Gebruiksaanwijzing /service van het product N3 van de fabrikant Tandberg Data
Ga naar pagina of 59
T ANDBERG Gatekeeper User Manual Software version N3 D13381.03 This document is not to be repr oduced in whole or in part without pe rmission in w riting from:.
TANDBERG Gatek eeper User Manual ii Trademarks and copyright Copyright 1993-2005 TANDBERG ASA. All rights reserved. This document contains information that is proprietary to TANDBERG ASA.
TANDBERG Gatek eeper User Manual iii Environmental Issues Thank y ou for bu y ing a product which contributes to a reduction in pollution , and thereby helps save the en vironment. Our produc ts reduce the need f or travel and transpor t and thereby reduce p ollution.
TANDBERG Gatek eeper User Manual iv Operator Safety Summary For your protect ion, please read these saf ety instructions com pletely before operating the equipment and k eep this manual for future reference. T he information in this sum mary is intended for opera tors.
v Table Of Conte nts TANDBERG Gatek eeper User Manual ............................. ................................ ..........................i Trademark s and copyright ............................. ................................ .................
TANDBERG Gatek eeper User Manual vi 4.1 Upgrading Us ing HTTP(S) ....................................................... ................................ . 30 4.2 Upgrading Us ing SCP ................................... ...............................
1 1 Introduction This User Manu al is provided to he lp you make the bes t use of your TANDBERG Gatekeeper. A Gatekeeper is a c entral part of an H. 323 infrastructure. It prov ides address translat ion and controls access to t he network for H.323 term inals, Gateways and MCU s.
TANDBERG Gatek eeper User Manual 2 1.1 TANDBERG Gatekeeper Overview On the front of the Gatekeeper there are t hree LAN interf aces, a serial port (Data 1) and a Light Emitting D iode (Power). T he LAN 1 interface is used f or connecting the s y stem to your local area network , LAN interfac e 2 and 3 are disabled.
3 2 Inst allation Precautions: Never install com munication equipm ent during a lightning st orm. Never install jac ks for comm unication cables in wet loc ations unless the jack is specificall y designed f or wet locations.
TANDBERG Gatek eeper User Manual 4 Do not place hea vy objects directl y on top of the Gatekeeper. Do not place hot o bjects directly on top, or directly beneath the Gatekeeper. Use a grounded AC power outlet for the G atekeeper. 2.2 Mounting The Gatek eeper comes with brack ets for mounting in standard 19" racks .
5 2.5 Gatekeeper Initial Configuration The T ANDBERG Gatekeeper requires s ome configuration before it can be used. This m ust be done using a PC connected to the ser ial port (Data 1). The main thing that needs to be conf igured is the IP settings of the Gatekeeper.
TANDBERG Gatek eeper User Manual 6 xConfiguration Gatekeeper AutoDiscovery comm and in section 5.2 for mor e information. 12. Reboot the Gat ekeeper b y typing the c ommand xCommand boot to m ake your new settings tak e effect. 13. Disconnect the ser ial cable.
7 3 Using the Gatekeeper The Gatek eeper is used by H.323 term inals, Gatewa ys and MCUs. These device s register with the Gatek eeper and the Gatek eeper then provides address translation and c ontrols access to the net work.
TANDBERG Gatek eeper User Manual 8 NOTE Automatic disc overy is a function that a llows the Gatek eeper to reply to multicast G atekeeper discovery m essages from the endpoint. NOTE If you have probl ems registering the endpoint, try turning o n automatic discover y .
9 Remote z ones can be c onfigured through t he web interface of the TANDBERG Gatek eeper by navigating to Gat ekeeper Configurat ion > Gatekeeper . See Figure 1 for a sc reenshot of the configurat ion. Figure 1 Screen shot of the A dding a New Zone configuration NOTE W hen using a local zo ne prefix do not start the E.
TANDBERG Gatek eeper User Manual 10 W hen a Gatekeeper rece ives a Location Requ est, if it cannot respond f rom its own registration databas e, it will quer y all of its A lternates before respond ing. This allows the poo l of registrations to be treated as if the y were reg istered with a singl e Gatekeeper.
11 3.5 Call Control W hen an end-point wants t o call another endpo int it presents the addres s it wants to call to the Gatek eeper using a protocol kno ws as RAS. The Gatek eeper tries to resolve t his address and supplies the ca lling endpoint with inf ormation about the c alled endpoint.
TANDBERG Gatek eeper User Manual 12 Figure 3 Admiss ion Request Proce ssing.
13 Figure 4 Location Request Processing.
TANDBERG Gatek eeper User Manual 14 3.6 Bandwidth Control The T ANDBERG Gatekeeper allows you to control endpoi nts ’ use of bandwidth on your network.
15 xConfiguration Links Link [1..100] Pipe2 Name Each subzone m ay be configured with its own bandwidth lim its. Calls placed bet ween two endpoints in the s ame subzone co nsume resource f rom the subzone ’ s allocation .
TANDBERG Gatek eeper User Manual 16 Figure 6 Config uration of a SubZone t hrough the web int erface Figure 7 Adding a new Pipe through the web interface Figure 8 Config uring the dow nspeeding parameters of the Gatekeeper 3.
17 3.6.2 Bandwidth Control Examples One possible conf iguration for the deploy ment in Figure 5 is sho wn in Fig ure 9. Each of the offices is represented as a separate su bzone, with band wi dth config ured according to loca l policy.
TANDBERG Gatek eeper User Manual 18 In Figure , the end points in the enterpr ise register with the Gat ekeeper, whilst thos e in the branch and hom e office register wi th the Border Controller.
19 Figure 12 Gatek eeper example config uration All of the endpo ints in the enterprise wi ll be assigned to the def ault subzone. The T raversal subzone controls tra versal traffic f lowing through the Gatek eeper, whilst the T raversal Zone controls all traf fic traversing the enterpr ise firewall and pass ing on to the Border C ontroller.
TANDBERG Gatek eeper User Manual 20 matc h an ent ry on the D enyList. Allow lists an d Deny lists are m utually exclusive: onl y one may be in use at an y given tim e.
21 To conf igure the Gatek eeper to use the loca l database of c redentials during authentica tion issue the follo wing commands xConfiguration Authentication Mode: On xConfiguration Authentication Database: LocalDatabase Each credential in the local database has a username and a password.
TANDBERG Gatek eeper User Manual 22 xConfiguration LDAP UserDN: "Your user DN" xConfiguration LDAP Password: "password" The status of the connection betwee n the Gatekeeper and the.
23 Figure 16 Config uring the Gatekeeper to authenticate w ith an LDAP server u sing TLS encryption 3.9 URI Dialing If an alias is not located in the Gatek eeper ’ s list of registrations, it m ay attempt to find an authoritative Gatek eeper through the DNS s ystem.
TANDBERG Gatek eeper User Manual 24 Figure 17 IP Conf iguration Screen 3.9.1 URI Dialing and firewall traversal If URI dialing is be ing used in conju nction with firewall t raversal, DNSResolut ionMode should only be enable d on the Border Control ler.
25 To conf igure the Gatek eeper for f irew all traversa l, use the Web or console interface (see Figure 18 for th is configuration screen on the web interf ace).
TANDBERG Gatek eeper User Manual 26 xConfiguration Gatekeeper Policy Mode <On/Off> Policy interacts with authentication (sec tion 3.7.2, Authentica tion).
27 “ display ” Not defined for a ny alias types address The address c onstruct is used within an a ddress-switch to spec ify addresses to match. Please note that al l address com parisons ignore uppe r/lower case differenc es so <address is= “ Fred ” > will matc h “ fred ” , “ freD ” etc .
TANDBERG Gatek eeper User Manual 28 an E.164 num ber. proxy On executing a prox y node the Gatek eeper will attem pt to forward the cal l to the locations specified in the curr ent location set.
29 User "fred" will n ot accept calls from anyone at "annoying.com ", or from any unauthenticate d users. All other users will allow an y calls.
TANDBERG Gatek eeper User Manual 30 4 Sof tware Upgrade Software upgra de can be done in one of two ways: Using a web bro wser (HTTP/HTT PS). Using secure cop y (SCP). NOTE To upgrade the G atekeeper, a valid Rel ease key and sof tware file is required.
31 4. Enter the releas e key and press Install Sof tware. You will get a new screen where you can upload the sof tware image: 5. Browse to the f ile containing the sof tware and press Install. You should see a pag e indicating that up load is in progress: 6.
TANDBERG Gatek eeper User Manual 32 NOTE Make sure y ou transfer the release key file bef ore transferr ing th e soft w are im age. Also make sure you nam e the files exactly as desc ribed below. NOTE The release k ey file should contain j ust the 16 character release key.
33 5 Configuring the Gatekeeper This chapter lists the basic usage of each command. The com mands also support more advanced usag e, which is outside th e scope of this do cument. 5.1 Status The status root com mand, xstatus, returns s tatus inform ation from the Gatekeeper.
TANDBERG Gatek eeper User Manual 34 Command Usage Description ResourceUsage xstatus Res ourceUsage Reports usage of system resour ces. Registratio ns : Number of curr ently registered endpoints. MaxRegistra tions : Max imum number of registered endpoints since system start.
35 xconfigurat ion ? To list all configur ation data, t y pe xconfigurat ion To show a specif ic configuration value, type xconfigurat ion <name> To show usage information f or a specific config.
TANDBERG Gatek eeper User Manual 36 Configuration com mands Description xConfigurat ion Gatekeep er Alternate GK [1..5]: <IP Addr> List of Alternate Ga tekeepers ’ IP addresses . xConfigurat ion Gatekeep er AutoDiscove ry: <On/Off> Specifies if the Gate keeper suppo rts automatic regi stration of endpoints.
37 Configuration com mands Description xConfigurat ion HTTPS Mo de: <On/Off> Enables/disables H TTPS support. Note that HTTP must also be enabled. You must restart the system for changes to take e ffect. xConfigurat ion IP Addre ss: <IPAddr> Specify the IP addre ss of the sys tem.
TANDBERG Gatek eeper User Manual 38 Configuration com mands Description xConfigurat ion Pipes Pi pe [1..100] Bandwidth T otal Limit: <1..10000000 0> Bandw idth associated w ith a pipe, keye d by index .
39 Configuration com mands Description xConfigurat ion SubZones TraversalSu bZone Bandwi dth Total Mo de: <None/Limit ed/Unlimited > Whether or not the traversal subz one is enforcing to tal bandw idth restrictions. None corre sponds to no bandw idth available.
TANDBERG Gatek eeper User Manual 40 Configuration com mands Description xConfigurat ion Zones Zo ne [1..100] Gatekeeper IP Port: <1. .65534> Specifies the IP port of the neighb or gatekeeper xConfigurat ion Zones Zo ne [1..100] Gatekeeper HopCount: <1 .
41 Comma nd Usage Description DenyListAdd xCommand DenyLis tAdd <denied_ali as> Add an entry to the deny list, used by the registratio n restriction policy . DenyListDelete xCommand De nyListDelete <index> Removes the pattern from the den y list at the speci fied index .
TANDBERG Gatek eeper User Manual 42 Comma nd Usage Description SubZoneDelete xCommand Su bZoneDelete: <index> Deletes the index ed subzone. ZoneAdd xCommand Zo neAdd <name> <address> < prefix> Adds a new z one with the specifie d name, zon e prefix and IP address.
43 xfeedback l ist To register a feed back expression, t y pe xfeedback r egister <exp ression> To deregister the f eedback expres sion with index <n>, type xfeedback d eregister <n >.
TANDBERG Gatek eeper User Manual 44 Comma nd Usage Description relkey Relkey Displays the relea se key that this softwar e has been installed with. syslog syslog <lev el> [ipaddr] [ipaddr] .. . Enables tracing. <level> - is the log level, 0-3, 3 giv es most logging .
45 6 Appendix: Configuring DNS Servers In the exam ples below, we set up an SRV record to handle H.323 U RIs of the for m user@exam ple.com. These are handled by the Gatekeeper with t he fully qualified dom ain name of Gatekeeper1.exam ple.com which is listening on port 1719, the defau lt registration port.
TANDBERG Gatek eeper User Manual 46 then instruct nam ed to reload the f ile s kill – s SIGHUP pid 4. Check the log f iles for any discrepanc ies tail /var/log/messages For m ore detail s of how to configure BIND ser vers and the DNS s ystem in general see the book “ DNS and BIND ” 6 .
47 7 Appendix: Configuring LDAP Servers 7.1 Microsoft Active Directory 7.1.1 Prerequisites These com prehensive step by step instructions assume tha t Active Director y is in stalled. For details on installi ng Active Directory please c onsult your W indows documentation .
TANDBERG Gatek eeper User Manual 48 commUniqueId: comm1 h323Identityh323-ID: MeetingRoom1 h323IdentitydialedDigits: 626262 h235IdentityEndpointID: meetingroom1 h235IdentityPassword: mypassword Add the ldif f ile to the server using the com mand: ldifde -i -c DC=X <ldap_base> -f filename.
49 H.350.2 – Director y service s architecture for H.235 - An LDAP schem a to represent H.235 elem ents. The schem as can be downloaded i n ldif format fr om the web interface on the Ga tekeeper. To do this, navigate t o the Gatekeeper Conf iguration > Files pag e and click on the li nks for the schemas.
TANDBERG Gatek eeper User Manual 50 commUniqueId: comm1 h323Identityh323-ID: MeetingRoom1 h323IdentitydialedDigits: 626262 h235IdentityEndpointID: meetingroom1 h235IdentityPassword: mypassword Add the ldif f ile to the server using the com mand: slapadd -l <ldif _file> This will add a si ngle H.
51 8 Approvals The product has been approved b y various international a pproval agencies, am ong others: UL and Nem ko. According to their Fo llow-Up Inspection Schem e, these agenci es also perform pr oduction inspections at a regu lar basis, for all product ion of TANDBERG ’ s equipment.
TANDBERG Gatek eeper User Manual 52 9 T echnical S pec ifications System Capacit y 100-1000 register ed endpoints 25-200 concurrent calls 0-100 traversal ca lls 100 zones (The s y stem ’ s capacit y.
53 10 Index AllowList, 19, 36, 40 Alternate, 9, 24, 36 Authentication LDAP, 35 local database, 35 Bandwidth Contro l, 37 CPL, 25, 36 examples, 28 unsupported elem ents, 28 Credentials, 21 DenyList, 19.
Een belangrijk punt na aankoop van elk apparaat Tandberg Data N3 (of zelfs voordat je het koopt) is om de handleiding te lezen. Dit moeten wij doen vanwege een paar simpele redenen:
Als u nog geen Tandberg Data N3 heb gekocht dan nu is een goed moment om kennis te maken met de basisgegevens van het product. Eerst kijk dan naar de eerste pagina\'s van de handleiding, die je hierboven vindt. Je moet daar de belangrijkste technische gegevens Tandberg Data N3 vinden. Op dit manier kan je controleren of het apparaat aan jouw behoeften voldoet. Op de volgende pagina's van de handleiding Tandberg Data N3 leer je over alle kenmerken van het product en krijg je informatie over de werking. De informatie die je over Tandberg Data N3 krijgt, zal je zeker helpen om een besluit over de aankoop te nemen.
In een situatie waarin je al een beziter van Tandberg Data N3 bent, maar toch heb je de instructies niet gelezen, moet je het doen voor de hierboven beschreven redenen. Je zult dan weten of je goed de alle beschikbare functies heb gebruikt, en of je fouten heb gemaakt die het leven van de Tandberg Data N3 kunnen verkorten.
Maar de belangrijkste taak van de handleiding is om de gebruiker bij het oplossen van problemen te helpen met Tandberg Data N3 . Bijna altijd, zal je daar het vinden Troubleshooting met de meest voorkomende storingen en defecten #MANUAl# samen met de instructies over hun opplosinge. Zelfs als je zelf niet kan om het probleem op te lossen, zal de instructie je de weg wijzen naar verdere andere procedure, bijv. door contact met de klantenservice of het dichtstbijzijnde servicecentrum.