Documentation Home
> SunScreen 3.1 Installation Guide
SunScreen 3.1 Installation Guide
Book Information
Preface
Chapter 1 Installation Overview
What Is SunScreen?
Local Administration
Remote Administration
Firewall Operation Modes
Routing Mode
Stealth Mode
Mixed Mode
Before You Install
Upgrading to SunScreen 3.1
Upgrading From Previous Versions of SunScreen
Upgrading From SPF-200 to SunScreen 3.1
Converting From FireWall-1 to SunScreen 3.1
Trusted Solaris
Security Issues
Software and Hardware Requirements
Operating System Package Requirements
Screen Solaris Packages
Administration Station Solaris Packages
Additional Requirements and Restrictions
Web Browser Requirements
Accessing Local System Resources
Browsers Without Local File Access
Browsers With Local File Access
Chapter 2 Installation Considerations
Determining Your Security Policy
Mapping Your Network Configuration
Deciding on Your Initial Security Level
Security Levels
Naming Services
Interfaces
Worksheets for Defining Security Policies
Creating Service Groups
Addresses
NAT
Rules
Four Action Types
Chapter 3 Installing in Routing Mode With Local Administration
Before You Begin
To Install SunScreen 3.1
Post Installation Tasks
To Set the PATH
To Install SKIP Upgrades
Managing Your Firewall
Chapter 4 Installing in Routing Mode With Remote Administration
Supported Administration Station Configurations
Installation Overview
Installing the Administration Software
To Install the Administration Software on the Administration Station
To Install SKIP Upgrades
What Is Next?
Installing Certificates on the Administration Station
To Install a Self-Generated Certificate
What Is Next?
To Install an Issued Certificate
What Is Next?
Installing the Software on the Screen
To Install Screen Software
Finishing the Screen Installation
To Set the PATH
To Install SKIP Upgrades
To Display the AdminSetup.readme File
What Is Next?
Completing SKIP Setup on the Administration Station
To Set Up SKIP on the Administration Station
Managing Your Firewall
To Launch the Administration GUI
Chapter 5 Installing in Stealth Mode
Stealth Mode Overview
Installation Overview
Installing the Administration Software
To Install the Software on the Administration Station
Installing the Software on the Screen
To Install the Software on the Screen
To Finish the Installation
To Launch the Administration GUI
Chapter 6 Installing on Trusted Solaris
Overview
Before You Install
To Edit the System Profile
To Give the Install Program the Proper Role
To Assign the Profile to the Root Role
Installing SunScreen Software
To Install the Screen
To Install the Administration Station
Chapter 7 Upgrading From SunScreen EFS and SunScreen SPF-200
Before You begin
Upgrade Overview (SunScreen EFS 1.1, 2.0, or 3.0)
Preparing to Upgrade
To Install the Solaris and Kernel Patches on the Screen
To Install the Solaris Packages on the Remote Administration Station
Upgrading a Locally Administered SunScreen EFS Screen
To Upgrade a Locally Administered SunScreen EFS Screen
Upgrading a Remotely Administered SunScreen EFS Screen
To Upgrade the Screen
To Upgrade the Remote Administration Station
Upgrading an High Availability (HA) System
Overview
To Upgrade a SunScreen EFS HA Secondary Machine
Remove the SunScreen EFS Software
Install SunScreen 3.1
Before You Begin
Install the Software
To Upgrade the HA Primary Machine
Run the Upgrade Program
Complete the HA Primary Upgrade
Overview
Steps
To Finish the HA Upgrade
SunScreen EFS 3.0 to SunScreen 3.1
SunScreen EFS 2.0 to SunScreen 3.1
Upgrading From SunScreen SPF-200 to SunScreen 3.1 in Stealth Mode
Chapter 8 Converting FireWall-1 to SunScreen 3.1 in Routing Mode
Preparing Your FireWall-1 Configuration
Reserved Characters
Reserved Words
What Does and Does Not Convert
SunScreen 3.1 Conversion Utility
Generating Conversion Files
To Run the Conversion Utility
Troubleshooting the fwconvert Utility
Conditions for Failure
To Clear Conversion Errors (Except Parse Errors)
To Clear Parse Errors
Verifying the Converted Rules
Command and Executable Files
Log Files
policy.name_Obj.log
policy.name_Rule.log
policy.name_Unused.log
Creating the SunScreen 3.1 Configuration
Option 1: To Prepare the FireWall-1 Machine to Run SunScreen 3.1
What Is Next?
Option 2: To Prepare a New SunScreen Machine to Run the Converted FireWall-1 Configuration
What Is Next?
To Generate the New SunScreen Configuration
Chapter 9 Removing SunScreen 3.1
To Remove SunScreen
Appendix A Command Line Installation
Installing the Administration Station
To Install the Software on the Administration Station
To Install Administration Station Certificates
To Create a Self-Generated Certificate on the Administration Station
To Install an Issued Certificate on the Administration Station
Installing the Screen
To Install the Screen
To Use Command-Line SKIP on the Administration Station
Appendix B Upgrading Cryptography Modules
To Install SKIP Upgrades
Index
A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
R
S
U
V
W
© 2010, Oracle Corporation and/or its affiliates