Lucent Technologies Network Card VPN Firewall Brick 20 User Manual |
®
VPN Firewall Brick 20
Security, VPN, and QoS Gateway
The VPN Firewall Brick® 20 platform offers a readily affordable CPE
solution for delivering service level-assured advanced security, IP VPN,
and bandwidth management services to small-office and home-office
locations. This carrier-class IP services platform stretches investment
dollars with low price/performance and total ownership costs and
delivers service-enhancing, revenue-building features.
Applications
Benefits
• Advanced security services
• Low price/performance — less than the per-Mbps price
of major competitors
• Site-to-site and remote access VPN services
• Bandwidth management services
• Mobile data services
• Low cost of ownership — one configuration
supports multiple IP services with no additional or
recurring licensing fees; VLAN and virtual firewall
support for up to 20 customers at no additional cost;
management efficiencies reduce staffing and
administrative expenses
• Shared Internet connectivity
• Secure intranets and extranets
• Flexible deployment options — premises or network-
based services with shared or dedicated hardware
environments
Features
• Integrates firewall, VPN, QoS, VLAN, and virtual
firewall capabilities in one configuration
• Economical growth path — migrate to advanced
security and VPN services with no added infrastructure
investments
• 140 Mbps firewall performance; 3 Mbps 3 DES
performance; 55 simultaneous VPN tunnels; 4,094
VLANs; 20 virtual firewalls
• No-touch CPE — no need for costly network
reconfigurations, truck-rolls, or onsite support
• Intrinsically secure, transparent Layer-2 bridge
• Enhanced user experiences — efficient bandwidth
management with customer-level, user-level, and
server-level QoS control
• Central staging and secure remote management via
Lucent Security Management Server (LSMS) software;
®
manages thousands of VPN Firewall Brick units and
• Assured business continuity — native high availability,
carrier-class reliability
Lucent IPSec Client users from one console
• Innovative security services: advanced distributed
denial of service attack protection; high-speed content
security (command blocking, URL filtering, virus
scanning); strong authentication; real-time
monitoring, logging, and reporting
• Scalable, carrier-class management — centrally manage
up to 1,000 VPN Firewall Brick units and 10,000
Lucent IPSec Client users
®
• High-availability architecture — no single point of
failure
• No advisories or reported vulnerabilities
13.VPN
Maximum number of dedicated VPN tunnels – 55
18.Certifications
ICSA V3.0A Firewall Certified, ICSA V1.0B IPSec Certified
Manual Key, IKE, PKI (X.509)
3DES (168-bit), DES (56-bit)
SHA-1 and MD5 authentication/integrity
Replay attack protection
National Security Agency EAL2 Government Protection Profile
Certified, EAL4 in progress
19.Mean Time Between Failure
127,000 Hrs.
Remote access VPN
Site-to-site VPN
20.Dimensions (W x L x H)
IPSec NAT Traversal (UDP encapsulated IPSec)
LZS compression
Spliced and nested tunneling
6.2” x 8.6” x 1.3” 16 cm x 22 cm x 3 cm
21.Cooling
Passive heatsink
14.VPN Authentication
22.Operating Altitude
Local passwords, RADIUS, SecurID, X.509 digital
certificates with Entrust CA
Up to 13,123 ft (4,000 m)
PKI Certificate requests (PKCS 12)
Automatic LDAP certificate retrieval
23. Environmental
Operating
Temperature: 0 to 40º C
15.High Availability
VPN Firewall Brick® platform to VPN Firewall Brick®
Shock: 2.5g at 15 – 20 ms on any axis
Relative Humidity: 5–95%
Vibration: 5g at 2 – 200Hz on any axis
Non-Operating
platform active/passive failover with full synchronization
400 millisecond device failure detection and activation
Session protection for firewall and VPN
Link failure detection
Temperature: 0 to 70º C
Shock: 35g at 15 – 20 ms on any axis
Relative Humidity: 5–95%
Vibration: 5g at 2 – 200Hz on any axis
Alarm notification on failover
Encryption and authentication of session
synchronization traffic
Self-healing synchronization links
Lucent Proxy Agent load sharing supports high
availability for content security services
24.Power
External AC to DC Power Supply: rated 25W Max
Switching mode, 100–240V AC, 50–60Hz
Consumption: 0.19A typical at 115VAC
16.Diagnostic Tools
Out of band debugging and analysis via serial
port/modem/terminal server
25.Safety Listings
Centralized, secure remote console to any VPN Firewall Brick®
unit supporting Ping, Traceroute, packet trace with filters
USA – UL® 1950
Canada – CSA 22.2 No. 950
EU – EN/IEC 60950
Japan – CB Scheme IEC 60950
Remote VPN Firewall Brick® platform bootstrapping
Real-time log viewer analysis tool
17.3-Tier Management Architecture
26.EMC Certifications
USA – FCC Part 15, Class B
Canada – IC-ES003
EU – EMC Directive
Japan – VCCI
Centralized, carrier-class, active/active management
architecture with Lucent Security Management Server
(LSMS) software
Secure VPN Firewall Brick® platform to LSMS
communications with Diffie-Helman and 3DES encryption,
SHA-1 authentication and integrity and digital certificates
for VPN Firewall Brick® platform/LSMS authentication
Up to 100 simultaneous administrators securely managing
all aspects of up to 1000 VPN Firewall Brick® units
Secure, reliable, redundant real-time alarms, logs, reports
®
VPN Firewall Brick 20 platform – Back Panel
3
Lucent Proxy Agent
1.Software Requirements
Solaris™ 8
2.Hardware Requirements
Sun® workstation
333 MHz Pentium® Pro processor (minimum)
512 MB system memory (minimum), higher recommended
CD-ROM drive
To learn more, contact your
dedicated Lucent Technologies
representative, authorized
reseller, or sales agent. You
can also visit our Web site at
1 Ethernet 10/100 card
Ordering Information
This document is provided for planning
purposes only and does not create,
modify, or supplement any warranties
which may be made by Lucent
Technologies relating to the products
and/or services described herein.
The publication of information
contained in this document does not
imply freedom from patent or other
protective rights of Lucent Technologies
or other third parties.
®
1.VPN Firewall Brick 20 platform
Part Number 300323748
2.External 3.25” Floppy Drive
Part Number 300318953
3.Lucent Security Management Server
See LSMS data sheet for ordering details
4.Lucent Proxy Agent
Included in LSMS software
VPN Firewall Brick is a registered
trademark of Lucent Technologies Inc.
5.Lucent IPSec Client
See Lucent IPSec Client data sheet for ordering details
ActiveX is a trademark of
Microsoft corporation.
InterScan is a registered trademark
of Trend Micro, Inc.
Java is a trademark of
Sun Microsystems, Inc.
Pentium is a registered trademark
of Intel Corporation.
Solaris is a trademark of
Sun Microsystems, Inc.
Sun is a registered trademark of
Sun Microsystems, Inc.
UL is a registered trademark of
Underwriter's Laboratories.
X-Stop is a trademark of
Log-On Data Corp.
Copyright © 2004
Lucent Technologies Inc.
All rights reserved
VPN v4.04/04
|