background image

2

Alcatel-Lucent OmniAccess 780 Unified Services Gateway

The OmniAccess 780 USG offers
superior high availability for a
regional or branch site, along with
comprehensive remote management
by leveraging a highly modular system
design and innovative management
architecture. The OmniAccess 780
USG also integrates critical security
features such as firewall, denial of
service (DoS) protection, application
level gateways, intrusion detection
and prevention, and IPSec virtual
private network (VPN), onto one
unified platform.

With a separate management plane,
dedicated management processors,
and multiple access mechanisms to
reach the system, Alcatel-Lucent's
Lifeline management framework
allows highly resilient remote system
administration, independent of the
state of the system. All services
provided by the OmniAccess 780 can be
managed remotely, thereby eliminating
the need for on-site intervention.

The Alcatel-Lucent ModuLive software
platform provides a fully modular,
always live software base that

maximizes system availability by
enabling in-service upgrades and
configuration changes, and by ensuring
that a fault in one service module
has minimal or no impact on other
services. It also allows for online
insertion and removal of line cards,
obviating the need for network
outages during hardware upgrades.
As multiple services are added, scalability
and performance are maintained
through Alcatel-Lucent's unique
OnePass approach, which performs
common packet classification across
multiple services.

T E C H N I C A L

S P E C I F I C A T I O N S

Hardware

• Module slots: 6 interface slots

• Interface cards

¬ 8-port 10/100/1000 Mbps Ethernet

¬ 4-port T1/E1

¬ 4-port serial (V.35/X.21)

• Services engine (SE): 2-port 10/100/1000

Mbps Ethernet (built-in)

• Hot swappable line cards

• RAM (default/max): 512 MB/1 GB

• FLASH memory: 512 MB

Routing

• Static routes

• RIP v1/v2 dynamic routing

• OSPF/BGP dynamic routing

• Multicast routing – PIM

• IGMP (v1, v2)

• GRE tunnels

• VRRP

• Policy-based routing

• Packet forward rate (64 byte pkts): 930 kpps *

• Forwarding performance: 2Gbps *

• Max. number of BGP peers: 200 **

• Max. number of VLANs: 4096 **

Firewall

• Stateful packet inspection and filtering (ACL)

• NAT (Source and Destination NAT)

• DoS and DDoS protection

• Protocol anomaly: IP, TCP, UDP

• ALGs: TFTP, FTP, NFS, DNS, RTSP, SIP, DHCP,

UA/NOE

• Common classification for all services

• Firewall performance: 2 Gbps *

• Concurrent sessions: 128,000 *

Quality of service

• L3/4 traffic policy definition

• Interface egress queues: 16 queues per interface

• Priority scheduling

• Weighted fair queuing

• Class-based queuing

• Hierarchical queuing: Up to 4 levels

• Ingress policing

• Egress shaping

• DSCP/TOS marking

• WRED

• DiffServ: RFC 3246, 2597, 2445

VPN (IPSec)

• Site-to-site VPN tunnels: Up to 1500 **

• Tunnel interfaces

• DES (56 bit), 3DES (168 bit), and AES (128,

192, 256 bit) encryptions

• MD-5 and SHA-1 authentication

• IKE with pre-shared key or PKI

• Perfect forward secrecy (DH groups): 1, 2, 5

• IPSec NAT traversal

• AES performance: 180 Mbps *

• Max. concurrent VPN tunnels: 1500 **

Intrusion detection/intrusion
prevention

• Detection mode

• Prevention mode

• Automatic signature updates

• Group-based IDS/IPS: Priority/protocol/

intrusion type

WAN protocols

• PPP

• MLPPP

• Frame relay

• MLFR

• HDLC

• PAP/CHAP Authentication

LAN protocols

• STP

• Bridging

• IEEE 802.1Q VLANs

• Per-VLAN STP (PVST+)

• IRB (Integrated Routing and Bridging)

Network services

• DHCP relay/server

• DNS client

• TFTP server/client

• FTP client

• ssh server/client

• HTTP server

• Transparent Firewall

VoIP Support

• SIP / NOE ALGs

• Priority scheduling

• Dynamic Pinholing in Firewall

• DSCP classification and marking

• TFTP Server for booting IP phones

• DHCP options for phones provisioning

* Performance numbers based on 2 GHz reference engine, capacity limits based on 512 MB RAM
** No preset limit in software. Numbers listed are verified. They could scale higher depending on services enabled.

Summary of Contents for OmniAccess 780

Page 1: ...y of the WAN access network infrastructure and allows new services to be implemented quickly and easily Integrates multiple services onto one platform Embedded encryption accelerator and an integrated digital signal processor for voice call processing Choice of optional interfaces Remote management Modular software design ModuLive OnePass packet processing LifeLIne management framework Eliminates ...

Page 2: ... 1 GB FLASH memory 512 MB Routing Static routes RIP v1 v2 dynamic routing OSPF BGP dynamic routing Multicast routing PIM IGMP v1 v2 GRE tunnels VRRP Policy based routing Packet forward rate 64 byte pkts 930 kpps Forwarding performance 2Gbps Max number of BGP peers 200 Max number of VLANs 4096 Firewall Stateful packet inspection and filtering ACL NAT Source and Destination NAT DoS and DDoS protecti...

Page 3: ... SCSI connectors with each connector supporting 2 serial synchronous ports Each port supports data rates from 64k up to 2M Field installable OA7 YSS V35MT 3 OmniAccess 780 740 Y Cable 10 foot 3 meter shielded male male supporting two serial V 35 DTE connections OA7 YSS V35FC 3 OmniAccess 780 740 Y Cable 10 foot 3 meter shielded female female supporting two serial V 35 DCE connections OA7 YSS X21MT...

Page 4: ... P N 031949 00 Rev D 5 08 To learn more contact your dedicated Alcatel Lucent representative authorized reseller or sales agent You can also visit our Web site at www alcatel lucent com This document is provided for planning purposes only and does not create modify or supplement any warranties which may be made by Alcatel Lucent relating to the products and or services described herein The publica...

Reviews: