2
Installing and Initially Configuring EFW
30
Registering EFW NICs Manually
If you are installing the EFW NICs using the diskette-keyed process, you must register NICs
manually from the Management Console. If you are installing the EFW firmware using the
network installation, you have the option of registering EFW NICs manually, or letting the
EFW NICs register automatically upon first contact with a Policy Server. The advantage of
manual registration is that when the EFW NIC first identifies itself to the Policy Server, the
Policy Server can assign a previously specified policy for the EFW NIC. Without manual
registration, the Policy Server simply adds the EFW NIC to the default device set and
downloads the policy for that device set.
For an EFW NIC that is registered manually, you can specify a host name, an IP address, or
a MAC address. A static IP address can be required by selecting the corresponding check
box. If you require static IP addresses, then the EFW NIC is always expected to have the
same IP address that it showed when the EFW NIC first contacted a Policy Server. If the
EFW NIC does not have the same IP address, the Policy Server does not respond to the
EFW NIC and generates an audit event.
To register EFW NICs manually, follow the steps below.
1
In the Management Console under the Main menu, select
New
->
NIC Registration
.
The Manual NIC Registration window appears.
2
Select the type of NIC you are registering:
Desktop NIC
or
Server NIC
.
3
Determine whether the NIC will be behind a NAT (network address translation) machine.
■
Direct
—Select this option if the NIC is not behind a NAT machine. You are
prompted to enter the secured computer host name or IP address. You can also
specify whether IP addresses must be static.
■
Behind a NAT Box
—Select this option if a NAT machine exists on the network path
between the NIC and its primary or any backup Policy Server. If the NIC is behind a
NAT machine, you are prompted to enter the EFW device name and MAC address.
4
From the Device Set drop-down list, select the device set to which the NIC will belong.
5
From the Policy Server drop-down list, select the primary Policy Server with which the
NIC will be associated.
6
Click
OK
to register the EFW NIC manually.
Distributing and Installing the EFW NIC Firmware
Before installing the EFW firmware and agent software, a 3Com interface network card
that supports EFW should be physically installed, and networking should be operational
using the factory drivers for this card.
The EFW NIC firmware must be installed onto the EFW NICs. The firmware can be
distributed in either of two ways:
■
Diskette-keyed distribution
For security reasons, you may want to distribute cryptographic keys used for
communication with the Policy Server directly to a computer that will be secured
via boot media.
For more information on diskette-keyed distribution, see “Determine How You Want
to Distribute EFW Firmware” on page 16.