Specifications
OmniAccess 5510 USG - Release Notes
September 2010
Factory Default Configuration
OmniAccess 5510 USG supports factory default configuration. In scenarios where OmniAccess 5510
USG is managed in a centralized management system, it is desirable to have a zero touch deployment.
OmniAccess 5510 USG may just be connected to network lines and powered on, and the rest of
configuration should be managed by the centralized location. This requires OmniAccess 5510 USG to
boot with predefined configuration from the factory. Such a configuration is stored in factory default
configuration. Whenever OmniAccess 5510 USG boots up for the first time, it always loads with this
factory default configuration.
VPN
VPN is a private network that uses a public network (usually the Internet) to connect remote sites or users
together. Instead of using a dedicated, real-world connection such as leased line, a VPN uses "virtual"
connections routed through the Internet from the company's private network to the remote site or employee.
IPsec Tunnel Interface
The OmniAccess 5510 USG provides support for IPsec in a tunnel mode with encryption, intended
for secure site-to-site communications over an untrusted network. IPsec as a tunnel interface is
required so that pre/post encryption or decryption policies for QoS, Filters, and ACLs can be applied.
• Traffic classifier will be route based rather than policy based, which means that routing can
control what traffic needs to be secure.
• Tunnel failover can be handled by having traffic routed through another tunnel interface.
• Allows for configuration of dynamic routing protocols over the tunnel.
IPsec VPN Server
IPsec VPN Server is key requirement for SMB deployment where gateway is supposed to act as VPN
gateway also. OmniAccess 5510 USG supports Alcatel-Lucent IPsec Client version 10.0. Uses
RADIUS to authenticate Alcatel-Lucent IPsec Client.
Dynamic Multipoint Virtual Private Network (DMVPN)
DMVPN forms site-to-site VPN in hub and spoke configuration. In typical deployments, branch
offices are spokes and central office is a hub. Financial institutions, transport service providers and
medical institutions are few of the common deployment sites where hub and spoke model is used.
OmniAccess 5510 USG supports spoke functionality of Dynamic MultiPoint VPN technology. Uses
NHRP client services and multi-Point GRE (Generic Routing Encapsulation) tunnel for DMVPN.
OmniAccess 5510 USG - Release 3.0 Page 23 of 33
032667-10 Rev. A