30.11.2014 Views

AT-AR770S Secure VPN Router

AT-AR770S Secure VPN Router

AT-AR770S Secure VPN Router

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Datasheet | <strong>Router</strong><br />

<strong>AT</strong>-<strong>AR770S</strong><br />

<strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

<strong>AT</strong>-<strong>AR770S</strong><br />

2 x WAN combo ports (SFP or 10/100/1000TX)<br />

4 x LAN 10/100/1000TX ports<br />

2 x PIC slots<br />

1 x Asynchronous console / modem port<br />

Flexible High Speed WAN Options<br />

The <strong>AT</strong>-<strong>AR770S</strong> is the first Allied Telesis router<br />

to offer gigabit connectivity for both the LAN<br />

switch and WAN Ethernet ports. Eth0 and Eth1<br />

are combo ports.This means that they can<br />

make use of an SFP instead of the standard<br />

copper RJ-45 connection.<br />

Both the SFP and RJ-45 physical ports are<br />

managed by the same interface IC, providing a<br />

single ‘port’ with two connectivity options.<br />

When using an SFP port on the <strong>AT</strong>-<strong>AR770S</strong>, the<br />

corresponding RJ-45 port is disabled. However,<br />

when the SFP transceiver is removed, the RJ-45<br />

port becomes operational again.<br />

<strong>Secure</strong> Modular Routing Solution<br />

The <strong>AT</strong>-<strong>AR770S</strong> has been designed with the needs<br />

of small to medium enterprises/businesses or<br />

branch office businesses in mind. The <strong>AT</strong>-<strong>AR770S</strong><br />

offers significant advances in processing<br />

performance, Quality of Service (QoS), routing,<br />

remote connectivity and security.<br />

Extensive <strong>VPN</strong> Capability<br />

The <strong>AT</strong>-<strong>AR770S</strong> provides extensive IPSec-based<br />

<strong>VPN</strong> capability, allowing the interconnection of<br />

offices, remote tele-workers, and other users<br />

who require secure access to a corporate<br />

network.The integrated hardware acceleration,<br />

standard on the <strong>AT</strong>-<strong>AR770S</strong>, maximises<br />

encryption throughput and removes the need<br />

to purchase a hardware upgrade package.The<br />

<strong>AT</strong>-<strong>AR770S</strong> is compatible with industry standard<br />

IPSec <strong>VPN</strong> clients.<br />

Key Features<br />

Hardware<br />

• 2 x SFP or 10/100/1000TX WAN interfaces<br />

• 2 x Port Interface Card (PIC) slots<br />

• 4 x 10/100/1000TX LAN ports<br />

• 1 x Asynchronous console / modem port<br />

• DMZ port: configurable on any of the<br />

WAN/LAN ports<br />

• 128MB RAM<br />

• 32MB Flash<br />

• RoHS compliant<br />

Security<br />

• IP Filtering<br />

• Stateful Inspection Firewall<br />

• 802.1x<br />

• N<strong>AT</strong>-T<br />

• Authentication: RADIUS,TACACS, MD5, PAP,<br />

CHAP<br />

<strong>VPN</strong>/Encryption<br />

• DES,AES, 3DES encryption<br />

• 5,000 configured IPsec <strong>VPN</strong> tunnels<br />

(1000 active tunnels)<br />

• HW accelerated IPsec performance: Up to<br />

500Mbps 1<br />

• Supports industry standard <strong>VPN</strong> clients<br />

Manageability<br />

• CLI management<br />

• SNMPv3<br />

Extensive routing support:<br />

• WAN load balancer<br />

• Software QoS<br />

• RIPv1 and v2<br />

• OSPFv1 and v2<br />

• GRE<br />

• IPX<br />

• VRRP<br />

• IPv6 – optional<br />

• BGP-4 – optional<br />

• RIPng – optional<br />

Multicast routing protocols:<br />

• PIM-DM<br />

• PIM-SM<br />

• DVMRP<br />

• IGMPv2<br />

• IGMP Snooping<br />

• IPv6 Multicast – optional<br />

• PIM6 – optional<br />

• MLD – optional<br />

Support for traditional network<br />

protocols:<br />

• X.25<br />

• Frame Relay<br />

1<br />

Performance figure estimates from pre-production units.<br />

Allied Telesis<br />

www.alliedtelesis.com


<strong>AT</strong>-<strong>AR770S</strong> | <strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

Security<br />

In addition to hardware-based encryption, the<br />

<strong>AT</strong>-<strong>AR770S</strong> comes with other advanced<br />

security features such as traffic filtering with<br />

event logging. Traffic filtering uses the source<br />

and destination address, port, protocol and TCP<br />

packet type to provide control over traffic that<br />

passes through the <strong>AT</strong>-<strong>AR770S</strong>. A Stateful<br />

Inspection Firewall provides an increased level<br />

of security and complements the packet filtering<br />

function. HTTP and SMTP proxies on the <strong>AT</strong>-<br />

<strong>AR770S</strong> provide improved control over web<br />

and mail communications.<br />

Quality of Service<br />

Allied Telesis’ QoS implementation enables the<br />

<strong>AT</strong>-<strong>AR770S</strong> to dynamically identify high priority<br />

voice, video and application traffic, so that<br />

appropriate service levels can be maintained in<br />

congested networks. Advanced QoS allows<br />

voice, video, and data traffic to have QoS<br />

applied within individual IPSec tunnels, over<br />

GRE, as well as IPv6 to IPv4 tunnels.<br />

Performance<br />

The <strong>AT</strong>-<strong>AR770S</strong> provides superior performance<br />

over other secure <strong>VPN</strong> routers in this market<br />

space. While most secure routers have stateful<br />

firewalls with N<strong>AT</strong>, QoS, and IPsec <strong>VPN</strong><br />

termination capability, very few can perform all<br />

three functions and still provide excellent<br />

performance with the mixed packed sizes seen<br />

in real networks.The <strong>AT</strong>-<strong>AR770S</strong> can support<br />

up to 1000 concurrent <strong>VPN</strong> tunnels or up to<br />

500 Mbps AES or 3DES throughput.<br />

This level of performance enables secure siteto-site<br />

<strong>VPN</strong>s over multiple WAN interfaces<br />

while still firewalling the local network across<br />

multiple LAN ports.<br />

Comprehensive Management and<br />

Configuration<br />

The <strong>AT</strong>-<strong>AR770S</strong> comes with a comprehensive<br />

suite of management features and is also<br />

compatible with SNMP-based management<br />

packages. An extensive command set is available<br />

via the Command Line Interface (CLI). Allied<br />

Telesis’ SNMP support extends to SNMPv3 to<br />

provide secure management.<br />

WAN Load Balancer<br />

The <strong>AT</strong>-<strong>AR770S</strong>’ WAN Load Balancer enables<br />

the router to combine bandwidth from multiple<br />

WAN connections for increased throughput,<br />

redundancy and reliable WAN connectivity.<br />

When a router simultaneously connects to<br />

multiple WAN networks, the WAN Load<br />

Balancer will distribute the traffic based on any<br />

one of a number of selectable balancing<br />

algorithms. A typical example would be a router<br />

that has two Internet connections each<br />

exchanging data to remote sites via different<br />

Internet providers. In this case an outage limited<br />

to one network will not result in a loss of<br />

connectivity to these sites.<br />

About Allied Telesis<br />

Allied Telesis is part of the Allied Telesis Group.<br />

Founded in 1987, the company is a global<br />

provider of secure Ethernet/IP access solutions<br />

and an industry leader in the deployment of<br />

IP Triple Play networks over copper and fiber<br />

access infrastructure. Our POTS-to-10G iMAP<br />

integrated Multiservice Access Platform and<br />

iMG intelligent Multiservice Gateways, in<br />

conjunction with advanced switching, routing<br />

and WDM-based transport solutions, enable<br />

public and private network operators and<br />

service providers of all sizes to deploy scalable,<br />

carrier-grade networks for the cost-effective<br />

delivery of packet-based voice, video and data<br />

services.<br />

Visit us online at www.alliedtelesis.com.<br />

Service and Support<br />

Allied Telesis provides value-added support<br />

services for its customers under its Net.Cover SM<br />

programs. For more information on<br />

Net.Cover SM support programs available in your<br />

area, contact your Allied Telesis sales<br />

representative or visit our website:<br />

www.alliedtelesis.com<br />

Feature Summary<br />

Hardware Features<br />

2 x WAN combo ports (SFP or 10/100/1000TX)<br />

4 x LAN 10/100/1000TX ports<br />

2 x PIC<br />

1 x Asynchronous console / Modem port<br />

DMZ port: Obtained by configuring one of the WAN or LAN<br />

ports<br />

Processor<br />

833MHz<br />

Internal security encryption engine<br />

Memory<br />

128MB Ram<br />

32MB Flash<br />

Power Characteristics<br />

Input Voltage: 100-240 VAC, 50-60 Hz<br />

Max Power Consumption: 40W<br />

Internal Battery Backup (1 year)<br />

Physical<br />

Dimensions: 1RU rack mount<br />

Depth 239mm, Width 440mm<br />

Height 44mm<br />

Weight: 2.95 kg<br />

Environmental<br />

Operating Temp: 0°C to 50°C<br />

Storage Temp: -25°C to 70°C<br />

Operating relative humidity: 5 to 80% non-condensing<br />

Acoustic: General Office @ 40dB V. Measured in<br />

accordance with ANSI S12.10<br />

Operating Altitude: Up to 10,000 feet<br />

Approvals & Certifications<br />

UL<br />

TUV<br />

UL60950-1<br />

CAN/CSA-C22.2 No. 60950-1-03<br />

EN60950-1<br />

AS/NZS 60950<br />

EN60825-1<br />

EN55022 class A<br />

EN55024<br />

FCC class A<br />

VCCI class A<br />

AS/NZS CISPR22 class A<br />

CE<br />

Reliability<br />

MTBF: >120 000 hrs (telcordia methodology, data path only)<br />

Allied Telesis<br />

www.alliedtelesis.com


<strong>AT</strong>-<strong>AR770S</strong> | <strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

Optional Extras<br />

Port Interface Cards:<br />

<strong>AT</strong>-AR020 Single configurable E1/T1 interface<br />

that supports channelized/unchannelized<br />

Primary Rate ISDN/Frame Relay<br />

<strong>AT</strong>-AR021S (V2)Single Basic Rate ISDN S/T interface<br />

<strong>AT</strong>-AR023 Single Synchronous port up to 2Mbps to an<br />

external CSU/DSU (<strong>AT</strong>-V.35-DTE-00 or<br />

<strong>AT</strong>-X.21-DTE-00 cable required)<br />

<strong>AT</strong>-AR024 Four Asynchronous RS-232 interfaces to<br />

115Kbps<br />

Software Features<br />

Routing and Multicast<br />

PPP and IP Routing<br />

RIP v1 & v2<br />

OSPF v1 & v2<br />

BGP-4 (optional)<br />

IPX<br />

IGMPv2<br />

PIM-SM / DM<br />

DVMRP (including draft_ietf_idmr_dvmrp_v3_10)<br />

DECNet<br />

WAN Protocols<br />

X.25<br />

Frame Relay<br />

Security<br />

IP Filtering<br />

Stateful Inspection Firewall<br />

N<strong>AT</strong>-T<br />

SMTP & HTTP Proxy<br />

802.1x<br />

Authentication: RADIUS, TACACS, MD5, PAP, CHAP<br />

SSH<br />

SSLv1<br />

<strong>VPN</strong><br />

L2TP<br />

GRE<br />

IPSec<br />

IKE<br />

ISAKMP<br />

PKI<br />

Encryption: DES, 3DES, AES<br />

Microsoft Windows XP <strong>VPN</strong> client interoperability<br />

Hardware acceleration<br />

QoS<br />

Extensive Traffic classifiers of L2 to L5 traffic to allow<br />

appropriate queuing of traffic<br />

IP: IP source / destination address, TOS & DiffServ<br />

Ethernet: MAC source / destination, 802.1q<br />

TCP / UDP: Port numbers<br />

VoIP: RTP source & destination<br />

Queuing:<br />

• Low latency queuing (LLQ)<br />

• Class-based weighted fair queuing (CBWFQ<br />

• Deficit Round Robin (DRR)<br />

Supported tunnel interfaces: PPP, L2TP, IPsec, GRE<br />

RSVP<br />

Management<br />

CLI<br />

SNMPv3<br />

IPv6<br />

RIPng<br />

IPv6 RFC 2460<br />

Neighbour discovery RFC 2461<br />

Stateless address auto configuration RFC 2462<br />

ICMPv6 RFC 2463<br />

Transmission of IPv6 packets RFC 2464<br />

Connection of IPv6 domains via IPv4 clouds RFC 3056<br />

DHCPv6<br />

Country of Origin<br />

China<br />

Standards and Protocols<br />

Software Release 2.9.1<br />

BGP-4<br />

RFC 1771 Border Gateway Protocol 4<br />

RFC 1966 BGP Route Reflection<br />

RFC 1997 BGP Communities Attribute<br />

RFC 1998 Multi-home Routing<br />

RFC 2385 Protection of BGP Sessions via the<br />

TCP MD5 Signature Option<br />

RFC 2439 BGP Route Flap Damping<br />

RFC 2858 Multiprotocol Extensions for BGP-4<br />

RFC 2918 Route Refresh Capability for BGP-4<br />

RFC 3065 Autonomous System Confederations for BGP<br />

RFC 3392 Capabilities Advertisement with BGP-4<br />

Encryption<br />

RFC 1321 MD5<br />

RFC 2104 HMAC<br />

RFC 2451 The ESP CBC-Mode Cipher Algorithms<br />

FIPS 180 SHA-1<br />

FIPS 186 RSA<br />

FIPS 197 AES 1<br />

FIPS 46-3 DES<br />

FIPS 46-3 3DES 1<br />

Ethernet<br />

RFC 894 Ethernet II Encapsulation<br />

IEEE 802.1D MAC Bridges<br />

IEEE 802.1G Remote MAC Bridging<br />

IEEE 802.1Q Virtual LANs<br />

IEEE 802.2 Logical Link Control<br />

IEEE 802.3ac VLAN TAG<br />

IEEE 802.3u 100BASE-T and 802.3u 1000 Base-T<br />

IEEE 802.3x Full Duplex Operation<br />

General Routing<br />

RFC 768 UDP<br />

RFC 791 IP<br />

RFC 792 ICMP<br />

RFC 793 TCP<br />

RFC 826 ARP<br />

RFC 903 Reverse ARP<br />

RFC 925 Multi-LAN ARP<br />

RFC 950 Subnetting, ICMP<br />

RFC 1027 Proxy ARP<br />

RFC 1035 DNS<br />

RFC 1055 SLIP<br />

RFC 1122 Internet Host Requirements<br />

RFC 1142 OSI IS-IS Intra-domain Routing Protocol<br />

RFC 1144 Van Jacobson's Compression<br />

RFC 1256 ICMP <strong>Router</strong> Discovery Messages<br />

RFC 1288 Finger<br />

RFC 1332 The PPP Internet Protocol Control Protocol (IPCP)<br />

RFC 1334 PPP Authentication Protocols<br />

RFC 1377 The PPP OSI Network Layer Control Protocol<br />

(OSINLCP)<br />

RFC 1378 The PPP AppleTalk Control Protocol (<strong>AT</strong>CP)<br />

RFC 1518 CIDR<br />

RFC 1519 CIDR<br />

RFC 1542 BootP<br />

RFC 1552 The PPP Internetworking Packet Exchange<br />

Control Protocol (IPXCP)<br />

RFC 1570 PPP LCP Extensions<br />

RFC 1582 RIP on Demand Circuits<br />

RFC 1598 PPP in X.25<br />

RFC 1618 PPP over ISDN<br />

Allied Telesis<br />

www.alliedtelesis.com


<strong>AT</strong>-<strong>AR770S</strong> | <strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

RFC 1661 The Point-to-Point Protocol (PPP)<br />

RFC 1662 PPP in HDLC-like Framing<br />

RFC 1701 GRE<br />

RFC 1702 GRE over IPv4<br />

RFC 1762 The PPP DECnet Phase IV Control Protocol (DNCP)<br />

RFC 1812 <strong>Router</strong> Requirements<br />

RFC 1877 PPP Internet Protocol Control Protocol<br />

Extensions for Name Server Addresses<br />

RFC 1918 IP Addressing<br />

RFC 1962 The PPP Compression Control Protocol (CCP)<br />

RFC 1968 The PPP Encryption Control Protocol (ECP)<br />

RFC 1974 PPP Stac LZS Compression Protocol<br />

RFC 1978 PPP Predictor Compression Protocol<br />

RFC 1989 PPP Link Quality Monitoring<br />

RFC 1990 The PPP Multilink Protocol (MP)<br />

RFC 1994 PPP Challenge Handshake Authentication Protocol<br />

(CHAP)<br />

RFC 2125 The PPP Bandwidth Allocation Protocol (BAP) /<br />

The PPP Bandwidth Allocation Control Protocol (BACP)<br />

RFC 2131 DHCP<br />

RFC 2390 Inverse Address Resolution Protocol<br />

RFC 2516 A Method for Transmitting PPP Over Ethernet<br />

(PPPoE)<br />

RFC 2822 Internet Message Format<br />

RFC 2878 PPP Bridging Control Protocol (BCP)<br />

RFC 2661 L2TP<br />

RFC 3046 DHCP Relay Agent Information Option<br />

RFC 3232 Assigned Numbers<br />

RFC 3993 Subscriber-ID Sub-option for DHCP Relay Agent Option<br />

"IPX <strong>Router</strong> Specification", v1.2, Novell, Inc., Part Number<br />

107-000029-001<br />

ISO 10589, ISO 10589 Technical Corrigendums 1, 2, 3, ISO<br />

Intermediate System-to-Intermediate System<br />

"ISO 8473, relevant parts of ISO 8348(X.213), ISO 8343/<br />

Add2, ISO 8648, ISO 8648, ISO TR 9577 Open System<br />

Interconnection"<br />

ISO 9542 End System to Intermediate System Protocol<br />

Encapsulation of IPsec Packets<br />

http://www.iana.org/assignments/bootp-dhcp-parameters<br />

BootP and DHCP parameters<br />

General Routing and Firewall<br />

RFC 3022 Traditional N<strong>AT</strong><br />

draft-ietf-ipsec-nat-t-ike-08.txt Negotiation of N<strong>AT</strong>-Traversal<br />

in the IKE<br />

draft-ietf-ipsec-udp-encaps-08.txt UDP Encapsulation of<br />

IPsec Packets<br />

IP Multicasting<br />

RFC 1075 DVMRP<br />

RFC 1112 Host Extensions<br />

RFC 1812 <strong>Router</strong> Requirements<br />

RFC 2236 IGMPv2<br />

RFC 2362 PIM-SM<br />

RFC 2715 Interoperability Rules for Multicast Routing Protocols<br />

draft-ietf-idmr-dvmrp-v3-9 DVMRP<br />

draft-ietf-pim-dm-new-v2-04 PIM-DM<br />

draft-ietf-pim-sm-v2-new-09 PIM-SM<br />

IPsec<br />

RFC 1829 IPsec algorithm<br />

RFC 3173 IPComp - IPsec compression<br />

RFC 2395 IPsec Compression - LZS<br />

RFC 1828 IP Authentication using Keyed MD5<br />

RFC 2401 Security Architecture for IP<br />

RFC 2402 AH - IP Authentication Header<br />

RFC 2403 IPsec Authentication - MD5<br />

RFC 2404 IPsec Authentication - SHA-1<br />

RFC 2405 IPsec Encryption - DES<br />

RFC 2406 ESP - IPsec encryption<br />

RFC 2407 IPsec DOI<br />

RFC 2408 ISAKMP<br />

RFC 2409 IKE<br />

RFC 2410 IPsec encryption - NULL<br />

RFC 2411 IP Security Document Roadmap<br />

RFC 2412 OAKLEY<br />

RFC 3173 IPComp - IPsec compression<br />

IPv6<br />

RFC 1981 Path MTU Discovery for IPv6<br />

RFC 2080 RIPng for IPv6<br />

RFC 2365 Administratively Scoped IP Multicast<br />

RFC 2375 IPv6 Multicast Address Assignments<br />

RFC 2460 IPv6<br />

RFC 2461 Neighbour Discovery for IPv6<br />

RFC 2462 IPv6 Stateless Address Autoconfiguration<br />

RFC 2463 ICMPv6<br />

RFC 2464 Transmission of IPv6 Packets over Ethernet<br />

Networks<br />

RFC 2465 Allocation Guidelines for Ipv6 Multicast<br />

RFC 2466 Management Information Base for IP Version 6:<br />

ICMPv6 Group<br />

RFC 2472 IPv6 over PPP<br />

RFC 2526 Reserved IPv6 Subnet Anycast Addresses<br />

RFC 2529 Transmission of IPv6 over IPv4 Domains without<br />

Explicit Tunnels<br />

RFC 2710 Multicast Listener Discovery (MLD) for IPv6<br />

RFC 2711 IPv6 <strong>Router</strong> Alert Option<br />

RFC 2851 Textual Conventions for Internet Network Addresses<br />

RFC 2893 Transition Mechanisms for IPv6 Hosts and<br />

<strong>Router</strong>s<br />

RFC 3056 Connection of IPv6 Domains via IPv4 Clouds<br />

RFC 3307 Allocation Guidelines for IPv6 Multicast Addresses<br />

RFC 3315 DHCPv6<br />

RFC 3484 Default Address Selection for IPv6<br />

RFC 3513 IPv6 Addressing Architecture<br />

RFC 3587 IPv6 Global Unicast Address Format<br />

RFC 3596 DNS Extensions to support IPv6<br />

RFC 3810 Multicast Listener Discovery Version 2 (MLDv2)<br />

for IPv6<br />

Addresses Management Information Base for IP Version 6:<br />

Textual Conventions and General Group<br />

Management<br />

RFC 1155 MIB<br />

RFC 1157 SNMP<br />

RFC 1212 Concise MIB definitions<br />

RFC 1213 MIB-II<br />

RFC 1493 Bridge MIB<br />

RFC 1643 Ethernet MIB<br />

RFC 1657 Definitions of Managed Objects for BGP-4 using SMIv2<br />

RFC 2011 SNMPv2 MIB for IP using SMIv2<br />

RFC 2012 SNMPv2 MIB for TCP using SMIv2<br />

RFC 2096 IP Forwarding Table MIB<br />

RFC 2576 Coexistence between V1, V2, and V3 of the<br />

Internet-standard Network Management Framework<br />

RFC 2578 Structure of Management Information Version 2 (SMIv2)<br />

RFC 2579 Textual Conventions for SMIv2<br />

RFC 2580 Conformance Statements for SMIv2<br />

RFC 2665 Definitions of Managed Objects for the Ethernetlike<br />

Interface Types<br />

RFC 2674 Definitions of Managed Objects for Bridges with Traffic<br />

Classes, Multicast Filtering and Virtual LAN Extensions (VLAN)<br />

RFC 2790 Host MIB<br />

RFC 2819 RMON (groups 1,2,3 and 9)<br />

RFC 2856 Textual Conventions for Additional High Capacity<br />

Data Types<br />

RFC 2863 The Interfaces Group MIB<br />

RFC 3164 Syslog Protocol<br />

RFC 3289 Management Information Base for the<br />

Differentiated Services Architecture<br />

CDP<br />

RFC 3410 Introduction and Applicability Statements for<br />

Internet-Standard Management Framework<br />

RFC 3411 An Architecture for Describing SNMP Management<br />

Frameworks<br />

RFC 3412 Message Processing and Dispatching for the SNMP<br />

RFC 3413 SNMP Applications<br />

RFC 3414 User-based Security Model (USM) for SNMPv3<br />

RFC 3415 View-based Access Control Model (VACM) for the SNMP<br />

RFC 3416 Version 2 of the Protocol Operations for SNMP<br />

RFC 3417 Transport Mappings for the SNMP<br />

RFC 3418 MIB for SNMP<br />

RFC 3636 Definitions of Managed Objects for IEEE 802.3 MAUs<br />

RFC 3768 VRRP<br />

draft-ietf-bridge-8021x-00.txt Port Access Control MIB<br />

IEEE 802.1AB LLDP<br />

OSPF<br />

RFC 1245 OSPF protocol analysis<br />

RFC 1246 Experience with the OSPF protocol<br />

RFC 2328 OSPFv2<br />

RFC 1586 OSPF over Frame Relay<br />

RFC 1793 Extending OSPF to Support Demand Circuits<br />

RFC 1587 The OSPF NSSA Option<br />

RFC 3101 The OSPF Not-So-Stubby Area (NSSA) Option<br />

QoS<br />

RFC 2205 Reservation Protocol<br />

RFC 2211 Controlled-Load<br />

RFC 2474 DCSP in the IPv4 and IPv6 Headers<br />

RFC 2475 An Architecture for Differentiated Services<br />

RFC 2597 Assured Forwarding PHB Group<br />

RFC 2697 A Single Rate Three Color Marker<br />

RFC 2698 A Two Rate Three Color Marker<br />

RFC 3246 An Expedited Forwarding PHB (Per-Hop Behavior)<br />

IEEE 802.1p Priority Tagging<br />

RIP<br />

RFC 1058 RIPv1<br />

RFC 2453 RIPv2<br />

RFC 2082 RIP-2 MD5 Authentication<br />

Security<br />

RFC 959 FTP<br />

RFC 1413 IDP<br />

RFC 1492 TACACS<br />

RFC 1779 X.500 String Representation of Distinguished Names.<br />

RFC 1858 Fragmentation<br />

RFC 2284 EAP<br />

RFC 2510 PKI X.509 Certificate Management Protocols<br />

RFC 2511 X.509 Certificate Request Message Format<br />

RFC 2559 PKI X.509 LDAPv2<br />

RFC 2585 PKI X.509 Operational Protocols<br />

RFC 2587 PKI X.509 LDAPv2 Schema<br />

RFC 2865 RADIUS<br />

RFC 2866 RADIUS Accounting<br />

RFC 3280 X.509 Certificate and CRL profile<br />

draft-grant-tacacs-02.txt TACACS+<br />

Allied Telesis<br />

www.alliedtelesis.com


<strong>AT</strong>-<strong>AR770S</strong> | <strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

Draft-IETF-PKIX-CMP-Transport-Protocols-01 Transport<br />

Protocols for CMP<br />

draft-ylonen-ssh-protocol-00.txt SSH Remote Login Protocol<br />

IEEE 802.1x Port Based Network Access Control<br />

PKCS #10 Certificate Request Syntax Standard<br />

Diffie-Hellman<br />

Services<br />

RFC 854 Telnet Protocol Specification<br />

RFC 855 Telnet Option Specifications<br />

RFC 856 Telnet Binary Transmission<br />

RFC 857 Telnet Echo Option<br />

RFC 858 Telnet Suppress Go Ahead Option<br />

RFC 932 Subnetwork addressing scheme<br />

RFC 951 BootP<br />

RFC 1091 Telnet terminal-type option<br />

RFC 1305 NTPv3<br />

RFC 1350 TFTP<br />

RFC 1510 Network Authentication<br />

RFC 1542 Clarifications and Extensions for the Bootstrap<br />

Protocol<br />

RFC 1985 SMTP Service Extension<br />

RFC 1945 HTTP/1.0<br />

RFC 2049 MIME<br />

RFC 2068 HTTP/1.1<br />

RFC 2156 MIXER<br />

RFC 2217 Telnet Com Port Control Option<br />

RFC 2821 SMTP<br />

SSL<br />

RFC 2246 The TLS Protocol Version 1.0<br />

Draft-freier-ssl-version3-02.txt SSLv3<br />

STP / RSTP<br />

IEEE 802.1t - 2001 802.1D maintenance<br />

IEEE 802.1w - 2001 RSTP<br />

X.25<br />

RFC 1356 Multiprotocol Interconnect on X.25 and ISDN in<br />

the Packet Mode<br />

ITU-T Recommendations X.25 (1988), X.121 (1988). X.25<br />

ISDN<br />

ANSI T1.231-1997 Digital Hierarchy - Layer 1 In-Service<br />

Digital Transmission Performance Monitoring<br />

Standardization<br />

ANSI T1.403-1995 Telecommunications - Network-to-<br />

Customer Installation - DS1 Metallic Interface<br />

ANSI T1.408-1990 ISDN Primary Rate - Customer<br />

Installation Metallic Interfaces, Layer 1 Specification<br />

<strong>AT</strong>&T TR 54016-1989 Requirements for Interfacing Digital<br />

Terminal Equipment to Services Employing the Extended<br />

Superframe Format<br />

Austel TS 013.1:1990 General Requirements for Customer<br />

Equipment Connected to ISDN Basic Rate Access - Vol. I:<br />

Customer Equipment Access Interface Specifications<br />

Bellcore SR-3887 1997 National ISDN Primary Rate Interface<br />

ETS 300 012:1992 Integrated Services Digital Network<br />

(ISDN); Basic user-network interface; Layer 1 specification<br />

and test principles<br />

ETS 300 102-1:1990 Integrated Services Digital Network (ISDN)<br />

;User-network interface layer 3;Specifications for basic call<br />

control<br />

ETS 300 102-2:1990 Integrated Services Digital Network<br />

(ISDN); User-network interface layer 3; Specifications for basic<br />

call control; Specification Description Language (SDL) diagrams<br />

ETS 300 125:1991 Integrated Services Digital Network<br />

(ISDN); User-network interface data link layer specification;<br />

Application of CCITT Recommendations Q.920/I.440 and<br />

Q.921/I.441<br />

ETS 300 153:1992 Integrated Services Digital Network<br />

(ISDN);Attachment requirements for terminal equipment to<br />

connect to an ISDN using ISDN basic access (Candidate NET 3<br />

Part 1)<br />

ETS 300 156:1992 Integrated Services Digital Network<br />

(ISDN); Attachment requirements for terminal equipment<br />

to connect to an ISDN using ISDN primary rate access<br />

(Candidate NET 5)<br />

ETS 300 011:1992 Integrated Services Digital Network<br />

(ISDN); Primary rate user-network interface; Layer 1<br />

specification and test principles<br />

G.706 (1988) Frame Alignment and CRC Procedures<br />

Relating to Basic Frame Structures Defined in G.704<br />

G.794 (1988) Characteristics of 24-channel<br />

transmultiplexing equipments<br />

German Monopol (BAPT 221) Type Approval Specification<br />

for Radio Equipment for Tagging and Identification<br />

I.120 (1988) Integrated services digital networks (ISDNs)<br />

I.121 (1988) Broadband aspects of ISDN<br />

I.411 (1988) ISDN user-network interface reference<br />

configurations<br />

I.430 (1988) Basic user-network interface - Layer 1 specification<br />

I.431 (1988) Primary rate user-network interface -<br />

Physical layer specification<br />

ITU-T G.703 Physical/electrical characteristics of<br />

hierarchical digital interfaces<br />

ITU-T G.704 Synchronous frame structures used at 1544,<br />

6312, 2048, 8488 and 44736 kbit/s hierarchical levels<br />

ITU-T G.706 Frame Alignment and CRC Procedures<br />

Relating to Basic Frame Structures Defined in G.704<br />

ITU-T Q.922 ISDN data link layer specification for frame<br />

mode bearer services<br />

ITU-T G.703 (1972) Physical/electrical characteristics of<br />

hierarchical digital interfaces<br />

Japan NTT I.430-a Leased Line Basic Rate User-Network<br />

Interface Layer 1-Specification<br />

New Zealand Telecom TNA 134 Telecom ISDN User-Network<br />

Interface: Layer 3: PART B Basic Call Control Procedures<br />

Q.920 (1988) Digital subscriber Signalling System No.1 (DSS1)<br />

- ISDN user-network interface data link layer - General<br />

aspects<br />

Q.921 (1988) ISDN user-network interface - Data link<br />

layer specification<br />

Q.930 (1988) Digital subscriber Signalling System No. 1<br />

(DSS 1) - ISDN user-network interface layer 3 - General<br />

aspects<br />

Q.931 (1988) Digital subscriber Signalling System No. 1<br />

(DSS 1) - ISDN user-network interface layer 3<br />

specification for basic call control<br />

Rockwell Bt8370 Fully Intergrated T1/E1 Framer and Line<br />

Interface data sheet<br />

Technical Reference of Frame Relay Interface, Ver. 1,<br />

November 1993, Nippon Telegraph and Telephone<br />

Corporation. Ver. 1, November 1993, Nippon Telegraph and<br />

Telephone Corporation.<br />

ACA TS 013.2:1990 General Requirements for Customer<br />

Equipment Connected to ISDN Basic Rate Access, Vol 2:<br />

Conformance Testing Specifications<br />

ACA TS 014.1:1990 General Requirements for Customer<br />

Equipment Connected to ISDN Primary Rate Access, Vol 1:<br />

Customer Access Interface Specifications<br />

ACA TS 014.2:1990 General Requirements for Customer<br />

Equipment Connected to ISDN Primary Rate Access, Vol 2:<br />

Conformance Testing Specifications<br />

Frame Relay<br />

ANSI T1S1 Frame relay<br />

RFC 1490, 2427 Multiprotocol Interconnect over Frame Relay<br />

Allied Telesis<br />

www.alliedtelesis.com


<strong>AT</strong>-<strong>AR770S</strong> | <strong>Secure</strong> <strong>VPN</strong> <strong>Router</strong><br />

Ordering Information<br />

<strong>AT</strong>-<strong>AR770S</strong><br />

Order number: 990-000818-00<br />

Includes power cords for US, UK, Australia & Europe<br />

Port Interface Card (PIC) Options<br />

<strong>AT</strong>-AR020<br />

Single software configurable E1/T1 interface that supports<br />

channelised/unchannelised Primary Rate ISDN/Frame Relay<br />

Order Number: 990-001304-00<br />

<strong>AT</strong>-AR021S (V2)<br />

(<strong>AT</strong>-AR021S V1 card is not supported on the <strong>AT</strong>-<strong>AR770S</strong>)<br />

Single basic rate ISDN S/T interface<br />

Order Number: 990-001103-00<br />

<strong>AT</strong>-AR023<br />

Single synchronous port up to 2Mbps to an external<br />

CSU/DSU (<strong>AT</strong>-V.35-DTE-00 or <strong>AT</strong>-X.21-DTE-00 cable required)<br />

Order number: 990-001104-00<br />

<strong>AT</strong>-AR024<br />

Four Asynchronous RS-232 interfaces to 115Kbps<br />

Order number: 990-001105-00<br />

SFP Options 2<br />

<strong>AT</strong>-SPFX/2<br />

100BASE-FX 1310nm fiber up to 2km<br />

Order number: 990-001198-00<br />

<strong>AT</strong>-SPFX/15<br />

100BASE-FX 1310nm fiber up to 15km<br />

Order number: 990-001199-00<br />

<strong>AT</strong>-SPFX/40<br />

100BASE-FX 1310nm fiber up to 40km<br />

Order number: 990-001200-00<br />

<strong>AT</strong>-SPTX<br />

10/100/1000 BASE-T 100m Copper<br />

Order number: 990-000262-00<br />

<strong>AT</strong>-SPSX<br />

1000BASE-SX<br />

GbE multi-mode 850nm fiber<br />

Order number: 990-00028-00<br />

<strong>AT</strong>-SPLX10<br />

1000BASE-LX<br />

GbE single-mode 1310nm fiber up to 10km<br />

Order number: 990-00029-00<br />

<strong>AT</strong>-SPLX40<br />

1000BASE-LX<br />

GbE single-mode 1310nm fiber up to 40km<br />

Order number: 990-00161-00<br />

<strong>AT</strong>-SPLX40/1550<br />

1000BASE-LX<br />

GbE single-mode 1550nm fiber up to 40km<br />

Order number: 990-00160-00<br />

<strong>AT</strong>-SPZX80<br />

1000BASE-ZX<br />

GbE single-mode 1550nm fiber up to 80km<br />

Order number: 990-00031-00<br />

<strong>AT</strong>-SPZX80/wwww<br />

1000BASE-ZX<br />

GbE single-mode CWDM fiber up to 80km<br />

Order number: 990-000xx-00<br />

CWDM Wavelength Where wwww= Where xx=<br />

1610NM 1610 32<br />

1590NM 1590 33<br />

1570NM 1570 34<br />

1550NM 1550 35<br />

1530NM 1530 36<br />

1510NM 1510 37<br />

1490NM 1490 38<br />

1470NM 1470 39<br />

2<br />

Please check with your sales representative, for ROHS<br />

compliance on SFP modules.<br />

Feature License<br />

<strong>AT</strong>-AR700 – ADVL3UPGRD<br />

AR700 series advanced Layer 3 upgrade – includes:<br />

• IPv6<br />

• BGP-4<br />

• Server Load Balancing<br />

Order Number: 980-10022-00<br />

USA Headquarters | 19800 North Creek Parkway | Suite 200 | Bothell | WA 98011 | USA | T: +1 800 424 4284 | F: +1 425 481 3895<br />

European Headquarters | Via Motta 24 | 6830 Chiasso | Switzerland | T: +41 91 69769.00 | F: +41 91 69769.11<br />

Asia-Pacific Headquarters | 11 Tai Seng Link | Singapore | 534182 | T: +65 6383 3832 | F: +65 6383 3830<br />

www.alliedtelesis.com<br />

© 2007 Allied Telesis Inc. All rights reserved. Information in this document is subject to change without notice. All company names, logos, and product designs that are trademarks or registered trademarks are the property of their respective owners. 617-000087 Rev. E

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!