancedVPNcapabilitiesforsmallofficethroughdata-centerrequirements

• Alcatel-Lucent Security Management Server –Softwareforrobust,tightlysynchronizedfirewall,VPN,servicequality,VLANandvirtualfirewallpolicymanagement.

• Alcatel-Lucent IPSec Client–SoftwarethatprovidessecureremoteaccessVPNservicesformobileworkforceandtelecommuters

Deploy robust security safeguards network-wideTheVPNFirewallBricksecurityappliancesarebuiltassecurity-specificdevices.Incontrasttotraditionalrouter-basedsystems,theyoperateasintrinsicallysecureEthernetlayerbridgesthatarevirtuallyinvisibletohackersscanningyournetwork.Completelysegregatedfromtheroutingprocess,thesesecurityappliancesarenotvulnerabletodynamicroutingprotocolattacks.Inmanyinstances,theyareundetectablebyanydevicenotonthesamenetworksegment,protectingenterpriseswithahighlevelofstealthsecurity.

Reinforcingthisdepthofdefenseisthesecurityappliances’innovative,operatingsystem,acompactreal-timekerneldesignedexclusivelyforsecurity.Farlesseasilycompromisedthangeneralpurposeoperatingsystemsrunningonserverplatforms,thisexceptionallythinsystemvirtuallyeliminatesallpointsofvulnerability.

Asaresult,theVPNFirewallBricksecurityapplianceshavenosecurity-threateningbackdoors(notelnet,ftp,HTTPorotherinsecureaccessmethodcanbeusedtocompromisetheconfigurationofthesesecuritydevices)andcanonlybeaccessedbyasecure,encryptedmanagementchannelfromtheAlcatel-LucentSecurityManagementServersoftware.Thesoftwareaddsexposure-limitingsafeguardsincludingstrongIP-specificdenial-of-serviceattackprotection,premiumfirewallandVPNauthenticationservices,applicationlayerdefenseandcontent-levelsecurityincludingcommandblocking,URLblockingandauniquerules-basedroutingcapabilitythatseamlesslyintegratestheVPNFirewallBrickportfoliowithanythirdpartysecurityappliance(forexample:contentfilteringorvirusscanningsystems).

FEATURES BENEFITS

•Provencarrier-classperformance •Matureproductwithovertenyearsofserviceintheworld’slargestnetworks

•Distributableacrossuptofournetworkoperationscenters(NOCs)foractive/activenetworkredundancywithno single point of failure

•Integratedsecurity •Networkiskeptsecurethroughintegratedfirewall,VPN,QoS,VLANand virtual firewall management

•Flexiblemanagementmodel •Providesawiderangeofcontrolspoliciesatglobal,customer,device, interface, VLAN and IP address range levels

•MultipleIPservicesdeploymentoptions •Addressesspecificneedswithpremises-based,network-based,tiered, and data-center architecture deployment options

•Highscalability •Supports20,000Alcatel-LucentVPNFirewallBricksecurityappliances and up to 500,000 simultaneously connected Alcatel-Lucent IPSec Client (or third party) VPN users

Page 3: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Alcatel-Lucent Security Management Server | Data Sheet 3

Implement large-scale VPN support with high-performance packet processingTheVPNFirewallBricksecurityappliancesdelivertheperformanceneededtoprovidevitalsecurityandVPNservicesforthousandsofenterpriseusers.Highcapacitypacketprocessingcapabilitieshelpmaximizeuserefficiencyandproductivity.Systemsintheportfoliocanprovideupto1.7GbpsVPNthroughputandafull4.75Gbpsfirewallthroughput.Portfolio-widescalabilityhelpsprotectexpandinguserpopulationscosteffectively.

AsingleVPNFirewallBrickunitcansupportupto3millionsimultaneoussessionsandover20,000simultaneousVPNtunnels.Itshighlyefficientoperatingsystemcontributestotheseoutstandingprocessingcapabilitiesbyfreeingmemoryforsessionandpolicymanagement.

Streamline firewall deployment, configuration and management TheVPNFirewallBricksecurityappliancescanbeinstalledandworkingatanynetworklocation.Theseflexiblebridgingfirewallsworkasquicklyasaphysicalconnectioncanbemade.There’snoneedtore-segmentthenetwork,worryaboutdowntimeduringnetworkconversiontothenewtopologyorwaitashostsaredirectedtoanewgateway.Alcatel-LucentSecurityManagementServersoftwaredelivers:

• SophisticatedIPservicesmanagementcapabilitieswithlowoperatingcoststomanagesecurity,notindividualdevices—easysecuritydeployment,managementandmaintenancewithcentrallycontrolledVPNFirewallBrickclients

• Scalabilitytorapidlyprovisionandmanageupto20,000VPNFirewallBricksecurityappliancesand500,000Alcatel-LucentIPSecClients(orthirdpartyIPSecClient)usersfromoneconsole—fewerdevicestomaintainandfewerpeopletomaintainthem

• Seamlessintegrationoffirewall,VPN,bandwidthmanagement,virtualLAN(VLAN)andvirtualfirewallpolicymanagement—centralizedreal-timemonitoring,robustloggingandcustomizedreportingcapabilities

• IntegratedDenialofServiceprotection,intrusiondetection/preventionfacilitiesandintelligentcachemanagementcapabilitiesmaximizesuptimeandmitigatesimpactsofnetworkattacks

Leverage high-availability bandwidth management for consistent service qualityTheVPNFirewallBricksecurityappliancescanincreasebothnetworksecurityandqualityofservicethroughuniquelygranularbandwidthmanage-ment.Theyincorporate—atnoextracharge—robustimplementationofclass-basedqueuing(CBQ)technologyforcommitted-ratebandwidthcontrolandtrafficprioritization.Bandwidthlimitstohelpdefendagainstfloodattacks,andbandwidthguaranteestoenhanceend-userexperiences,areenforcedattheserveranduserlevels.Trafficcanbeclassifiedbyphysicalinterface,virtualfirewall,policyruleandsession,enablingsimplifiedyetpreciselytargetedsecurityimplementations.

Sustain business continuity with carrier-class reliability and availability Ahigh-availabilityarchitectureisbuiltintoeverycomponentoftheAlcatel-LucentBrickportfolio.Thereisnosinglepointoffailuresolution-wide.AllVPNFirewallBrickmodelssupportnativesub-secondfailovertoastandbyunit.Inanoutage,servicescontinueuninterrupted.Out-of-bandmanage-mentcapabilitiesensurecontinuedserviceevenifcommunicationsarelostduetoanetworkoutage.Foraddedreliability,Alcatel-LucentSecurityManagementServersoftwarecanbedistributedacrossmultiplegeographi-callydispersedoperationscentersforactive/activenetworkredundancy.Thisenablesimmediatedisasterrecoveryintheeventofacatastropheattheprimarymanagementlocation.

Keep your total ownership costs lowSolutionsbasedontheVPNFirewallBrickportfolioefficientlyaddresstheneedtocontainoperationsoutlays,makeefficientuseofin-housetechnicalexpertiseandprotectnetworkinvestments.Allsolutioncomponentsarebuilttointeroperatesmoothlywithexistinginfrastructureelements.Introducingthemrequiresnocostlynetworkretrofits.

TheVPNFirewallBrickportfoliohelpscutITstaffhoursandshortentime-to-servicewithitsfull-featuredbridgingsupport.Andbecauseitdoesn’trunonageneralpurposeoperatingsystem,iteliminatesthehighcostsandtime-intensiveeffortsassociatedwithOSupgradesandpatches.

Theperformance-provenAlcatel-LucentSecurityManagementServersecuritymanagementsolutionoffersonesimple,economicallicensingstructure—withoutcostlyadditionalmodulesorrecurringlicensefees.Itshigh-capacityprocessingandhighdevicecountmanagementcapabilitieshelpminimizeadditionalcapital-equipmentpurchases.

Anditscomprehensivesecuritysafe-guardsdramaticallyreducenetworkvulnerabilitiesthatconsumeITstafftimeandbudget.

Alcatel-Lucent VPN Firewall Brick portfolio

• Simplified management–Uniqueclient/serverdesign;centralizedstaging,real-timemonitoringandno-touchmanagementofallVPN,securityandservice-qualityassurancecapabilitiesviascalable,provenAlcatel-LucentSecurityManagementServer

• Full-featured bridging–Enablesstealthy,depthofdefensesecuritythatconventionalrouter-basedfirewallscannotmatch

Page 4: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Alcatel-Lucent Security Management Server | Data Sheet4

• Advanced security safeguards –Denial-of-serviceattackprotection;high-speedcontentsecurity;premiumauthenticationservices;withnooccurrencesofreportedadvisoriesorvulnerabilitiesandnobackdoors

• Uniquely granular bandwidth management–Maximizeservicequalityviaflexibleclass-basedqueuing(CBQ)technology,server-levelanduser-levellimitsandguarantees

• Carrier-grade reliability–Nativehigh-availabilityarchitecturewithnosinglepointoffailure

• Rules-based routing–Routesallpacketsmatchingtheruletoaproxy

server,routerorotherdeviceusingthird-partysoftwaretoperformcontentfilteringfunctionssuchascommandblocking,URLfilteringandvirusscan-ning.Itallowstransparentinteractionwithanythird-partyequipment

• High performance packet processing –Rangeofsystemsavailabletosupportuptothreemillionsimulta-neoussessions,1,100virtualfirewallsand20,000VPNtunnels

• Ultra-thin, highly secure operating system–Virtuallyimpenetrabletohackerattacks;freesmemoryforpacketprocessing,policymanagement

• Virtual firewall and VLAN support–Easilyassignandenforcesecuritypoliciesfordiverseusergroups

• Plug-and-play deployment–Imple-mentsecuremissioncriticalapplica-tionswithoutcostly,time-intensivenetworkreconfiguration

• Low ownership costs–Noongoingfeature-licensingexpenses;easyinstallation,managementandupgradessaveITstafftimeandeffort;highperformance,highcapacityfeaturesreducetheneedtopurchaseadditionalequipment

Technical specifications

Mode of operation•Centralizesfirewall,virtual

firewall, VLAN, VPN and QoS policy management

• ProactivelymonitorsallVPNFirewallBrick security appliances and Alcatel-Lucent IPSec Client users

•Providesreal-timemonitoring,log collection, reporting and alarm generation

• Supportsnetwork-basedandpremises-based deployments

Performance and capacity• Supports1,000customergroupseachwithhundredsofuniquepolicies

•Centrallycollectsupto30,000log records per Alcatel-Lucent Security Management Server or Compute Server for a maximum of 300,000 log records per second

•Centralmanagementofupto20,000 Brick devices and 500,000 simultaneously connected IPSec-based VPN users from a single management cluster

¬Hierarchicalsolutionconsistingofredundant Security Management Server and Compute Servers

¬ Each Alcatel-Lucent Security Management Server can manage up to 1,000 VPN Firewalls Brick and 100,000 IPSec based Remote Access VPN Users

¬ Up to four Security Management Server systems can be configured in a load sharing (co-located or geo-diverse) configuration

¬ Each Security Management Server System can support up to five Alcatel-Lucent Security Management Server Compute Servers for logging and management offloading

Policy management•Usesagroup-basedmodelto

manage a collection of devices, security policies, VPN tunnels, and user authentication components as a single entity

•Controlspoliciesattheglobal,customer, device, interface, VLAN and IP address range level

• Includespreconfiguredtypicalsecurity and VPN policy templates thatcanbetailoredtosuituniquerequirements

•Usesuser-definablehostgroups,service groups, application filters and user groups

Role-based administration•Usestwoadministrativeclasses:

¬ Alcatel-Lucent Security Man-agement Server Administrators – full privileges over all groups, devices, policies and users

¬ Group administrators – restricted privileges and access only to assigned group(s)

• Supportssharedadministrationwith customers

• Localandremoteadministration via Alcatel-Lucent Security Management Server Remote Navigator utility (included); provides secure access to all Alcatel-Lucent Security Management Server utilities

• Allowsconcurrentadministratorsto exchange messages via a real-time messenger service

Secure 3-tier architecture•Alcatel-LucentSecurity

Management Server to VPN Firewall Brick security appliance communications secured with Diffie-Helmanand3DES encryption,SHA-1authenticationand integrity, and digital certificates for VPN Firewall Brick Security Management Server authentication

•Alcatel-LucentSecurity Management Server Remote Navigator to Security Management Server communications secured with3DESencryptionandSHA-1authentication and integrity, and either local password or external database authentication with SecurID or RADIUS servers

• Transferslogsinreal-timeoverreliable, secured, AES-encrypted connections

Authentication•Built-ininternaldatabase–

10,000 users

•Browser-basedauthenticationallows authentication of any user protocol

• Localpasswords,RADIUS,SecurID,X.509 digital certificates

• PKICertificaterequests(PKCS12)

•UserassignableRADIUSattributes

•DoDPKI

Remote access VPN tunnel management• SupportsIKEv1andIKEv2remote

access VPN Clients, including the Alcatel-Lucent IPSec Client, third partyIPSecVPNclientsandIKEv2clients embedded in next-generation mobile products. Provides support forEAP-SIM,EAP-AKA,EAP-TLSand EAP-MD5

•CentralizesmanagementoftheAlcatel-Lucent IPSec Clients, includ-ing software distribution, software updates, client VPN configurations and client personal firewall settings

•Allowsanycombinationofauthentication methods; configurable per user, user group or application

• Supportsvirtualaddresses for tunnel end points

• Allowsadministratortoterminatespecific tunnels when necessary, or terminate all tunnels in a single action

Site-to-site VPN tunnel management•ProvidesSLAprobesforreal-time

round trip delay statistics and tunnel status indicators to verify tunnel availability in real-time; configurable with alarm notifications

• Supportsvirtualaddressesfortunnel end points

• Configurabletunneldefaultsettings

• IncludespreconfiguredVPNpolicy templates fully integrated with firewall policy

•SupportsIKEv1andIKEv2 site-to-site tunnels

Page 5: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

Alcatel-Lucent Security Management Server | Data Sheet 5

High availability/redundancy• Supportsactive/activemanagement

with up to four geographically distributed servers and realtime database replication

• Internaldatabaseautomaticallybacks up to a local and remote disk daily; additional backups can be scheduled at any time

• BackupfilecontainsALLpolicy,configuration, and security information for all configured devices and policies

Central staging with secure upgrades• SecurelypushestheVPNFirewall

Brick operating system to each device with no truck rolls or on site hardware support; maintains all sessions during an operating system upgrade with a failover pair of VPN Firewall Brick units

Application programming interfaces (APIs)• Scriptablecommandlineinterface

• Parse-ableASCIIlogfiles (for per-customer reporting)

• SupportsSNMPGETv2c(read-only)and SNMP traps v1 and v2c

Audit log management•Sixcategoriesofauditlogscre-ateddaily:

¬ VPN log

¬ Firewall session logs

¬ Administrative event logs

¬ User authentication logs

¬ Proactive monitoring statistic logs

¬ SOX audit log

•RealtimelogsviewablewithLogViewer; historical logs viewable with Log Viewer or Reporting System (see below).

• Logviewingandmanipulationfollows administrative permissions model

•Configurablelogfiledisk management

•Automatedlogschedulingandforwarding for post-processing

Real-time log viewer•Displayslogrecordsasreceived

from all VPN Firewall Brick security appliances; messages can be filtered, sorted and highlighted

• Includeshistoricalrecordsearchcapabilities with specified time parameters

Reporting system•Automaticallymergesdatafrom

geographically distributed log servers

•GeneratesHTML-basedreportswith full filtering, sorting and scheduling capabilities; configurable per administrator

•Reportsincludesessionsovertime, policy snapshots, administrator events and configuration changes

• Includespreconfiguredreportsforfast initial deployment

Customer specific report generation and delivery• IntegrateswiththeWebTrends

Firewall Reporting Suite; uses theWebTrendsEnhancedLogFormat(WELF)

• Fullyautomatesgenerationanddelivery of customer-specific, traffic statistic graphic reports to customers via FTP, e-mail or http server

Policy change control•Recordsalladministrativeactivity

to audit logs

• Capturesallpolicyandconfigurationchanges in detailed, user-configu-rable history files that are secured fromtampering/modificationandsupport policy roll-back

Alarms•GeneratesalarmsbasedonVPN

Firewall Brick log messages and locally generated log messages from Alcatel-Lucent Security Management Server subsystems; configurable per-administrator

• Includespreconfiguredalarms for fast initial deployment

• Configurablealarmtriggersinclude:

¬ Security Management Server Error

¬ VPN Firewall Brick Error

¬VPNFirewallBrickLost/Found

¬ VPN Firewall Brick Interface Up/Down

¬ Proactive Monitoring Threshold Crossing

¬ VPN Firewall Brick Redundancy Alarms

¬ Security Management Server Redundancy Alarms

• Configurablenotificationmethods:

¬ Console Alarm (via the Alcatel-Lucent Security Management Server Remote Navigator)

¬ E-mail

¬ Out-of-band modem-dialed alphanumeric message sent to pager (via the TAP protocol)

¬ SNMP Trap

¬ SYSLOG Message (with configurable SYSLOG level)

•Alarmtriggerscanbemappedtoany combination of notification methods

Real-time status monitors• Supportreal-timeandhistorical

dynamically-updating text and graphical monitoring

•VPNFirewallBricksecurity appliance monitor – provides windows for each device and aggregate collection of devices; monitors statistics for each physical port, packet, byte, andsession;includesqualityof service graphs to monitor throughput and performance relative to configured guarantees and limits

•VPNtunnelmonitor–providesstatus of each VPN tunnel; monitors service level agreements (SLAs) for VPN tunnel round- trip delay

•AdministratorandAlcatel-LucentSecurity Management Server monitor – views all logged-in administrators and connection statistics; reports connection status of each Security Management Server or Compute Server in real-time

Command line interface• Allowsadministratorstoscriptthe

configuration of many Alcatel-Lucent Security Management Server components and policy objects using a text file-based interface

SNMP agent•Access-limitedconfigurationand

statistic information regarding the system and associated VPN Firewall Brick security appliances in a read only manner via the Alcatel-Lucent Security Management Server. Access limited configuration and statistic information regarding the “VPN Firewall” Brick security appliances is available from either the Alcatel-Lucent Security Man-agement Server or from the VPN Firewall Brick Security appliance in SNMP v2c format.

VPN Firewall Brick remote console• Providesasecureremoteconsole

to any VPN Firewall Brick security applianceandexecutesdebugging/troubleshooting commands

•Nopolicymodificationscanbemade from this Remote Console or any VPN Firewall Brick console interface

Rules-based routing• ProvidescapabilitytoconfigurearuleforHTTP,FTP,orSMTPprotocol traffic. Routes all packets matching the rule to a proxy server, router or other device utilizingthirdpartysoftwaretoperform content filtering functions such as command blocking, URL filtering, and virus scanning. Allows transparent interaction withanythirdpartyequipment

Alcatel-Lucent Security Management Server and Compute ServerSoftware requirements:

• SunSolaris™ 2.9 or 2.10 on SPARC processors

•RedHatLinuxversionRHEL4andRHEL5supportonx86processors

•WindowsXPProfessional,WindowsServer2003,orWindowsVistaBusiness

Hardware requirements:Sun®WorkstationorserverforSunSolarisOperatingSystem:

• SolarisSparc:

¬600MHzUltraSPARCorbetter

¬ 512 MB of memory or more

• LinuxRHEL4/5:

¬700MHzPentiumIIIorbetter

¬ 1 GB of memory or more

•WindowsXP/2003:

¬700MHzPentiumIIIorbetter

¬ 512 MB of memory or more

•Vista:

¬700MHzPentiumIIIorbetter

¬ 1 GB of memory or more

•Common:

¬ Swap space at least as large as system memory

¬ 4GB free disk space in file system partition where software is to be installed

¬ 50MB free disk space in root partition

¬One10/100Ethernetinterface

¬ CD-ROM drive

¬ 3.5” floppy drive, USB port and serial port (Floppy is only requiredforoldermodelBricks.Brick50,150,700,1200 Models donotrequiretheFloppy)

¬ Video card capable of supporting minimum resolution of 1024x768 (65,535 colors)

Page 6: Alcatel-Lucent Security Management Serversupport.alcadis.nl/files/get_file?file=Alcatel-Lucent%2FBrick+VPN... · 2 Alcatel-Lucent Security Management Server | Data Sheet Complete,

www.alcatel-lucent.com Alcatel, Lucent, Alcatel-Lucent and the Alcatel-Lucent logo are trademarks of Alcatel-Lucent. All other trademarks are the property of their respective owners. The information presented is subject to change without notice. Alcatel-Lucent assumes no responsibility for inaccuracies contained herein. Copyright © 2009 Alcatel-Lucent. All rights reserved. EPG3310090808 (09)

PART NUMBER DESCRIPTION

301033320 Alcatel-Lucent Security Management Server v9.4 Base Package (includes license to manage up to five VPN Firewall Brick products, and 100 simultaneous client tunnels (including IPSec client and third party IPSec VPN clients)

301033338 Alcatel-Lucent Security Management Server v9.4 Redundancy Package (for high availability applications – up to three supported per Security Management Server v9.4 base package)

301033346 Alcatel-Lucent Security Management Server v9.4 Compute Server Package (for offloading logging and management functions – up to five supported per Security Management Server (either Base or Redundancy package)

301033411 Management license to manage five additional VPN Firewall Brick devices

301033429 Management license to manage 25 additional VPN Firewall Brick devices

301033437 Management license to manage 50 additional VPN Firewall Brick devices

301033445 Management license to manage 100 additional VPN Firewall Brick devices

301033452 Management license to manage 250 additional VPN Firewall Brick devices

301033460 Management license to manage 500 additional VPN Firewall Brick devices

301033387 V9.4 upgrade Alcatel-Lucent Security Management Server v9.4 Base package to v9.4 base

301033478 SMS 9.4 Radius Accounting License – enables the use of Radius Accounting for dual mode services

301033395 9.4 Redundant upgrade package

301033403 9.4 Compute server upgrade package

301033379 9.4 Lawful Intercept License

301033353 9.4 Radius Accounting License

Ordering Information