1. Choose
join
from the Setup menu to add the ASA 310-FIPS to an existing
cluster.
[Setup Menu]
join - Join an existing iSD cluster
new - Initialize iSD as a new installation
boot - Boot menu
info - Information menu
exit - Exit [global command, always available]
>> Setup#
join
Setup will guide you through the initial configuration of the
iSD.
2. Follow the instructions for joining a VPN Gateway to an existing cluster.
Read the sections starting with
Joining a VPN Gateway to an Existing Cluster
on
page 51. When the basic setup is completed, new prompts for configuring the ASA
310-FIPS will automatically appear (see
3
on page 62).
3. Initialize HSM card 0 by inserting the first pair of HSM-SO and HSM-USER iKeys,
and by defining passwords.
Step 3
on page 63 and
step 4
on page 63 are related to initializing the HSM
cards that your ASA 310-FIPS is equipped with. The Setup utility will identify the
first HSM card as card 0, and the second HSM card as card 1. Make sure you have
the required iKeys before proceeding. To successfully initialize both HSM cards,
you need to have the following iKeys:
• One pair of iKeys to be used for initializing HSM card 0.
- The purple HSM Security Officer iKey, embossed with "HSM-SO".
- The blue HSM User iKey, embossed with "HSM-USER".
Label these iKeys and HSM card 0 in a way so that the connection between
them is obvious. After HSM card 0 has been initialized, this card will only accept
the HSM-SO and HSM-USER iKeys used when initializing this particular HSM
card. Even if you choose to use the same HSM-SO and HSM-USER
passwords when you initialize card 1 as the passwords you defined when
initializing card 0, the HSM-SO and HSM-USER iKeys for card 1 are not
interchangeable with the HSM-SO and HSM-USER iKeys for card 0.
• One pair of iKeys to be used for initializing HSM card 1.
- The purple HSM Security Officer iKey, embossed with "HSM-SO".
- The blue HSM User iKey, embossed with "HSM-USER".
Label these iKeys and HSM card 1 in a way so that the connection between
them is obvious. Because you will have more than one ASA 310-FIPS ASA
310-FIPS device in the cluster, you must also take steps to identify which pair
of iKeys is used on which HSM card on which device in the cluster.
You also need to make sure that you can easily access the USB ports on the HSM
cards, located on the rear of the ASA 310-FIPS device. When an operation requires
Initial Setup
62 User Guide
April 2013
Comments? infodev@avaya.com
Summary of Contents for 3050-VM
Page 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Page 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Page 12: ...12 User Guide April 2013 ...
Page 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Page 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Page 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Page 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Page 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Page 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Page 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Page 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Page 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Page 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Page 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Page 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...