Nokia IP Networking


Nokia IP Family

Nokia CryptoCluster Family

Nokia IP 330
Nokia IP 440
Nokia IP 650
VPN Accelerator Card
High Availability Module

CryptoCluster 500
CryptoCluster 2500
CryptoCluster 5010
SafeNet Remote Access Client
CryptoConsole Management Software

The Nokia CryptoCluster™ 2500 VPN Gateway

Product Overview
The CryptoCluster line of VPN gateways represents a brand new class of products able to scale from the most reliable small office applications up to large enterprise-gateway or service provider deployments. This product line delivers an exceptional combination of never-before-attained reliability, scalability and manageability, together with an outstanding price/performance ratio. CryptoCluster gateways support IPSec, L2TP and PPTP tunneling protocols, giving customers the ability to provide secure communications for remote users, as well as the ability to establish private VPN communication from site to site.

The CryptoCluster 2500 VPN gateways are typically deployed in regional offices or the facilities of an e-commerce business partner. By comparison, the CryptoCluster 5000 VPN gateways typically operate as a hub for implementing an enterprise-wide VPN, and the CryptoCluster 500 VPN gateways are deployed in small office environments.

The CryptoCluster 2500 VPN gateways introduce a tremendous advance in the design of networking products. Benefiting from the power of IP Clustering, CryptoCluster nodes act as one network device. Because individual gateways can be clustered together to enable the transparent distribution of IP packet flows, multiple CryptoCluster 2500 VPN gateways provide extreme scalability. In addition, the Nokia unique, patented Active Session Failover technology retains all existing sessions in the event that any node in a cluster becomes unavailable due to upgrade, maintenance, or even disaster. Both enterprise organizations and service providers can benefit from this previously unheard-of reliability. For the first time ever, VPN gateways can provide the kind of global, mission-critical communications required by large enterprises, and can do so with the level of reliability that these operations require.

An individual CryptoCluster 2500 VPN gateway can handle IPSec ESP protection of traffic using 3DES/SHA-1 at up to 45 Mbps. The tunneling capacity of a single CryptoCluster 2500 VPN gateway allows it to easily support 2,500 remote users simultaneously with individual Layer 2 Tunneling Protocol (L2TP) or Microsoft Point to Point Tunneling Protocol (PPTP) tunnels. In clustered configurations, with multiple CryptoCluster 2500 VPN gateways behaving as one device, they are able to dramatically increase the number of tunnel terminations. Because additional CryptoCluster 2500 VPN gateways can be transparently added to a pre-existing cluster while the cluster is running, zero maintenance downtime is attainable. This provides for convenient incremental expansion of the cluster as VPN requirements grow over time. Moreover, because of Active Session Failover technology, if any node in the cluster becomes unavailable, the cluster will automatically reassign the active sessions among the remaining nodes with no disruption in service. IPSec Security Associations (SA) are securely shared across the cluster, avoiding costly re-keying and frustrating flow termination.

Security Features
Authentication is available through standard Public Key Infrastructure (PKI) mechanisms, using either a built-in certification authority (CA) feature or an external CA, such as Baltimore, Entrust, or VeriSign. Automated secure key exchange is performed using industry standard cryptographic methods. This can be done via the Internet Key Exchange (IKE) protocol using public-key cryptography or based on pre-shared keys, as the administrator's policy dictates. Standard public/private key cryptography is used in authenticating ISO X.509v3 digital certificates. All keys used in encryption and authentication of traffic are derived through the Diffie-Hellman key exchange.

A complementary component, the CryptoConsole™ management software, gives complete, centralized control of connectivity and security policy. Administrators can configure and manage services including security modes (type of encryption and/or authentication to use), re-keying interval, key exchange method, as well as IP addressing. Per-user policy is simply configured and administered. Management of policy can be based on ISO X.509v3 certificates, IP addresses or ranges of addresses. L2TP & PPTP authentication can be done locally or via RADIUS.

Manageability and Serviceability
As with the CryptoCluster 5000 and CryptoCluster 500 VPN gateways, simplified management of the CryptoCluster 2500 VPN gateways is achieved with the use of the CryptoConsole management software. This Java tool provides an easy-to-use configuration utility, which allows for quick configuration of even complex security policies, and provides a mechanism for administrators to check status or modify configuration through point-and-click operations. The CryptoConsole tool provides remote configuration, fault, performance and security management of the CryptoCluster gateways. All communication between the PC or laptop running this management software and the cluster is done using Secure Sockets Layer (SSL) to ensure the authenticity and privacy of the configuration information through the network.

Automated operational features incorporated into the CryptoConsole software include the ability to remotely manage and configure the CryptoCluster gateways. The management software allows a single, centralized point of administration, eliminating the need to visit each CryptoCluster gateway site when upgrading software. SNMP is also integrated into the CryptoCluster gateway for network management integration with administrator's current systems.

Management features

Secure Code Update & Cluster communication

Performance Statistics & Operational Statistics

Cryptographic Standards

IETF standards, drafts and RFCs supported

IP services

Physical Specifications

Dimensions and Weight

Power Requirements

Regulatory Compliance

The CryptoCluster 2500 gateway is fully compliant with:

 
home | search | products | services | research | company | partners | downloads | contact
Please contact our Webmaster with any questions or comments.
Copyright 1999, 2000, 2001 I.D.T., Inc.. All rights reserved.