IronKey EMS On-Prem 7.1 Quick Start Guide

Similar documents
IronKey EMS Quick Start Guide. version 7.2 DataLocker Inc. June, 2018

Quick Start Guide. IronKey Enterprise Server 5.2

IronKey EMS On-Prem 7.1 Setup Guide

Ironkey EMS On-Prem Setup Guide. version 7.2 DataLocker Inc. June, 2018

Setup Guide. IronKey Enterprise Server 5.0

IronKey EMS Cloud. Quick Start Guide

VMware vfabric Data Director Installation Guide

VMware ESX ESXi and vsphere. Installation Guide

Free Download: Quick Start Guide

ITCorporation HOW DO I INSTALL A FRESH INSTANCE OF ANALYZER? DESCRIPTION RESOLUTION. Knowledge Database KNOWLEDGE DATABASE

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide

Quick Start Guide ViPR Controller & ViPR SolutionPack

MaaS360.com. MaaS360 On-Premises. Database Virtual Appliance Setup Guide

VMware vfabric Data Director Installation Guide

Dell Storage Compellent Integration Tools for VMware

ECDS MDE 100XVB Installation Guide on ISR G2 UCS-E and VMWare vsphere Hypervisor (ESXi)

Quick Start Guide ViPR Controller & ViPR SolutionPack

Cisco Prime Collaboration Deployment

Global Management System (GMS) Virtual Appliance 6.0 Getting Started Guide

Installing Cisco WebEx Social

Installation of Cisco Business Edition 6000H/M

Installing and Configuring vcloud Connector

vrealize Network Insight Installation Guide

VMware Skyline Collector Installation and Configuration Guide. VMware Skyline 1.4

VMware Identity Manager Connector Installation and Configuration (Legacy Mode)

dctrack Quick Setup Guide (Recommended) Obtain a dctrack Support Website Username and Password

Installing the Cisco Virtual Network Management Center

Installing vrealize Network Insight. VMware vrealize Network Insight 3.3

Deploying the Cisco Tetration Analytics Virtual

Product Version 1.1 Document Version 1.0-A

Basic Configuration Installation Guide

vrealize Network Insight Installation Guide

on VMware Deployment Guide November 2018 Deployment Guide for Unitrends Free on VMware Release 10.3 Version Provide feedback

Installing vrealize Network Insight

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2

Plexxi HCN Plexxi Connect Installation, Upgrade and Administration Guide Release 3.0.0

Cisco VVB Installation

SRA Virtual Appliance Getting Started Guide

Installing Your System Using Manual Deployment

Installing Cisco Virtual Switch Update Manager

Dell Storage Integration Tools for VMware

Installing and Upgrading Cisco Network Registrar Virtual Appliance

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0)

Install and Configure FindIT Network Manager and FindIT Network Probe on a VMware Virtual Machine

Cisco WebEx Meetings Server Administration Guide Release 1.5

Using vrealize Operations Tenant App as a Service Provider

Cisco WebEx Meetings Server Administration Guide

Dell Storage Compellent Integration Tools for VMware

akkadian Provisioning Manager Express

SteelCentral AppResponse 11 Virtual Edition Installation Guide

Netwrix Auditor. Virtual Appliance and Cloud Deployment Guide. Version: /25/2017

VMware Skyline Collector Installation and Configuration Guide. VMware Skyline Collector 2.0

KEMP360 Central - VMware vsphere. KEMP360 Central using VMware vsphere. Installation Guide

OneSign Virtual Appliance Guide

Using a Virtual Machine for Cisco IPICS on a Cisco UCS C-Series Server

Installing the Cisco Nexus 1000V Software Using ISO or OVA Files

Platform Compatibility... 1 Known Issues... 1 Resolved Issues... 2 Deploying the SRA Virtual Appliance... 3 Related Technical Documentation...

Installing and Configuring vcenter Support Assistant

Installing or Upgrading ANM Virtual Appliance

HiveManager Virtual Appliance QuickStart

Contents. Limitations. Prerequisites. Configuration

Connectra Virtual Appliance Evaluation Guide

Proofpoint Threat Response

RecoverPoint for Virtual Machines

Basic Configuration Installation Guide

Installing and Configuring vcloud Connector

Gnostice StarDocs On-Premises API Virtual Appliance

VMware Identity Manager Cloud Deployment. Modified on 01 OCT 2017 VMware Identity Manager

VMware Identity Manager Cloud Deployment. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager


akkadian Global Directory 3.0 System Administration Guide

Administration Guide for Cisco WebEx Meetings Server Release 2.8

Installing Cisco MSE in a VMware Virtual Machine

WatchGuard XTMv Setup Guide

Videoscape Distribution Suite Software Installation Guide

KEMP 360 Central for vsphere. Installation Guide

QUICK START GUIDE Cisco Virtual Network Management Center 2.0 Quick Start Guide

Deploy the ExtraHop Discover Appliance with VMware

Installation. Power on and initial setup. Before You Begin. Procedure

RealPresence Platform Director

DSI Optimized Backup & Deduplication for VTL Installation & User Guide

UDP Director Virtual Edition

WatchGuard XTMv Setup Guide Fireware XTM v11.8

Deploying the Cisco ASA 1000V

Online Help StruxureWare Central

Dell EMC Ready Architectures for VDI

NetScaler Analysis and Reporting. Goliath for NetScaler Installation Guide v4.0 For Deployment on VMware ESX/ESXi

Storage Manager 2018 R1. Installation Guide

Threat Response Auto Pull (TRAP) - Installation Guide

vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017

HyTrust CloudControl Installation Guide

Dell EMC Ready Architectures for VDI

Cisco Business Edition 7000 Installation Guide, Release 10.6

Installing vrealize Network Insight. VMware vrealize Network Insight 3.5

Cisco VDS Service Broker Software Installation Guide for UCS Platforms


Easy Setup Guide. Cisco FindIT Network Probe. You can easily set up your FindIT Network Probe in this step-by-step guide.

Cisco UCS Performance Manager Installation Guide

HyTrust Appliance Installation Guide

Transcription:

IronKey EMS On-Prem 7.1 Quick Start Guide Last Updated June 2017

System Requirements Requirement Description Database Microsoft SQL Server 2005, Microsoft SQL Server 2008, or Microsoft SQL Server 2012, Microsoft SQL Server Express 2005, Microsoft SQL Server Express 2008, Microsoft SQL Server Express 2012 Note: Only the default database instance is supported. IronKey EMS On-Prem does not support named instances. Host system requirements in ESXi environment vsphere ESXi version 5.0 or higher (the ESXi version must support the Guest OS CentOS v6.6 the OS on which IronKey EMS On-Prem is installed). See the VMware Compatibility Guide for more information. Ethernet physical network adapter Memory Physical datastore space Host machine must meet the minimum system requirements for this version in addition to minimum ESXi requirements provided by VMware. See VMware product documentation for more details: http://www.vmware.com Note: You must have VMware vsphere ESXi already installed and set up on your host before you install IronKey EMS On-Prem. Information on installing ESXi is outside the scope of this guide, see VMware product documentation. 1Gb or faster 4GB physical RAM 70GB available space Host system requirements in VMware Workstation 12 Player environment VMware Workstation 12 Player (or higher) Host machine must meet the minimum system requirements for this version in addition to minimum requirements provided by VMware. See VMware product documentation for more details: http://www.vmware.com NOTE: You must have VMware Workstation 12 Player already installed and set up on your host before you deploy IronKey EMS On-Prem. Information on installing VMware Workstation is outside the scope of this guide, see VMware product documentation. 2

Requirement Description Operating system Windows Server 2008 or Windows Server 2012 Ethernet physical network adapter Memory Hard Disk 1Gb or faster 4GB physical RAM 30GB free disk space required; 60GB recommended 3

4

Installation Worksheet Complete this worksheet to speed up installation. IronKey EMS ACCOUNT NUMBER (from Welcome Email) DOWNLOAD LINK TO IronKey EMS On-Prem SERVER OR PASSWORD FOR THE SETUP DEVICE IF YOU RECEIVED A SERVER KIT (from Welcome Email) CLI USERNAME (from Welcome Email) CLI PASSWORD (from Welcome Email) HOST NAME (to be assigned to IronKey EMS On-Prem) DNS SERVER IP STATIC IP ADDRESS (assigned to IronKey EMS On-Prem) SUBNET MASK (for IronKey EMS On-Prem) DATABASE SERVER IP OR FQDN DATABASE PORT DATABASE USERNAME & PASSWORD (required: db_owner privileges) DATABASE NAME (example: ent_server) SITE NAME FOR SSL CERTIFICATE (FQDN of server used on certificate) SSL CERTIFICATE FILE & CERTIFICATE CHAIN FILE (Save a backup copy of these files in a secure location) IP OR FQDN FOR SYSLOG SERVER (Optional) PRIMARY SYSTEM ADMIN EMAIL AND USERNAME DEFAULT GATEWAY IP (for IronKey EMS On-Prem) SECONDARY SYSTEM ADMIN EMAIL AND USERNAME NTP SERVER IP OR FQDN (optional) SMTP SERVER IP OR FQDN (check if your SMTP required a password) 5

Before Starting To speed up your installation, gather the following information and resources: Any required network (DNS, Gateway, IP assignment, SMTP, and NTP) information to set up a new machine in your data center. Database administration access for your Microsoft SQL Server required to install an instance of the database. Access to the network, systems, and ports that the above components will require. An SSL website certificate for a valid public domain from an approved certificate authority (VeriSign, RSA Security Inc., Thawte, GoDaddy, Comodo, Entrust. net, GeoTrust, Valicert, Visa, BeTrusted, Aba.com, AddTrust, Baltimore, DST, GTE, GlobalSign, Sonera, TC TrustCenter) A host computer with network capability and sufficient configuration (disk, memory) required to support the software you will install (see the System Requirements section) The Welcome Email sent to you by Customer Service at DataLocker. IronKey EMS On-Prem software downloaded or received in the Server Kit. This installation takes about an hour if all of the above items are ready. 6

Install IronKey EMS On-Prem Before installing the Server, give the IronKey_EMS_OnPrem_v71.bak file, located in the Utils folder of the server download (or on the Setup device if you received the Server Kit), to your database administrator to set up the database. IronKey EMS On-Prem provides two options for installing the server:» VMware vsphere ESXi environment» VMware Workstation 12 Player environment Choose the option that corresponds to your operating environment. Deploy IronKey EMS On-Prem in vsphere ESXi environment Steps 1 If you received IronKey EMS On-Prem as a download, go to step 3. If you received the IronKey EMS On-Prem Server Kit, insert the Setup device into the USB port of the host computer. If you do not see a prompt to unlock the device, in a file manager, go to My Computer and double-click the IronKey icon, then double-click IronKey.exe. 2 Enter the Setup device password, and then click the Unlock button. The Control Panel opens. The password is the same as your account number, which you received in the Server Kit and in the Welcome Email. 3 Login to the VMware vsphere ESXi server using VMware vsphere ESXi Client. You will be asked for the IP address/name of the host as well as the Username and Password. 4 In vsphere Client, click File, Deploy OVF Template. Note: If you have multiple Resource Pools in your ESXi environment, choose the Resource Pool to which you want to deploy the Server, and then click File, Deploy OVF Template. If you do not select a Resource Pool, you will be prompted to do so later in the setup. 5 On the Deploy OVF Template screen, click Browse. Navigate to the IronKey_EMS_OnPrem OVA folder from the server download file (or on the Setup device if you received the Server Kit) and select the IronKey_EMS_OnPrem.ova file, then click Next. 6 Click Next after verifying the details of the IronKey EMS On-Prem virtual machine template. 7 On the Name and Location screen, enter a virtual machine name that is unique to your ESXi inventory and click Next. 8 If prompted to select a Resource Pool, select it and click Next. 7

Steps 9 Select the destination storage for the virtual machine files. This screen will not display on ESXi servers with a single datastore. Click Next. 10 On the Disk Format screen, it is recommended that you choose the Thin Provision option to reduce the install time and to minimize disk space usage. Click Next. 11 On the Network Mapping screen, select the network that you want IronKey EMS On-Prem to use from the Destination Networks list box. This screen will not display on ESXi servers with only one VM network. Click Next. 12 Verify the installation options and click to enable the Power on after deployment check box. Click Finish. If you do not enable the Power on after deployment check box, you must start the VM manually after the deployment is completed. 13 An installation status dialog box will display to indicate how much time is left in the install process. Total time will vary depending on the ESXi CPU and the server disk throughput. 14 When the Deployment Completed Successfully dialog box displays, click Close. Deploy IronKey EMS On-Prem to VMware Workstation 12 Player Steps 1 If you received IronKey EMS On-Prem Server as a download, go to step 3. If you received the IronKey EMS On-Prem Server Kit, insert the Setup device into the USB port of the host computer. If you do not see a prompt to unlock the device, in a file manager, go to My Computer and double-click the IronKey icon, then double-click IronKey.exe. 2 Enter the Setup device password, and then click the Unlock button. The Control Panel opens. The password is the same as your account number, which you received in the Server Kit and in the Welcome Email. 3 Start VMware Workstation Player. On the Welcome screen, select Open a Virtual Machine. 8

Steps 4 Navigate to the IronKey_EMS_OnPrem OVA folder of the IronKey EMS On-Prem server download file (or on the Setup device if you received the Server Kit), select the IronKey_EMS_OnPrem.ova file, and then click Open. 5 On the Import Virtual Machine screen, do the following: Type a name for the IronKey EMS On-Prem virtual machine, for example IronKey_EMS. Provide a path to the location where the VM will be stored or click Browse to navigate to the storage location. Click Import. By default the VM is powered off after it s imported. 6 To start the IronKey EMS On-Prem VM, select it from the list and click Play virtual machine. TIP: You can also start the Server by right-clicking the Server and choosing Power On or double-clicking the Server. NOTE: You may see a warning about binary translation incompatibility if the Virtualization Technology setting is disabled in the BIOS of the host system. This is because IronKey EMS On-Prem uses a 32-bit operating system and this feature is not supported with a 32-bit OS. To avoid seeing the warning when you start the Server, do one of the following: Click the Do not show this hint again check box if you do not require the Virtualization Technology setting to be enabled in the BIOS. Then click OK. Enable the Virtualization Technology setting in the BIOS. The warning will not display the next time you start IronKey EMS On-Prem. 7 Select IronKey EMS On-Prem and press ENTER to start the server. 8 At the IronKey EMS Command Line Interface (CLI) for IronKey EMS On-Prem, log in using the CLI username and password provided in your Welcome Email. You will be required to change your login password. The password requirements are: 10 character minimum 1 uppercase letter 1 lowercase letter 1 digit 1 special character 9

Configure IronKey EMS On-Prem Steps 1 Start the IronKey EMS On-Prem VM if not already running.»» ESXi environment: Right-click the Server and choose Power, Power On.»» VMware Workstation 12 Player environment: Right-click the Server and choose Power On. 2 Log in to the Command Line Interface (CLI) shell using the CLI user and CLI password from your Welcome Email. The first time you log in, you will be required to change the password. 3 Set the host name: network hostname myhost.domain.com 4 Configure a static IP address: network interface static <static IP> <IP mask> <Gateway> 5 Add the DNS name server: network dns add <DNS server IP> 6 Add the NTP server: sysconf ntp addserver <NTP server IP or FQDN> If no NTP server is available, set the time (GMT) using the sysconf time command. IronKey EMS On-Prem will show the correct time once you set the date or add the NTP server. 7 Configure the SMTP server: sysconf smtp set <SMTP server IP or hostname:port> Answer Y or N to the authentication question. Does the relayhost <SMTP_server> require authentication (y/n)? 8 Configure the database server information: application database configure <DB server IP or hostname> <port ID> <DB username> <DB password> mssql <Database Name> 9 Set the URL of the server as it will be accessed by devices: application sitename set <site name> 10 Concatenate your private key and your SSL certificate into a single file, and then name the file: server.crt Name the certificate chain file: issuer.crt Use a Secure Copy (SCP) utility (e.g. command-line PSCP or GUI-based WinSCP) to copy the files to: /upload 11 Install the certificates: application certificate install 10

Steps 12 Enable HTTPS: application SSL enable 13 Start the application server: service start appserver Set up your IronKey EMS account Steps 1 Go to: https://<application sitename>/enterprisesetup (where <application sitename> is the value you entered in step 10 of the Configure IronKey EMS On-Prem procedure) From your Welcome email, copy the 10-digit account number (in the format XXXXX-XXXXX) and paste it into the IronKey EMS Account Number box. Click Enter. 2 In the License Request page, copy the string from the text box on the left and email it to: license@datalocker.com Check your email for a message from Customer Service. This may take 24-48 hours to complete. 3 On the License Request page, copy the license key from the Customer Service email and paste it into the text box on the right. Click Enter. 4 Select the check box to confirm that you are authorized to set up your organization s IronKey EMS account. Click Continue. 5 On the Create an online account for the first and second System Administrators page, enter an email address and the First and Last name of the first and second System Administrator. Click Continue. 6 On the Create the Default User Policy page, click Create Policy to open the policy setup. NOTE: The Default User Policy will be applied to the 1st and 2nd System Admin when they activate their online account. 11

Steps 7 On the Default User Policy page, scroll through and review each section. Configure the settings that you want to be included in the Default User Policy for your IronKey EMS Account. Each policy section displays the system default settings. When you finish setting all user policy options, scroll to the end of the Default User Policy and click OK to continue with the IronKey EMS Account Setup. 8 On the Review Default User Policy page, verify the policy settings and do one of the following. If you are satisfied with the policy selections, click Finish to complete the IronKey EMS Account Setup. If you need to change a setting, click Edit Policy. 9 A confirmation message will indicate that your IronKey EMS Account has been successfully created. Each System Admin will receive an email message with instructions on how to activate their online account. NOTE: It is recommended that you keep this confirmation page open until the System Admin users have received the activation email. If they do not receive it, you can resend the email by clicking Resend Activation Email. 10 Reboot IronKey EMS On-Prem. CLI command: sysconf reboot IMPORTANT If you do not reboot the Server before users activate devices, the activation process will fail. Be sure to perform this step before activating any devices. Activate the System Admin online account Steps 1 Open the activation email that was sent during the setup of the IronKey EMS Account. NOTE: If you did not receive an email, check your spam or bulk mail folder. 2 In the email message, click the Activation link. The Online Account Setup screen will open in a web browser. 12

Steps 3 On the Online Account Setup screen, do the following: In the Username text box, create a user name for your account. In the Password text box, create an account password and confirm the password. Passwords are case-sensitive and must comply with the password policy defined during the IronKey EMS Account setup. Select a question from the Secret Question list box or create your own secret question. In the Answer to Secret Question text box, provide the response to the secret question. The secret question will be used to verify your identity if you have to reset your password. Click Create Account. A confirmation message will display to indicate that you have successfully created your online account. 4 To log in to the management console, enter your IronKey EMS credentials (Username and Password) and click Log in. 5 On the Access Code page, follow the instructions onscreen to retrieve and paste the Access Code in the field provided, and then click the Submit button. A Welcome page will appear with information and instructions on next steps. 6 If you are the first System Admin to activate your online account and access the Admin Console, the Welcome page will prompt you to create the Default Device Policy. Click the Create Default Device Policy button to continue. NOTE: If you are the second System Admin to activate your online account, you will not be prompted to create the Default Device Policy. The management console will appear as soon as you close the Welcome page. 7 On the Default Device Policy page, scroll through and review each section. Configure the settings and applications that you want to be included in the Default Device Policy for your IronKey EMS Account. Each policy section displays the system default settings and lists the devices to which these settings apply. IMPORTANT: In the Password Policy section, under General Password Settings, configure the Max Failed Unlock Attempts setting with a balance of security and end-user convenience in mind. If the user exceeds the maximum, the device will self-destruct and all data will be permanently lost. The drive can no longer be used. D300M and Sentry EMS devices do not self-destruct but will reset to a factory state, erasing all onboard data. 13

Steps 8 When you finish setting all device policy options, scroll to the end of the Default Device Policy and click Save. 9 The management console will open in your web browser. You can now start adding users and managing your IronKey EMS account. This product provides warranty and compliance agreements as noted at http://support.datalocker.com. NOTE: DataLocker is not liable for technical or editorial errors and/or omissions contained herein; nor for incidental or consequential damages resulting from the furnishing or use of this material. The information provided herein is subject to change without notice. The information contained in this document represents the current view of DataLocker on the issue discussed as of the date of publication. DataLocker cannot guarantee the accuracy of any information presented after the date of publication. This document is for information purposes only. DataLocker makes no warranties, expressed or implied, in this document. DataLocker, and the DataLocker logo are trademarks of DataLocker Inc. and its subsidiaries. All other trademarks are the property of their respective owners. is a registered trade mark of Kingston Technologies, used under permission of Kingston Technologies. All rights reserved.. 2017 DataLocker Inc.. All rights reserved. IronKey EMS On-Prem Server v7.1.0.0 software June 2017. IK-EMS-QSG01-6.0 See the IronKey EMS On-Prem Setup Guide and the Admin Guide for more information. 14