Review Resources for UNIX or Linux
Before installation, review any network and security-specific configuration details relevant for the hardware used to install CM and the engine. Consider details that are specific to your environment.
Refer to the following list of resources as you plan the use of network and security-related resources to install and configure Secure Proxy:
Configuration Resource |
Secure Proxy Usage |
|---|---|
TCP ports |
Use available port numbers, in appropriate port ranges. The following Secure Proxy components require listening ports:
|
Internet Explorer or Firefox |
Access the CM logon screen from Microsoft™ Internet Explorer or Mozilla Firefox. |
CM |
Install CM in the trusted company zone. You can set up multiple engines with the same CM, but only one CM can be set up to control an engine. CM port handles listen requests from the Jetty web server. The default port number is 62366. |
Jetty web server |
The Jetty web server is installed when you install CM, and handles listen requests from the web browser. The web server port number is an element specified in the address bar when connecting to the logon screen. The default port number for the Jetty web server is 8443. |
Secure Proxy engine |
The engine operates during production, and routes traffic. Install an engine in the DMZ. The default port number is 63366. If you install the engine on a computer with more than one Network Interface Card (NIC), specify the IP bind address of the card associated with that engine. When you define an engine in CM, you identify either the host name or the IP address in the definition. Create only one definition for each engine you install. |
Perimeter server |
A local perimeter server is installed when you install the engine. It manages communications between the engine and other nodes. You can install a remote perimeter server separately on another computer. |
Sterling External Authentication Server |
To provide another level of security by authenticating users or certificates, or mapping users, install Sterling External Authentication Server. For more information, refer to the Sterling External Authentication Server documentation library. |
Default certificates |
To secure communication, Secure Proxy is configured with default certificates that are exchanged between CM and the engine. Replace these certificates with your own after installation. Refer to Manage Certificates Between Secure Proxy Components on the documentation library. |