[Setup Menu]
join - Join an existing iSD cluster
new - Initialize iSD as a new installation
boot - Boot menu
info - Information menu
exit - Exit [global command, always available]
>> Setup#
new
Setup will guide you through the initial configuration of the
iSD.
2. Follow the instructions for installing a VPN Gateway in a new cluster.
Read the sections starting with
Installing an AVG in a New Cluster
on page 42.
When the basic setup is completed, new prompts for configuring an ASA 310-FIPS
will automatically appear.
3. Choose the appropriate security mode for the ASA 310-FIPS cluster.
Decide which security mode to use for the new ASA 310-FIPS cluster—FIPS mode
or Extended Security mode. The default Extended Security mode should be used
whenever your security policy does not explicitly require conforming to the FIPS
140-1, Level 3 standard.
For more information about the FIPS mode and the Extended Security mode, see
Introducing the ASA 310-FIPS
on page 31.
( new setup, continued)
Use FIPS or Extended Security Mode? (fips/extended)
[extended]:
<Press ENTER to accept the default extended mode, or
change the security mode to fips>
4. Initialize HSM card 0 by inserting the first pair of HSM-SO and HSM-USER iKeys,
and by defining passwords.
Step 4
on page 57 and
step 5
on page 58 are related to initializing the HSM cards
that your ASA 310-FIPS is equipped with. The Setup utility will identify the first HSM
card as card 0, and the second HSM card as card 1. Each HSM card is initialized
by inserting the proper iKeys and defining a password for each user role. To
successfully initialize both HSM cards, you need to have the following iKeys:
• One pair of iKeys to be used for initializing HSM card 0.
- The purple HSM Security Officer iKey, embossed with "HSM-SO".
- The blue HSM User iKey, embossed with "HSM-USER".
Label these iKeys and HSM card 0 in a way so that the connection between
them is obvious. After HSM card 0 has been initialized, this card will only accept
the HSM-SO and HSM-USER iKeys that were used when initializing this
particular HSM card. Even if you choose to use the same HSM-SO and HSM-
USER passwords when you initialize card 1 as the passwords you defined
Installing an ASA 310-FIPS
User Guide
April 2013 57
Summary of Contents for 3050-VM
Page 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Page 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Page 12: ...12 User Guide April 2013 ...
Page 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Page 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Page 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Page 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Page 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Page 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Page 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Page 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Page 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Page 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Page 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Page 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...