Setting Up NSM to Work With Infranet Controller and Infranet Enforcer
A ScreenOS firewall that is managed by NSM can also be configured as an Infranet
Enforcer in a UAC solution.
The Infranet Controller specifies an authorization server $infranet for each Infranet
Enforcer in its list. This name is required for correct operation between the Infranet
Controller and the Infranet Enforcer. Conversely, if NSM has multiple Infranet Enforcers
in its global domain, it will distinguish among them by renaming additional Infranet
Enforcers $infranet_1, $infranet_2, and so on. To resolve this naming conflict, you must
move each Infranet Controller to a separate NSM domain.
In addition, because the Infranet Controller regularly changes its NACN password with
the Infranet Enforcer, you should always import the Infranet Enforcer into NSM before
performing a device update to it.
The following procedures prevent these conflicts between NSM and the Infranet
Controller:
•
Avoiding Naming Conflicts of the Authorization Server Object on page 181
•
Avoiding NACN Password Conflicts on page 183
Avoiding Naming Conflicts of the Authorization Server Object
To avoid naming conflicts with the authorization server objects, follow these steps:
1.
On the Infranet Controller, create the Infranet Enforcer instances:
a.
On the Infranet Controller, select
UAC -> Infranet Enforcer -> Connection
.
b.
Click
New Enforcer
.
c.
Fill out the information requested in the display.
Enter an NACN password. Remember it because you will need to use it again
while setting up the Infranet Enforcer. If you are setting up a cluster instead of
a single device, enter all the serial numbers in the cluster, one per line.
d.
Click
Save Changes
.
e.
Repeat Steps b through d until all of your Infranet Enforcers have been entered.
2.
If you do not have one already, create a CA certificate for each Infranet Enforcer.
a.
Create a certificate signing request (CSR) for an Infranet Controller server
certificate, and use the CA certificate to sign the server certificate.
b.
Import the server certificate into the Infranet Controller.
c.
Import the CA certificate into the Infranet Enforcer.
181
Copyright © 2010, Juniper Networks, Inc.
Chapter 4: Adding Devices
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...