Setting up Centralized Management
If the Secondary members of a centralized
management group must go through a firewall to communicate with the
Primary Screen, configure the firewall that is being traversed to allow
the following traffic:
-
SKIP
-
Certificate discovery
Use the following procedure to set up centralized mangement.
On the Primary Screen
-
Install the SunScreen software.
-
Display the Policy Edit page of the Administration GUI.
-
Generate a certificate for the Primary Screen. Note: Generating a certificate
provides the Certificate ID, also known as an MKID, that you will use
to associate the Primary Screen's certificate on the Secondary Screen
later.
-
Choose Certificate from the Type menu.
-
Choose Generate Screen Certificate from the Add New menu.
-
Type a name for the certificate in the Name field.
-
Choose Generate New Certificate. The Certificate ID is generated.
-
Choose OK
On the Secondary Screens
-
Install SunScreen software.
-
Display the Policy Edit page of the Administration GUI.
-
Generate a certificate for the Secondary Screen. Note: Generating a certificate
provides the Certificate ID that you will use to associate the Secondary
Screen's certificate on the Primary Screen later. From the Common Objects panel:
-
Choose Certificate from the Type menu.
-
Choose Generate Screen Certificate from the Add New menu.
-
Type a name for the certificate in the Name field.
-
Choose Generate New Certificate. The Certificate ID is generated.
-
Choose OK
-
Associate the Primary Screen's Certificate ID on the Secondary Screen.
From the Common Objects panel:
-
Choose Certificate from the Type menu.
-
Choose Associate MKID from the Add New menu.
-
Type a name for the Primary Screen's Certificate ID in the Name field.
-
Type the Certificate ID of Primary Screen's certificate in the Certificate ID
field.
(Use the Certificate ID value that you got in step 3d.)
-
Choose OK
-
Create a new Screen object for the Primary Screen.
From the Common Objects panel:
-
Choose Screen from the Type menu.
-
Choose New from the Add New menu.
-
Choose the HA/Master Config tab.
-
Type the name of the Primary Screen's certificate in the
Administration Certificate field (This name is the same name
that you used for step 7c.)
-
Choose OK
-
Edit the Screen object for the Secondary Screen.
From the Common Objects panel:
-
Choose Screen from the Type menu.
-
Search the Screen Object for the Secondary Screen that you are configuring.
-
Choose the Edit button. The Screen Dialog is displayed.
-
Choose HA/Master Config.
-
Select the Primary Screen's name from the Primary Name menu.
-
Type the Secondary Screen's name in Administration Certificate.
-
Type the Administrative Interface's IP address in Administrative IP
Address.
-
Select the encryption parameters if you are using parameters that are different
from the default.
-
Choose OK
-
Save the configuration.
-
Activate the configuration.
On the Primary Screen
-
Display the Policy Edit page of the Administration GUI.
-
Associate the Secondary Screen's Certificate ID. From the Common Objects panel:
-
Choose Certificate from the Type menu.
-
Choose Associate MKID from the Add New menu.
-
Type a name for the Secondary Screen's certificate in the Name field.
-
Type the Certificate ID value of the Secondary Screen's certificate in
Certificate ID. (Use the Certificate ID value that you got in
step 6d.)
-
Choose OK
-
Create a new Screen object for the Secondary Screen.
From the Common Objects panel:
-
Choose Screen from the Type menu.
-
Choose New from the Add New menu.
-
Choose the HA/Master Config tab.
-
Select the Primary Screen's name from the Primary Name menu.
-
Type the name of the Secondary Screen's certificate in
Administration Certificate. (This name is the same name
that you used for step 13c)
-
Type the Administrative Interface's IP address in Administrative IP
Address.
-
Select the encryption parameters if you are using parameters that are different
from the default.
-
Choose OK.
-
Edit the Screen object for the Primary Screen. From the Common Objects panel:
-
Choose Screen from the Type menu.
-
Search the Screen Object for the Primary Screen.
-
Choose Edit. The Screen Dialog is displayed.
-
Choose HA/Master Config.
-
Type the name of the Primary Screen's certificate in Administration Certificate
. (This is the same name that you used for step 3c.)
-
Choose OK
- Define the Address groups for the interfaces of the Secondary Screens. See
Address for more
information.
-
Define the Interfaces for the Secondary Screens. From the Common Objects panel:
-
Choose Interface from the Type menu.
-
Choose New from the Add New menu.
-
Use the Interface definition dialog to create an Interface object for each
interface on each Screen. Note: Use the
Screen combo box to select the name of the Screen with which each
interface is associated.
-
Choose OK
-
Add a remote access rule to allow the Primary Screen to connect to the
Secondary Screens in the centralized management group. From the Policy
Rules panel:
-
Choose the Administrative Access tab.
-
Choose Add New from Access Rules for Remote Administration.
-
Use the Remote Access Rules dialog to enter the following information.
-
Screen Leave blank.
-
Address Object Select (*).
-
User Type the name of an administrative user.
-
Encryption Select SKIP_VERSION_2.
-
Certificate Group Select the name of the Primary Screen's
certificate or a certificate group that contains the Primary Screen's
certificate.
-
Key Algorithm Select as appropriate.
-
Data Algorithm Select as appropriate.
-
MAC Algorithm Select as appropriate.
-
Tunnel Leave blank.
-
Access Level Select as appropriate.
-
Modify the Policy Rules for the management group. Note: You can configure
packet filter rules to make a specific rule apply to only one screen.
The rules apply globally by default.