User's Manual
Table Of Contents
- ===============================
- MAIN MENU
- MASTER INDEX
- GLOSSARY
- ===============================
- DEFINITY® ECS Release 8.2 Administration for Network Connectivity
- Contents
- Preface
- 1 Networking Overview
- 2 H.323 Trunks
- Overview
- H.323 Trunk Administration
- Enabling Administration
- H.323 Trunk Administration — Task Summary
- H.323 Trunk Administration — Task Detail
- Task 1 — Assign Node Names
- Task 2 — Define IP Interfaces
- Task 3 — Assign Link via ethernet Data Module to the LAN
- Task 4 — Create a signaling group
- Task 5 — Create a trunk group
- Task 6 — Modify signaling group
- Task 7 — Specify codecs
- Troubleshooting IP Solutions
- 3 C-LAN Administration
- Overview
- Configuration 1: R8r <—ppp—> R8si
- Task Summary
- Prerequisite Administration
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign Link via ppp Data Module to Switch 2
- Switch 1 Task — Assign Processor Channels
- Switch 2 Task — Assign Node Names
- Switch 2 Task — Assign Link via ppp Data Module to Switch 1
- Switch 2 Task — Assign Processor Channels
- Enable links and processor channels
- Configuration 2: R7r (+CMS) <—ethernet—> R7csi
- Task Summary
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign IP Interfaces
- Switch 1 Task — Assign Link via ethernet Data Module to the LAN
- Switch 1 Task — Assign Processor Channels
- Switch 2 Task — Enable Bus Bridge Connectivity
- Switch 2 Task — Assign Node Names
- Switch 2 Task — Define IP Interfaces
- Switch 2 Task— Assign Link via ethernet Data Module to the LAN
- Switch 2 Task — Assign IP Route (to Switch 1)
- Switch 2 Task— Assign Processor Channels
- Intuity System Administration
- Administer Subscribers
- Worksheet A: Names and IP Addresses for Lucent Intuity System
- Worksheet B: LAN Data for the Lucent Intuity System
- Enable links and processor channels
- Configuration 3:R8si<—x.25 —> R8r Gateway <—ethernet—> R8si
- Task Summary
- Prerequisite Administration
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign pdm Data Module
- Switch 1 Task — Assign Link via x.25 Data Module to Switch 2
- Switch 1 Task — Assign IP Interfaces
- Switch 1 Task — Assign Link via ethernet Data Module to the LAN
- Switch 1 Task — Assign Processor Channels
- Switch 2 Task — Assign Link via procr-intf Data Module to Switch 1
- Switch 2 Task — Assign Processor Channels
- Switch 3 Task — Assign Node Names
- Switch 1 Task — Assign IP Interfaces
- Switch 3 Task — Assign Link via ethernet Data Module to the LAN
- Switch 3 Task — Assign Processor Channels
- Enable links and processor channels
- Configuration 4: R8csi <—ISDN—> R8si Gateway <—ppp—> R8csi
- Task Summary
- Prerequisite Administration
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign Link via ppp Data Module to Switch 3
- Switch 1 Task — Assign Processor Channels
- Switch 1 Task — Assign Signaling Group and administered NCA TSC
- Switch 1 Task — Assign ISDN-TSC Gateway
- Switch 2 Task — Assign Signaling Group and administered NCA TSC
- Switch 3 Task — Enable Bus Bridge Connectivity
- Switch 3 Task — Assign Node Names
- Switch 3 Task — Assign Link via ppp Data Module to Switch 1
- Switch 3 Task — Assign Processor Channels
- Enable links and processor channels
- Configuration 5A: R8csi <—ppp—> R8r (one C-LAN) <—ethernet—> R8si
- Task Summary
- Prerequisite Administration
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign Link via ppp Data Module to Switch 2
- Switch 1 Task — Assign IP Interfaces
- Switch 1 Task — Assign Link via ethernet Data Module to Ethernet
- Switch 1 Task — Assign Processor Channels
- Switch 2 Task — Enable Bus Bridge Connectivity
- Switch 2 Task — Assign Node Names
- Switch 2 Task — Assign Link via ppp Data Module to Switch 1
- Switch 2 Task — Assign Processor Channels
- Switch 2 Task — Assign IP Route to node-3
- Switch 3 Task — Assign Node Names
- Switch 3 Task — Assign IP Interfaces
- Switch 3 Task — Assign Link via ethernet Data Module to the LAN
- Switch 3 Task — Assign Processor Channels
- Enable links and processor channels
- Configuration 5B:R8csi <—ppp—> R8r (2 C-LANs) <—ethernet—> R8si
- Task Summary
- Prerequisite Administration
- Switch 1 Task — Assign Node Names
- Switch 1 Task — Assign Link via ppp Data Module to Switch 2
- Switch 1 Task — Assign IP Interfaces
- Switch 1 Task — Assign Link via ethernet Data Module to the LAN
- Switch 1 Task — Assign Link via ppp Data Module to C-LAN(a)
- Switch 1 Task — Assign Link via ppp Data Module to C-LAN(b)
- Switch 1 Task — Assign Processor Channels
- Switch 1 Task — Assign IP Route: C-LAN(a) to node-3
- Switch 1 Task — Assign IP Route: C-LAN(b) to node-2
- Switch 2 Task — Enable Bus Bridge Connectivity
- Switch 2 Task — Assign Node Names
- Switch 2 Task — Assign Link via ppp Data Module to Switch 1
- Switch 2 Task — Assign Processor Channels
- Switch 2 Task — Assign IP Route to node-3
- Switch 3 Task — Assign Node Names
- Switch 3 Task — Assign IP Interfaces
- Switch 3 Task — Assign Link via ethernet Data Module to the LAN
- Switch 3 Task — Assign Processor Channels
- Enable links and processor channels
- 4 Networking Example
- A Screens Reference
- Networking Screens
- Other Network-Related DEFINITY Screens
- Networking Screens
- Node Names
- page 1
- Pages 2 – 6
- IP Interfaces
- IP Routing
- IP Media Parameters
- Data Module Screens
- Common Data Module Fields
- Data Module — Type ethernet
- Data Module — Type ppp
- Data Module — Type procr-intf (used for BX.25 connections with the si model)
- Data Module - type X.25 (used for BX.25 connections with the r model)
- Data Module - type pdm (used for BX.25 connections with the r model)
- Communication-Interface Processor Channel
- Circuit Packs
- Signaling Group
- ISDN TSC Gateway Channel Assignments
- Other Networking-Related DEFINITY Screens
- Communication Interface Links
- Data Module - type netcon
- Data Module - type analog-dm
- Extended Trunk Access Call Screening
- Extension Number Portability Numbering Plan
- Hop Channel Assignments Screen
- Implementation notes
- Node Number Routing
- Message Waiting Indication Subscriber Number Prefixes
- Synchronization Plan
- Pages 1–X of the screen
- Uniform Dial Plan
- B Private Networking
- Contents of this Appendix
- Distributed Communications System
- Description of DCS
- DCS Features
- Italian DCS Protocol
- ISDN/X.25 gateway
- DCS Over ISDN-PRI D-channel
- DCS feature considerations
- DCS Interactions
- Example DCS configurations
- Centralized Attendant Service
- Extended Trunk Access
- Extension Number Portability
- Inter-PBX Attendant Service
- Private Network Access
- Uniform Dial Plan
- ISDN Feature Plus
- QSIG
- Centralized Voice Mail Via Mode Code
- Japan TTC Q931-a Private Networking Protocols
- C Security Issues
- D Capacities and Performance
- E C-LAN Installation
- F IP Trunk Installation and Administration
- IP Trunk Installation
- IP Trunk Administration
- Procedures for Extension Dialing Between Sites
- DCS over IP Trunk
- DCS or Dedicated Trunks to Specific Locations Configurations
- Rerouting calls when IP transmission quality is poor
- Placing a test telephone call
- Setting up alerts on IP trunks
- Alert types
- Viewing error messages
- Troubleshooting IP trunk
- Maintaining the performance of the IP trunk server
- Configuring Microsoft NetMeeting™ on a PC
- IP Trunk Worksheets
- G References
- Glossary
- Index

Network Security Issues C Security Issues
Administration for Network Connectivity
CID: 77730 555-233-504 — Issue 1 — April 2000
404
A second line of defense can be thought of as damage control — how to limit the
amount of damage that can be done if someone does gain unauthorized access to the
system? Damage control can be provided by application restrictions.
Each of these control methods is described below.
Access control —
network topology
Network topology refers to how the DEFINITY ECS network is connected to the
customer’s network.
Private network
One option to restrict access is to make sure that the DEFINITY ECS network is not
connected to any other network; that is, the DEFINITY ECS network is private. This
topology clearly solves all three access security concerns mentioned above. However,
a private network is not an option for all customers.
Private segment
Another topology is to put the DEFINITY ECS network on a private segment, behind
a router or a firewall. This approach can also solve all three concerns above by
implementing packet filtering in the router/firewall such that only legitimate traffic
can pass through.
Open network
One other topology that may be chosen is a completely open network, where
DEFINITY ECS nodes are placed on the customer network just like any other piece
of data networking equipment. An open network topology addresses none of the three
security concerns above, and other methods of access control must be used for these
installations.
Access control —
network administration
Network administration refers to how a DEFINITY ECS (specifically, the C-LAN
circuit pack) is administered in terms of dial-up PPP ports and routing information. A
carefully administered system has only dialup ports in service for DCS and adjunct
sessions that will be established at boot time. This means that normally there will not
be any ports available for a hacker to dial into. Additionally, the C-LAN circuit pack
should be administered only with routes specific to the DCS and adjunct nodes. This
ensures that anyone getting into a DEFINITY ECS can only get to other DCS or
adjunct nodes, not anywhere else on the customer network. Careful administration
will address concerns #1 and #2 above.
Note that no new access to the system access terminal (SAT), such as network-based
SAT, is introduced in Release 7. As in earlier releases of DEFINITY ECS, all port
and route administration can be done only via the SAT, and all changes are logged.
Access control —
authentication
Authentication also plays a role in providing access control to dial-up PPP ports. All
of these ports can be protected by Challenge Handshake Authentication Protocol
(CHAP). This provides an extra level of assurance that no unauthorized user will be
able to connect to a PPP port on C-LAN.