background image

C

HAPTER

 1: B

EFORE

 Y

OU

 B

EGIN

M86 S

ECURITY

SWG S

ETUP

 G

UIDE

  

V

. 10.2

 

5

Chapter 1: Before You Begin

This guide provides the instructions you need to install and setup 
your M86 Security SWG appliance.

You should perform the following tasks in the order listed:

1. Install the appliance (see 

Chapter 2

).

2. Set up the appliance (see 

Chapter 3

).

3. Optional appliance configuration (see 

Chapter 4

).

After you have setup the appliance, you can configure the 
Management Console according to your needs. Instructions are 
provided in a separate guide – the 

Management Console 

Reference Guide

NOTE: 

Physical SWG appliances come with the required image 

already loaded. Should you need to reload or replace the image, 
you can find instructions in the SWG Installation Utility Guide.

Summary of Contents for SWG

Page 1: ...SWG Setup Guide Secure Web Gateway OVF Release 10 2...

Page 2: ...ver M86 Security makes no warranties with respect to this documentation and disclaims any implied war ranties of merchantability and fitness for a particular purpose M86 Security shall not be liable f...

Page 3: ...e 11 Preparing Values for the Appliance Setup 11 Setting Up the Appliance 13 Chapter 4 Performing Additional Configuration Optional 14 Limited Shell Commands Summary List 14 Limited Shell Configuratio...

Page 4: ...TABLE OF CONTENTS M86 SECURITY SWG SETUP GUIDE OVF V 10 2 4 uptime 28 vmstat 28 w 28 wget 28...

Page 5: ...ce see Chapter 2 2 Set up the appliance see Chapter 3 3 Optional appliance configuration see Chapter 4 After you have setup the appliance you can configure the Management Console according to your nee...

Page 6: ...keyboard and monitor Instructions for connecting are provided on the following pages Before connecting to the appliance ensure that the following requirements are satisfied Requirements Before Install...

Page 7: ...gical network subnet as the appliance s GE0 interface For example configure the IP on the PC as 10 0 0 101 and the PC s netmask as255 255 255 0 4 Continue with Initial Setup of your SWG Appliance usin...

Page 8: ...attached to the chassis displays output from the blade being powered up b Press the Power button until the blade turns on After the blade finishes booting a login prompt is displayed 5 Continue by doi...

Page 9: ...onnect the PC to the appliance s Serial Console using the serial cable 2 Using the Hyper Terminal application enter the appropriate Port settings y Bits per Second Baud Rate 19 200 y Data Bits Word 8...

Page 10: ...ile Deploy OVF Template 2 In the wizard browse to the OVF file and then complete the deployment When done it is recommended that you set the attributes for the virtual machine according to the values...

Page 11: ...the detailed information and values that you will need to supply as part of setup Table 2 Appliance Setup Preparation Details What to Prepare Details 1 Decide the role of the appliance You must defin...

Page 12: ...vailable for SWG 5000 and the Policy Server in SWG 7000 only Allows communication at a speed of up to 1GB with Auto Negotiation enabled GE3 eth3 1GB Auto negotiation Available for SWG 5000 and the Pol...

Page 13: ...ctively y For a physical machine you can connect from a remote machine using an SSH client serial cable or by connecting a keyboard and monitor to the appliance y For a virtual appliance connect throu...

Page 14: ...and values Limited Shell commands are divided into two categories y Configuration commands y Monitoring commands This chapter contains the following sections y Limited Shell Commands Summary List y Li...

Page 15: ...k usage disable_ C Disables service Double tab to view the disable_service_snmpd and disable_service_ssh commands enable_ C Enables service Double tab to view the enable_service_snmpd and enable_servi...

Page 16: ...Shows system or service status Double tab to view the show_bridge show_config show_network show_service show_dbsize show_proxy_buffers show_proxy_connections show_route show_time and show_version com...

Page 17: ...ations on predefined ports such as HTTP FTP ICAP or System ports internal ports Any IP address not defined in the IP range will then be blocked from accessing these applications on the ports defined b...

Page 18: ...ation Enter y to change the network configuration Select an option from the following commands y View This command allows you to view the current network configuration The IP address assigned to each...

Page 19: ...earch Hostname Allows configuring the appliance hostname Hosts Allows configuring the host files config_time Allows system administrators to set the system date and time the time zone and also the NTP...

Page 20: ...rver add the new Port settings config_exclude Defines bypass rules in intercepting proxy mode config_bridge Configures intercepting proxy to work in bridge mode In Bridge mode only traffic that should...

Page 21: ...uring the Network Interface parameters Enter the ethconf command and choose the required interface Choose the required speed or select Auto negotiation to enable the appliance to negotiate its own spe...

Page 22: ...E V 10 2 22 flush_dnscache Flushes the dns cache reset_config Rebuilds the appliance configuration in extreme situations where the appliance for whatever reason was disconnected for a period of time T...

Page 23: ...file systems Enter the df command to display the disk usage ifconfig This Unix command is used to display TCP IP network interfaces Enter the ifconfig command to display configuration and statistics...

Page 24: ...me2ip command followed by a hostname to display the associated IP address netstat This command is a useful tool for checking your network configuration and activity It displays the status of network c...

Page 25: ...t any time show_ Shows system or service status The show command includes show_bridge show_config show_network show_service show_dbsize show_proxy_buffers show_proxy_connections show_route show_time a...

Page 26: ...the Kernel IP routing table show_time Allows system administrators to view the time date time zone and ntp settings show_version Allows system administrators to view the time date time zone and ntp se...

Page 27: ...stination It can help you determine why connections to a given server might be poor and can often help you figure out where exactly the problem is uptime Produces a single line of output that shows th...

Reviews: