Atrust M320 Guida Utente

Navigare online o scaricare Guida Utente per Server Atrust M320. Atrust M320 User guide Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
  • Pagina
    / 142
  • Indice
  • SEGNALIBRI
  • Valutato. / 5. Basato su recensioni clienti
Vedere la pagina 0
www.juniper.net
CORPORATE HEADQUARTERS
Juniper Networks, Inc.
1194 North Mathilda Avenue
Sunnyvale, CA 94089 USA
Phone 408 745 2000 or 888 JUNIPER
Fax 408 745 2100
Juniper Networks, Inc. has sales offices worldwide.
For contact information, refer to www.juniper.net.
Printed on recycled paper
Juniper Networks, Inc.
Odyssey Access Client
User Guide
M320
Internet Router Hardware Guide
M-series
Routing Platforms
Juniper
Networks,
Inc.
530-010089-01, Revision 1
Allows for variable-width spine. Assume for now that spine is 1.25" wide; maximum spine width is 2.5".
A book with .25" spine would cut here.
A book with 2.5" spine would cut here.
A 2.5" spine would fold here.
A 1.25" spine would fold here.
Cover size is 8.3 x 10.75".
This is the hardware version: has blue line and blue bar
Vedere la pagina 0
1 2 3 4 5 6 ... 141 142

Sommario

Pagina 1 - User Guide

www.juniper.netCORPORATE HEADQUARTERSJuniper Networks, Inc.1194 North Mathilda AvenueSunnyvale, CA 94089 USAPhone 408 745 2000 or 888 JUNIPERFax 408 7

Pagina 2

viii  Table of ContentsOdyssey Access Client User Guide

Pagina 3

Odyssey Access Client Administration Guide86  Using the Advanced Method to Configure TrustRemoving NodesTo remove a node:1. Select the node in the tr

Pagina 4

Using the Advanced Method to Configure Trust  87Chapter 9: Managing Trusted ServersTo trust a server permanently:1. Select Add this trusted server to

Pagina 5

Odyssey Access Client Administration Guide88  Using the Advanced Method to Configure Trust

Pagina 6

Accessing Log Files—UE Only  89Chapter 10Viewing Log Files and DiagnosticsThis chapter describes how to access and view log files and diagnostics inf

Pagina 7 - Table of Contents  v

Odyssey Access Client User Guide90  Accessing DiagnosticsFigure 20: Odyssey Log Viewer DialogDepending on the size of the log file or the specific c

Pagina 8

Accessing Diagnostics  91Chapter 10: Viewing Log Files and DiagnosticsFigure 21: Sample IPsec Diagnostics DialogIPsec Configuration—UE OnlyIPsec Con

Pagina 9 - Table of Contents  vii

Odyssey Access Client User Guide92  Accessing DiagnosticsSave All DiagnosticsSave All Diagnostics collates the output of all the diagnostic functions

Pagina 10 - Table of Contents

Network Security  93Appendix A Network Security ConceptsThis appendix contains background information for anyone needing a better understanding of th

Pagina 11 - About This Guide

Odyssey Access Client User Guide94  Network Security IPsec is a set of protocols used to secure (encrypt) IP data packets being exchanged on a netwo

Pagina 12 - Documentation

Network Security  95Network Security Concepts Preshared passphrases used to generate keys for WPA or WPA2 association. Preshared passphrases enable

Pagina 13 - Contacting Customer Support

Audience  vAbout This GuideThis guide describes how to install, use, and configure Odyssey Access Client (OAC) for wired or wireless network access.

Pagina 14

Odyssey Access Client User Guide96  802.11 Wireless Networking802.11 Wireless NetworkingThere are many types of wireless communication. Odyssey Acces

Pagina 15 - Connecting to a Network

802.11 Wireless Networking  97Network Security ConceptsThe 802.11 standard refers to peer-to-peer network connectivity as ad-hoc mode. See “Specify t

Pagina 16 - OAC in a Traditional Network

Odyssey Access Client User Guide98  802.11 Wireless NetworkingSee the following topics: “Specifying an Association Mode” on page 60 for directions f

Pagina 17

802.1X Authentication  99Network Security ConceptsSee the following topics: “Specifying an Association Mode” on page 60 to use WPA2 or WPA associati

Pagina 18

Odyssey Access Client User Guide100  802.1X AuthenticationWhen preconfigured WEP keys are used, it is the wireless client PC that is authenticated to

Pagina 19 - Quarantine and Remediation

802.1X Authentication  101Network Security ConceptsMutual AuthenticationEAP-TTLS, EAP-PEAP, EAP-TLS, and EAP-FAST provide mutual authentication of th

Pagina 20

Odyssey Access Client User Guide102  802.1X AuthenticationEach certificate is issued by a certificate authority. By issuing a certificate, the certif

Pagina 21 - Installing OAC

802.1X Authentication  103Network Security ConceptsIf your enterprise has a user-based certificate infrastructure in place, you have the option to co

Pagina 22 - Requirements

Odyssey Access Client User Guide104  802.1X AuthenticationEAP-LEAPEAP-LEAP (Lightweight EAP, also known as EAP-Cisco Wireless) is a protocol that ena

Pagina 23 - Licenses

802.1X Authentication  105Network Security ConceptsRecommended practice is to enable session resumption. The necessity for some form of reauthenticat

Pagina 24

Odyssey Access Client User Guidevi  DocumentationDocumentationThe following sections describe how to access copies of the product documentation and t

Pagina 25 - Opening OAC Manager

Odyssey Access Client User Guide106  802.1X Authentication

Pagina 26 - Menu Options

 107Appendix B GlossaryAAAA—Authentication, Authorization, and Accounting.Access Control List (ACL)—A listing of users and their associated access ri

Pagina 27 - File Menu Options

Odyssey Access Client User Guide108 Asymmetric algorithm—A pair of key values, one public and one private, used to encrypt and decrypt data. Only the

Pagina 28 - “Managing Trusted Servers”

 109GlossaryCertificate Authority (CA)—An online system that issues, distributes, and maintains currency information about digital certificates. Abbr

Pagina 29 - Tools Menu Options

Odyssey Access Client User Guide110 DData Encryption Standard (DES)—A cryptographic algorithm designed for protection of unclassified data and publis

Pagina 30 - Preferences

 111GlossaryEncryption hash—A method in which a selection of data is mixed into a section data based on an algorithm. The result is called a hashed v

Pagina 31 - Menu Options  17

Odyssey Access Client User Guide112 Firewall—A hardware device or software application designed to filter incoming or outgoing traffic based on prede

Pagina 32 - . Contact your network

 113GlossaryIntegrity—A monitoring and management system that performs integrity checks and protects systems from unauthorized modifications to data,

Pagina 33 - Enabling Temporary Trust

Odyssey Access Client User Guide114 Key Pair—A public key and its corresponding private key as used in public key cryptography.Key recovery—A mechani

Pagina 34 - Help Menu Options

 115GlossaryNode—A point of concentrated communications; a central point of communications.Nonrepudiation—The condition when a receiver knows or has

Pagina 35 - Configuration Folder

Contacting Customer Support  viiAbout This GuideRelease Notes Release notes are included with the product software and are available on the product C

Pagina 36 - Content Dialogs

Odyssey Access Client User Guide116 Private key—A piece of data generated by an asymmetric algorithm that’s used by the host to encrypt data encrypte

Pagina 37 - Connection Status

 117GlossarySSecure channel—A means of conveying information from one entity to another such that an adversary does not have the ability to reorder,

Pagina 38 - Shortcut Keys

Odyssey Access Client User Guide118 TTACACS+—An enhanced version of Terminal Access Controller Access Control System. TACACS+ is TCP based authentica

Pagina 39 - Exiting from OAC Manager

 119GlossaryWWired Equivalent Privacy (WEP)—A security protocol used in 802.11 wireless networking, WEP is designed to provide security equivalent to

Pagina 40 - 26  Exiting from OAC Manager

Odyssey Access Client User Guide120 

Pagina 41 - Managing Network Adapters

Index  121IndexNumerics802.11ad-hoc mode ...96defined...

Pagina 42 - Removing an Adapter

Odyssey Access Client User Guide122  Indexvalidate ...46validation ...

Pagina 43

Index  123Indexcertificate requirement ...14compliance...

Pagina 44

Odyssey Access Client User Guide124  Indexpeer-to-peer...60preemptive...

Pagina 45 - Disconnecting from a Network

Index  125IndexFIPS...13Layer 2 protocol ...

Pagina 46 - Checking Adapter Status

Odyssey Access Client User Guideviii  Contacting Customer Support

Pagina 47 - Connecting to a Network  33

Odyssey Access Client User Guide126  Indexdynamic ... 62open mode...

Pagina 48

Juniper Networks Secure Access Administration Guide

Pagina 49 - Status Message Definition

www.juniper.netCORPORATE HEADQUARTERSJuniper Networks, Inc.1194 North Mathilda AvenueSunnyvale, CA 94089 USAPhone 408 745 2000 or 888 JUNIPERFax 408 7

Pagina 50

Connecting to a Network  1Chapter 1Odyssey Access Client OverviewOdyssey Access Client (OAC) is networking software that runs on endpoints (PCs, lapt

Pagina 51 - Managing Profiles

Odyssey Access Client User Guide2  How OAC Operates in a NetworkHow OAC Operates in a NetworkWhen you attempt to connect to an 802.1X network, OAC re

Pagina 52 - Adding or Modifying a Profile

OAC in an Enhanced Security Network with Unified Access Control  3Chapter 1: Odyssey Access Client Overview2. In the case of either a wired or a wire

Pagina 53 - Specifying User Info

Odyssey Access Client User Guide4  OAC in an Enhanced Security Network with Unified Access ControlIn a UAC network, OAC communicates with the Infrane

Pagina 54 - Setting Passwords

OAC in an Enhanced Security Network with Unified Access Control  5Chapter 1: Odyssey Access Client OverviewFigure 3: OAC Authentication in a Network

Pagina 56 - Using Soft Tokens

Odyssey Access Client User Guide6  Understanding Network SecurityIf an endpoint does not comply with an organization’s security policies, the Infrane

Pagina 57 - Setting a SIM Card ID

Before You Begin  7Chapter 2Installing OACBefore installing OAC, you should be familiar with networking concepts relating to your wireless or wired n

Pagina 58 - Setting Up Authentication

Odyssey Access Client User Guide8  RequirementsRequirementsThe following sections describe hardware and software requirements for OAC.Operating Syste

Pagina 59 - Chapter 5: Managing Profiles

Installing OAC in a Traditional Network—EE and FE Only  9Chapter 2: Installing OACLicensesYou must have a valid license to run OAC. Each OAC edition

Pagina 60

Odyssey Access Client User Guide10  Installing OAC in a UAC Network You can install OAC by opening a Web browser and navigating to the IP address or

Pagina 61 - Setting an Anonymous Name

Opening OAC Manager  11Chapter 3Using Odyssey Access Client ManagerThis chapter discusses how to use the OAC Manager to configure OAC. Depending on t

Pagina 62 - TTLS Settings

Odyssey Access Client User Guide12  Overview of the OAC Manager InterfaceOverview of the OAC Manager InterfaceThis section describes the OAC Manager

Pagina 63 - TTLS Settings  49

Menu Options  13Chapter 3: Using Odyssey Access Client ManagerFile Menu OptionsForget PasswordUse this option if you want OAC to discard the current

Pagina 64 - 50  TTLS Settings

Odyssey Access Client User Guide14  Menu Options See the OAC User Web Page for more information about the appropriate adapter drivers for use with t

Pagina 65 - PEAP Settings

Menu Options  15Chapter 3: Using Odyssey Access Client ManagerTools Menu OptionsOAC Administrator (EE and FE Only)This is a set of special tools for

Pagina 66 - EAP-POTP Run-Time Dialogs

Juniper Networks, Inc.1194 North Mathilda AvenueSunnyvale, CA 94089USA408-745-2000www.juniper.netPart Number: ODR-ZA-ODYCAUG, Revision A00Juniper Netw

Pagina 67

Odyssey Access Client User Guide16  Menu OptionsTo run a script from a known location:1. Select Tools > Run Script. 2. In the Select Script File d

Pagina 68

Menu Options  17Chapter 3: Using Odyssey Access Client ManagerOptionsIndividual tabs in this dialog enable you to configure the settings for security

Pagina 69 - Removing a Profile

Odyssey Access Client User Guide18  Menu Options Cache PIN (EE and FE Only)—With this option enabled, OAC caches the PIN that you enter and does not

Pagina 70 - Sample Profile Configuration

Menu Options  19Chapter 3: Using Odyssey Access Client Manager3. Set Do not resume sessions older than to the maximum number of hours that a session

Pagina 71 - Managing Network Access

Odyssey Access Client User Guide20  Menu OptionsPeriodic reauthentication serves two purposes: As a general security measure, it verifies that you a

Pagina 72

Sidebar  21Chapter 3: Using Odyssey Access Client ManagerPurchase InformationUse this option to access the Juniper Networks Web page to buy other pro

Pagina 73 - Network Settings

Odyssey Access Client User Guide22  Content DialogsAuto-Scan ListsUse this option to set up an ordered list of wireless networks that you have config

Pagina 74 - Specifying a Channel

Content Dialogs  23Chapter 3: Using Odyssey Access Client ManagerInformational Graphics and Detailed StatusGraphical status icons appear in the lower

Pagina 75

Odyssey Access Client User Guide24  Content Dialogs(black) – Connected, but authentication not in use(blue) – Connected and authenticatedThe status d

Pagina 76 - Authentication Settings

Exiting from OAC Manager  25Chapter 3: Using Odyssey Access Client ManagerTo move between the dialogs of the OAC, press the up and down arrows on you

Pagina 77 - Preconfigured Keys (WEP)

Copyright© 2002-2006 Juniper Networks, Inc. All rights reserved. Printed in USA.Odyssey, Juniper Networks, and the Juniper Networks logo are registere

Pagina 78 - Removing a Network

Odyssey Access Client User Guide26  Exiting from OAC Manager

Pagina 79 - Setting Value

Adding Network Adapters  27Chapter 4Managing Network Adapters This chapter describes how to add or remove a wired or wireless network adapter in an O

Pagina 80

Odyssey Access Client User Guide28  Adding Network AdaptersRenaming an AdapterWhen you add a adapter to the OAC configuration, the adapter appears in

Pagina 81 - Managing Auto-Scan Lists

Connecting to a Network  29Chapter 4: Managing Network AdaptersConnecting to a NetworkThis section describes how to use OAC to connect to a specific

Pagina 82 - Adding an Auto-Scan List

Odyssey Access Client User Guide30  Connecting to a NetworkConnecting to a NetworkWhen you connect to a network, OAC uses the adapter that you select

Pagina 83 - Modifying an Auto-Scan List

Connecting to a Network  31Chapter 4: Managing Network AdaptersConfiguring Multiple Simultaneous Network ConnectionsEach adapter on your computer can

Pagina 84

Odyssey Access Client User Guide32  Connecting to a NetworkReconnecting to a Network Use the Reconnect button (located at the bottom of the Adapter d

Pagina 85 - Connections

Connecting to a Network  33Chapter 4: Managing Network AdaptersFigure 7: Disconnected Adapter Status You can check other adapter status, as describe

Pagina 86 - FIPS Mode Constraint

Odyssey Access Client User Guide34  Connecting to a NetworkConnection StatusConnection status shows summary information about the current adapter and

Pagina 87

Interaction with Other Adapter Software  35Chapter 4: Managing Network AdaptersInteraction with Other Adapter SoftwareYour wireless adapter might com

Pagina 88

Table of Contents  iiiTable of ContentsAbout This Guide vAudience...

Pagina 89

Odyssey Access Client User Guide36  Interaction with Other Adapter Software

Pagina 90

 37Chapter 5Managing ProfilesThis chapter describes how to set up an OAC profile for an authenticated network connection.A profile contains all of th

Pagina 91

Odyssey Access Client User Guide38  Adding or Modifying a ProfileThe Profiles dialog lists the configured profiles. The list might include a default

Pagina 92

Specifying User Info  39Chapter 5: Managing Profiles TTLS—The EAP-TTLS outer protocols and, where they apply, one or more inner protocols. See “TTLS

Pagina 93 - Managing Trusted Servers

Odyssey Access Client User Guide40  Specifying User Info SIM Card—Configure this section when you use a mobile wireless device to authenticate to a

Pagina 94 - Configuring Trust in OAC

Specifying User Info  41Chapter 5: Managing Profiles Select Prompt for login name and password to have OAC prompt you when you connect to the networ

Pagina 95 - Adding a Trusted Server Entry

Odyssey Access Client User Guide42  Specifying User InfoUsing Certificates for AuthenticationTo use certificate credentials for authentication:1. Sel

Pagina 96 - Server Identity

Specifying User Info  43Chapter 5: Managing ProfilesEnabling Soft Token IdentificationTo enable soft token authentication:1. If you want to create a

Pagina 97 - Displaying a Trust Tree

Odyssey Access Client User Guide44  Setting Up AuthenticationManaging PIN SettingsYou might have already set a PIN on your SIM card hardware. You hav

Pagina 98 - Adding Certificate Nodes

Setting Up Authentication  45Chapter 5: Managing ProfilesThe authentication protocols specified on the Authentication tab are the outer authenticatio

Pagina 99

iv  Table of ContentsOdyssey Access Client User GuideOAC Manager Display Layout ... 12

Pagina 100 - Managing Untrusted Servers

Odyssey Access Client User Guide46  Setting Up AuthenticationTo select more than one protocol at a time, hold down Ctrl on the keyboard as you select

Pagina 101

Setting Up Authentication  47Chapter 5: Managing ProfilesIf you use EAP-GenericTokenCard as one of the inner authentication methods or if you use EAP

Pagina 102

Odyssey Access Client User Guide48  TTLS Settings It is possible that anonymous EAP-PEAP authentication does not work with your network authenticati

Pagina 103 - Accessing Log Files—UE Only

TTLS Settings  49Chapter 5: Managing ProfilesTo select an inner authentication protocol:1. Select a profile and open the Profile Properties dialog.2.

Pagina 104 - Accessing Diagnostics

Odyssey Access Client User Guide50  TTLS SettingsEAP as an Inner Authentication ProtocolIf you select EAP as your inner authentication protocol, you

Pagina 105 - IPsec Configuration—UE Only

PEAP Settings  51Chapter 5: Managing Profiles None—Configure EAP-TTLS authentication without a client-side certificate. This option specifies the mo

Pagina 106 - Save All Diagnostics

Odyssey Access Client User Guide52  EAP-POTP Run-Time DialogsUsing Certificates with EAP-PEAP AuthenticationTo select EAP-PEAP personal certificate o

Pagina 107 - Network Security Concepts

Infranet Controller Profile Configuration—UAC Networks Only  53Chapter 5: Managing Profilesc. Re-type the PIN under Please confirm your PIN. d. Click

Pagina 108 - Authentication Overview

Odyssey Access Client User Guide54  Infranet Controller Profile Configuration—UAC Networks OnlyTo set a preferred order of inner EAP protocols:1. Sel

Pagina 109 - Network Security  95

Removing a Profile  55Chapter 5: Managing ProfilesSetting the Preferred Realm and RoleThis section describes the JUAC tab in the Profile Properties d

Pagina 110 - 802.11 Wireless Networking

Table of ContentsTable of Contents  vRenaming an Adapter... 28Removing an

Pagina 111 - Wired-Equivalent Privacy

Odyssey Access Client User Guide56  Sample Profile ConfigurationSample Profile ConfigurationThis section shows a sample authentication profile for a

Pagina 112

Configuring Network Settings  57Chapter 6Managing Network AccessThis chapter describes how to define and configure the networks to which you intend t

Pagina 113 - 802.1X Authentication

Odyssey Access Client User Guide58  Adding or Modifying Network PropertiesAdding or Modifying Network PropertiesWhether you add a network by clicking

Pagina 114 - 100  802.1X Authentication

Adding or Modifying Network Properties  59Chapter 6: Managing Network AccessNetwork SettingsThe following sections describe each of the Network confi

Pagina 115 - Certificates

Odyssey Access Client User Guide60  Adding or Modifying Network PropertiesSpecifying a Network TypeIf you do not click Scan to select a network, spec

Pagina 116 - EAP-TTLS

Adding or Modifying Network Properties  61Chapter 6: Managing Network AccessEncryption Methods for an Association ModeYour choice of encryption metho

Pagina 117 - EAP-SIM and EAP-AKA

Odyssey Access Client User Guide62  Adding or Modifying Network PropertiesAuthentication SettingsUse the Authentication fields to specify whether or

Pagina 118 - Session Resumption

Adding or Modifying Network Properties  63Chapter 6: Managing Network AccessPreshared Keys (WPA or WPA2)If you associate using WPA or WPA2 and if you

Pagina 119 - 802.1X Authentication  105

Odyssey Access Client User Guide64  Removing a NetworkWEP keys are either 40 or 104 bits long. This corresponds to either 5 or 13 characters when you

Pagina 120 - 106  802.1X Authentication

Sample Network Configuration Setups  65Chapter 6: Managing Network AccessSample Network Configuration SetupsThis section shows three examples of sett

Pagina 121 - Glossary

vi  Table of ContentsOdyssey Access Client User GuideChapter 6 Managing Network Access 57Configuring Network Settings...

Pagina 122

Odyssey Access Client User Guide66  Sample Network Configuration SetupsSample Configuration for a Home Wireless NetworkTable 9: Sample Configuration

Pagina 123

 67Chapter 7Managing Auto-Scan ListsAn auto-scan list is an ordered list of networks that you have configured. You can create one or more auto-scan l

Pagina 124

Odyssey Access Client User Guide68  Using the Auto-Scan List DialogUsing the Auto-Scan List DialogTo set up or modify an auto-scan list, open the Con

Pagina 125

Using the Auto-Scan List Dialog  69Chapter 7: Managing Auto-Scan Lists5. Order the selected networks based on the frequency with which you expect to

Pagina 126

Odyssey Access Client User Guide70  Using the Auto-Scan List DialogViewing the Names in an Auto-Scan ListTo view the names in an auto-scan list:Doubl

Pagina 127

Adding an Infranet Controller to the OAC Configuration  71Chapter 8Managing Infranet Controller ConnectionsThis chapter describes how to add an Infra

Pagina 128

Odyssey Access Client User Guide72  Connecting and Signing on to an Infranet Controller4. In the Server URL field, enter the DNS name or the IP addre

Pagina 129

Connecting and Signing on to an Infranet Controller  73Chapter 8: Managing Infranet Controller Connections3. An Infranet Controller dialog opens (Fig

Pagina 130

Odyssey Access Client User Guide74  Connecting and Signing on to an Infranet ControllerUse the Reconnect button at the bottom of the dialog to reinit

Pagina 131

Connecting and Signing on to an Infranet Controller  75Chapter 8: Managing Infranet Controller ConnectionsChecking Infranet Controller StatusOne way

Pagina 132

Table of ContentsTable of Contents  viiEditing a Trusted Server Entry ...83Using the Ad

Pagina 133

Odyssey Access Client User Guide76  Connecting and Signing on to an Infranet ControllerFigure 17: Compliance Failure DialogWhen you click the How do

Pagina 134

Disconnecting from an Infranet Controller  77Chapter 8: Managing Infranet Controller ConnectionsDisconnecting from an Infranet ControllerTo disconnec

Pagina 135 - Numerics

Odyssey Access Client User Guide78  Disconnecting from an Infranet Controller

Pagina 136 - 122  Index

Overview of Trust Configuration  79Chapter 9Managing Trusted ServersThis chapter describes trusted servers and the configuration tasks that pertain t

Pagina 137 - Index  123

Odyssey Access Client Administration Guide80  Configuring Trust in OAC Add or remove certificate nodes. Add authentication servers or intermediate

Pagina 138 - 124  Index

Using the Simple Method to Configure Trust  81Chapter 9: Managing Trusted ServersFigure 19: Trusted Servers DialogWhen you configure OAC to trust a

Pagina 139 - Index  125

Odyssey Access Client Administration Guide82  Using the Simple Method to Configure Trust Use an intermediate CA or authentication server domain name

Pagina 140 - 126  Index

Using the Advanced Method to Configure Trust  83Chapter 9: Managing Trusted Servers2. Click Remove.Editing a Trusted Server EntryYou might need to ch

Pagina 141

Odyssey Access Client Administration Guide84  Using the Advanced Method to Configure TrustAdding Certificate NodesTo add a new certificate to the top

Pagina 142 - Quick Start

Using the Advanced Method to Configure Trust  85Chapter 9: Managing Trusted Servers2. For Server or intermediate CA name, enter the name (or final el

Commenti su questo manuale

Nessun commento