background image

 

Creating and retaining a recovery diskette

 

5

 

To add the activation keys, follow the steps below.

 

1

 

In the Management Console 

 

Tools

 

 menu, select 

 

License Manager

 

The License Summary window appears.

 

2

 

Click 

 

Add Keys

 

. The Add Activation Key window appears. Enter the 

activation key and click 

 

Add

 

 for each activation key that you want to add.

 

3

 

When you have finished adding activation keys, click 

 

Close

 

 to close the 

Add Activation Key window. 

 

4

 

Click 

 

Close

 

 to close the License Summary window. All EFW system 

functionality is now available.

For more information on license-activation keys, refer to the section “Licensing 
Overview” in the 

3Com Embedded Firewall Administration Guide.

Creating and retaining a recovery diskette

Communication is encrypted between EFW devices and the Policy Server, 
between the Management Console and the Policy Server, and between Policy 
Servers. Policy Servers identify themselves to each other, to the Management 
Console, and to their EFW devices (NICs) using two public/private key pairs 
generated upon creation of a new EFW domain. 

After installing your first policy server in an EFW domain, it is critical to make a 
copy of the files named 

public.key

 and 

server.keystore

 from your installation. 

Save this data indefinitely in a safe, secure location.

In the unlikely event of a disaster, such as a disk crash on all of your policy 
server machines and a simultaneous loss of all disk backups for these 
machines, this recovery diskette allows you to “clone” your policy server and 
regain management control of your NICs. A clean installation of the policy 
server cannot communicate with your EFW NICs (which is the intended design, 
for security reasons).

If you do not create a recovery diskette and you lose all policy server 
installation data, you will not be able to recover your NICs. 

They 

continue to enforce the fallback mode specified in their last EFW policy, 
indefinitely. These NICs must be replaced in order to obtain a different policy.

To create a recovery diskette, follow the steps below.

1

Insert a formatted 3.5” diskette into the a: drive of the computer hosting 
the Policy Server.

2

Save the 

public.key

 and 

server.keystore

 files to diskette. (These files are 

located in 

Program Files -> 3Com Corporation

 -> 

3Com EFW.) 

Summary of Contents for 3CR990

Page 1: ...3Com Embedded Firewall Software for the 3CR990 Network Interface Card NIC Family Quick Start Guide http www 3com com http www 3com com registration frontpg pl 09 2110 000 Published December 2001...

Page 2: ...ges in the product s and or the program s described in this documentation at any time If there is any software on removable media described in this documentation it is furnished under a license agreem...

Page 3: ...ecovery diskette 5 Importing the No sniffing no spoofing pre defined Policy and Assigning it to the Default Device Set 6 Installing and Registering an EFW NIC 7 Verifying NIC Registration 8 Changing t...

Page 4: ......

Page 5: ...information for expanding your EFW system to best suit your security needs What You Will Need Before you install the EFW software you will need A computer to host the Policy Server and Management Cons...

Page 6: ...w provide instructions for installing a Policy Server and Management Console on a single system using the Typical installation method 1 Insert the 3Com product CD in the appropriate drive the Installa...

Page 7: ...s offered on this screen 2 Select Confirm Create New Domain 3 Enter a domain name in the Domain Name field The domain name is used only as a reference to assist you in identifying a particular domain...

Page 8: ...w system are as follows Login admin Password admin 3 Select the Policy Server that you just created from the Policy Server list 4 Click Connect The Embedded Firewall Management Console window appears...

Page 9: ...upon creation of a new EFW domain After installing your first policy server in an EFW domain it is critical to make a copy of the files named public key and server keystore from your installation Sav...

Page 10: ...fing pre defined policy follow the steps below 1 From the Main menu select Import Policy Rule set The Import Policy Rule Set window appears 2 Select Policy and click Next 3 Click Browse and navigate t...

Page 11: ...ry on the computer that will receive the EFW NIC installation on a computer on which a 3Com 3CR990 NIC is installed NOTE You may assign any policy to the default device set The No sniffing no spoofing...

Page 12: ...w frame The NIC should be listed in the default device set 4 If desired remove the temporary directory created for the NIC installation package For information on other installation methods refer to t...

Page 13: ...indows 2000 Standard rule set you can create a sample policy by following the steps in the section below Creating a Policy In this section you will create a sample policy called the No IP Initiation p...

Page 14: ...include information about what the policy does or when to use it for example the bulleted information provided at the beginning of this section 6 The access control list ACL initially contains only t...

Page 15: ...evious section A device set is a collection of EFW devices that are associated with a specific policy You can define any number of device sets and assign EFW devices to any one of those device sets To...

Page 16: ...ion policy To ensure that the policy is functioning as expected the following steps attempt to connect to the Internet by initiating the TCP protocol HTTP which should be denied by the policy being en...

Page 17: ...de Expanding Your EFW Configuration Now that you have a basic EFW system configured and running you can expand your configuration as needed to best suit your organization s security needs The followin...

Page 18: ......

Reviews: