Creating a Connect:Direct netmap
You define connection information for every Connect:Direct® node that communicates by using Secure Proxy. These values are stored in a netmap. The netmap is associated with a policy and an adapter.
About this task
Before you begin this procedure, create a policy to associate with the netmap.
To create a netmap and define Connect:Direct nodes:
Procedure
What to do next
- Check Enable Access Control for Outbound connections.
- Select a node from the list of nodes.
- Click Edit.
- Click the Outbound ACL tab.
- From the Available Outbound Nodes: list, select the nodes that you want the PNode to communicate with.
- Click → to move the selected nodes to Authorized Outbound Nodes.
- Repeat steps 2 through 6 to create more ACLs.
- Click Save. Attention: If you check Enable Access Control for Outbound connections and do not configure any ACLs, a warning message is displayed when you click Save. The netmap is successfully saved.Attention: If you do not check Enable Access Control for Outbound connections and configure one or more ACLs, Secure Proxy does not enforce the ACLs.Important: If you use standard routing to connect to Connect:Direct in the secure zone, you identify a primary server to connect to in the adapter. You can also identify up to three alternate outbound nodes for situations when the primary Connect:Direct server is not available. Two methods of configuring alternate server routing are available:
- Select a previously defined outbound node from the netmap–you must include this alternate outbound node in the ACL or the connection fails.
- Enter an IP address and port–the ACL is not applied to this alternate outbound node and the connection does not fail because of the ACL.
- If the ACL check fails on the primary outbound node, the Connect:Direct proxy adapter does not attempt connections with any of the specified alternate nodes.
- If the ACL check fails on any specified alternate node, the Connect:Direct proxy adapter attempts connections with the remaining alternate nodes.