Ensure that the required Solaris software packages reside on the Screen and the Administration Station as described below.
Install third-party content scanning products on a system separate from your SunScreen firewall to avoid possible security risks, as well as to avoid overloading your system when the content is large.
When installing the SunScreen software on your Screen remotely from an Administration Station or if you choose to use the command-line interface instead of the administration GUI, install the Solaris Core Distribution software as well as the packages listed in the following table from your Solaris CD, if not already on your system.
When installing only the Solaris Core Distribution software, either change your DISPLAY variable for using the installer to a windowing system or install SunScreen using the command-line installation procedure described in the "Command Line Installation" appendix in this manual.
When installing the SunScreen software on your Screen locally, install the Solaris End User Distribution software as well as the packages listed in the following table from your Solaris CD, if not already on your system.
Table 1-2 Solaris Packages for Screen System
Package Name |
Description |
---|---|
SUNWlibc |
Sun Workshop Compilers Bundled libC |
SUNWlibms |
Sun WorkShop Bundled shared libm |
SUNWsprot |
Solaris Bundled tools |
SUNWxwplt |
X Window System platform software |
SUNWmfrun |
Motif RunTime Kit |
SUNWloc |
System Localization |
SUNWxwice |
X Window System Inter-Client Exchange (ICE) Components |
SUNWxwrtl |
X Window System & Graphics Runtime Library Links in /usr/lib |
SUNWtoo |
Programming Tools |
SUNWtoox |
Programming Tools (64-bit) |
SUNWeuluf |
UTF-8 L10N For Language Environment User Files |
SUNWeulux |
UTF-8 L10N For Language Environment User Files (64-bit) |
SUNWjvrt |
JavaVM run time environment |
For Trusted Solaris 8 only SUNWj2rt |
JDK 1.2 run time environment |
For Solaris 9 only SUNWj3rt SUNWapchr SUNWapchu SUNWeu8os SUNWeu8osx |
J2SDK 1.4 runtime environment Apache Web Server (root) Apache Web Server (usr) American English/UTF-8 L10N For OS Environment User Files American English/UTF-8 L10N For OS Environment User Files (64-bit) |
SUNWcryr |
Cryptography packages for IKE. Optional for Solaris 9 unless AES or Blowfish is required. Required for Trusted Solaris. |
SUNWcryrx |
Cryptography packages for IKE(64-bit). Optional for Solaris 9 unless AES or Blowfish is required. Required for Trusted Solaris.
|
When installing the SunScreen software remotely using the administration GUI, install the following packages on your Administration Station from your Solaris CD, if not already on your system.
Table 1-3 Solaris Packages for Administration Station
Package Name |
Description |
---|---|
SUNWjvrt |
JavaVM run time environment |
SUNWxwplt |
X Window System platform software |
SUNWmfrun |
Motif RunTime Kit |
SUNWcryr |
Cryptography packages for IKE. Optional for Solaris 9 unless AES or Blowfish is required. Required for Trusted Solaris 8. |
SUNWcryrx |
Cryptography packages for IKE(64-bit). Optional for Solaris 9 unless AES or Blowfish is required. Required for Trusted Solaris 8.
|
In addition to the patches included on your SunScreen CD, make sure you install all recommended security patches available for your operating environment. For security reasons, always keep your operating environment up to date with available patches.
Use the command-line interface to create IKE self-generated certificates.
SunScreen 3.2 on the Solaris 8 operating environment supports IPv4 packets according to the policy but blocks IPv6 packets.
A routing-mode Screen supports an unlimited amount of network interfaces, all of which must be configured in Solaris; while a stealth-mode Screen supports up to 15 network interfaces at one time, and only the network interface that is used for remote administration is configured in Solaris. See the documentation accompanying your Solaris software.
The SunScreen CD includes the SunScreen SKIP, revision 1.5.1, software. The SunScreen SKIP version of Windows 95/98 and NT4.0 is available separately.
A remote Administration Station connects directly to a Screen only through an Ethernet local area network (LAN) or a Fiber Distributed Data Interface (FDDI). Once connected directly to the network by way of an Ethernet or FDDI connection, it can connect to the Screen by an asynchronous transfer mode (ATM) or Token Ring LAN.