background image

Initial Configuration 

23

3.

(

Optional

) Fill in the Key fingerprint (also shown when you saved the 

initial configuration). Filling it in increases the security of the 

communications.

4.

Highlight 

Finish

 and press E

NTER

.

The engine now tries to make initial Management Server contact.

• If you see a “connection refused” error message, ensure that the 

one-time password is correct and the Management Server IP address 

is reachable from the node. Save a new initial configuration if unsure 

about the password.

• If the engine is unable to contact the Management Server, make sure 

there are no networking problems, that all information defined in the 

Firewall element corresponds to what you entered in the configuration 

wizard and, if NAT is in use, that you have configured contact 

addresses for NAT as explained in the 

Firewall/VPN Installation Guide

.

After Successful Management Server Contact

After you see a notification that Management Server contact has 

succeeded or the appliance has rebooted itself after automatic 

configuration with a USB stick, the firewall engine installation is 

complete and the firewall is ready to receive a policy. In a while, the 

firewall’s status changes in the Management Client from 

Unknown

 to 

No 

Policy Installed

, and the connection state is 

Connected

 indicating that 

the Management Server can connect to the node.
The next step is creating a security policy and installing it on the engine. 

See the 

Online Help

 of the Management Client for detailed instructions.

Note – 

Once initial contact has been made, the engine receives a 

certificate from the Management Center for identification. If the 

certificate is deleted or expires, you must repeat the initial contact 

using a new one-time password.

Caution – 

When using the command prompt, use the 

reboot

 

command to reboot and 

halt

 command to shut down the node. Do 

not use the 

init

 command. You can also reboot the node using the 

Management Client.

Summary of Contents for FW-1030

Page 1: ...Appliance Installation Guide Stonesoft FW 1030 and FW 1060...

Page 2: ...ese materials are provided pursuant to the general terms for support and maintenance services and the related service description which can be found at the Stonesoft website www stonesoft com en suppo...

Page 3: ...which can be found at the Stonesoft website Contents Installation Procedure 4 Product Documentation 4 Safety Precautions 5 Unpacking the Appliance 7 Front Panel 8 Back Panel 9 Rack Mounting 10 Connec...

Page 4: ...Initial Configuration page 16 Product Documentation Press F1 in any Management Client window to view the Online Help All PDF guides are available On the Management Center CD ROM in the Documentation...

Page 5: ...y one hand when working with powered on electrical equipment This is to avoid making a complete circuit which will cause electrical shock Use extreme caution when using metal tools which can easily da...

Page 6: ...ot open the power supply casing Power supplies can only be accessed and serviced by a qualified technician of the manufacturer Operating and Storage Temperatures The allowed operating temperature of t...

Page 7: ...he appliance was shipped in and note if it was damaged in any way If the appliance itself shows damage file a damage claim with the carrier who delivered it Confirm that the Stonesoft anti tamper tape...

Page 8: ...system even when the appliance is turned off Table 1 Power and Disk Activity Indicators Indicator Status Explanation Power Blue Indicates power is being supplied to the system s power supply unit This...

Page 9: ...ty Unlit No link Amber Link ok Link Unlit Speed is 10 Mbps Green Speed is 100 Mbps Orange Speed is 1 Gbps Table 3 SFP Port Indicators on FW 1060 SFP Indicator Status Explanation Activity Unlit No link...

Page 10: ...cal noise and electromagnetic fields are generated Leave enough clearance in front of the rack to enable you to open the front door completely 63 cm 25 inches Leave enough clearance in the back of the...

Page 11: ...to prevent components falling off from the appliance Be sure to install an AC power disconnect for the entire rack assembly This power disconnect must be clearly marked The rack assembly must be prope...

Page 12: ...the front panel illustration for the location of the holes 2 Repeat step 1 with the bracket on the other side of the appliance Proceed to Connecting the Cables page 14 Installing the Appliance Into a...

Page 13: ...h the bracket on the other side of the appliance 4 Attach each bracket to the rack using two screws and cage nuts Insert the screws through the holes in the front of the bracket one screw through the...

Page 14: ...0 SFP has two SFP ports ports 6 7 You can use these ports as either copper or fiber ports by inserting a small form factor pluggable SFP transceiver for copper or fiber optic cable in the port slot No...

Page 15: ...ngs Network cards at both ends of each cable must have identical speed duplex settings This also applies to the automatic negotiation setting if one end of the cable is set to autonegotiate the other...

Page 16: ...erver as outlined in the sections below To successfully complete this configuration the following prerequisites must be met The Firewall element must be defined in the Management Center You must have...

Page 17: ...If you configure the engine with a USB stick you must set a password for the root account in the Management Client to enable command line access to the engine If you want to allow remote access to the...

Page 18: ...he appliance using the power on off switch The engine bootup process is shown in the console and after some time the engine configuration wizard starts To select the configuration method 1 Do one of t...

Page 19: ...sing the arrow keys and press ENTER 2 Select the correct timezone in the dialog that opens Note If the desired keyboard layout is not available use the best matching available layout or select US_Engl...

Page 20: ...n your keyboard to select the option and allow remote access to engine command line using SSH 4 Highlight Next and press ENTER The Configure Network Interfaces window is displayed Note It is not neces...

Page 21: ...gement Server 4 Highlight Next and press ENTER to continue Contacting the Management Server The Prepare for Management Contact window opens If the initial configuration was imported most of this infor...

Page 22: ...licy that allows only administration related connections and blocks everything else In the second part of the configuration you define the information needed for establishing a trust relationship betw...

Page 23: ...anagement Server Contact After you see a notification that Management Server contact has succeeded or the appliance has rebooted itself after automatic configuration with a USB stick the firewall engi...

Page 24: ...sion it automatically switches to the previous configuration at the next reboot You can also switch back to the previously installed software version manually as instructed here whenever necessary To...

Page 25: ...Press Enter A list of available commands opens 5 Select System Restore Options and press Enter 6 Type 1 and press Enter to clear the settings A confirmation prompt is shown 7 Type YES and press Enter...

Page 26: ...Unplug all power cords from the system or the wall outlets 4 Disconnect the cable from the SFP transceiver 5 Pull down the latch on the transceiver 6 Pull the SFP transceiver carefully out of the port...

Page 27: ...documentation See inside for further details All documentation and our technical knowledge base is available at www stonesoft com support Copyright 2012 Stonesoft Corporation Stonesoft Inc Americas He...

Reviews: