
SpeedStream 5935 back panel view
SpeedStream 5930 back panel view
Siemens Subscriber Networks, Inc.
4849 Alpha Road
Dallas, TX 75244
+1(972) 852-1000
Fax +1(972) 852-1001
www.icn.siemens.com/subscriber
Copyright© 2004 SIEMENS SUBSCRIBER NETWORKS, INC. All rights reserved. Siemens and the Siemens logo are trademarks of Siemens AG, Germany. All
other trademarks are held by their respective companies. Siemens reserves the right to make changes to product speci cations at any time without notice.
Global network of innovation
Software Features
Security
Secure Management
• User authentication (PAP/CHAP) with PPP (RFC 1334,
RFC 1994)
• Password control for con guration manager
• SNMP community name reassignment
• Telnet/SNMP port reassignment/Access Control List
• Role-based management
– Four pre-con gured templates
– Up to 15 user names stored in the local database
• RADIUS management authentication support
• SSH and IPSec secure management channels
Basic Business Firewall
• Filter on source and/or destination IP address/port value
• Filter on SYN, ACK ags and ICMP
• Apply input, output, transmit, and receive lters on
each interface
• Stateful inspection when NAT is enabled
• Logging and scripting
ICSA-Compliant Stateful Inspection Firewall
• Provides enterprise-grade rewall protection from
– Common Denial of Service (DoS) attacks and
exploits including Killwin, Land, Ping of Death,
Smurf, Teardrop, Tiny Fragments, and WinNuke
– Distributed Denial of Service (DDoS) attacks
including ICMP, SYN and UDP oods
– Other hacking attacks including IP address
sweeping, IP spoo ng, port scanning
• Opens ports to serve legitimate requests and
automatically closes them when the request or
session ends
• Full-time Stateful Packet Inspection with built-in
support for most popular applications
• No pre-de ned limit on the number of rules that can be
created and applied
• All rewall messages can be logged to the router
console and to syslog servers
• Maintains a log of the most recently dropped packets in
the browser-based user interface
Secure Virtual Private Networking
• L2TP, IPSec, and L2TP inside of IPSec
• No pre-de ned limit on VPN tunnels
• IPSec Tunnel and Transport modes with AH and ESP
• Internet Key Exchange (IKE) including Aggressive Mode
• DES (56-bit) and 3DES (168-bit) encryption
• Supports Perfect Forward Secrecy (DH Groups 1 and 2)
• Provides protection from replay attacks
• Implements RFCs 1321, 1828, 1829, 2085, 2104,
2401-2410, 2412, 2420, 2437, 2451, and 2631
(Groups 1 and 2)
Con guration, Management
and Monitoring
• Easy setup through a browser-based user interface
• Con guration and management using HTTP, serial
console, SNMP, SSH, or Telnet
• Out-of-band con guration and management using
serial console port
• Supports dedicated routed management PVC in bridged
and routed mode
• TFTP download/upload of new software, con guration
les, and scripts
• Stores backup copy of rmware on dual bank ash
memory for system recovery
• Performance monitoring data available using SNMP
• Dynamic event and history logging
• Network boot using a BootP server (RFC 2131,
RFC 2132)
• Syslog server support
IP Quality of Service (IP QoS)
• DiffServ traf c prioritization through ToS byte marking
• Weighted Fair Queuing traf c prioritization
• Con gurable queue weighting
• Con gurable traf c prioritization policies by
– Date, day of week, and time
– Source and destination addresses
– Port, protocol, and application
High Availability
• Dial backup support – Integrated v.90 modem
• Virtual Router Redundancy Protocol (VRRP) (RFC 2338)
for failover support to other VRRP-capable routers
Protocols
ATM
• Encapsulation (IP, Bridging, and Bridge Encapsulated
Routing) (RFC 2684/1483)
• PPP over ATM (LLC and VC multiplexing) (RFC 2364)
• Classical IP over ATM (RFC 2225)
• Classical IP (RFC 1577)
• AAL5
• Virtual Circuit (VC) traf c shaping (CBR, PCR, UBR, VBR)
• No pre-de ned limit on VCs
• I.610 OAM F5 end-to-end and segment LoopBack
• Initiates and responds to LoopBack signaling
Frame Relay
• Support of frame relay ANSI T1.618 and CCITT Q.922
formats
• DLCI support
• Inverse ARP support
• LMI support including LMI protocol discovery
• LLCP auto-update
• CIR & EIR rate enforcement
• Network congestion management
PPP (RFC 1661, RFC 2364)
• PPP over Ethernet (RFC 2516)
• PPP over ATM (RFC 2364)
• Bridging (RFC 1638)
• IP Routing (RFC 1331)
• IPX Routing (RFC 1552)
• Multiclass extensions to MLPPP (RFC 2686)
• MLPPP (RFC 1990)
• Data compression of up to 4:1 (STAC™ LZS) (RFC 1974)
• Van Jacobson header compression (RFC 1144)
• Spoo ng and ltering (IP-RIP, IPX-RIP, SAP, Watchdog
serialization)
• Automatic IP and DNS assignment (RFC 1877)
Routing
• TCP/IP with RIP1 (RFC 1058), RIP1-compatible and RIP2
(RFC 1389), or static routing on the LAN and/or WAN
• Novell® IPX with RIP/SAP (RFC 1552)
• DHCP server (RFC 2131, RFC 2132), relay agent (RFC
1542), and client (RFC 2132)
– Automatically defers to other DHCP servers on
the network
– Automatically adjusts to changes in LAN IP
addressing
– No pre-de ned limit on DHCP clients
• DNS relay
• Multiple subnets on the LAN support NAT, RIP1, RIP2,
ARP and IP lters
• Virtual routes can be de ned based on user IP addresses
or ranges
IP Address Translation
• Network renumbering (RFC 1631)
• Network Address Translation (NAT/PAT/NAPT)
• NAT passthrough support for numerous applications
including IPSec, PPTP, H.323, SIP and NetMeeting
• Supports public Web and e-mail servers with NAT
Hardware Features
WAN Interface
• 5930: Compliant with ADSL ITU G.992.1 Annex A and
ANSI T1.413 G.DMT, ADSL ITU G.992.2 Annex A G.Lite
• 5935: Compliant with ADSL ITU G.992.1 Annex B
G.DMT, ADSL ETSI TS101388, and Deutsche Telekom
U-R2
• Supports line rates
– From 64Kbps to 8,128Kbps downstream
– From 64Kbps to 1,024Kbps upstream
• Embedded Operations Channel (EOC) support
LAN Interface
• Built-in 8-port 10/100Base-T Ethernet switch with link
status LED for each port
• Auto detects full or half duplex operation
• Auto detects regular or crossover cable for easy
connection to a switch or hub
• Ports can be con gured individually and manually for:
– Enabling/disabling
– Speed and duplex
– Port mirroring
Serial Interface
• One asynchronous serial console port
VPN Accelerator
• Dedicated encryption processor maximizes IPSec 3DES
VPN throughput
Product Enclosure
• Front panel LED status for Power, Test, WAN, LAN,
and backup
• Rear panel LED status for each Ethernet port link
• Installation options: Desktop or wall mount
Kommentare zu diesen Handbüchern