Veritas Access Appliance 8.4 Initial Configuration Guide

Last Published:
Product(s): Appliances (8.4)
Platform: Veritas 3350,Veritas 3340,Veritas 3360
  1. Getting to know the Access Appliance
    1.  
      About the Veritas Access Appliance
    2. About the Access Appliance administration interfaces
      1.  
        Using the Access Appliance shell menu
    3. About licensing the Access Appliance
      1.  
        About subscription licensing
    4.  
      Where to find the documentation
  2. Preparing to configure the appliance
    1.  
      Initial configuration requirements
    2.  
      About obtaining IP addresses for Veritas Access
    3.  
      Network and firewall requirements
    4.  
      About network connections for the appliance
  3. Configuring the appliance for the first time
    1. How to configure the Access Appliance for the first time
      1.  
        Configuring the Access cluster on the appliance
  4. Getting started with the Veritas Access GUI
    1.  
      Accessing the Veritas Access web interface
  5. Network connection management
    1. Configuring network address settings on the appliance nodes
      1.  
        Deleting network settings on appliance nodes
      2.  
        About NIC1 (eth0) port usage on the appliance nodes
      3.  
        About IPv4-IPv6-based network support on the Access Appliance
    2. Configuring VLAN settings on the appliance nodes
      1.  
        Viewing VLAN settings
      2.  
        Deleting a VLAN
    3. About the Veritas Remote Management Console
      1.  
        Configuring the IPMI port on an appliance node
      2.  
        Managing IPMI users on an appliance node
      3.  
        Resetting the IPMI on an appliance node
  6. Resetting the appliance to factory settings
    1.  
      About appliance factory reset
    2.  
      Performing factory reset for cluster nodes
  7. Appliance security
    1.  
      About Access Appliance security
    2. About Access appliance user account privileges
      1. Access appliance admin password specifications
        1.  
          Password encryption and handling on the Access appliance
    3.  
      About forced password changes
    4.  
      Changing the Maintenance user account password
    5. About the Access Appliance intrusion detection system
      1.  
        Reviewing SDCS events on the Access Appliance
      2.  
        Auditing the SDCS logs on an Access Appliance
      3.  
        About SDCS event type codes and severity codes on an Access appliance node
      4.  
        Changing the SDCS log retention settings on an Access Appliance node
    6.  
      About the Access Appliance intrusion prevention system
    7. About Access appliance operating system security
      1.  
        Vulnerability scanning of the Access Appliance
      2.  
        Disabled service accounts on the Access appliance
    8.  
      About data security on the Access appliance
    9.  
      About data integrity on the Access appliance
    10. Recommended IPMI settings on the Access appliance
      1.  
        Replacing the default IPMI SSL certificate on the Access appliance

Initial configuration requirements

Review the information in this topic before you perform the initial configuration on the Veritas Access Appliance.

Network information

For the appliance itself, you need to acquire the following network information:

  • Two IP addresses for appliance node management over IPMI for a two-node appliance configuration. One IP address for the appliance node management over IPMI for a 3360 one-node appliance configuration.

  • Two IP addresses for appliance node management over eth1 for a two-node appliance configuration. One IP address for appliance node management over eth1 for a 3360 one-node appliance configuration.

  • DNS (used for AutoSupport services)

  • Static route and other advanced routing information

  • IP address or the FQDN of the Network Time Protocol (NTP) server. If you use an FQDN for the NTP server, you must configure the DNS server.

  • (Optional) VLAN information

  • (Optional) Proxy server addresses and credentials (used for AutoSupport services)

  • (Optional) SMTP or SNMP information for receiving appliance notifications and alerts

Required DNS settings

Veritas strongly recommends that you configure DNS on the appliance node. The IP address assigned to the eth1 network interface must be resolved to a valid host name via the DNS server lookup or the local hosts file. A unique DNS entry is required for eth1 on each node.

The DNS server must be configured if you use the CallHome feature. Without the DNS entries, the AutoSupport client cannot send out alert emails and the system health collector cannot work properly.

You must also configure the DNS server if you use an FQDN for the NTP server.

Required credentials

Two user accounts are used during initial configuration: admin and maintenance. The admin account is the user that logs into the appliance nodes and performs all necessary configuration steps. The maintenance user account is required when you perform operations that require access to the operating system.

You are required to change the factory default admin and maintenance passwords during the initial configuration.

Both the admin and maintenance user accounts use the same default password on new appliances:

  • User name: admin or maintenance

  • Password: P@ssw0rd

Access to the Access Appliance shell menu

Ensure that you can access the Access Appliance shell menu. All initial configuration tasks are done using this interface.

Table: Methods to access the Access Appliance shell menu

Method

Description

Veritas Remote Management Console (recommended)

You can use the Veritas Remote Management Console to launch a virtual KVM of the Access Appliance shell menu as if you were using a keyboard and mouse that are connected directly to the appliance.

Note:

You can only access the Veritas Remote Management Console if you have provisioned network access to the IPMI port on the appliance nodes (which is normally done as part of the hardware installation process).

See Configuring the IPMI port on an appliance node.

SSH

You can use SSH for initial configuration if you have provisioned network access to the eth0 port on the appliance nodes.

See About NIC1 (eth0) port usage on the appliance nodes.

Physical keyboard and monitor connected to the appliance

You can physically connect a standard VGA monitor and USB keyboard to the appliance node. If the appliance is powered on, the monitor displays the logon prompt for the Access Appliance shell menu.

Connectivity during initial configuration

If you configure the appliance from a remote computer, you must take precautions to avoid loss of connectivity. Any loss of connectivity during initial configuration results in failure.

Before you log onto the Access Appliance shell menu, ensure that your computer is set up to avoid the following:

  • Conditions that cause the computer to go to sleep

  • Conditions that cause the computer to turn off or to lose power

  • Conditions that cause the computer to lose its network connection