
split onto these two iKeys. When adding an additional ASA 310-FIPS to the cluster, the CODE-
SO and the CODE-USER iKeys are used to transfer the wrap key to the HSM cards on AVG
device(s) that have been added. Once the wrap key has been transferred, all synchronization
of sensitive information within the cluster takes place transparently to the user.
No passwords are associated with the CODE-SO and CODE-USER iKeys. However, for all
operations that involves using the CODE-SO and CODE-USER iKeys, these keys are used in
addition
to the HSM-SO and HSM-USER iKeys (which in turn require the correct passwords
for successful authentication).
Caution:
If you enter the wrong password for the HSM-USER fifteen (15) times in a row, the HSM-
USER iKey will be rendered unusable. This is due to the strict security specifications placed
on the ASA 310-FIPS.
Available Operations and iKeys Required
For information about the type of iKeys required to perform a specific operation, see
Table 1:
Available Operations and iKeys Required
on page 34.
Table 1: Available Operations and iKeys Required
Type of iKey Required
Operation Performed
HSM-SO
HSM-USER
CODE-SO and CODE-
USER
Installing a new ASA 310-FIPS in
a new cluster
■
■
■
Adding an ASA 310-FIPS to an
existing cluster
■
■
■
Logging in to the HSM card
■
Splitting the wrap key onto a pair
of CODE iKeys
■
■
■
Changing the HSM-SO iKey
password
Note:
To resume normal operations
after having changed the HSM-
SO iKey password, the HSM-
USER iKey is required to re-
login to the HSM card.
■
■
Changing the HSM-USER iKey
password
■
Introducing the ASA 310-FIPS
34 User Guide
April 2013
Comments? [email protected]
Summary of Contents for 3050-VM
Page 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Page 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Page 12: ...12 User Guide April 2013 ...
Page 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Page 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Page 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Page 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Page 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Page 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Page 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Page 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Page 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Page 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Page 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Page 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...