SunScreen 3.1 Reference Manual

Primary/Secondary Tab

The Primary/Secondary tab associates a certificate object with a Screen that is part of an HA cluster or a CMG. The High Availability choice (No, Primary, or Secondary) and the Primary Name choice determine the role a Screen has within an HA cluster and centralized management group (CMG). The settings you choose determine which other controls on the Primary/Secondary tab are active. FIGURE 5-25 shows the Primary/Secondary tab of the Screen dialog box.

Figure 5-25 Primary/Secondary Tab on the Screen Dialog Box

Graphic

TABLE 5-25 describes the controls for the Primary/Secondary tab.

Table 5-25 Controls for the Primary/Secondary Tab of the Screen Dialog Box

Control 

Description 

Name 

Specifies a name for the Screen object. 

  1. The entry in the Name field must be the same as the entry that exists in the nameservice lookup or in the /etc/hosts file. The IP address associated with this name must match the IP address of the administrative interface.

  2. The type of interfaces must be the same on all the machines in the HA cluster. This interface must be dedicated on each machine in the HA cluster with a dedicated network connection. For reasons of security, the HA network should not be connected to any other network. The HA primary Screen is always the Screen you administer whether it is the active or passive Screen.

Description 

(Optional) Provides a brief description of the Screen object. 

High Availability 

Specifies whether the Screen is used for HA. If you are using it for HA, you can specify whether the Screen is a primary HA Screen or a secondary HA Screen.  

Primary Name 

Specifies the name of the primary Screen. This is the primary of this Screen if this Screen is an HA secondary, or the primary of a centralized management group if you want this Screen to be a CMG secondary. 

Administrative IP 

IP address of the Screen that is used for administration. This is the IP address or an address group that contains all interface addresses of the Screen. 

Administration Certificate 

Specifies the name of the Screen's Administration certificate.  

High Availability IP Address 

Specifies the IP address of the HA interface.  

Ethernet Address 

Generated by the system.  

Key Algorithm 

  • Specifies the key encryption algorithm that will be used. The options available depend upon the strength of the encryption installed.

Data Algorithm 

  • Specifies the key encryption algorithm that will be used. The options available depend upon the strength of the encryption installed.

MAC Algorithm 

Specifies the MAC (authentication) algorithm that will be used. The options are: 

  • none

  • MD5

  • MD5-NAT

OK Button 

Stores the new or changed information and makes the Save Changes command button active. 

Cancel Button 

Cancels any new or changed information. 

Help Button 

Calls up the page of online help for this common object.