background image

20 

Blue Coat SG210 Installation Guide

4

(Optional) On page 3, you might restrict the use of the console account to a specific workstation. On 
this screen, you can add one IP address to the list of authorized workstations that are approved to use 
the console account. Additional workstations maybe configured later using the CLI or through the 
Management Console.

Figure 2-13:   Initial Setup—Page Three

Note:

For maximum security, restrict physical access to the SG210. 

Note:

After completing the initial configuration, you can change the workstation restriction 
settings through the security commands in the CLI or the Console Access page in the 
Management Console (under Authentication). You can add or remove IP addresses or 
you can enable or disable workstation restrictions. Refer to Volume 4: Securing the Blue 
Coat ProxySG Appliance
 of the 

Blue Coat ProxySG Configuration and Management Guide Suite

 

for details.

---------------------- (page 3 of 5) --------------------- 

    Press <ESC> at any time to return to the main menu                                                      

DIRECTIONS: 

The console username and password are special. They can be used to log in 
to the CLI or Web Management interface even in circumstances where this is 
denied by VPM or CPL policy. 

This makes the console account useful in emergencies,as a way to log in 
when policy is broken, but it may also create a security hole.                                           

To close the security hole, we recommend that you restrict the use of the 
console account to specific workstations, identified by their IP address. 

This dialog allows you to add one IP address to the list of workstations 
that are authorized to use the console account. (This same list is also 
used to restrict which workstations can use SSH with RSA authentication.) 

Additional workstations may be configured later from the command line 
interface or the Web interface.                                                         

WARNING: The console account can currently be used to log in from any 
workstation. 

Would you like to restrict access to an authorized workstation? Y/N [Yes] 

Y

Authorized workstation [0.0.0.0]: 

10.2.33.1

Summary of Contents for SG210 series

Page 1: ...Blue Coat Systems SG210 Series Installation Guide Version SGOS 5 2 x...

Page 2: ...he written consent of Blue Coat Systems Inc All right title and interest in and to the Software and documentation are and shall remain the exclusive property of Blue Coat Systems Inc and its licensors...

Page 3: ...the Serial Console 18 Section C Configuring the SG210 Using the Web Setup Wizard 23 Section D Configuring the SG210 Using Director Registration 26 Section E Logging in to the SG210 30 Logging in to th...

Page 4: ...ctrical 47 Appendix C Regulatory Statements 49 Rack Mounting Safety Instructions 49 Class A Digital Warning 49 EC Community EMC Warning 49 Canadian EC EMC Warning 49 Australia New Zealand EMC Warning...

Page 5: ...ing only by appropriately trained technical personnel Dieses Produkt wird f r Betrieb vorgehabt und wird nur durch passend ausgebildeten technisches Personal gewartet Front and Back Panel Features Thi...

Page 6: ...tem Off Nothing to report SG210 is not powered on Green SG210 is healthy Amber SG210 is unhealthy inspect the appliance and perform a maintenance check before it becomes critical Flashing Green to Amb...

Page 7: ...ations are lost when you reset the appliance Installing the SG210 There are three methods of installing the SG210 appliance placing it on a shelf or tabletop mounting it on a wall or mounting it in an...

Page 8: ...o the Wall 3 Locate the two notches on the bottom front of the chassis of the SG210 an arrow on each side of the SG210 points to each notch 4 Mount the SG210 on the wall mount bracket by inserting the...

Page 9: ...ition is not achieved due to uneven mechanical loading D Circuit Overloading Consideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of t...

Page 10: ...e Equipment Rack Powering on the SG210 Power on the SG210 by plugging in the power supply adapter and power cable 1 Plug the power supply adapter into the SG210 ensuring that the barrel of the power s...

Page 11: ...booting up an initial configuration has already been performed If you did not perform an initial configuration restore the appliance to its factory defaults to restart the initial configuration see Re...

Page 12: ...12 Blue Coat SG210 Installation Guide...

Page 13: ...all IP addresses To make sure that the appropriate traffic is directed to the ProxySG deploy hardware such as a Layer 4 switch or a WCCP router or the ProxySG appliance s software bridge that can redi...

Page 14: ...up wizard see Section D Configuring the SG210 Using Director Registration on page 26 After first time configuration is complete log on to the SG210 and use the command line interface CLI or Management...

Page 15: ...here necessary In the procedure below entries in bold text are ones for which you are required to enter data Initial Configuration Using a Direct Serial Port Connection 1 Power on and connect the seri...

Page 16: ...gistration This option requires you to assign the IP address IP subnet mask and the IP gateway for the SG210 and the IP address for the Director through the serial console before registering the SG210...

Page 17: ...on page 23 To use the Director Registration feature see Section D Configuring the SG210 Using Director Registration on page 26 Welcome to the ProxySG Appliance Setup Console page 1 of 5 Press ESC at a...

Page 18: ...in place change it for stronger security Usernames and passwords can each be from 1 to 64 characters in length Passwords that contain special characters such as an exclamation point must be in quotes...

Page 19: ...sole If the password is lost the appliance must be restored to its original factory defaults see Resetting the SG210 to Its Factory Defaults on page 38 You might still be able to access the Management...

Page 20: ...gement Guide Suite for details page 3 of 5 Press ESC at any time to return to the main menu DIRECTIONS The console username and password are special They can be used to log in to the CLI or Web Manage...

Page 21: ...TIONS An SG can have either a MACH5 Edition or Proxy Edition license The SGOS MACH5 Edition is designed to optimize and secure WAN networks being used in Application Delivery Networks ADN The MACH5 Ed...

Page 22: ..._IP 8082 where proxysg_IP is the IP address that you configured for this SG210 See Logging in to the SG210 Management Console on page 30 for more information about accessing the SG210 page 5 of 5 DIRE...

Page 23: ...the SG210 using the Web Setup Wizard 1 Complete the procedure described in Using the Serial Console to Configure Initial Settings on page 15 2 Connect the SG210 to a PC or place it within your network...

Page 24: ...Enable password in Security CLI c Optional but highly recommended Secure the serial port in Security Serial Port The serial port allows you to configure and access the SG210 using a serial cable This...

Page 25: ...ercept in Services Intercepted Traffic g Set the Default Settings policy to either the MACH5 settings for WAN acceleration or retain the default settings which are more secure Note Select the license...

Page 26: ...u do not have Internet access you might have to manually initiate the process of obtaining an appliance certificate For details on manually obtaining an appliance certificate refer to the Blue Coat Pr...

Page 27: ...Coat Systems Director Configuration and Management Guide Note The SG210 does not prompt for a registration password if it detects that it has an appliance certificate d Enter the appliance name The a...

Page 28: ...edition of SGOS would you like to run during the trial period M ACH5 Edition P roxy Edition Choose edition Proxy Proxy Edition You have chosen Proxy Edition as the trial edition Would you like to chan...

Page 29: ...e SG210 Enter 1 in the serial console menu to select the CLI See Logging in to the SG210 CLI on page 31 for information about using the SG210 CLI To access the SG210 Management Console enter the follo...

Page 30: ...er 8082 For example enter https 10 2 36 147 8082 A security warning dialog displays 4 Click Yes or OK depending on your browser in the security warning dialog You can verify the serial number in the c...

Page 31: ...e Initial Settings on page 15 The following text displays Figure 2 18 Serial Console Login Page 2 Enter 1 to access the Command Line Interface 3 At the command prompt enter enable then enter the enabl...

Page 32: ...word that you configured during initial configuration 3 At the command prompt enter enable then enter the enable password that you configured during initial configuration SGOS enable Enable Password S...

Page 33: ...ing Appears for the Initial Configuration Web Page on page 37 Resetting the SG210 to Its Factory Defaults on page 38 The SG210 Appliance Certificate is No Longer Valid After the IP Address Changes on...

Page 34: ...as a switch Verify that you entered the correct initial configuration URL https proxysg_ip 8083 where proxysg_ip is the IP address configured for this SG210 Verify that the browser is not proxied To...

Page 35: ...Verify that the workstation is configured and working properly by connecting to other Web sites This test might fail if your browser is configured to use the SG210 as a proxy server and there is a pr...

Page 36: ...ement Console on page 30 for information 2 Click the Maintenance tab click System and Disks and select the Environment tab The Environment tab displays Figure 3 3 The Environment Tab 3 Click View Sens...

Page 37: ...are not registered with a known certificate authority Normally accepting such a credential represents a security risk because of the possibility of a man in the middle attack However when you have co...

Page 38: ...push in the reset button hold it in until the appliance powers off about five seconds The appliance performs a soft restart The power LED turns amber during the restart Wait until the reset is comple...

Page 39: ...cted by the Director The Director rejects a registration request when it fails to match the SG appliance request information with the pre staged Device ID on the Director If more than one parameter ex...

Page 40: ...40 Blue Coat SG210 Installation Guide...

Page 41: ...series appliance contact your Blue Coat sales representative for more information Activate the SG210 license You must have a Blue Coat WebPower account Note If you have new SG210 hardware that previou...

Page 42: ...g the other one for future reference You can attach it to this document and file it or attach it to another document as required in your enterprise Table 4 1 Licensed Users Hardware Model Number of Us...

Page 43: ...or loses power for any reason the bridge fails open that is Web traffic passes from one Ethernet port to the other Therefore Web traffic is uninterrupted but does not route through the appliance Beca...

Page 44: ...ush the SG210 chassis away from you at the same time Lift the cover up and off Figure 5 8 Remove the Rack Mounting Brackets and the Cover Important The appliance will not remain grounded if you take o...

Page 45: ...ew if you are facing the front of the SG210 the pass through card is located near the back of the SG210 on the left Figure 5 9 Remove the Pass Through Card Screw 7 Remove the pass through card grasp i...

Page 46: ...n removed you can configure software bridging which unlike hardware bridging allows you to configure failover Failover is accomplished by creating virtual IP addresses on each proxy creating a failove...

Page 47: ...L nge 356 mm 14 in Weight Gewicht System 2 5 kg 5 6 lb Power adapter 0 5 kg 1 lb Power Input AC for external adapter Stromversorgung 100 240V 1 8 A 50 60 Hz Disk Drives Festplatte 1 x 80 GB IDE ATA 10...

Page 48: ...48 Blue Coat SG210 Installation Guide...

Page 49: ...on of equipment nameplate ratings should be used when addressing this concern E Reliable Earthing Reliable earthing of rack mounted equipment should be maintained Particular attention should be given...

Page 50: ...rrectly placed Replace only with the same or equivalent type recommended by the manufacturer Dispose of used batteries according to the manufacturer s instructions ATTENTION Il y a danger d explosion...

Page 51: ...rectamente Substituya solo con el modelo original o la recomendaci n del fabricante Disponga de las bater as usadas seg n las instrucciones del fabricante Connection to ports not defined for normal op...

Page 52: ...andards EN 60950 1 2001 A11 EN 55022 1998 A1 2000 A2 2003 Following the provisions of the 73 23 EEC and 89 336 EEC Directives including the Amending Directive 93 68 EEC Blue Coat Systems model 210 is...

Page 53: ...ns required 23 problems with first time configuration page 34 Web setup wizard 13 front panel LEDs description of 6 I installing the SG210 mounting on a wall 7 mounting on an equipment rack 9 placing...

Page 54: ...alid certificate 38 problems powering on 34 removing the pass through card 43 46 resetting to factory defaults 38 specifications 47 specifications environmental and electrical 47 system LED descriptio...

Reviews: