...
Panel | ||||
---|---|---|---|---|
| ||||
As the GSM policies that are in the header have priority over those of the UTM, It is recommended that when creating a policy package to be used in provisioning, that they are created in the footer for security so that they do not overwrite important permissions of the UTM policies. |
...
Panel | ||||
---|---|---|---|---|
| ||||
Network - Traffic Shaping, otherwise the policy will not work. When deploying using a policy that uses QoS, it will be necessary to activate the WAN interface in |
...
1. Click on the “Create Device” option;
Provisioning – Create Device
...
2. The "Device" window is made up of the "General", "Network" and "Certificate" tab. When adding a device for provisioning fill the fields with the device settings, basically as if you were going to install a UTM normally. Complete the fields as shown below:
Create Device – Device - General
...
3. After filling in the fields on the "General" tab, fill in the fields on the "Network" tab, as shown below:
Create Device – Device - Network
...
- Hostname: Defines the Hostname. It can be anyone as long as it complies with the FQDN - Fully Qualified Domain Name. Ex.: GSM;
- Language: Select the default language. Ex.: English;
- Timezone: Select the time zone. Ex.: America/Sao_Paulo;
- Gateway: Sets the default route for the network. Ex.: 176.16.102.1;
- Suffix DNS: Determines the domain of the network. Ex.: blockbit.com;
- DNS Server: Defines the network or internet DNS server. Ex.: 176.16.102.161;
- NTP Server 1: Sets the clock synchronization server. Ex.: a.ntp.br;
- ETH[
- IP Address: Inform which network address the settings will be applied to;
- Net Mask: Inform which will be the netmask;
- Network zone: Determine the Network Zone. By default, the default options are: LAN, WAN and DMZ;
- DHCP Server[ ]: Enable this checkbox to distribute IP addresses as network devices request connection.
]: Activate the desired network interfaces by checking the checkbox;
...
Panel | ||||
---|---|---|---|---|
| ||||
If an IP is defined on the eth0 port, when performing the UTM provisioning, the IP change will be applied replacing DHCP, thus requiring the user to access the IP defined on port 98. |
...
4. After completing the fields on the "Network" tab, complete the fields on the "Certificate" tab, as shown below:
Create Device – Device - Certificate
...
5. To save changes, click [.
], otherwise click [ ] to close the windowSaved successfully
...
When saving the settings, a confirmation email will be sent to the address that is registered on the Blockbit License Portal. You will need to click on the link that will appear in the body of the email to actually start provisioning itself.
Provisioning - Confirmation email
...
A confirmation email will be sent when authorizing provisioning, as shown below:
Provisioning - Provisioning confirmation
...
It is possible to track the progress of provisioning through the Status and Progress column in the Provisioning tab of the GSM, as shown below:
Provisioning - Provisioning progress
...
It is also possible to see the provisioning progress through the UTM interface that will be provisioned. As shown in the following image:
Provisioning - Provisioning in progress
...
Panel | ||||
---|---|---|---|---|
| ||||
This screen will be displayed in Portuguese or English according to the user's browser settings. |
...
If provisioning is completed successfully, an automatic redirection to the login screen will occur, as shown below:
Provisioning - Redirect
...
Panel | ||||
---|---|---|---|---|
| ||||
Provisioning tab to get a more accurate view of the progress of the procedure. If there is a power outage at any time during provisioning, it is recommended to remove the provisioning that was made in GSM, access the CLI and use the rewizard command on the appliance, so that provisioning is restarted from the initial step and also to restart all installation settings that will be made in the UTM. ATTENTION: When performing Zero Touch provisioning, DO NOT turn off the device before you are actually able to log into UTM. Check the Status and Progress column on the GSM |
...
If provisioning is successful, the device will be displayed in the Inventory tab, in the same way as a manually linked device.
Provisioning - Device moved to Inventory tab
...
Panel | ||||
---|---|---|---|---|
| ||||
After finishing configuring Zero Touch Provisioning, if you need to send logs to GSM, access the Settings menu, Administration option, Central Management tab in UTM, check the Enable Manager [ ] checkbox and configure the Manager Address field with the IP of the GSM logger. |
...
If provisioning is not completed successfully, a panel with two buttons will appear:
Provisioning - Configure Provisioning
...
If provisioning does not occur because the DNS is unable to provide a valid path to the Blockbit License Portal, click on the button [
] so that the panel illustrated below is displayed, it is possible to configure a valid IP so that the UTM can properly license.Provisioning - Add a valid IP
Through the option [page.
] it is possible to make the configuration manually, when selecting this option you will be directed to the standard Wizard. This will also happen if the license has expired or expired, the user will be notified and directed to the normal Wizard. For more information on how to configure it, see the UTM Wizard configuration...