12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Setting Up the Management ServerSetting Up the Management ServerThe Management Server Setup wizard creates a new Management Server on your workstation. If youused earlier versions of <strong>WatchGuard</strong>® System Manager and VPN Manager, you can also use the wizard tomigrate a DVCP Server that is installed on a Firebox® to a new Management Server on a workstation. Tomove a Management Server off a Firebox, see the WFS to Fireware Migration <strong>Guide</strong>.We recommend that you install the Management Server software on a computer with a static IP addressthat is behind a Firebox with a static external IP address. Otherwise, the Management Server may notoperate correctly.This procedure shows the steps you must use to successfully set up a new Management Server. Use thisprocedure if you do not have a Management Server at this time.1 Right-click the Management Server icon in the <strong>WatchGuard</strong> toolbar on the Windows taskbarYou do not see this icon if you have not installed the Management Server.2 Select Start Service.3 The Management Server Setup wizard starts. Click Next.4 A master encryption key is necessary to control access to the <strong>WatchGuard</strong> management station.Type a passphrase that has a minimum of eight characters and then type it again to confirm. ClickNext.Make sure you keep this passphrase in a safe place.5 Type the Management Server passphrase to use when you configure and monitor the <strong>WatchGuard</strong>Management Server. Use a passphrase that has a minimum of eight characters and then type itagain to confirm. Click Next.6 Type the IP address and passphrases for your gateway Firebox. The gateway Firebox protects theManagement Server from the Internet. When you add an IP address, the wizard does three things:- The wizard uses this IP address to configure the gateway Firebox to allow connections to theManagement Server. If you do not type an IP address here, you must configure any firewallbetween the Management Server and the Internet to allow connections to the ManagementServer on TCP ports 4110, 4112, and 4113.- If you have an earlier version of <strong>WatchGuard</strong> System Manager, and have a Firebox configuredas a DVCP server, the wizard gets the DVCP server information from the gateway Firebox andmoves these settings to your Management Server. See the Migration <strong>Guide</strong> for moreinformation.- The wizard sets the IP address for the Certificate Revocation List. The devices you add asmanaged clients use this IP address to connect to the Management Server. This IP addressmust be the public IP address your Management Server shows to the Internet. If you do nottype an IP address here, the wizard uses the current IP address on your Management Servercomputer for the CRL IP address. If this is not the IP address your computers shows to theInternet because your computer is behind a device that does Network Address Translation(NAT), you must edit the CRL and type the public IP address your Management Server uses.For more information, see “Changing the Management Server Configuration” on page 200.7 Type the license key for the Management Server. Click Next.For more information on Management Server license keys, see this Advanced FAQ:https://www.watchguard.com/support/AdvancedFaqs/wsm8_srvrkey.asp8 Type the name of your organization. Click Next.This name is used for the Certificate Authority on the Management Server.<strong>User</strong> <strong>Guide</strong> 199

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!