SafeNet ProtectServer External 2 Installation Manual Download Page 19

 

13 

Once a table configuration has been created that provides suitable network access, it 
can be stored as the active network configuration using the following command: 

/etc/init.d/iptables save active

 

Before 

iptables

(8)

 is completely configured it should have an inactive table 

defined. This is less critical as there is very little running in the operating system by 
the time the inactive table is loaded. The following is a suitable inactive table: 
 

iptables -F INPUT

 

iptables -F OUTPUT

 

iptables -F FORWARD

 

iptables -A INPUT -j DROP

 

iptables -A OUTPUT -j DROP

 

iptables -A FORWARD -j DROP

 

/etc/init.d/iptables save inactive

 

The active iptables configuration must now be restored before 
connections to the PSe are allowed. The following command will 
restore the previously saved active configuration.

 

/etc/init.d/iptables stop 

/etc/init.d/iptables start 

SSH network access 

After you have completed the network configuration, you can access the PSE2 over 
the network using the SSH protocol. To access the PSE2 using SSH, you require an 
SSH client such as puTTY (available for free fro

www.putty.org

). 

Note:

 

You must log in as the admin user when accessing the PSE2 over an SSH connection. 

Restarting networking 

After making any change to the networking configuration, reboot the PSE2 or enter 
the following command to restart networking: 

/etc/init.d/networking restart 

Powering off the PSE2 

You must be logged in as root to power off the PSE2. 

To power off the PSE2 

1.

 

Enter the 

shutdown

 or 

poweroff

 command to shut down the operating system. The 

fan and LEDs will remain operational. 

2.

 

Toggle the power switch, located on the rear of the PSE2, to the off position. The 
fan and LEDs will turn off. 

Upgrading the PSe 

You can upgrade the PSE2 to a later revision using USB media, such as USB memory 
sticks or a USB-connected CDROM drive. 

Summary of Contents for ProtectServer External 2

Page 1: ...i ProtectServer External 2 PSE2 Installation Guide...

Page 2: ...FCC compliance only devices also known to comply should be connected to the adapter s serial ports If such devices do not feature their own cables shielded cables must be used Disclaimer SafeNet make...

Page 3: ...United States 800 545 6608 Web www safenet inc com Support and Down loads www safenet inc com support Provides access to the SafeNet Knowledge Base and quick downloads for various products Technical...

Page 4: ...allation procedure 7 To install the hardware 7 Smart Card Reader Installation 7 Chapter 5 Testing and configuration 9 Equipment requirements 9 Procedure overview 9 System testing 11 The PSE_status com...

Page 5: ......

Page 6: ......

Page 7: ...ps are given References to further documentation are cited where needed Chapter 4 describes the installation procedure Chapter 5 deals with testing and network setting configuration A troubleshooting...

Page 8: ...services include encryption decryption signature generation and verification and key management with a tamper resistant and battery backed key storage To implement a cryptographic service provider use...

Page 9: ...liance using the included USB to serial cable HSM serial port pin configuration The serial port on the USB to serial cable uses a standard RS232 male DB9 pinout as illustrated in Figure 2 Figure 2 HSM...

Page 10: ...o destroy any keys currently stored on the HSM When the key is in the horizontal Active position the HSM is in normal operating mode When the key is in the vertical Tamper position the HSM is in the t...

Page 11: ...ted using a standalone SafeNet Protect Server External 2 PSE2 HSM the cryptographic service provider will operate in network mode In network mode Network HSM Access Provider software is installed on t...

Page 12: ...nd configured to support operation in network mode Full details are in the Hardware Security Module Access Provider Install Configuration Guide supplied with the software 5 Install the high level cryp...

Page 13: ...ic API software is installed Connect the PSE2 to the network by inserting standard Ethernet cables into the LAN connectors located on the front of the PSE2 The LAN connectors are autosensing 10 100 10...

Page 14: ...r crypto server for security reasons then connect a PS 2 to USB adapter cable between the card reader and a standalone powered USB hub Again the USB connection is for power only No data transfer occur...

Page 15: ...he RJ45 console port to a terminal emulation device such as a laptop or terminal server Note If you want to access the PSE2 console remotely using the console port you will need a cable If your termin...

Page 16: ...as admin only The default passwords for the root and admin users are as follows User name Default password root password admin password At this time we strongly recommend that you use the passwd comm...

Page 17: ...y displays the current status of the Protect Server External 2 PSE2 It provides the following information the status of the HSM installed in the PSE2 If the unit is functioning correctly a message tha...

Page 18: ...ces to operate as their own name servers If name resolution is required it needs to be provided by a DNS server on the network In order for the PSE2 to use the DNS server you must add an entry for the...

Page 19: ...bles stop etc init d iptables start SSH network access After you have completed the network configuration you can access the PSE2 over the network using the SSH protocol To access the PSE2 using SSH y...

Page 20: ...tories listed above usbflash cdrecorder are just examples The name can vary depending on the device capability and how it is detected Troubleshooting Each Protect Server External 2 is tested during ma...

Page 21: ...isk DOM 10 100 1000 Mbps autosensing Network Interface with RJ45 LAN connector Pre installed Software Linux operating system SafeNet PCI HSM Access Provider software SafeNet HSM Net Server software Po...

Page 22: ...END OF DOCUMENT...

Reviews: