
Secure Remote Access Technical Solution Guide v1.0
______________________________________________________________________________________________________
22
For complete information about this solution, see the CS 1000-C200 VoIP Solution and
Configuration Guide in the VPN Router 200 Series section of the Nortel customer support portal
at www.nortel.com/cs
.
4.2.4 Network management
The primary element management solution for the VPN Gateway is the browser based interface
(BBI) or command line interface (CLI). Both support secure encrypted connections through
HTTPS or SSH, and these should be used instead of clear-text protocols. To provide accurate
administrative access control and auditing, use a network-based authentication system such as
RADIUS for administrative access rather than local administrative accounts. Configure an
administrative Access Control List to limit which hosts and subnets can connect to the
management interfaces. When possible, employ a separate management VLAN and interface.
Use SNMPv3 for network-based performance management and fault reporting.
As with all network security products, follow a process to track software patches and upgrades.
The Nortel support portal at www.nortel.com/cs
provides a My Alerts feature for timely
information about patches and updates.
4.2.5 Converged applications and clients
The Secure Remote Access Solution described and detailed in the preceding sections provides
the infrastructure for the media-rich clients. The infrastructure is a means, and the applications
and clients are the end. The ability to provide a secure, resilient, and high performing
infrastructure is key to enhancing productivity and the end-user experience. As applications and
services converge onto a single infrastructure, it is critical to ensure resiliency and quality of
service from end to end – the network is now mission critical to the enterprise.
There are many clients and applications that can now take advantage of the Secure Remote
Access Solution. These include:
¾ IP Telephony
¾ IP Softphone 2050
¾ IP Phones (see SOHO solution is section 4.2.3.2)
¾ Multimedia Communication Server (MCS)
¾ Unified Messaging, including Nortel CallPilot
The following sections provide a brief overview of the solutions available.
4.2.5.1 Small IP Telephony platforms – Business Communications Manager
The Nortel Business Communications Manager 50/200/400 is an integrated communications
platform for both multisite enterprises and single-site small to medium businesses. Each delivers
a highly reliable, innovative, converged voice/data solution that enables a business to save
money by streamlining costs, and to make money by increasing revenues, expanding market
reach, and improving customer service. The BCM delivers PBX functionality along with no-
compromise voice mail and auto attendant features. Combined with its robust quality of service
(QoS) routing capability, it provides a single cost-effective solution for both data and voice needs.
As businesses grow, the BCM functionality can be extended with a simple key code to deliver
business-critical applications that positively impact the bottom line. The BCM provides enterprise-
level telephony and data services, all in an easily managed platform. From one platform, a
business can cost-effectively extend its communication capabilities. The Nortel Business
Communications Manager system’s built-in routing capabilities and data services such as firewall,
web caching, and network address translation (NAT) enable a business to connect its LAN to the
Internet quickly, reliably, and securely. The Nortel Business Communications Manager also offers
Kommentare zu diesen Handbüchern