Setting up Centralized Management

If the Secondary members of a centralized management group must go through a firewall to communicate with the Primary Screen, configure the firewall that is being traversed to allow the following traffic:

Use the following procedure to set up centralized mangement.

On the Primary Screen

  1. Install the SunScreen software.
  2. Display the Policy Edit page of the Administration GUI.
  3. Generate a certificate for the Primary Screen. Note: Generating a certificate provides the Certificate ID, also known as an MKID, that you will use to associate the Primary Screen's certificate on the Secondary Screen later.
    1. Choose Certificate from the Type menu.
    2. Choose Generate Screen Certificate from the Add New menu.
    3. Type a name for the certificate in the Name field.
    4. Choose Generate New Certificate. The Certificate ID is generated.
    5. Choose OK

On the Secondary Screens

  1. Install SunScreen software.
  2. Display the Policy Edit page of the Administration GUI.
  3. Generate a certificate for the Secondary Screen. Note: Generating a certificate provides the Certificate ID that you will use to associate the Secondary Screen's certificate on the Primary Screen later. From the Common Objects panel:
    1. Choose Certificate from the Type menu.
    2. Choose Generate Screen Certificate from the Add New menu.
    3. Type a name for the certificate in the Name field.
    4. Choose Generate New Certificate. The Certificate ID is generated.
    5. Choose OK
  4. Associate the Primary Screen's Certificate ID on the Secondary Screen. From the Common Objects panel:
    1. Choose Certificate from the Type menu.
    2. Choose Associate MKID from the Add New menu.
    3. Type a name for the Primary Screen's Certificate ID in the Name field.
    4. Type the Certificate ID of Primary Screen's certificate in the Certificate ID field. (Use the Certificate ID value that you got in step 3d.)
    5. Choose OK
  5. Create a new Screen object for the Primary Screen. From the Common Objects panel:
    1. Choose Screen from the Type menu.
    2. Choose New from the Add New menu.
    3. Choose the HA/Master Config tab.
    4. Type the name of the Primary Screen's certificate in the Administration Certificate field (This name is the same name that you used for step 7c.)
    5. Choose OK
  6. Edit the Screen object for the Secondary Screen. From the Common Objects panel:
    1. Choose Screen from the Type menu.
    2. Search the Screen Object for the Secondary Screen that you are configuring.
    3. Choose the Edit button. The Screen Dialog is displayed.
    4. Choose HA/Master Config.
    5. Select the Primary Screen's name from the Primary Name menu.
    6. Type the Secondary Screen's name in Administration Certificate.
    7. Type the Administrative Interface's IP address in Administrative IP Address.
    8. Select the encryption parameters if you are using parameters that are different from the default.
    9. Choose OK
  7. Save the configuration.
  8. Activate the configuration.

On the Primary Screen

  1. Display the Policy Edit page of the Administration GUI.
  2. Associate the Secondary Screen's Certificate ID. From the Common Objects panel:
    1. Choose Certificate from the Type menu.
    2. Choose Associate MKID from the Add New menu.
    3. Type a name for the Secondary Screen's certificate in the Name field.
    4. Type the Certificate ID value of the Secondary Screen's certificate in Certificate ID. (Use the Certificate ID value that you got in step 6d.)
    5. Choose OK
  3. Create a new Screen object for the Secondary Screen. From the Common Objects panel:
    1. Choose Screen from the Type menu.
    2. Choose New from the Add New menu.
    3. Choose the HA/Master Config tab.
    4. Select the Primary Screen's name from the Primary Name menu.
    5. Type the name of the Secondary Screen's certificate in Administration Certificate. (This name is the same name that you used for step 13c)
    6. Type the Administrative Interface's IP address in Administrative IP Address.
    7. Select the encryption parameters if you are using parameters that are different from the default.
    8. Choose OK.
  4. Edit the Screen object for the Primary Screen. From the Common Objects panel:
    1. Choose Screen from the Type menu.
    2. Search the Screen Object for the Primary Screen.
    3. Choose Edit. The Screen Dialog is displayed.
    4. Choose HA/Master Config.
    5. Type the name of the Primary Screen's certificate in Administration Certificate . (This is the same name that you used for step 3c.)
    6. Choose OK
  5. Define the Address groups for the interfaces of the Secondary Screens. See Address for more information.
  6. Define the Interfaces for the Secondary Screens. From the Common Objects panel:
    1. Choose Interface from the Type menu.
    2. Choose New from the Add New menu.
    3. Use the Interface definition dialog to create an Interface object for each interface on each Screen. Note: Use the Screen combo box to select the name of the Screen with which each interface is associated.
    4. Choose OK
  7. Add a remote access rule to allow the Primary Screen to connect to the Secondary Screens in the centralized management group. From the Policy Rules panel:
    1. Choose the Administrative Access tab.
    2. Choose Add New from Access Rules for Remote Administration.
    3. Use the Remote Access Rules dialog to enter the following information.
      • Screen Leave blank.
      • Address Object Select (*).
      • User Type the name of an administrative user.
      • Encryption Select SKIP_VERSION_2.
      • Certificate Group Select the name of the Primary Screen's certificate or a certificate group that contains the Primary Screen's certificate.
      • Key Algorithm Select as appropriate.
      • Data Algorithm Select as appropriate.
      • MAC Algorithm Select as appropriate.
      • Tunnel Leave blank.
      • Access Level Select as appropriate.
  8. Modify the Policy Rules for the management group. Note: You can configure packet filter rules to make a specific rule apply to only one screen. The rules apply globally by default.