background image

Chapter 5: Installing and Configuring Tufin Orchestration
Suite Aurora

This section includes instructions to install and configure Tufin Orchestration Suite Aurora R21-1 and above running on TufinOS 3.60.

Note:

After you install Tufin Orchestration Aurora on the appliance, you will be unable to revert it to Tufin Orchestration Suite

Classic.

Network Requirements for Tufin Orchestration Suite Aurora

If you are installing Tufin Orchestration Suite Aurora on the appliance, you need to do the following:

l

Allow access to the required ports and services. For more information, see

https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/PortsAndServices.htm

.

l

Dedicate a 24-bit CIDR subnet on your network to Tufin Orchestration Suite Aurora for internal use. It must not overlap with
CIDR 10.244.0.0/16 or with the physical and VIP (Virtual IP) network addresses of your 

SecureTrack Aurora servers

.

l

Dedicate two different IP addresses to Tufin Orchestration Suite Aurora:

l

The virtual IP (VIP) that will serve as the external IP address used to access Tufin Orchestration Suite Aurora from your browser
and from devices that send it data. The VIP will not be needed in the installation, except in the last step - the installation
command.

l

The physical network IP that will serve as the internal IP address used by the administrator for CLI commands and this is the one
you will use in all other steps of the installation.

l

If additional nodes are subsequently added to the cluster, each node will require an additional dedicated physical network IP. The
VIP and all the physical network IPs must be on the same subnet.

Install Tufin Orchestration Suite Aurora

1.

Reconfigure TufinOS

a.

Open a command line via SSH to the IP address of

eth0

(if you have not changed it:

192.168.1.100

).

b.

Log in as

tufin-admin

with password

admin

You are prompted to change the default password when you first log in.

c.

Run the following commands:

screen -S switch

switch-tos-mainstream

d.

When prompted to reconfigure TufinOS, select

yes

. This process can run about five minutes.

e.

Reboot the appliance.

f.

Reconnect to the appliance (steps 2-3).

g.

To install Tufin Orchestration Suite Aurora, run the following commands:

screen -S install

cd /opt/tufin/data/aurora

sudo sh <filename>

The installation file is in

/opt/tufin/data/aurora

.

2.

Configure the appliance for Tufin Orchestration Suite Aurora

a.

To access the appliance with Mozilla Firefox or Google Chrome, browse with https to the IP address of

eth0

. If you have not

changed the IP address, browse to

https://192.168.1.100

.

b.

Accept the certificate.

T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora

Copyright 2003-2021, Tufin Software Technologies Ltd.

13

Summary of Contents for T-1200

Page 1: ...T 800 1200 Quick Start Guide Version 13 11...

Page 2: ...gure SecureChange 11 Chapter 5 Installing and Configuring Tufin Orchestration Suite Aurora 13 Network Requirements for Tufin Orchestration Suite Aurora 13 Install Tufin Orchestration Suite Aurora 13 C...

Page 3: ...liances come pre installed with TufinOS and are designed to support both Tufin Orchestration Suite Classic default and Aurora You will need to choose the desired Tufin Orchestration Suite product and...

Page 4: ...the front of the appliance Item Feature Description A Information LED Indicates system status as follows l Continuously on and red An overheat condition has occurred which may be caused by cable conge...

Page 5: ...the system is operating normally F UID button LED The unit identification UID button turns on or off the blue light function of the Information LED and a blue LED on the rear of the chassis These are...

Page 6: ...ts out management of the system I Serial port Standard serial port that gives you serial access to the system via console redirection J VGA port K 1 PCI E 3 0 low profile slot L 2 PCI E 3 0 full heigh...

Page 7: ...up the appliance by pressing the Power button on the front panel 3 Connect a network cable to the ethernet port 1 Chapter 2 Rear Panel item C and to a PC with a crossover cable or to a local network...

Page 8: ...classic sh filename The installation file is in opt tufin data classic d Follow the installation instructions in the command line If you disabled SecureTrack and will not be using it on this appliance...

Page 9: ...the End User License Agreement l Password Type system for the Old Password of the TufinOS root user and change the password T 800 1200 Quick Start Guide Chapter 4 Installing and Configuring Tufin Orch...

Page 10: ...interface l Time Configure date and time settings l User Details Configure the admin user s details Username and password cannot be changed in this page T 800 1200 Quick Start Guide Chapter 4 Installi...

Page 11: ...ing to your networking needs eth0 may still have the preconfigured IP address of 192 168 1 100 For instructions see https forum tufin com support kc latest Content Suite 1584 htm l Change the root pas...

Page 12: ...https forum tufin com support kc latest Content Suite 2353 htm To add devices to be monitored see the https forum tufin com support kc latest Content Suite 4034 htm To add SecureTrack on this applian...

Page 13: ...k IP that will serve as the internal IP address used by the administrator for CLI commands and this is the one you will use in all other steps of the installation l If additional nodes are subsequentl...

Page 14: ...y and DNS Servers to the IPs used by your organization l or Edit the configuration files directly 1 Edit the file etc sysconfig network scripts ifcfg eno1 2 Change line BOOTPROTO dhcp to BOOTPROTO sta...

Page 15: ...192 168 1 2 services network 10 10 10 0 24 The End User License Agreement EULA appears c After reading enter q to exit the document and then enter y to accept the EULA and continue until the commands...

Page 16: ...ict the administrator to selected domains For more information see https forum tufin com support kc aurora Content Suite 1073 htm 2 Log in to SecureChange a Go to https IP securechangeworkflow where I...

Page 17: ...n be done now or at a later stage l Connect to a mail server For instructions see https forum tufin com support kc aurora Content Suite 1794 htm l optional Connect to an LDAP directory to use LDAP use...

Page 18: ...twork as the appliance l Web browser We recommend Internet Explorer with anti virus enforcement and browser protection disabled l Java version 8 or later Ports The following ports must be open between...

Page 19: ...bnet Netmask ipmitool lan set 1 defgw ipaddr Default Gateway IP Address 3 Verify the configuration ipmitool lan print 1 4 Ping the RMM IP address to confirm connectivity ping RMM IP Address 5 Configur...

Page 20: ...using the username and password defined in the previous step https RMM IP Address Now you can securely connect to the RMM to do remote administration tasks For more about using the RMM refer to the I...

Page 21: ...ation using serial console l serial aurora For Aurora supported installation using serial console If there is no reply within 60 seconds all installation messages are directed to the serial console If...

Page 22: ...need immediate assistance please call 1 877 270 7711 Tufin at a Glance Offices North America EMEA and Asia Pacific Customers More than 2100 in over 50 countries Leading verticals Finance telecom energ...

Reviews: