123
Establishing your network
Deployment scenarios
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
None.
Configuring advanced enclave management for nonroutable addresses
This method supports situations where the enclave security gateway’s external interface IP address is
nonroutable. This approach uses the security gateway’s service redirect feature, which changes the
management connection’s destination IP address to the enclave security gateway’s external interface
IP address as it passes through the perimeter security gateway. It also requires a GSP, new protocol, a
service group, and a rule. Changes that you make take effect immediately after saving and activating.
Prerequisites
None.
Configure advanced enclave management method for nonroutable addresses
To configure advanced enclave management for nonroutable addresses, you must do the following:
■
Ensure that TCP GSP is running
■
Create a new protocol for SGMI management
■
Create a service group for SGMI management
■
Create an allow rule for SGMI management
■
Create a service redirect for SGMI management
To ensure that TCP GSP is running
1
In the SGMI, in the left pane, under Assets, click
Proxies
.
2
In the right pane, in the Proxies table, click
GSP
, and then click
Properties
.
3
In the Proxy Properties dialog box, on the General tab, do the following:
■
To enable the GSP proxy, click
Enable
.
■
To enable TCP GSP, click
Enable TCP
.
4
In the Caption text box, type a brief description of the GSP.
5
Optionally, on the Description tab, type a more detailed description than you typed in the Caption
text box.
6
Click
OK
.
7
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
To create a new protocol for SGMI management
1
In the SGMI, in the left pane, under Assets, click
Protocols
.
2
In the right pane, on the Protocols tab, click
New > TCP UDP Based Protocol
.
3
In the TCP UDP Based Protocol Properties dialog box, on the General tab, in the Protocol name text
box, type a name for this protocol.
Summary of Contents for Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Page 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Page 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Page 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Page 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Page 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Page 509: ...508 Generating reports Upgrade reports...
Page 553: ...552 Advanced system settings Configuring advanced options...
Page 557: ...556 SSL server certificate management Installing a signed certificate...
Page 861: ...860 Index...