Page 3 - ONTENTS; NETB; UILDER; New Features Application Notes 17
C ONTENTS NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Encryption Packages Notice 9Supported Platforms 10New Products 10 SuperStack II SI 5xx (4-port) 10 Supported PC Flash Memory Cards 10Approved DRAM SIMMs 11New Features 11 VPN Features 11New and Enhanced Protocol Features 13System Features...
Page 5 - Limitations 45
DHCP Address Pool Changes 41Displaying Configuration Profiles 41Dynamic Paths 41Extensible Authentication Protocol 41File System Error 41Frame Relay Congestion Control 41History-Based Compression Negotiation Failure 42IPX to Non-IPX Configuration Error 42MBRI Ownership During Board Swapping 42Micros...
Page 6 - IP; Configuring IPsec 51; IPSEC S; CONFiguration 73
SDLC Ports and NetView Service Point 48Source-Route Transparent Gateway 48Token Ring+ Modules 48VRRP Configuration 48 C ONFIGURING IP SEC Configuring IPsec 51 Creating Policies 51Creating Key Sets 52Configuring Manual Key Information 53Enabling IPsec 54Setting up a VPN PPTP Tunnel 54Establishing the...
Page 7 - WEBL; INK; StatPollInterval 75
Page 8 - Reference for NETBuilder Family Software
Part No. 86-0595-001Published July 1998 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES These release notes provide information on the following topics for NETBuilder ® software version 11.1: ■ Encryption Packages Notice ■ Supported platforms ■ New products ■ Supported PC flash memory cards ■ Ap...
Page 9 - Supported Platforms; SuperStack II SI 5xx; Table 1; Approved 20 MB Flash Memory Cards
10 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Multi-protocol Router with 56-bit Encryption (DE) Multi-protocol Router with 128-bit Encryption (DS) ■ SuperStack ® II IP/IPX/AT Router with 56-bit Encryption (NE) (SI model) IP/IPX/AT Router with 128-bit Encryption (NS) (SI model) Multi-protoco...
Page 10 - New Features; VPN Features; Table 2; Com–approved DRAM SIMMs
Approved DRAM SIMMs 11 Approved DRAM SIMMs Table 2 lists 3Com–approved vendors of the 32 MB DRAM SIMM for upgrading the DPE 40 module. New Features This section describes new features in software version 11.1 for the NETBuilder II, SuperStack II, and OfficeConnect NETBuilder bridge/routers. VPN Feat...
Page 11 - Additional RAS Enhancements; Generic Token Card; DHCP Proxy
12 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Additional RAS Enhancements The RAS service has been enhanced in this release to add support for routers acting as RAS clients. Support was added for the RADIUS attributes “Framed_Route” and “Framed_Netmask.” Previous releases of software ignore...
Page 12 - RSVP; This section describes new and enhanced protocol features.; Virtual Router Redundancy Protocol (VRRP) Phase 2; Table 3; Summary of Encryption Strengths
New Features 13 < 56 bit support packages/kits contain: ■ A package identifier ending in ‘E’ (example, NE) ■ A 3CR number containing/ending in ‘91’ (examples, 3CR856791, 3CR6452P91FLASH) Table 3 contains a summary of the encryption strengths and the associated package ids. RSVP RSVP is a dynamic ...
Page 13 - Firewall Enhancements
14 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES of the queue policies, Priority Queuing, and Protocol Reservation are supported. In addition to the currently supported policies, a metering algorithm has been added. If the queue handler detects that the underlying bandwidth exceeds a certain t...
Page 14 - Frame Relay PVC Q.933 Support; This release implements the following general system features.; Boundary Router Remote LAN Detection
New Features 15 OSPF Not-So-Stubby-Area (NSSA) For inter-area routing, the Area Border Router (the only attachment to the backbone for leaf sites) advertised a default route. However, when fairly complex leaf sites are connected to the backbone via a Stub Area, inter-area routing into and out of the...
Page 15 - Network Management; This release adds the following new network management features.; ASCII Boot
16 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES the two edge devices are both physically attached to the same ATM network fabric, then the edge devices should be able to communicate directly with each other, bypassing one or more intermediate routers in the data path. Multiprotocol Over ATM (...
Page 16 - Upgrade Management Utilities and NETBuilder Upgrade Link; Upgrading NETBuilder Family Software; Flash Load
New Features Application Notes 17 ■ Improved error handling ■ Help frame resizing now persists across page changes ■ A logout icon for improved security ■ Port list support ■ Support for user-level password changing Upgrade Management Utilities and NETBuilder Upgrade Link The remote upgrade process ...
Page 17 - Example
18 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES needed to disable any echo cancellers on the line. Consult with the owner of the destination equipment to see whether it has this capability. In order to configure this feature, you must define the DialNoList entry with a type of BriV, by enteri...
Page 19 - NETBuilder II; Table 4; NETBuilder II Software Features
20 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES 11.1 Software Packages The tables in this section list the features in the packages available in software version 11.1 for the NETBuilder bridge/router platforms. NETBuilder II Table 4 lists the software features of each package for NETBuilder I...
Page 20 - NETBuilder II Software Features (continued); Table 5; NETBuilder II Firmware Requirements
11.1 Software Packages 21 NETBuilder II Firmware Requirements The NETBuilder II I/O modules require firmware upgrades to support the NETBuilder software version 11.1 (see Table 5 for firmware requirements). You can determine your I/O module firmware version through the software by entering: SHow -SY...
Page 21 - SuperStack II SI; Table 6; SuperStack II NETBuilder SI Software Features; Routing Protocols
22 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES SuperStack II SI Table 6 lists the software features of each package for SuperStack II SI bridge/routers. HSS 3-port (V.35) FW/HSS3-V35,1.1.9 HSS 3-port (RS449) FW/HSS3-449,1.1.9 HSS 3-port (RS232) FW/HSS3-232,1.1.9 HSS 4-port FW/4PORTWAN-FW,1.2...
Page 22 - WAN Protocols; SuperStack II NETBuilder SI Software Features (continued)
11.1 Software Packages 23 RAS Traps X X X X X IPX X X X X X X X XNS X X X X OSI X X X X OSI connection services X VINES X X X DECnet X X X AppleTalk X X X X X X X BR Remote LAN Detection X WAN Protocols PPP/Multilink PPP X X X X X X X X PPTP X X X X X X X L2TP X X X X X X X EAP X X X X X Frame Relay...
Page 23 - SuperStack II Token Ring; Memory Requirements; Table 7; SuperStack II NETBuilder Ethernet and Token Ring Features
24 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES SuperStack II Token Ring Table 7 lists software features for each package for the SuperStack II bridge/routers. Flash Load X X X X X X X X Virtual Ports (48 max.) X X X X X X X X Memory Requirements DRAM: 16 MB 16 MB 16 MB 16 MB 16 MB 16 MB 16 M...
Page 24 - OfficeConnect; OfficeConnect NETBuilder Software Features
11.1 Software Packages 25 OfficeConnect Table 8 and Table 9 list software features for each package for OfficeConnect bridge/routers. WAN Protocols PPP/Multilink PPP X X PPTP X X L2TP X X Frame Relay X X SMDS X X X.25 X X X.25 switching/tunneling X X IBM Protocols DLSw X X BRITSS X X LAA X X Polled ...
Page 25 - Table 8; OfficeConnect NETBuilder Software Features (continued)
26 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Routing Protocols IPv4 X X X X X IP services: Multicast IP X X X X X OSPF X X X X X Network Address Translation (NAT) X X X X X VRRP X X X X DHCP X X X X RIP/RIP v2/NTP X X X X X X DHCP Proxy X X X X IPCP X X X X IP security: IPsec X X X DES X X...
Page 26 - Table 9; Additional OfficeConnect NETBuilder Models Software Features
11.1 Software Packages 27 Table 9 Additional OfficeConnect NETBuilder Models Software Features SHDLC X X BSC conversion X QLLC/LLC2 conversion X X Other Features FTP X X X X X X Data over Voice X X X X X X CSU/DSU Loopback X X X X Zmodem X X X X X X Dial-on-demand X X X X X X Quick Step VPN applicat...
Page 29 - Item Not Supported; SuperStack II NETBuilder 227 Full Router (Ethernet); Downloading; The UNIX files are as follows:; Windows Files
30 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Item Not Supported The NETBuilder software version 11.1 does not support the following bridge/routers: ■ SuperStack II NETBuilder 227 Full Router (Ethernet) ■ SuperStack II NETBuilder 427 Router (Ethernet, ISDN) NETBuilder Upgrade Management Uti...
Page 30 - Upgrading
NETBuilder Upgrade Management Utilities 31 or http://infodeli.3com.com/infodeli/swlib For instructions on how to decompress and install the utilities, see the ruu111.txt file. The Windows files are as follows: Executing profile.bat When using the 11.1 NETBuilder Upgrade Management Utilities from a W...
Page 31 - This section contains known upgrade management issues.
32 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES Upgrade Management Known Issues This section contains known upgrade management issues. bcmdiagnose Error Message When you execute bcmdiagnose on HP-UX and the TFTP server is configured to use the Safe Directory method, the error message "No ...
Page 32 - Do not use the bcmfdinteg utility. The bcmfdinteg utility is used
Upgrade Management Known Issues 33 WARNING: Do not use the bcmfdinteg utility. The bcmfdinteg utility is used internally by the bcminstall utility. The bcmfdinteg utility should not be used by itself, because by default it removes all files from the current directory. File Conversion Considerations ...
Page 33 - or; Notes and Cautions
34 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES or UpgradeLink -NA Otherwise, an error dialog box is returned with the message “Could not verify user.” If you use tftp, the “Verify Upgrade Services” step does not need the user or password to be verified, so those entries as well as the FTP Cl...
Page 34 - Supported Asynchronous Modems
Notes and Cautions 35 Baud Rates for WAN Ports in DCE Mode The following baud rates are supported in DCE mode (synchronous, internal clocking): If you configure a baud rate that is different from those listed, the system will fall back to the nearest lower supported rate. Supported Modems Table 10 l...
Page 36 - These messages do not indicate a problem and can be ignored.; IBM-Related Services in; IBM-Related Feature Settings for Token Ring Ports
Notes and Cautions 37 These messages do not indicate a problem and can be ignored. IBM-Related Services in Token Ring IBM-related services such as DLSw and APPN are affected by parameter settings in the BRidge, SR, and LLC2 Services. Table 12 shows the required settings in source route (SR), source ...
Page 37 - Token Ring Frame Copy Errors; Com Bridge/Routers and Supported Features
38 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES and route discovery are configured, bridge numbers must be unique for each bridge/router on the same ring, and LLC2 is enabled on token ring ports. Token Ring Frame Copy Errors For transparent bridge or source route transparent configurations, t...
Page 38 - SETDefault -BRidge TransparentBridge = NoTransparentBridge; ”), the Web Link assumes that access to the; Known Problems
Known Problems 39 LAN Network Manager with NETBuilder II Systems If you have previously configured your LAN Network Manager to use the NETBuilder II system as a virtual ring, and you want to use it as a physical ring, you must set your virtual ring number back to None. LLC2 Frames and PPP LLC2 frame...
Page 44 - Limitations; Use these parameters for the leaf node and central node WAN ports.
Limitations 45 Limitations This section describes limitations of NETBuilder software version 11.1. Topics are in alphabetical order. ACCM Not Configurable The ACCM (Async Control Character Map) used for Async PPP cannot be configured. During LCP negotiation, the NETBuilder bridge/router always propo...
Page 45 - DLSw Circuit Maximums with CONNectionUsage Parameter Settings
46 NETB UILDER S OFTWARE V ERSION 11.1 R ELEASE N OTES parameter settings. The practical limit may be lower and depends on the traffic load, CPU, and memory usage by other services. Number of TCP Connections 3Com LLC2 tunneling uses one TCP connection for each LLC2 session. DLSw scales to large netw...
Page 46 - When configuring MLP:
Limitations 47 NetBIOS sessions occurs if the primary link fails and the redundant link is activated. If this happens, end users need to log on and initiate another session. Maximum BSC Line Speed For V.35 and RS-232 links, the maximum baud rate supported for BSC traffic is 38.4. If the baud rate is...
Page 48 - SING; PDATE; This section includes update pages with changes and additions to; Place the update pages at the front of each specified chapter.
U SING NETB UILDER F AMILY S OFTWARE U PDATE P AGES This section includes update pages with changes and additions to Using NETBuilder Family Software , software version 11.1. Place the update pages at the front of each specified chapter.
Page 49 - ONFIGURING; SEC; Release Notes, Using NETBuilder Family Software Version 11.0; Replace Chapter 17 with this chapter.; For conceptual information, see “How IPsec Works”; Configuring IPsec; The procedures in this section describe how to configure IPsec.; Creating Policies; Action AhXport provides data integrity and authentication.
17 C ONFIGURING IP SEC 11.1 Release Notes, Using NETBuilder Family Software Version 11.0 Replace Chapter 17 with this chapter. This chapter describes how to configure the IP Security Protocol (IPsec) on your IP router. IPsec provides security at the network layer. Because IPsec is integrated into IP...
Page 50 - Creating an Encryption Policy
52 C HAPTER 17: C ONFIGURING IP SEC <auth_algorithm> : MD5 | SHA <portlist >: 1-65535 | * | Archie | DNS | Finger | FTP | FTPData | Gopher | HTTP | NFS | NNTP | NTP | POP2 | POP3 | PortMap | RIP | SMTP | SNMP | SNMPTrap | Syslog | Telnet | TFTP | WAIS The default for encrypt_algorithms i...
Page 51 - ADD IPSEC KeySet esp_key EncryptKey “hello124”; To create a key set for both encryption and authentication, enter:; ADD IPSEC KeySet ahesp_key EncryptKey “hello124” AuthKey “world236”; Configuring Manual Key
Configuring IPsec 53 <encrypt_key> and <auth_key> can be 1 to 128 bytes entered as either ASCII text strings or as a series of hexadecimal digits. See “Configuring Manual Key Information” next for more information about key set usage. To delete a key set, use: DELete -IPSEC KeySet [<k...
Page 52 - Enabling IPsec; Enable IPsec policy checking on the port using:; Setting up a
54 C HAPTER 17: C ONFIGURING IP SEC When you specify a key that is too short, the policy binding operation generates an error message informing you of the key length discrepancy and the key is rejected. If this should occur you will need to delete the specified key and reenter a key of the appropria...
Page 53 - Figure 1; VPN PPTP Tunnel; Assign an IP address to the tunnel virtual port by entering:
Configuring IPsec 55 Figure 1 VPN PPTP Tunnel On router 1, set up the tunnel from 170.0.0.1 to 180.0.0.1 by following these steps. 1 Set the system name to "router1" by entering: SETDefault scid = "router1" 2 Create a virtual port to accept connection requests from only router 2 by e...
Page 54 - Establishing the Dialup; How IPsec Works
56 C HAPTER 17: C ONFIGURING IP SEC On router 2, setup the PPTP tunnel from 170.0.0.1 to 180.0.0.1 by following these steps: 1 Set the system name of router 2 to "router2" by entering: SETDefault scid="router2" 2 Create a virtual port that will accept connection requests from only ro...
Page 55 - Policies
How IPsec Works 57 IPsec works with the existing Internet infrastructure using encapsulation. It secures a packet of data by encrypting it before sending it over the Internet. On the receiving end, an IPsec-compliant device decrypts the data. On each end of the link (systems at both ends comprise a ...
Page 56 - ESP can be applied alone or with authentication headers.; Authentication Header
58 C HAPTER 17: C ONFIGURING IP SEC DES-CBC CANNOT be exported without a legal export license. See the release notes for your software for export restrictions. ESP can be applied alone or with authentication headers. Authentication Header (AH) AH is used to provide data integrity and data origin aut...
Page 58 - ERVICE; Release Notes, Reference for NETBuilder Family Software; Replace Chapter 33 with this chapter.; CONFiguration; Default; Syntax; Default; KeyEncryptionKey; Syntax; IPSEC Service Parameters and Commands
33 IPSEC S ERVICE P ARAMETERS 11.1 Release Notes, Reference for NETBuilder Family Software Replace Chapter 33 with this chapter. This chapter describes the IPSEC Service parameters. Table 1 lists the IPSEC Service parameters and commands. CONFiguration Syntax SHow -IPSEC CONFiguration Default No def...
Page 59 - No Default; KeySet; Description
62 C HAPTER 33: IPSEC S ERVICE P ARAMETERS Default No Default Description All keysets are encrypted and protected with the current KeyEncryptionKey and stored in the IPSEC configuration file. The value of the KeyEncryptionKey parameter which is stored in the EEPROM, can be updated by root, but is no...
Page 60 - Values; ManualKeyInfo; manualPOLicy; An ASCII text string or a string of hexadecimal numbers.
ManualKeyInfo 63 When you specify a key that is too short, the policy binding operation generates an error message informing you of the key length discrepancy and the key is rejected. If this should occur you will need to delete the specified key and reenter a key of the appropriate length. Values M...
Page 62 - DES
manualPOLicy 65 The mask is a number in the range of 0-32, which indicates the number of bits in the IP address that remain unchanged for the IP addresses in that block. The remaining bits in the IP address should be all 0s. The address block includes all addresses except for the first address and t...
Page 64 - RSVP S; Replace Chapter 60 with this chapter.; RSVP Service Parameters and Commands
60 RSVP S ERVICE P ARAMETERS 11.1 Release Notes, Reference for NETBuilder Family Software Replace Chapter 60 with this chapter. This chapter describes the Resource Reservation Protocol (RSVP) Service parameters. RSVP is used in multicasting applications like video conferencing, multimedia, and virtu...
Page 65 - MaxFlowRate; Amount of bandwidth reserved for RSVP.; REQuest; RESerVation; UDPEndcap
68 C HAPTER 60: RSVP S ERVICE P ARAMETERS MaxFlowRate Syntax SETD !<port> -RSVP MaxFlowRate = <bytes/sec>(0-562500) SHow [ !<port> | !* ] -RSVP MaxFlowRate Default Amount of bandwidth reserved for RSVP. Description The MaxFlowRate parameter specifies the maximum amount of bandwidth...
Page 66 - SR S; Place this page in front of Chapter 69.; AllRoutes; All routes in the routing table in decimal format; Specifies the number of entries to be displayed.
69 SR S ERVICE P ARAMETERS 11.1 Release Notes, Reference for NETBuilder Family Software Place this page in front of Chapter 69. AllRoutes Syntax FLush [!<port> | !*] -SR AllRoutes [Dec | Hex] [<Transparent | Null | route segment>] [Discover | Static] SHow [!<port> | !*] -SR AllRout...
Page 67 - ROUte; Override
70 C HAPTER 69: SR S ERVICE P ARAMETERS ROUte Syntax ADD !<port> -SR ROUte <media address> [Override] [Dec | Hex] [ Transparent | {Null | <source route> [<largestframesize>]}] DELete !<port> -SR ROUte <media address> SHow [!<port> | !*] -SR ROUte [[Cmac | Nc...
Page 70 - SYS S; Place this page in front of Chapter 71.
71 SYS S ERVICE P ARAMETERS 11.1 Release Notes, Reference for NETBuilder Family Software Place this page in front of Chapter 71. CONFiguration Syntax SHow -SYS CONFiguration Description The CONFiguration parameter displays various SYS Service parameter values. The display generated with this paramet...
Page 72 - Place this page in front of Chapter 77.; StatPollInterval
77 WEBL INK S ERVICE P ARAMETERS 11.1 Release Notes, Reference for NETBuilder Family Software Place this page in front of Chapter 77. StatPollInterval Syntax SETDefault -WEBLink StatPollInterval = <value> (0-120) SHow -WEBLink StatPollInterval Default 60 (minutes) Description The StatPollInter...