SunScreen 3.2 Installation Guide
    
A
 
 access control list, ACL ( Index Term Link )
 
 administration GUI
  launching ( Index Term Link )
  launching error ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  MKID ( Index Term Link )
  proxy error ( Index Term Link )
  remote Administration Station ( Index Term Link )
 
 administration software
  Administration Station ( Index Term Link )
  administrative Screen ( Index Term Link )
 
 Administration Station
  adding certificate ( Index Term Link )
  administer Screen ( Index Term Link )
  define rules ( Index Term Link )
  IPsec ( Index Term Link ) ( Index Term Link )
  launch administration GUI ( Index Term Link ) ( Index Term Link )
  PC SKIP ( Index Term Link ) ( Index Term Link )
 
 administration station, PC SKIP ( Index Term Link )
 
 Administration Station
  remote administration packages ( Index Term Link )
  SKIP certificates ( Index Term Link ) ( Index Term Link )
  Solaris Core Distribution ( Index Term Link )
  Solaris packages ( Index Term Link )
  supported configurations ( Index Term Link ) ( Index Term Link )
 
 Administration Station packages, remote installation ( Index Term Link )
 
 administrative Screen
  IKE certificates ( Index Term Link )
  IPsec ( Index Term Link )
 
 algorithm
  Data ( Index Term Link )
  Key ( Index Term Link )
  MAC ( Index Term Link )
    
C
 
 CD-ROM, SKIP 1.5.1 ( Index Term Link )
 
 certificates
  Administration Station ( Index Term Link )
  Administration Station command line ( Index Term Link )
  command line ( Index Term Link )
  creating through command line ( Index Term Link )
  generate through command line ( Index Term Link )
  IKE rules ( Index Term Link )
  IKE self-generated ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  MKID ( Index Term Link ) ( Index Term Link )
  routing mode ( Index Term Link ) ( Index Term Link )
  Screen ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  Screen's certificate ID ( Index Term Link ) ( Index Term Link )
  SKIP CA-issued ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  SKIP UDH ( Index Term Link )
  SKIP UDH self-generated ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  stealth mode ( Index Term Link ) ( Index Term Link )
 
 command line
  administration packages ( Index Term Link )
  default installation ( Index Term Link )
  IKE self-generated ( Index Term Link )
  installation ( Index Term Link )
  IPsec IKE ( Index Term Link )
  limitations and requirements ( Index Term Link )
  local routing ( Index Term Link )
  packages ( Index Term Link )
  pkgadd ( Index Term Link )
  windows 2000 ( Index Term Link )
 
 command line installation
  Administration Station ( Index Term Link )
  required packages ( Index Term Link )
 
 configuration
  creating ( Index Term Link ) ( Index Term Link )
 
 content scanning, third-party products ( Index Term Link )
 
 conversion
  FireWall-1 ( Index Term Link ) ( Index Term Link )
 
 cryptography, 4096-bit ( Index Term Link )
 
 Custom installation
  remote administration ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
D
 
 documentation, reading ( Index Term Link )
    
E
 
 encrypted communication
  IKE ( Index Term Link )
  SKIP ( Index Term Link ) ( Index Term Link )
 
 encryption ( Index Term Link )
  IPsec ( Index Term Link )
  predefined rule ( Index Term Link )
  SKIP ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  skiptool GUI ( Index Term Link )
 
 end-system SKIP, Administration Station ( Index Term Link )
    
F
 
 FireWall-1
  conversion errors ( Index Term Link )
  preparing for conversion ( Index Term Link )
  reserved characters ( Index Term Link )
  reserved words ( Index Term Link )
  verifying converted rules ( Index Term Link )
 
 FireWall-1 conversion failure, troubleshooting ( Index Term Link )
    
G
 
 gateway ( Index Term Link )
 
 generate
  conversion files ( Index Term Link )
  new configuration ( Index Term Link )
    
H
 
 hardening
  dedicated firewall ( Index Term Link )
  stealth mode ( Index Term Link )
 
 hardening Screen
  mixed mode ( Index Term Link )
  stealth mode ( Index Term Link )
 
 hardware, minimum requirements ( Index Term Link )
    
I
 
 IKE
  command line ( Index Term Link )
  generate keys ( Index Term Link )
  issued certificates ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link )
  routing mode ( Index Term Link )
  syntax and options examples ( Index Term Link )
  using with SunScreen ( Index Term Link )
 
 IKE certificates
  administrative Screen ( Index Term Link )
  routing mode ( Index Term Link )
 
 IKE pre-shared, windows 2000 ( Index Term Link )
 
 IKE self-generated, IKE rules ( Index Term Link )
 
 installation
  Administration Station ( Index Term Link )
  certificates ( Index Term Link )
  command line ( Index Term Link )
  conversion utility ( Index Term Link )
  default ( Index Term Link )
  default command line ( Index Term Link )
  IKE self-generated ( Index Term Link )
  local administration ( Index Term Link ) ( Index Term Link )
  local routing ( Index Term Link )
  local using command line ( Index Term Link )
  overview ( Index Term Link ) ( Index Term Link )
  packages ( Index Term Link )
  pkgadd ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  remote using command line ( Index Term Link )
  requirements ( Index Term Link )
  routing mode ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  SKIP CA-issued ( Index Term Link )
  SKIP UDH self-generated ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  stealth Administration Station ( Index Term Link )
  stealth mode ( Index Term Link ) ( Index Term Link )
  stealth Screen ( Index Term Link )
  summary ( Index Term Link ) ( Index Term Link )
  Trusted Solaris ( Index Term Link )
  Trusted Solaris 8 ( Index Term Link )
 
 IP
  addresses ( Index Term Link )
  interfaces ( Index Term Link )
  routing ( Index Term Link )
  stack ( Index Term Link )
 
 IPsec, routing mode ( Index Term Link )
 
 IPv4 ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
J
 
 Java plug-in
  CD-ROM ( Index Term Link )
  compatibility with SunScreen ( Index Term Link )
  installing ( Index Term Link )
    
K
 
 keys and certificates, CA-issued ( Index Term Link )
    
L
 
 list, Key algorithm ( Index Term Link )
 
 login
  change default name and password ( Index Term Link ) ( Index Term Link )
  change default user name and password ( Index Term Link )
  change name and password ( Index Term Link )
  default user name and password ( Index Term Link ) ( Index Term Link )
  name and password ( Index Term Link )
    
M
 
 MD5 ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 mixed mode, hardening Screen ( Index Term Link )
 
 MKID, key and certificate ( Index Term Link )
 
 modes of operation
  mixed ( Index Term Link )
  routing ( Index Term Link )
  stealth ( Index Term Link )
    
N
 
 NAT
  upgrading ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 network ( Index Term Link )
 
 network interfaces
  configuration ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  configure ( Index Term Link )
  routing Screen interface support ( Index Term Link )
  stealth mode ( Index Term Link )
  stealth Screen interface support ( Index Term Link )
 
 network security policy
  action types ( Index Term Link )
  address group worksheet ( Index Term Link )
  address ranges worksheet ( Index Term Link )
  Administration Station interfaces worksheet ( Index Term Link )
  authorized users worksheet ( Index Term Link )
  considerations ( Index Term Link )
  control access ( Index Term Link )
  data objects ( Index Term Link )
  determining ( Index Term Link )
  host addresses worksheet ( Index Term Link )
  information on creating ( Index Term Link )
  initial security level ( Index Term Link )
  interfaces ( Index Term Link )
  IP addresses ( Index Term Link )
  map your network ( Index Term Link )
  naming services ( Index Term Link )
  NAT map worksheet ( Index Term Link )
  rules worksheet ( Index Term Link )
  sample rules worksheet ( Index Term Link )
  Screen interfaces worksheet ( Index Term Link )
  worksheets ( Index Term Link )
    
O
 
 ordered NAT mappings ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
    
P
 
 packages
  command line ( Index Term Link )
  end-system SKIP ( Index Term Link ) ( Index Term Link )
  hardening Screen ( Index Term Link )
  IKE ( Index Term Link )
  installation through command line ( Index Term Link )
  minimum Solaris ( Index Term Link )
  missing ( Index Term Link )
  removing note ( Index Term Link )
  SKIP ( Index Term Link )
  SPARC platform edition ( Index Term Link )
 
 packet filtering rules ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
 
 patches
  security patches ( Index Term Link )
  Solaris 2.6 kernel patches ( Index Term Link )
  Trusted Solaris ( Index Term Link )
  upgrading ( Index Term Link ) ( Index Term Link )
 
 pkgadd
  administration packages ( Index Term Link ) ( Index Term Link )
  local administration ( Index Term Link ) ( Index Term Link )
  remote administration ( Index Term Link )
 
 pkgadd command ( Index Term Link )
 
 pkgrm command ( Index Term Link ) ( Index Term Link )
 
 private keys, generate through command line ( Index Term Link )
    
R
 
 remote administration
  configuring interfaces ( Index Term Link )
  connections ( Index Term Link )
 
 remote installation
  Administration Station ( Index Term Link ) ( Index Term Link )
 
 removing
  #efs# proxy prefix ( Index Term Link )
  configuration proxy rules ( Index Term Link )
  configurations and log files ( Index Term Link )
  GUI uninstaller ( Index Term Link )
  moving SMTP proxy option ( Index Term Link )
  product registry ( Index Term Link )
  reboot removes packet filtering modules ( Index Term Link )
  software using pkgadd ( Index Term Link )
  SunScreen software ( Index Term Link )
  verifying ( Index Term Link )
 
 requirements and restrictions
  IPv4 ( Index Term Link )
  IPv6 ( Index Term Link )
 
 routing, local installation through command line ( Index Term Link )
 
 routing mode
  considerations ( Index Term Link )
  default installation ( Index Term Link )
  IKE ( Index Term Link )
  install icon ( Index Term Link ) ( Index Term Link )
  installation ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  local administration ( Index Term Link )
  mixing stealth and routing ( Index Term Link )
  proxies ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link )
  router and firewall ( Index Term Link )
  SKIP ( Index Term Link )
  Web Start Wizards SDK 3.0.1 ( Index Term Link )
    
S
 
 Screen ( Index Term Link )
  firewall ( Index Term Link )
  local administration packages ( Index Term Link )
  remote administration packages ( Index Term Link )
  Solaris End User Distribution ( Index Term Link )
  Solaris packages ( Index Term Link )
 
 Screen and administration software
  Screens ( Index Term Link ) ( Index Term Link )
 
 Screen packages
  local installation ( Index Term Link )
  remote installation ( Index Term Link )
 
 Screen software, firewall Screen ( Index Term Link )
 
 security issues ( Index Term Link )
 
 security policy
  implementation ( Index Term Link )
  mapping ( Index Term Link )
  security levels ( Index Term Link )
 
 SKIP
  1.5.1 on CD-ROM ( Index Term Link )
  RC2 limitation ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link )
  routing mode ( Index Term Link ) ( Index Term Link )
  skiptool GUI ( Index Term Link )
  stealth mode ( Index Term Link )
  user's guide ( Index Term Link )
  windows and NT ( Index Term Link )
 
 SKIP CA-issued, load through command line ( Index Term Link )
 
 SKIP certificates
  Administration Station ( Index Term Link )
  routing mode ( Index Term Link )
  Screen ( Index Term Link )
  stealth mode ( Index Term Link )
 
 SKIP encryption, predefined rule ( Index Term Link )
 
 SKIP private key and certificates, load through command line ( Index Term Link )
 
 SKIP UDH key and certificates, create through command line ( Index Term Link )
 
 software
  minimum requirements ( Index Term Link )
  stealth Administration Station ( Index Term Link )
  stealth Screen ( Index Term Link )
 
 Solaris 2.6, kernel patches ( Index Term Link )
 
 Solaris packages
  Administration Station ( Index Term Link )
  Screen ( Index Term Link )
 
 Solaris SunScreen, windows 2000 ( Index Term Link )
 
 stealth mode
  bridge ( Index Term Link )
  considerations ( Index Term Link )
  hardening ( Index Term Link )
  hardening Screen ( Index Term Link )
  installation ( Index Term Link ) ( Index Term Link )
  IP interfaces ( Index Term Link )
  remote administration ( Index Term Link ) ( Index Term Link )
  SKIP ( Index Term Link )
  with routing ( Index Term Link )
 
 subnetwork ( Index Term Link )
 
 SunScreen
  administration GUI ( Index Term Link )
  Administration Station software installation ( Index Term Link ) ( Index Term Link )
  administrative Screen software installation ( Index Term Link )
  books and publications ( Index Term Link )
  converting from FireWall-1 ( Index Term Link )
  getting support ( Index Term Link )
  IKE self-generated certificate ( Index Term Link ) ( Index Term Link )
  installation tasks ( Index Term Link )
  installer ( Index Term Link )
  installing as Custom ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  installing as Typical ( Index Term Link )
  installing with local administration ( Index Term Link )
  installing with remote administration ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  network interfaces ( Index Term Link )
  operation modes ( Index Term Link )
  package requirements ( Index Term Link )
  patches ( Index Term Link )
  removing configurations and log files ( Index Term Link )
  removing proxy rules ( Index Term Link )
  removing software ( Index Term Link )
  removing software using pkgadd ( Index Term Link )
  requirements and restrictions ( Index Term Link )
  resources ( Index Term Link )
  security patches ( Index Term Link )
  security solution ( Index Term Link )
  SKIP CA-issued certificate ( Index Term Link ) ( Index Term Link )
  SKIP UDH self-generated certificate ( Index Term Link ) ( Index Term Link )
  third-party products ( Index Term Link )
  Trusted Solaris 8 ( Index Term Link ) ( Index Term Link )
  upgrading prior releases ( Index Term Link )
  user profile ( Index Term Link )
  using IKE ( Index Term Link )
  Web browser ( Index Term Link )
  Web server ( Index Term Link )
  windows 2000 ( Index Term Link )
 
 SunScreen overview
  Trusted Solaris ( Index Term Link )
  upgrading ( Index Term Link )
 
 SunScreen SPF-200
  changed NAT mappings ( Index Term Link )
  upgrading from ( Index Term Link )
    
T
 
 Trusted Solaris
  allowed privileges ( Index Term Link )
  effective privileges ( Index Term Link )
  installation overview ( Index Term Link )
  installing Administration Station software ( Index Term Link )
  installing Screen software ( Index Term Link )
  patches ( Index Term Link )
  rights ( Index Term Link )
  SunScreen software installation ( Index Term Link )
  trusted networking details ( Index Term Link )
  TSOL templates ( Index Term Link )
  tsolpeerinfo ( Index Term Link ) ( Index Term Link )
  UNLABELED templates ( Index Term Link )
 
 tsolpeerinfo
  DYNAMIC NAT ( Index Term Link )
  STATIC NAT ( Index Term Link )
 
 Typical installation, local administration ( Index Term Link )
    
U
 
 U.S. export laws, currently allows 4096-bit ( Index Term Link )
 
 upgrading
  administration GUI ( Index Term Link )
  administration GUI key-size limitation ( Index Term Link )
  automatic backup ( Index Term Link )
  backup SunScreen SPF-200 Administration Station ( Index Term Link )
  backup SunScreen SPF-200 Screen ( Index Term Link )
  backups ( Index Term Link )
  command or argument changes ( Index Term Link )
  cryptography modules ( Index Term Link )
  current mode ( Index Term Link )
  custom scripts ( Index Term Link )
  define HA screen object ( Index Term Link )
  existing policies ( Index Term Link )
  from prior SunScreen releases ( Index Term Link )
  gathering SunScreen SPF-200 Screen configurations ( Index Term Link )
  HA primary Screen ( Index Term Link ) ( Index Term Link )
  HA secondary Screen ( Index Term Link )
  high availability system ( Index Term Link )
  install patch 105047-21 ( Index Term Link )
  install patch on Screen from Administration Station ( Index Term Link )
  install software on Administration Station ( Index Term Link )
  kernel patches ( Index Term Link )
  kernel patches for Screen ( Index Term Link )
  locally-administered Screen ( Index Term Link )
  MKID ( Index Term Link )
  order of installation ( Index Term Link )
  ordered NAT mappings ( Index Term Link )
  overview ( Index Term Link )
  patch ( Index Term Link )
  patches ( Index Term Link )
  prerequisite Solaris packages ( Index Term Link )
  recommended security patches ( Index Term Link )
  remote Administration Station ( Index Term Link )
  remotely-administered Screen ( Index Term Link )
  removing packages ( Index Term Link )
  retaining existing policies ( Index Term Link )
  review packet filtering rules ( Index Term Link )
  routing mode ( Index Term Link )
  save existing log files ( Index Term Link )
  saving files ( Index Term Link )
  saving log files ( Index Term Link )
  software installation order ( Index Term Link )
  Solaris 2.6 kernel patches ( Index Term Link )
  SunScreen SPF-200 ( Index Term Link ) ( Index Term Link ) ( Index Term Link )
  upgrade icon ( Index Term Link )
  verify migrated configurations ( Index Term Link )
  verify remote administration ( Index Term Link )
  Web browser ( Index Term Link )
    
V
 
 VPN ( Index Term Link )
    
W
 
 Web browser
  administration GUI ( Index Term Link )
  Java-enabled ( Index Term Link )
  local file access requirements ( Index Term Link )
  view status and logs ( Index Term Link )
  with local file access ( Index Term Link )
  without local file access ( Index Term Link )
 
 Web server
  Apache ( Index Term Link )
  Solaris Web Start ( Index Term Link )
 
 windows 2000
  IKE pre-shared ( Index Term Link )
  IPsec IKE ( Index Term Link )