12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing Devices with the Management ServerNoteIf the Firebox you want to manage has a static IP address on its external interface, you can stop here.Save the configuration to this Firebox. You can now add the device to your Management Serverconfiguration. When you add this Firebox to the Management Server configuration, the ManagementServer automatically connects to the static IP address and configures the Firebox as a managed Fireboxclient.If the Firebox you want to manage has a dynamic IP address, go on to step 8.8 From Policy Manager, select VPN > Managed Client.The Managed Client Setup dialog box appears.9 To set up a Firebox as a managed device, select the Enable this Firebox as a Managed Client checkbox.10 In the Client Name box, type the name you want to give the Firebox when you add it to theManagement Server configuration.This name is case-sensitive and must match the name you use when you add the device to the Management Serverconfiguration.11 To enable the managed client to send log messages to the Log Server, select the Enable diagnosticlogs check box. (We recommend this option only to perform troubleshooting.)12 In the Management Server address box, type the IP address of the Management Server if it has apublic IP address. Or, type the public IP address of the Firebox that protects the Management Server.The Firebox protecting the Management Server automatically monitors all ports used by the ManagementServer and will forward any connection on these ports to the configured Management Server. The Fireboxprotecting the Management Server is configured to do this when you run the Management Server SetupWizard.If you did not use the Management Server Setup Wizard on the Management Server, or, if you skipped the“Gateway Firebox” step in the wizard, configure the gateway Firebox to forward TCP ports 4110, 4112, and4113 to the private IP address of the Management Server.13 In the Shared Secret box, type the shared secret. Type it again to confirm.The shared secret you type here must match the shared secret you type when you add the Firebox to the ManagementServer configuration.14 Click the Import button and import the CA-Admin.pem file as your certificate.<strong>User</strong> <strong>Guide</strong> 209

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!