BinTec X8500 User manual

X8500 Software Configuration Guide 1
X8500
Software Configuration Guide
Installation and Configuration
Copyright ©2004 BinTec Access Networks GmbH, all rights reserved.
Version 1.4
Document #71000R
October 2004

2 BinTec Access Networks GmbH
Purpose This manual explains the installation and initial configuration of X8500 with soft-
ware release 6.1.5 or later. For up-to-the-minute information and instructions
concerning the latest software release, you should always read our release
notes, especially when carrying out a software update to a later release level.
The latest release notes can always be found at www.bintec.net.
Liability While every effort has been made to ensure the accuracy of all information in
this manual, BinTec Access Networks GmbH cannot assume liability to any par-
ty for any loss or damage caused by errors or omissions or by statements of any
kind in this document and is only liable within the scope of its terms of sale and
delivery.
The information in this manual is subject to change without notice. Additional
information, including changes and release notes for X8500, can be found at
www.bintec.net.
As a multiprotocol router, X8500 sets up WAN connections in accordance with
the system configuration. To prevent unintentional charges accumulating, the
operation of the product should be carefully monitored. BinTec Access Net-
works GmbH accepts no liability for loss of data, unintentional connection costs
and damages resulting from unsupervised operation of the product.
Trademarks BinTec and the BinTec logo are registered trademarks of BinTec Access Net-
works GmbH.
All other product names and trademarks mentioned are the property of the re-
spective companies and manufacturers.
Copyright All rights are reserved. No part of this publication may be reproduced or trans-
mitted in any form or by any means – graphic, electronic, or mechanical – in-
cluding photocopying, recording in any medium, taping, or storage in
information retrieval systems, without the prior written permission of BinTec Ac-
cess Networks GmbH. Adaptation and especially translation of the document is
inadmissible without the prior consent of BinTec Access Networks GmbH.
Guidelines and
standards X8500 complies with the following guidelines and standards:
■R&TTE Directive 1999/5/EC
■CE marking for all EU countries and Switzerland

X8500 Software Configuration Guide 3
You will find further information in the "Declarations of Conformity" at
www.bintec.net.
How to reach BinTec BinTec Access Networks GmbH
Südwestpark 94
D-90449 Nürnberg
Germany
Telephone: +49 911 96 73 0
Fax: +49 911 688 07 25
Internet: www.bintec.de
BinTec France
6/8 Avenue de la Grande Lande
F-33174 Gradignan
France
Telephone: +33 5 57 35 63 00
Fax: +33 5 56 89 14 05
Internet: www.bintec.fr

4 BinTec Access Networks GmbH

X8500 Software Configuration Guide 5
Table of Contents
Table of Contents
Table of Contents 5
1 Welcome! 11
1.1 BinTec’s X8500 CD 13
1.2 Documentation from BinTec 14
1.3 About this Manual 16
1.3.1 Contents 16
1.3.2 Meaning of Symbols 17
1.3.3 Typographical Elements 18
2 General Safety Precautions 19
3 Getting Started 23
3.1 Connection Methods 24
3.1.1 Connecting Over the Serial Interface 25
3.1.2 Connecting Over a LAN 27
3.1.3 Connection Over ISDN 28
3.2 Logging In 30
3.3 Configuration Options 32
3.4 Using the Setup Tool 33
3.4.1 Menu Layout 34
3.4.2 Menu Navigation 35
3.4.3 Menu Commands 36
3.4.4 Searching Lists 37
3.4.5 Changing the Password 38
3.4.6 Convention 39
3.4.7 Menu Structure 40
3.5 In Advance of Configuration 45
3.5.1 Gathering Information 45

6 BinTec Access Networks GmbH
Table of Contents
3.5.2 Checking the TCP/IP Protocol 46
3.5.3 Installing BRICKware Under Windows 49
4 Initial Configuration with Setup Tool 53
4.1 Basic Router Settings 55
4.1.1 Entering License(s) 56
4.1.2 Entering System Data 58
4.1.3 Configuring the LAN Interface 61
4.1.4 Configuring X8500 as DHCP Server 65
4.1.5 Setting Filters 68
4.2 Configuring WAN Interfaces 73
4.2.1 Configuring ISDN BRI interface 73
4.2.2 Broadband Internet Access (xDSL) with X8500 86
4.3 X8500 and the WAN 94
4.3.1 Entering a WAN Partner 94
4.3.2 Creating a Routing Entry 115
4.3.3 Activating Network Address Translation (NAT) 121
4.3.4 Examples 122
4.4 Saving the Configuration File 126
4.5 Configuring PCs in Your LAN 127
4.5.1 Configuring a PC 127
4.5.2 Remote CAPI Interface Configuration 130
4.5.3 Finding PCs on Your Partner’s Network 131
4.6 Testing Your Configuration 134
5 Advanced Configuration with the Setup Tool 135
5.1 General WAN Settings 136
5.1.1 Dynamic IP Address Server 136
5.1.2 CAPI User Concept 138
5.1.3 General PPP Settings 142

X8500 Software Configuration Guide 7
Table of Contents
5.1.4 X.31 TEI (Terminal Endpoint Identifier) 144
5.2 Settings Specific to WAN Partners 146
5.2.1 Delay After Connection Failure 146
5.2.2 Channel Bundling 147
5.2.3 Channel Bundling – Bandwidth On Demand (BOD) 149
5.2.4 Always On/Dynamic ISDN (AO/DI) 157
5.2.5 Application-Controlled Bandwidth Management (BOD) 165
5.2.6 Layer 1 Protocol (ISDN B-Channel) 171
5.2.7 IP Transit Network 173
5.2.8 Name Server 177
5.2.9 Routing Information Protocol (RIP) 180
5.2.10 Compression 183
5.2.11 Proxy ARP (Address Resolution Protocol) 185
5.2.12 Keepalive Monitoring 187
5.3 Basic IP Settings 193
5.3.1 System Time 193
5.3.2 Name Resolution in X8500 with DNS Proxy 197
5.3.3 Port Numbers 214
5.3.4 BOOTP Relay Agent 215
5.4 Quality of Service 218
5.4.1 Defining IP Filters 220
5.4.2 Classification and (TOS) Signaling 221
5.4.3 Activating the Classification 226
5.4.4 Defining QoS Bandwidth Management Policies 227
5.5 Bridging 239
5.6 Extra License Features 240
6 Configuration of Expansion Cards and Modules 241
6.1 WAN Interface Expansion Card for
ISDN PRI and G.703 243

8 BinTec Access Networks GmbH
Table of Contents
6.2 WAN Interface Expansion Card for E3 252
6.3 Expansion Card X8E-2BC 258
6.3.1 Communication Modules for ISDN BRI 258
6.3.2 Communication Module CM-PRI for ISDN PRI 261
6.3.3 Communication Module CM-100BT 262
6.3.4 Serial WAN Interfaces Communication Module CM-X21 263
6.4 Expansion Card X8E-DSP 268
6.5 Expansion Card for X.21/V.35 269
6.6 Resource Modules with Digital Modems 276
6.7 Resource Module for Encryption and Compression (XT-VPN) 286
6.8 Resource Module for X.21/V.35 (XT-2SYNC) 287
7 Configuration of Security Functions and Firewall 289
7.1 Activity Monitoring 290
7.1.1 Syslog Messages 290
7.1.2 Monitoring Functions in the Setup Tool 295
7.1.3 Credits Based Accounting System 299
7.1.4 Activity Monitor 302
7.2 Access Security 305
7.2.1 Logging In 305
7.2.2 Checking the Calling Party Number 306
7.2.3 Authentication of PPP Connections with PAP, CHAP or MS-CHAP 307
7.2.4 Callback 308
7.2.5 Closed User Group 310
7.2.6 Access to Remote CAPI 310
7.2.7 NAT (Network Address Translation) 310
7.2.8 Filters (Access Lists) 321
7.2.9 Local Filters 334
7.2.10 Back Route Verification 337
7.2.11 TAF Agent 338

X8500 Software Configuration Guide 9
Table of Contents
7.2.12 Extended IP Routing (XIPR) 338
7.3 Line Tapping Security 344
7.3.1 Encryption 344
7.3.2 VPN (with extra license) 347
7.3.3 IPSec (with extra license) 347
7.4 Special Features 349
7.4.1 Start-up Procedure 349
7.4.2 Auto Logout 349
7.4.3 Prevention of Denial-of-Service Attacks 349
7.5 Checklist 351
8 Configuration Management and Flash Card 353
8.1 Administration of Configuration Files 354
8.2 Smart Media Flash Card 362
8.2.1 Formatting the Flash Card 362
8.2.2 File System and Directory Structures on the Flash Card 362
8.2.3 Behavior of X8500 with Flash Card in Boot
Operation and Saving the Configuration 363
8.2.4 Configuration Management for the Flash Card 365
8.2.5 Command fssh in the SNMP Shell of X8500 369
8.3 Updating Software 374
8.3.1 BOOT Sequence 375
8.3.2 Updating BOOTmonitor 376
8.3.3 Update System Software 377
8.3.4 Updating Module Logic 379
9 Troubleshooting 381
9.1 Aids to Troubleshooting 382
9.1.1 Local SNMP Shell Commands 382
9.1.2 External Aids 383

X8500 Software Configuration Guide 11
1
1 Welcome!
Congratulations on deciding to buy the X8500 modular communications server
from BinTec Access Networks GmbH – a remote access server solution for cen-
tral corporations and for Internet Service Providers.
Figure 1-1: X8500 - the central site router for professional applications
X8500 Feature List
System card The system card (X8A-SYS or X8A-SYS-VPN, for details about the system
cards, see the Hardware Installation Guide) is the control unit of X8500. With
its Basic Rate Interface, two or three Fast Ethernet ports, respectively, and the
serial console port, the system card provides for local and remote configuration,
administration and monitoring of X8500.
Expansion cards Eight slots for expansion cards enable X8500 to grow in line with your require-
ments. Thus a high degree of flexibility is assured.
Resource modules The expansion cards can also be equipped with powerful and scalable resource
modules. This offers extremely high efficiency through high port or modem den-
sity.

12 BinTec Access Networks GmbH
Welcome!
1
Module carrier card The module carrier card can be fitted with BIANCA/BRICK-XL2 or BIAN-
CA/BRICK-XM modules.
Hot Swap Any expansion card may be inserted into an unused slot while X8500 is oper-
ating. Likewise, a PRI, G.703, DSP or SYNC expansion card can be replaced
with a new one of the same type with the same licenses, as long as the new
card has as many interfaces and as many modules as the old one.
Redundancy Two slots are provided for power supply units so you can set up a redundant
power supply system with X8500.
RAS The flexible remote access server X8500 can be used for WAN access, remote
CAPI server or LAN router. X8500 supports the TCP/IP and X.25 protocols and
is also suitable for bridging other protocols based on the spanning tree method.
Remote CAPI Using BinTec’s remote CAPI software, applications based on the widely used
CAPI interface can be used network-wide. Thus the available ISDN connec-
tions can be used more effectively.
Security The features supplied include BinTec’s well-tried security package SAFER-
NETTM. This package contains security technologies such as filters, Network
Address Translation (NAT) and access passwords. The security functions pro-
tect X8500 and the network connected to it against unauthorized access.
The future New technologies and developments are vital for BinTec Access Networks Gm-
bH. X8500’s flexible platform with eight expansion slots and a powerful proces-
sor permits the immediate integration of new WAN/LAN technologies and
features. This makes X8500 a future-oriented and migration-capable device.
You can download BinTec’s current software at www.bintec.net.

X8500 Software Configuration Guide 13
BinTec’s X8500 CD 1
1.1 BinTec’s X8500 CD
You will find all the programs you need for the installation, configuration and ad-
ministration of X8500 on your X8500 CD.
BRICKware BRICKware for Windows contains Windows utility programs:
■DIME Tools are for monitoring and administration of your X8500.
■You gain access to X8500 via the serial interface using the terminal pro-
gram Device at COM1 or Device at COM2.
■The Configuration Manager allows you to configure and administrate all
BinTec routers in the network via a graphic interface. Here you can view
and edit SNMP tables and variables.
■Remote CAPI Client:
The Remote CAPI Client allows you to use communications applications
based on the standard CAPI interface.
■Token Authentication Firewall (TAF) program (optional):
This software package is required if you are using the Security Dynamics
security system.
■The Activity Monitor enables you to monitor the utilization of X8500 at a
glance.
More detailed descriptions of all software programs can be found in our online
document BRICKware for Windows.
What else? On the X8500 CD, you will find a range of other useful directories in which you
can find the following, for example:
■The documentation in electronic form (see also chapter 1.2, page 14)
■A copy of the router software
■UNIX tools (administration)
■Adobe’s Acrobat Reader

14 BinTec Access Networks GmbH
Welcome!
1
1.2 Documentation from BinTec
The following documentation is currently available:
■Software Configuration Guide
This manual.
■Hardware Installation Guide
Included with X8A-BOSS.
■Installation guide for the X8500 expansion cards
Included with the expansion card(s) you purchase.
■Installation guide for the X8500 power supply unit(s)
Included with X8A-PS.
■Installation guide for the X8500 fan unit
Included with X85-FAN.
■Installation guide for rack-mounting X8500
Included with X85-RACK.
■Reference manuals (English, PDF/HTML)
–Software Reference (PDF)
Online reference with detailed information on functions described here,
a reference for the internal SNMP table structures and the operation of
the SNMP shell.
– MIB Reference
HTML document with short descriptions of SNMP tables and variables
for X8500.
■BRICKware for Windows (English, PDF)
User’s guide for Windows utility programs (BRICKware).
■Release Notes (PDF and/or printed)
Up-to-the-minute information and instructions concerning the latest soft-
ware release, description of all changes undertaken since the previous re-
lease.
In the Release Notes Firmware Logic and BOOTmonitor Update, you
will find instructions to help you upgrade BOOTmonitor and/or firmware log-
ic, if applicable.

X8500 Software Configuration Guide 15
Documentation from BinTec 1
■Release Notes for the operation of routers in UK (English, PDF)
Instructions for the operation of BinTec routers in Great Britain.
You received this documentation together with X8500. The Hardware Installa-
tion Guide manual is provided in printed form. Your BinTec Companion CD
also contains the complete documentation in electronic form (PDF, HTML). In
addition to your Companion CD documentation, you can download all the latest
documentation free of charge from our WWW server at www.bintec.net.

16 BinTec Access Networks GmbH
Welcome!
1
1.3 About this Manual
1.3.1 Contents
This manual is structured as follows:
Table 1-1: Short description of chapters
Chapter Contents
1: "Welcome!" General introduction, scope of supply, informa-
tion about this manual.
2: "General Safety Pre-
cautions" General safety precautions in English.
3: "Getting Started" Instructions on taking X8500 into operation.
4: "Initial Configuration
with Setup Tool" How to activate licenses, enter system data
and configure basic router settings.
5: "Advanced Configura-
tion with the Setup Tool" How to configure advanced router settings.
6: "Configuration of
Expansion Cards and
Modules"
How to configure the expansion cards, commu-
nication modules and resource modules.
7: "Configuration of Secu-
rity Functions and Fire-
wall"
How to configure security functions and fire-
wall.
8: "Configuration Man-
agement and Flash Card" How to manage configuration files and SMFCs,
and how to carry out software updates.
9: "Troubleshooting" Important tips on fault clearance.
10: "Important Com-
mands" A brief overview of the most important com-
mands of the SNMP shell and BRICKtools for
Unix.
11: "General Safety Pre-
cautions in German" General safety precautions in German.

X8500 Software Configuration Guide 17
About this Manual 1
1.3.2 Meaning of Symbols
To help you locate and interpret information easily, this manual uses the follow-
ing visual aids:
Table 1-2: List of visual aids
Symbol Meaning
Points out useful and relevant tips and tricks.
Predicts potential pitfalls and explains how to
avoid them.
Brings to your attention general and important
points.
Explains additional background information.
Brings your attention to important safety pre-
cautions. Levels of danger are in accordance
with ANSI:
■Caution (indicates possible danger that, if
unheeded, could cause material damage)
■Warning (indicates possible danger that, if
unheeded, could cause bodily harm)
■Danger (indicates danger that, if unheeded,
could lead to serious bodily harm or death)

18 BinTec Access Networks GmbH
Welcome!
1
1.3.3 Typographical Elements
In order to help you find and interpret the information in this manual, the follow-
ing typographical elements are used:
Table 1-3: Typographical elements
Typographical element Meaning
➤Here you are requested to do something.
■–
–
Lists including two levels.
M
ENU
➧
S
UBMENU
File
➧
Open
Indicates menus and submenus in the Setup
Tool.
Indicates menus and submenus under Windows.
Non-proportional
(Courier), e.g.
ping 192.168.1.254
■Indicates commands (e.g. in the SNMP shell)
that you must enter as shown.
■Used to display the Setup Tool.
<IP address> Indicates inputs in which you enter a value for
the term shown in the brackets. Do not enter the
pointed brackets.
bold, italics, e.g.
BigBoss
Indicates example terms.
bold, e.g.
➤➤ MIB
Indicates terms that you can find in the glossary
(for online texts, click the double arrow).
bold, e.g.
biboAdmLoginTable,
Windows Start menu
■Indicates fields in the Setup Tool and MIB
tables and variables.
■Indicates keys/key combinations and
Windows terms.
italics, e.g.
none
Indicates values that can be entered or set in the
Setup Tool or MIB variables.
Online:blue Indicates links.

X8500 Software Configuration Guide 19
2
2 General Safety Precautions
General Safety Precautions in English
The following sections contain safety precautions you are strongly advised to
heed when working with your equipment.
Transport and storage ■Only transport and store X8500 in its original packaging or use other appro-
priate packaging to protect against knocking and shaking.
Installation and
operation ■Read the information on the ambient conditions (see Technical Data) be-
fore installing and operating X8500.
■Please comply with the general conditions applicable in your country when
installing external ISDN basic rate accesses. In some cases, you may have
to consult a technician who possesses the relevant approval. Obtain infor-
mation about the special requirements of national regulations and make
sure that your installation complies with these legal requirements.
■Electrostatic charges may cause damage to the equipment. You should
therefore wear a grounded wrist strap or touch a grounded surface before
you touch sockets or extension cards of X8500. Only grip extension cards
at the edges and do not touch components or conductor tracks.
■Be sure to install the dummy front-panel sections in any unused slotsto en-
sure that emissions causing electromagnetic interference are prevented.
■Condensation may occur externally or internally if the equipment is moved
from a colder room to a warmer room. When moving the equipment under
such conditions, allow ample time for the equipment to reach room temper-
ature and to dry out completely before operating. Observe the ambient con-
ditions under Technical Data.
■Never open the X8500 power supply unit X8A-PS, as this can create a le-
thal danger through electric shock. Opening the X8500 power supply unit
invalidates the guarantee and the product liability.
■Make sure that the connection requirements for the power supply unit are
observed.

20 BinTec Access Networks GmbH
General Safety Precautions
2
■Be sure to insert and fasten the X8500 power supply unit properly before
bringing X8500 into operation. This ensures that the housing is reliably
earthed.
■Make sure to connect the power cord only to a power supply unit that has
been properly inserted and fixed.
■Make sure the local mains voltage is the same as the nominal voltages of
the power supply unit. The X8500 power supply unit X8A-PS may only be
operated under the following conditions.
– 100 - 240 V AC
– 50/60 Hz
– max. 3 A
■Only connect the equipment to a safety mains socket that is grounded in
accordance with the regulations (the equipment is equipped with a tested
safety power cord).
■Make sure the safety mains socket in the building is freely accessible.
■Make sure you follow the correct cabling sequence, as described in the
manual. Use only the cables supplied with the equipment or cables that
meet the specifications in this manual. If you use other cables, BinTec Ac-
cess Networks GmbH cannot accept liability for any damage occurring or
for any adverse effects on operation. The equipment guarantee is invalidat-
ed in such cases.
■Connect the equipment as described in the manual.
■Arrange the cables so that they are not in the way and cannot be tripped
over or damaged.
■Do not connect, disconnect or touch the data lines during lightning storms.
■Only connect terminals to X8500 that meet the general safety requirements
for telecommunications equipment. Terminals approved by CETECON
(formerly BZT) meet these requirements. ISDN terminals connected to
X8500 must be approved for use with Euro ISDN (DSS1).
Operation according to
the regulations ■X8500 establishes WAN connections depending on the system configura-
tion. To avoid extra charges, you should carefully monitor the product.
Other manuals for X8500
2
This manual suits for next models
1
Table of contents
Other BinTec Server manuals