Initial Configuration
StoneGate SG-250/SG-200 Quick Start Guide
17
• Dynamic IP Address
: Select
Obtain node IP address from a DHCP
server
and then continue on with after the Static IP-only steps. The
DHCP server will automatically assign the IP address and netmask.
•
Static IP Address
: Select
Enter node IP address manually
and then
continue below for the Static IP-only steps. The IP address must be the
same as specified control IP address in the firewall element on the
Management Server.
3. (Static IP-only) Next, define the netmask for the IP address used
for the management connections to the firewall node. For this
example, we are using the netmask
255.255.255.0
.
4. (Static IP-only) Define the address of the default gateway needed
for the firewall engine to contact the Management Server. If the
engine and the Management Server are on the same network, you
can leave this line empty.
5. Highlight
Contact Management Server
and press
SPACEBAR
to
enable the initial connection to the Management Server. During
this contact, the trust relationship is established between the
engine and the Management Server. An asterisk (*) indicates that
the option is active.
6. In the
One-time password
field, enter the password for
contacting the Management Server. The password is engine-
specific and can be used only for one initial connection to the
Management Server.
7. Optionally, enter the Management Server certificate’s fingerprint
for verification.
8. To complete the configuration, highlight
Finish
and press E
NTER
.
3.7.4 Verifying Management Connections
If the initial Management Server contact was selected, the firewall engine
tries to connect to the Management Server. If the initial management
contact fails for some reason, the configuration can be started again with
the
sg-reconfigure
command.
If the firewall cannot communicate with the Management Server and you
receive a “connection refused” error message. Make sure that the one-
time password is correct and the Management Server IP address is
reachable from the node.
After a successful Management Server contact, the firewall engine
installation is complete and ready for security policy upload from the