Chapter 2: First-Time Configuration
25
7
(Optional) The options on page 3 restrict access to the SG200.
Figure 2-12: Initial Setup—Page Three
8
On page 4, press <Enter> or type
No
if you do not want to enter a forwarding host at this time, or type
Yes
to enter a forwarding host.
If you type
Yes
, you must also provide a host alias and a host name or IP address.
Note:
For maximum security, restrict physical access to the SG200.
Note:
After completing the initial configuration, you can change the workstation restriction
settings through the security commands in the CLI or the Console Access page in the
Management Console (under Authentication). You can add or remove IP addresses or
you can enable or disable workstation restrictions. Refer to
Volume 5: Securing the
ProxySG
of the
Blue Coat ProxySG Configuration and Management Guide Suite
for
details.
--------------------- (page 3 of 5) --------------------
Press <ESC> at any time to return to the main menu
DIRECTIONS:
The console username and password are special: they can be used to
log in to the CLI or Web Management interface even in circumstances
where this is denied by VPM or CPL policy. This makes the console
account useful in emergencies, as a way to log in when policy is
broken, but it may also create a security hole.
To close the security hole, we recommend that you restrict the use of
the console account to specific workstations, identified by their IP
address.
This dialog allows you to add one IP address to the list of
workstations that are authorized to use the console account. (This
same list is also used to restrict which workstations can use SSH
with RSA authentication.) Additional workstations may be configured
later, from the command line interface or the Web interface.
WARNING: The console account can currently be used to log in from any
workstation.
Would you like to restrict access to an authorized workstation? Y/N
[Yes]
Y
Authorized workstation [0.0.0.0]:
10.2.33.1