18.11.2014 Views

Clavister cOS Core Administration Guide

Clavister cOS Core Administration Guide

Clavister cOS Core Administration Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2: Management and Maintenance<br />

based computer. The server serves as a repository for all <strong>cOS</strong> <strong>Core</strong><br />

configuration data and mediates all management commands sent<br />

by clients.<br />

More information about InControl can be found in the separate<br />

InControl Administrators <strong>Guide</strong>.<br />

The Web Interface<br />

The Web Interface (also known as the Web User Interface or WebUI)<br />

is built into <strong>cOS</strong> <strong>Core</strong> and provides a user-friendly and intuitive<br />

graphical management interface, accessible from a standard web<br />

browser.<br />

The browser connects to one of the hardware's Ethernet interfaces<br />

using HTTP or HTTPS and the <strong>cOS</strong> <strong>Core</strong> responds like a web server,<br />

allowing web pages to be used as the management interface.<br />

The Web Interface does not provide centralized management<br />

control of multiple <strong>Clavister</strong> Security Gateways. One browser<br />

window can communicate with one <strong>Clavister</strong> Security Gateway,<br />

although it is possible to have multiple browser windows open at<br />

the same time.<br />

This feature is fully described in Section 2.1.3, “The Web Interface”.<br />

The CLI The Command Line Interface (CLI), accessible locally via serial<br />

console port or remotely using the Secure Shell (SSH) protocol,<br />

provides the most fine-grained control over all parameters in <strong>cOS</strong><br />

<strong>Core</strong>.<br />

This feature is fully described in Section 2.1.4, “The CLI”.<br />

Secure Copy<br />

Secure Copy (SCP) is a widely used communication protocol for file<br />

transfer. No specific SCP client is provided with <strong>cOS</strong> <strong>Core</strong><br />

distributions but there exists a wide selection of SCP clients<br />

available for nearly all workstation platforms.<br />

SCP is a complement to CLI usage and provides a secure means of<br />

file transfer between the administrator's workstation and the<br />

<strong>Clavister</strong> Security Gateway. Various files used by <strong>cOS</strong> <strong>Core</strong> can be<br />

both uploaded and downloaded with SCP.<br />

This feature is fully described in Section 2.1.6, “Secure Copy”.<br />

Console Boot Menu<br />

Before <strong>cOS</strong> <strong>Core</strong> starts running, a console connected directly to the<br />

<strong>Clavister</strong> Security Gateway's RS232 port can be used to do basic<br />

configuration through the boot menu. This menu can be entered<br />

by pressing any console key between power-up and <strong>cOS</strong> <strong>Core</strong><br />

starting. It is the <strong>Clavister</strong> firmware loader that is being accessed<br />

with the boot menu.<br />

The menu is fully described in Section 2.1.7, “The Console Boot<br />

Menu”.<br />

Remote Management Policies<br />

Access to remote management interfaces can be regulated by a remote management policy so<br />

the administrator can restrict management access based on source network, source interface<br />

and username/password credentials.<br />

32

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!