data:image/s3,"s3://crabby-images/9145d/9145dd429cac213cbb6840ccf5407ab019372633" alt="Thales SafeNet ProtectServer Network HSM 5.9 Скачать руководство пользователя страница 24"
Chapter 4: Testing and Configuration
Configuring the Network Parameters
You can use the serial connection to configure all of your network parameters, or configure a single port and
use it to access the appliance over the network and complete the configuration.
NOTE
Use a locally-connected serial terminal when changing the appliance IP address, to
avoid SSH admin console disconnection.
To configure the appliance and port network parameters
It is recommended that you configure and test each device. You need to know the IP address of at least one
network interface to establish an SSH connection to the appliance.
1.
Login to the appliance as
admin
or
pseoperator
.
2.
Configure the IP address, network mask, and gateway (optional) on at least one of the Ethernet LAN ports
(eth0 or eth1). You can specify a static address, or retrieve one from a DHCP server. You can configure
each port to use an IPv4 or IPv6 address.
Static
psesh:>
network interface static -device
<netdevice>
-ip
<IP_address>
-netmask
<netmask> [
-
gateway
<IP_address>]
DHCP
psesh:>
network interface dhcp -device
<netdevice>
Either of these commands will prompt you to restart the network service.
3.
[Optional] Configure network interface bonding. This allows the two network devices to function as a single
interface, with a single MAC address, improving bandwidth and providing redundancy.
NOTE
Use network interface bonding with static IP addresses only. If DHCP is used, the
bond will be broken if one interface is assigned a different IP.
psesh:>
network interface bonding config -ip
<IP>
-netmask
<IP> [
-gateway
<IP>] [
-mode
<mode>]
psesh:>
network interface bonding enable
psesh:>
sysconf appliance reboot
Multiple bonding modes provide different options for load-balancing between the two physical interfaces:
•
0
: Balance Round Robin. Packets are transmitted alternately on each device in the bond, providing load
balancing and fault tolerance.
•
1
: Active-Backup. One bonded device is active and the other serves as a backup. The backup only
becomes active if the active device loses connectivity.
•
2
: Balance XOR. Transmits based on an XOR formula, where the source MAC address is XOR'd with the
destination MAC address. The same bonded device is selected for each destination MAC address,
providing load balancing and fault tolerance.
•
3
: Broadcast. All packets are transmitted on both bonded interfaces, providing fault tolerance.
•
4
: 802.3ad (Dynamic Link Aggregation). Creates aggregated groups that share the same speed and
duplex settings. This mode requires a switch that supports IEEE 802.3ad dynamic links. The dvice used
for an outgoing packet is selected by the transmit hash policy (by default, a simple XOR). This policy can
SafeNet ProtectToolkit 5.9 Installation and Configuration Guide
007-013682-007 Rev. A 08 January 2020 Copyright 2009-2020 Thales
24