Académique Documents
Professionnel Documents
Culture Documents
Installation Guide
Contact Information
Blue Coat Systems Inc. 420 North Mary Ave Sunnyvale, CA 94085-4121 http://www.bluecoat.com/support/contact.html bcs.info@bluecoat.com http://www.bluecoat.com
For concerns or feedback about the documentation: documentation@bluecoat.com Note This equipment has been tested and found to comply with the limits for a Class A Digital device pursuant to Part 15 of the FCC Rules. These limits are designed to provide reasonable protection against harmful interference when the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency energy, and if not installed and used in accordance with the instruction manual, might cause harmful interference to radio communications. Operation of this equipment in a residential area is likely to cause harmful interference in which case the users are required to correct the interference at their own expense. Copyright 1999-2008 Blue Coat Systems, Inc. All rights reserved worldwide. No part of this document may be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the written consent of Blue Coat Systems, Inc. All right, title and interest in and to the Software and documentation are and shall remain the exclusive property of Blue Coat Systems, Inc. and its licensors. ProxyAV, CacheOS, SGOS, SG, Spyware Interceptor, Scope, RA Connector, RA Manager, Remote Access and MACH5 are trademarks of Blue Coat Systems, Inc. and CacheFlow, Blue Coat, Accelerating The Internet, ProxySG, WinProxy, AccessNow, Ositis, Powering Internet Management, The Ultimate Internet Sharing Solution, Cerberian, Permeo, Permeo Technologies, Inc., and the Cerberian and Permeo logos are registered trademarks of Blue Coat Systems, Inc. All other trademarks contained in this document and in the Software are the property of their respective owners. BLUE COAT SYSTEMS, INC. DISCLAIMS ALL WARRANTIES, CONDITIONS OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON SOFTWARE AND DOCUMENTATION FURNISHED HEREUNDER INCLUDING WITHOUT LIMITATION THE WARRANTIES OF DESIGN, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL BLUE COAT SYSTEMS, INC., ITS SUPPLIERS OR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY EVEN IF BLUE COAT SYSTEMS, INC. HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Document Number: 231-02940 Document Revision: B.0 1
ii
P/N 231-02940
Contents
Chapter 1: The SG8100 Unpacking the SG8100 6 SG8100 Connection Ports 7 SG8100 Front Panel 8 Chapter 2: Installing the SG8100 Installing the SG8100 into an Equipment Rack 11 Attaching the Cables 13 Opening the Front Panel 16 Initial Installation of the Disk Drives 17 Powering the SG8100 On and Off 20 Checking Status with the Front Panel LEDs 21 Checking LAN Activity with Back Panel LEDs 23 Chapter 3: First-Time Configuration About First-Time Configuration 25 Requirements 35 Chapter 4: Next Steps Chapter 5: Maintaining and Upgrading the SG8100 Hot-Swapping a Disk Drive 69 Hot-Swapping a Power Supply 72 Option Upgrade Cards 78 Chapter 6: Troubleshooting System Warning LED Indicates System Malfunction 79 Testing the SG8100 80 Accessing the Serial Console Port 80 CLI Session Times Out 81 CLI Limited to 16 Sessions 81 Cannot Access the Web Interface 81 The Disk Drive LED Has A Solid Amber Light 82 A Security Warning Appears for the Initial Configuration Web Page 82 The Web Setup Wizard Page is Not Accessible 82
P/N 231-02940
iii
Web Interface Username and Password Fail 83 Web Interface Java Errors Occur 84 Client Requests Fail 84 Client Responses Are Slow 85 The SG8100 Does Not Come Back Up After Rebooting 86 The ProxySG Certificate is not Valid 86 The SG8100 Cannot Connect to the Director 87 Connection Request Rejected by the Director 87 Resetting the ProxySG to Factory Defaults 88 Appendix A: Specifications Environmental and Electrical 91 Lasers 92 Connector 92 Appendix B: Regulatory Statements Class A Digital Warning 94 EC Community EMC Warning 94 Canadian EC EMC Warning 94 Australia/New Zealand EC EMC Warning 95 Taiwan BSMI Notification 95 China CCC Notification 95 Japan VCCI EMC Notification 95 Battery Warning Notification 95 General Warning 96 Declaration of Conformity 97 Index
iv
P/N 231-02940
P/N 231-02940
Important: This product is intended for operation and servicing only by appropriately trained technical personnel. Dieses Produkt wird fr Betrieb vorgehabt und wird nur durch passend ausgebildeten technisches Personal gewartet.
If any of the items are missing or damaged, contact Blue Coat Technical Support at http://www.bluecoat.com/support/contact.html.
P/N 231-02940
P/N 231-02940
2 USB ports
2 Gigabit 2 upgrade slots (for (1000 Mbps) optional Dual/Quad Ethernet ports Fiber/copper LX cards serial console port
P/N 231-02940
The front panel LED status indicators and the LCD are visible when the front panel is closed, as shown below.
LEDs LCD
P/N 231-02940
When the front panel is open, as shown below, the power button, the control buttons, and the disk-drive bays are visible.
Power button Control buttons
10
P/N 231-02940
Note:
An SG8100 unit weighs up to 68 pounds (30.8 kg), depending on the model. Blue Coat recommends that you install the SG8100 into an equipment rack with a shelf, using the front rack-mounting brackets to fasten the unit to the equipment rack.
Elevated Operating AmbientIf installed in a closed or multi-unit rack assembly, the operating ambient temperature of the rack environment may be greater than room ambient. Therefore, consideration should be given to installing the equipment in an environment compatible with the maximum ambient temperature (Tma) specified by the manufacturer. Reduced Air FlowInstallation of the equipment in a rack should be such that the amount of air flow required for safe operation of the equipment is not compromised. Mechanical LoadingMounting of the equipment in the rack should be such that a hazardous condition is not achieved due to uneven mechanical loading.
P/N 231-02940
11
Circuit OverloadingConsideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of the circuits might have on overcurrent protection and supply wiring. Appropriate consideration of equipment nameplate ratings should be used when addressing this concern. Earthing (Grounding)Reliable earthing of rack-mounted equipment should be maintained. Particular attention should be given to supply connections other than direct connections to the branch circuit (for example, use of power strips).
2 Use four equipment-rack screws (two on each side) to securely fasten the
SG8100 to the equipment rack.
12
P/N 231-02940
2 Use four equipment-rack screws (two on each side) to securely fasten the
ProxySG to the equipment rack.
P/N 231-02940
13
2 Attach the serial cable that came with the ProxySG to the serial port
connection, if necessary. The serial cable allows you to hook up to a PC, a serial terminal, or a standalone serial console port to configure and manage the SG8100.
Attach the power cords (2 AC power supplies shown) Figure 2-4: Attach the Power Cords
WARNING! You must connect the grounding/earthing wire included with the SG8100 from the DC power supply to an electrically neutral ground before connecting the DC power cords. You must also use a 20A circuit breaker to connect to your DC power source as an over-current protection device.
14
P/N 231-02940
Connect at least two of the three DC power connectors to the SG8100 DC power supply
P/N 231-02940
15
WARNING! If you use the cables supplied by Blue Coat to reconnect the DC power connections to a DC power source, ALWAYS connect the yellow DC power cord to a negative DC outlet, and connect the black DC power cord to a positive DC outlet.
ALWAYS plug the yellow cord to a negative outlet
16
P/N 231-02940
Bezel tab
1 Open the front panel and ensure that the Power LED is off. If not, press
the Power button to power off the system.
2 Remove the disk drives from the shipping container and prepare each for
insertion into the drive bays, as follows:
Install the disk drives, alternating between channels A and Binsert one disk drive into Slot 1 in Channel A and then one disk drive into Slot 1 in Channel B. When you insert a disk drive, the disk lever (the black latch) must be on top. The left edge of the disk-drive container must align with both the plastic guide rail at the bottom of the disk drive bay and the metal guide rail at the top. Insert disk drives carefully to avoid damaging the SCSI connectors.
P/N 231-02940
17
Disk lever
Align this edge with the upper drive bay guide rail
Align this edge with the lower drive bay guide rail
3 To insert a disk drive, hold the disk lever up, align the disk drive with the
drive bay guide rails, and gently push the disk drive into the drive bay. Push the disk drive as far back as possible to ensure a complete connection.
18
P/N 231-02940
Figure 2-9: Inserting a Disk by Sliding Inside Upper and Lower Guide Rails
4 When the disk lever meets the ProxySG frame, push the lever down
slowly until the lever locks in place. Note: Do not force the disk drive into the slot if the latch is unable to lock. The hard disk drive connector will be damaged if not properly seated.
P/N 231-02940
19
1 Open the front panel of the SG8100 and press the power button.
Power button Power LED
Successful Power Off: The LCD and LEDs go off when the SG8100 powers off.
20
P/N 231-02940
The table below describes the appearance and meaning of LED colors and flash rates.
Front Panel LEDs Description
Power
The Power LED indicates if power is being supplied to the SG8100. If the SG8100 is powered on and configured, the Power LED is green. If the SG 8100 is powered on and not configured, the Power LED will blink from green to amber. If the SG8100 is without power, the Power LED is off.
P/N 231-02940
21
Description
LAN
The two LAN LEDs indicate network connection status for Adapter 0 (Interfaces 0 and 1). If a network link is not established for a particular adapter/interface, the LAN LED is off. If a network link is established for a particular adapter/interface, but no activity is detected, the LAN LED colors are as follows: 10 Mbps: Solid orange 100 Mbps: Solid blue 1000 Mbps connection: Solid purple If a network link is established for a particular adapter/interface and activity is detected, the LAN LED colors are as follows: 10 Mbps: Flashes orange 100 Mbps: Flashes blue 1000 Mbps: Flashes pink
The System Warning LED indicates if the system has a malfunction. If this LED is off, there is no status on the health of SG8100. If the SG8100 is operating normally, the System Warning LED is solid green. If a system warning occurs, the System Warning LED is System Warning solid amber. If a serious problem requiring immediate attention occurs, the System Warning LED flashes amber. If the System Warning LED is solid or flashing amber, see System Warning LED Indicates System Malfunction on page 79 for information about detecting the problem.
22
P/N 231-02940
Description
Disk Drive
The Disk Drive LEDs indicate the connection and activity status of the corresponding disk drives. If a disk drive is not connected, the corresponding Disk Drive LED is off. If a disk drive is connected, but no activity is detected, the corresponding Disk Drive LED is solid green. If a disk drive is connected and activity is detected, the corresponding Disk Drive LED is either solid amber or flashes between green and amber at an irregular interval. If a disk drive is connected but is not functioning (either because it has been taken offline or is faulty), the corresponding Disk Drive LED flashes from green to amber at a regular interval. A Disk Drive LED that flashes amber at a regular interval indicates that the drive can be removed. If the Disk Drive LED is solid red, the drive is down.
Figure 2-12: LAN Connection Port LEDs at the Back of the SG8100
P/N 231-02940
23
The table below describes the appearance and meaning of the LAN Connection Port LED colors and flash rates.
Note:
Link established: no activity detected solid green solid yellow solid orange
Link established: activity detected flashing green flashing yellow flashing orange
24
P/N 231-02940
P/N 231-02940
25
While there are several available methods to configure the SG8100, all require that the SG8100 have an IP address. After you put an IP address on the system (using either the front panel or the serial setup console), you can complete initial configuration using one of the following methods: Front Panel Buttons Use this method to configure basic settings, only if you do not immediately require traffic interception of specific services. This is the fastest method of initial configuration. To configure traffic interception or ADN settings as part of the initial setup, choose the Web Setup Wizard option. Note that all configuration settings can be modified after initial configuration is complete. To use the front panel method, go to Section A: Using the Front Panel to Configure Basic Settings on the SG8100 on page l28. Web Setup Wizard Use the Web Setup Wizard to immediately configure traffic interception or ADN settings. To use the Web Setup Wizard, you must first configure an IP address for the appliance using the serial setup console. See Section C: Using a Direct Serial Port Connection to Configure Basic Settings on the SG8100 on page l39 to configure initial settings. To continue with the configuration using the Web setup wizard see Section B: Using the Web Setup Wizard Basic Settings on the SG8100 on page l35. Serial Setup Console Use this method if you want to configure basic settings only and do not immediately require traffic interception of specific services. To configure traffic interception or ADN settings, choose the Web Setup Wizard option. To continue with the configuration using the serial setup console see Section C: Using a Direct Serial Port Connection to Configure Basic Settings on the SG8100 on page l39.
26
P/N 231-02940
Director Registration Use this method only if you have a Blue Coat 510 Director. The Director allows you to configure an SG appliance and automatically register it with the Director. See Section A: Using the Front Panel to Configure Basic Settings on the SG8100 on page l28 to configure initial settings. To continue with the configuration using Director, see Section D: Using Director Registration to Configure the SG8100 on page l51.
After first-time configuration is complete, log on to the ProxySG and use the command-line interface (CLI) or Management Console to fully configure the system. At this point, you can modify any settings that already were made. Refer to the Blue Coat ProxySG Configuration and Management Guide Suite for information on how to fully configure the software. Download this manual from the Blue Coat WebPower site at: https://www.bluecoat.com/support/manuals You must have a WebPower account to access the documentation.
P/N 231-02940
27
Section A: Using the Front Panel to Configure Basic Settings on the SG8100
Using the front panel control buttons and LCD is the quickest and easiest way to do a first-time configuration. Using the front panel you can: Manually configure the basic settings. Configure access to the Web setup wizard, and continue further configuration using the Web browser. Register the ProxySG with the Director (if you have a 510 Director). You might then push the configurations pre-staged on the Director to the ProxySG.
Figure 3-1 shows the front panel LCD and control buttons.
LCD Up/Down Arrow buttons Menu button Enter button Figure 3-1: Front Panel LCD and Control Buttons
Use the LCD and control buttons to set the basic networking parameters and monitor the SG8100.
LCD Behavior
The default behavior of the front-panel LCD is to turn off after 30 seconds. Press any front-panel control button to return the light to normal behavior. The front-panel LCD behavior is configurable; see Section G: Configuring the Front-Panel LCD Behavior on page l62 for information.
28
P/N 231-02940
The default mode. Before the SG8100 is configured, the LCD in Status mode displays IP address not configured. After initial configuration, the LCD in Status mode displays CPU utilization and proxied traffic statistics. In Status mode, there is no cursor in the LCD.
Configuration Mode
From Status mode, push the Enter button to go to Configuration mode. In Configuration mode, you can use the Up and Down arrow buttons to cycle the LCD through the six networking parameters (IP Address, Subnet mask, Gateway address, DNS address, Console Password, and Enable Password). In Configuration mode, the cursor is an underscore in the LCD.
P/N 231-02940
29
Edit Mode
From Configuration mode, use the Up or Down arrow button until the parameter you want to configure is displayed, then press the Enter button to go to Edit mode for that parameter (for a first-time configuration, you must begin with the first displayed parameterIP address). To configure the parameter, use the Left and Right arrow buttons to position the cursor over a character you want to change, then use the Up and Down arrow buttons to cycle through the characters. When the parameter is configured correctly, press the Enter button to save the setting and return to Configuration mode.
Note:
The SG8100 automatically exits Edit mode, without saving parameter configurations, if no activity is detected for 20 seconds.
30
P/N 231-02940
The Enter button functions as follows: Status mode: When you push the Enter button in Status mode, the system enters Configuration mode. In Configuration mode, one of the six configurable parameters displays in the LCD (starting with IP address). Configuration mode: When you push the Enter button in Configuration mode, the system enters Edit mode for the parameter displayed. Edit mode: When you push the Enter button in Edit mode, the system saves any changes you made to the parameter displayed and returns to Configuration mode.
Menu Button
The Menu button functions like an Escape key. When you push the Menu button in Edit mode, the SG8100 returns to Configuration mode, cancelling any changes you made to the parameter displayed. When you push the Menu button in Configuration mode, the SG8100 returns to Status mode. Any changes you made while in Edit mode have already been saved, and are not affected when you push the Menu button in Configuration mode.
Left and Right Arrow When you push the Left and Right arrow buttons in Edit Buttons mode, the cursor moves back and forth over the
configurable parameters. When you push the Up and Down arrow buttons in Edit mode, the SG8100 cycles through the characters available for the selected setting of the parameter (the selected setting is the character that the cursor is over when you push the arrow buttons).
P/N 231-02940
31
The networking parameters that you provide information on, varies according to the configuration option you select on the front panel.
Important: A default username (admin) is already set on the SG8100. A unique console and enable password are generated automatically. You can configure the passwords now, or write down the auto-generated passwords and use them to log in, changing them later. The enable password is not required if you log in using a browser.
1 When the LCD displays IP address not configured, press the Enter
button to enter Configure mode.
32
P/N 231-02940
4 Press the Left or Right arrow buttons to position the cursor over the
characters you want to change; press the Up or Down arrow buttons to change them.
5 When you have entered all the characters of the parameter, press the Enter
button to save the changes and return to Configure mode.
6 Press the Down arrow button to move to the next parameter; press the
Enter button to enter Edit mode.
Note:
If you selected the Web wizard, you are directed to use the Web browser for the rest of the configuration, see Section B: Using the Web Setup Wizard Basic Settings on the SG8100 on page l35. If you selected Director registration, see Section D: Using Director Registration to Configure the SG8100 on page l51. If you selected Manual setup, continue with the instructions below.
1 When the LCD reads, Console password: Push to set,, press the Enter
button to enter Edit mode and complete one of the following steps:
To configure the password later (after you log in), write down the auto-generated password and press the Enter button to return to Configure mode. To configure the password now, follow Steps 5.
2 Set the enable password parameter; when the LCD displays Enable
password: Push to configure when you are back in Configuration mode. Do not push the Enter button again, or a new auto-generated enable password will be created (if that happens, repeat Step 4).
P/N 231-02940
33
4 Select the trial edition license that you purchased Proxy or MACH5. If
you leave the None option selected, an Invalid trial edition error message is displayed.
34
P/N 231-02940
Section B: Using the Web Setup Wizard Basic Settings on the SG8100
After you have configured connection information (such as the IP address) for the SG8100, you can switch to the Web wizard to complete initial configuration. This section describes how to configure the ProxySG with a Web browser.
Requirements
To configure your ProxySG using a browser, you must meet the following requirements. Requirements The browser must support Javascript and Javascript must be enabled. The browser must not be proxied. For information about proxied browsers, see Cannot Access the Web Interface on page 81. Your ProxySG must not already be configured. Note: If the ProxySG has already been configured, you cannot access the Web wizard unless you reset the ProxySG to factory defaults as described in Resetting the ProxySG to Factory Defaults on page 88. You must configure the ProxySG IP address, subnet mask, gateway, using the front panel or the serial setup console before accessing the Setup Wizard through the Web browser.
P/N 231-02940
35
A security warning dialog appears. For more information about this warning dialog, see A Security Warning Appears for the Initial Configuration Web Page on page 82.
Note:
The appearance of the dialog varies depending on the browser that you use.
Important: If you do not see the warning dialog or if you cannot connect to the Initial Configuration page, see The Web Setup Wizard Page is Not Accessible on page 82.
When the appliance connects, the Setup Wizard displays as shown in the following figure.
36
P/N 231-02940
Each page is described; some pages include mouse-over help. If you entered network settings from the serial setup console, they are already filled in. To complete the Setup Wizard you must:
a. Enter the console access information in Security > Console. b. Enter the CLI Enable password in Security > CLI . c. (Optional but highly recommended) Secure the serial port in
Security > Serial Port. This option allows you to set a password for the serial setup console, thus enabling only authorized personnel (who have access to the serial port password) to reconfigure the appliance.
Important: Record the password in a secure location. If you secure the serial console port and forget the password, you have to reset the ProxySG to factory defaults and re-do initial setup of the appliance. You might still access the Management Console or CLI if you know the administrative credentials console username, password, and the enable password.
P/N 231-02940
37
f. Select the traffic types that the appliance should intercept in Services >
Intercepted Traffic.
g. Set the Default Settings policy to either the MACH5 settings for WAN
acceleration or retain the default more secure settings.
Note:
Select the license trial version that matches the license you purchased for the SG8100.
Note:
The Web-based wizard is available only for initial appliance configuration (or following a reset to factory defaults). After you click Configure during the final step, the wizard is no longer available.
38
P/N 231-02940
Section C: Using a Direct Serial Port Connection to Configure Basic Settings on the SG8100
Use the following procedure to configure the SG8100 with a direct serial port connection. Use a standalone serial terminal or a PC and the ProxySG command line interface (CLI) to perform a first-time configuration of the following basic network information: IP address IP gateway address Console username Enable password IP subnet mask DNS server Console password Serial port password (optional)
PC Note:
If the PC is using standard serial port settings, you should have a problem-free connection. Problems can occur if there are non-standard PC serial port settings.
Do the procedure by reading on-screen material and entering data where necessary. The on-screen instructions display as four separate pages. In the procedure below, places that require you to enter data show example entries in bold text. A number of screens display, one at a time, as shown in the following steps.
P/N 231-02940
39
Baud rate: 9600 bps Parity: none Flow control: none Emulation: VT 100
2 Power on the ProxySG and wait for the system to finish booting.
The following configuration alert displays:
******************* CONFIGURATION ALERT ****************** System startup cannot continue for one of these reasons: (a) Need at least one adapter (or bridge) configured with an IP address and subnet. (b) Need the console password and enable password. (c) Need to specify the trial edition. ********** SYSTEM STARTUP TEMPORARILY SUSPENDED Figure 3-2: Initial SetupConfiguration Alert *********
40
P/N 231-02940
P/N 231-02940
41
Welcome to the SG Appliance Setup Console --------------------- (page 1 of 5) -------------------Press <ESC> at any time to return to the main menu Setup mode: Manual DIRECTIONS: Please enter the IP addresses for the SG Appliance. The following interfaces are available for configuration: 1. Interface 0:0 (link) 2. Interface 1:0 (no link) Enter interface number to configure [1]: IP address [0.0.0.0]: 10.25.36.47 IP subnet mask [255.255.255.0]: 255.255.255.0 IP gateway [0.0.0.0]: 400.0.1.1 DNS server [0.0.0.0.]: 400.52.23.101 You have entered the following IP addresses: IP address: 10.25.36.47 IP subnet mask: 255.255.255.0 IP gateway: 400.25.36.1 DNS server: 400.52.23.101 Would you like to change any of them? Y/N [No] N
42
P/N 231-02940
Web Wizard
DIRECTIONS: Please open your web browser and use the URI below to access the SG Setup Wizard https://10.25.36.47:8083/
For information on completing initial configuration through the Web wizard, continue with Section B: Using the Web Setup Wizard Basic Settings on the SG8100 on page l35. Director
Connecting to 10.35.46.57 to determine Director serial number This can take up to 90 seconds ... please wait
For information on completing initial configuration through Director, continue with Section D: Using Director Registration to Configure the SG8100 on page l51.
P/N 231-02940
43
7 Initial SetupPasswords
----------------------(page 2 of 5)--------------------Press <ESC> at any time to return to the main menu DIRECTIONS: The console username, password and enable password are special administrative credentials which can be used to log in to the command line interface or web management interface. WARNING - The console password and enable password are not defined. The system cannot start up until these are defined. You must configure the console user account now. Enter console username [admin]: name123 Enter console password: ****** Verify console password: ****** Enter enable password: ****** Verify enable password: ******
Enter a console username and a console and enable password. A default username (admin) is already in placechange it for stronger security. Usernames and passwords can each be from 1 to 64 characters in length. Passwords that contain special characters (such as an exclamation point) must be in quotes. (Optional) For maximum security, secure the serial port.
44
P/N 231-02940
Do you want to secure the serial port? Y/N [Yes] Y Enter setup password: ****** Verify setup password: ****** WARNING: If you continue and enable the secure serial port it will not be possible to enter the setup console without the setup password. If the setup password is lost, assistance from Blue Coat Systems will be required and all system configuration may be lost. It is recommended that this password be stored in a physically secure location. Access to the CLI on the serial port will challenge for credentials. To enable the secure serial port, re-enter the setup password: ******
The serial port allows you to configure and access the ProxySG using a serial cable. This can pose a security risk because anyone with access to the appliance can reconfigure the ProxySG settings. This optional step sets a password for the serial console port, allowing only authorized personnel the ability to reconfigure the appliance.
WARNING! If you set the serial console password and later lose the password, you must restore the appliance to its original factory defaults to access the Management Console or CLI.
P/N 231-02940
45
Note:
9 On page 3, you might restrict the use of the console account to a specific
workstation. On this screen, you can add one IP address to the list of authorized workstations that are approved to use the console account. Additional workstations maybe configured later using the CLI or through the Management Console.
--------------------- (page 3 of 5) -------------------Press <ESC> at any time to return to the main menu DIRECTIONS: The console username and password are special: they can be used to log in to the CLI or Web Management interface even in circumstances where this is denied by VPM or CPL policy. This makes the console account useful in emergencies, as a way to log in when policy is broken, but it may also create a security hole. To close the security hole, we recommend that you restrict the use of the console account to specific workstations, identified by their IP address. This dialog allows you to add one IP address to the list of workstations that are authorized to use the console account. (This same list is also used to restrict which workstations can use SSH with RSA authentication.) Additional workstations may be configured later, from the command line interface or the Web interface. WARNING: The console account can currently be used to log in from any workstation. Would you like to restrict access to an authorized workstation? Y/N [Yes] Y Authorized workstation [0.0.0.0]:10.2.33.1
46
P/N 231-02940
See Section E: Logging on to the SG8100 on page l56 for more information.
10 Select the trial license version that matches the license that you purchased
for the ProxySG.
Important: You can obtain a license and migrate between the Proxy Edition and the MACH5 edition. If you move from the Proxy edition to the MACH5 edition, the ProxySG loses all configuration settings. Conversely, if you move from the MACH5 edition to the Proxy edition you might need to reconfigure the ProxySG, because some default settings for the Proxy edition differ from those of the MACH5 edition.
P/N 231-02940
47
---------------------- (page 4 of 5) --------------------Press <ESC> at any time to return to the main menu DIRECTIONS: An SG can have either a MACH5 Edition or Proxy Edition license. The SGOS MACH5 Edition is designed to optimize and secure WAN networks being used in Application Delivery Networks (ADN). The MACH5 Edition does not include all of the security and control features included in the Proxy Edition. All SGOS MACH5 Edition features, including ADN optimization, are available in the Proxy Edition. A new SG will run with a 60 day trial prior to installing a license. The SG can run either the MACH5 or Proxy Edition of SGOS during the trial period. It is important to note that a downgrade from Proxy Edition to MACH5 Edition will result in a loss of configuration. As well, some defaults differ between the MACH5 and Proxy Edition of SGOS so settings may need to be changed after an upgrade from MACH5 Edition to Proxy Edition. Which edition would you like to run during the trial period? M)ACH5 Edition P)roxy Edition Choose edition [Proxy]: MACH5 Edition You have chosen MACH5 Edition as the trial edition. Would you like to change it? Y/N [No]
48
P/N 231-02940
11 The ProxySG is configured, and Page 5 displays. This page explains how
to access the ProxySG from an SSH Client or with a Web browser. See Section E: Logging on to the SG8100 on page l56 for more information.
--------------------- (page 5 of 5) -------------------DIRECTIONS: The ProxySG Appliance has been successfully configured to use IP address: "10.25.36.47" You can connect to the command line interface or Web interface to perform additional management tasks. To connect to the command line interface, open the following location from your SSH application: 10.25.36.47 To connect to the Web management interface, go to the following location with your web browser: https://10.25.36.47:8082/ --------------- CONFIGURATION COMPLETE ----------------Press "enter" three times to activate the serial console
where proxysg_IP_address is the IP address that you configured for this ProxySG.
P/N 231-02940
49
See Section E: Logging on to the SG8100 on page l56 for more information about accessing the ProxySG. When you have set the basic networking parameters and connected the ProxySG to the network, you are ready to fully configure the appliance. For a list of all CLI commands, refer to Volume 11: Command Line Interface Reference. For information about configuring and administering the ProxySG (including information about setting policies that will explicitly grant or deny proxied transactions), refer to the Blue Coat ProxySG Configuration and Management Guide Suite.
50
P/N 231-02940
Note:
P/N 231-02940
51
Important: Before using Director Registration in the SG8100 set up console, log in to the Director and obtain the Director appliance certificate. Director must have an appliance certificate and be configured properly so that it can receive the registration request from the SG8100.
1 Connect the ProxySG to a serial console port, PC, or place it within your
network, and configure an IP address, subnet mask, and IP gateway using the serial setup console or the front panel buttons. See About First-Time Configuration on page 25.
2 Power on the SG8100 and wait for the system to finish booting. 3 Enter information on the screen, as prompted, and press <Enter> to
proceed to the next line.
52
P/N 231-02940
P/N 231-02940
53
f.
mode: Choose setup mode:R IP address[0.0.0.0]:10.0.0.146 IP subnet mask [255.255.255.0]: Director IP address [0.0.0.0]: 10.0.0.146 IP gateway [0.0.0.0]:10.0.1.1 Registration password: Appliance name (optional): You have entered the following IP addresses: IP address:10.0.0.1 IP subnet mask: 255.255.255.0 Director IP: 10.0.0.146 IP gateway: 10.9.44.1
Would you like to change any of them? Y/N N Connecting to 10.0.0.146 to determine Director serial number This can take up to 90 seconds ... please wait Director reports serial number: 1234567899 e Is that the expected serial number? Y/N Y Connecting to 10.0.0.146 to register with Director 1234567899 Registration succeeded Press "enter" three times to activate the serial console
4 To log in to the serial console right away, press <Enter> three times.
A menu offers two choices:
1) Command Line Interface 2) Setup Console
54
P/N 231-02940
where proxysg_IP is the IP address that you configured for this ProxySG. See Section E: Logging on to the SG8100 on page l56 for more information about accessing the ProxySG.
P/N 231-02940
55
1 Start the SG8100. 2 Open a browser. 3 Enter the IP address configured during initial configuration, followed by
the port number 8082. For example, enter https://10.25.36.47:8082. A security warning dialog appears.
4 Click Yes in the Security Alert dialog; enter a username and password in
the Enter Network Password dialog that displays. If the username has not been changed, the default is admin. The password is the one you wrote down or configured during initial configuration. The SG8100 home page displays.
5 Click the Management Console link from the list on the left.
The Management Console page displays.
56
P/N 231-02940
P/N 231-02940
57
Note:
The CLI uses two passwords: The console password is required to establish a connection to the interface, and the enable password can be set to restrict access to the privileged mode configuration options. If you forget the username or password, you can reset them using either the front panel control buttons and LCD or a serial terminal or PC.
2 After the system has finished booting, press the computer keyboard Enter
key three times. The following text displays:
Welcome to the Appliance Serial Console Version: SGOS 5.2.2.0, Release id: 22527 ------------------------ MENU ---------------------------1) Command Line Interface 2) Setup Console ---------------------------------------------------------Enter option: Figure 3-3: Serial Connection Login Page
3 Enter 1 to select the Command Line Interface option. 4 Enter the username and password when prompted. If the username has
not been changed, the default is admin. The password is the one you wrote down or configured during initial configuration.
5 At the command prompt, enter enable, then enter the enable password
that you wrote down or configured during initial configuration:
58
P/N 231-02940
For information about configuring and administering the SG8100, refer to the Blue Coat ProxySG Configuration and Management Guide Suite. To Connect to the SG8100 CLI Using an SSH Client:
Note:
You must already have an SSH Client installed before you proceed with the steps below.
1 Start the SG8100. 2 Launch your SSH Cliententer the following settings as necessary:
The IP address that you configured during initial configuration. A port number, if necessary (Port 22 is the default). The username and password. If the username has not been changed, the default is admin. The password is the one you wrote down or configured during initial configuration.
3 At the command prompt, enter enable, then enter the enable password
that you wrote down or configured during initial configuration:
SGOS>enable Enable Password: SGOS#
P/N 231-02940
59
commands:
SGOS#configure terminal Enter configuration commands, one per line. SGOS#(config) End with CTRL-Z.
For information about configuring and administering the SG8100, refer to the Blue Coat ProxySG Configuration and Management Guide Suite.
60
P/N 231-02940
2 From the privileged mode command prompt, change the SG8100 front
panel PIN by entering one of the following commands:
SGOS#(config) security front-panel-pin PIN
where PIN is an unhashed PIN and hashed_PIN is a PIN in hashed format. After entering one of these commands, anyone who attempts to configure the SG8100 through the front panel will be prompted to enter the PIN.
P/N 231-02940
61
62
P/N 231-02940
where:
flash Configures the LCD to flash. When set, the LCD continues to flash until the user presses a front panel button or the setting is changed through the CLI command no backlight flash. The flash setting can overwrite the backlight state setting. state off on timeout Configures the LCD to always remain off when the SG 8100 is powered on. This is the default behavior. Configures the LCD to always remain lit when the SG 8100 is powered on. Configures the LCD to dim after a specified number of seconds. Use the backlight timeout seconds command (described below) to specify the number of seconds. Specifies the number of seconds that the LCD remains lit without activity. The backlight state timeout command specifies an LCD timeout; this command specifies the number of seconds before dimming occurs.
timeout
seconds
P/N 231-02940
63
64
P/N 231-02940
Note:
To activate the SG8100 license: 1. Open a Web browser. 2. Disable the browsers pop-up blocker. 3. Enter the IP address you assigned to this appliance during initial setup:
https://ip_address:8082
P/N 231-02940
65
5. Click Management Console. The license warning/registration screen displays. 6. Enter your WebPower credentials and click Register Now; this automatically registers the hardware and software. 7. From the Management Console, go to the License page to begin the license retrieval process: Maintenance > Licensing > Install. 8. Click Retrieve. The Request License Key dialog displays. 9. Enter your WebPower credentials and click Send Request. 10.To verify license installation, click the View tab and click Refresh Data. If you require detailed procedures regarding registration, license retrieval, and installation, refer to the Licensing chapter in Volume 1: Getting Started, or click the Help button to view the contents of that chapter in HTML format. Blue Coat recommends attaching one of the software license stickers to the chassis and saving the other one for future reference. You can attach it to this document and file it, or attach it to another document, as required in your enterprise. Archive your system configuration and store it in a remote location so that you may restore it, if needed. (Optional) Purchase the SG8100 option card kits. The different option cards that are compatible with the SG8100 are listed below: Dual GigE Copper Card Quad GigE Copper Card with Pass-Through Quad GigE Fiber LX Card SSL Accelerator Card: Note that the SG8100 supports only one SSL card. If the system shipped with an SSL accelerator card, you cannot add a second.
(Optional) Purchase the SG8100 upgrade kits. For more details and upgrade paths, refer to the table on the following page.
66
P/N 231-02940
The following table describes the components included in each upgrade kit. To purchase your upgrade kit, find the table entry that matches your upgrade
Upgrading from. . . to. . . Part Number Kit contains:
8100-5
8100-10
085-02506
Two 2GB DIMM; two 1GB DIMM; two 300GB HDD SCSI; one four-port Pass-Through card; one SSL card One 2.2 Ghz dual-core Opteron processor; eight 1GB DIMM; six 300GB HDD SCSI; one four-port Pass-Through card; one SSL card One 2.2 Ghz dual-core Opteron processor; eight 1GB DIMM; four 300GB HDD SCSI
8100-5
8100-20
085-02507
8100-20
8100-A
8100-10
085-02529
Two 2GB DIMM; two 1GB DIMM; four 300GB HDD SCSI; one four-port Pass-Through card; one SSL card One 2.2 Ghz dual-core Opteron processor; eight 1GB DIMM; eight 300GB HDD SCSI; one four-port Pass-Through card; one SSL card Two 2GB DIMM; two 1GB DIMM; four 300GB HDD SCSI; one four-port Pass-Through card; one SSL card One 2.2 Ghz dual-core Opteron processor; eight 1GB DIMM; eight 300GB HDD SCSI; one four-port Pass-Through card; one SSL card Eight 1GB DIMM; eight 300GB HDD SCSI; one four-port Pass-Through card; one SSL card
8100-A
8100-20
085-02530
8100-B
8100-10
085-02532
8100-B
8100-20
085-02533
8100-C
8100-20
085-02536
P/N 231-02940
67
8100-G
8100-20
085-02541
Eight 1GB DIMM; eight 300GB HDD SCSI; one four-port Pass-Through card; one SSL card
Each kit also includes the following: Upgrade Instructions Upgrade Sticker Software License Agreement ESD Wrist Strap
68
P/N 231-02940
2 Click Yes in the Security Alert dialog; enter your username and password
and click OK in the Enter Network Password dialog.
3 Click the Management Console link in the SG8100 home page that appears. 4 In the Management Console page that appears, select the Maintenance tab,
then click System and Disks and click Disks 1-8.
P/N 231-02940
69
6 Click the Take disk # offline button, where # is the number of the disk
selected (this button will be grayed out if the disk selected is not currently online).
7 Click OK in the Take disk offline dialog that displays. 8 Close the Management Console. 9 Make sure that the disk drive is offline before you remove itthe front
panel disk drive LED corresponding to that drive will flash between amber and green at a regular interval when it is offline. See Removing and Replacing a Hot-Swappable Disk Drive on page 71, for removal instructions. Take a Disk Offline Using the CLI:
1 Open a terminal session with the SG8100; enter your password at the
prompt.
where disk_number is the number of the disk that is going offline (a number from 2 to 8).
70
P/N 231-02940
4 Make sure that the disk drive is offline before you remove itthe front
panel disk drive LED corresponding to that drive will flash between amber and green at a regular interval when it is offline. See Removing and Replacing a Hot-Swappable Disk Drive, below, for removal instructions.
Important: Always take a disk drive offline before removing it (see Taking a Disk Offline starting on page 69).
1 Open the front panel of the SG8100. 2 Release the disk lever and remove the disk drive: hold the disk lever up
(the black latch on top of the disk) and carefully pull the disk drive towards you.
3 Insert and seat the replacement disk drive in the same orientation as the
drive you just removed. To insert the disk drive, hold the disk lever up, align the disk drive with the guide rails at the top and the bottom of the bay, and carefully insert the disk drive.
4 When the disk lever meets the frame of the unit, push the lever down
slowly until the lever locks in place. When the new disk is connected, the corresponding disk drive LED is solid green to show that power has been established. When activity is detected on the disk drive, the Disk Drive LED is either solid amber or flashes between green and amber at an irregular interval. If the Disk Drive LED flashes amber at a regular interval, either the connection is faulty or the disk drive is bad.
P/N 231-02940
71
Important: Be careful as you insert the power supply. The guiding prongs on the power supply can easily be bent if the power supply is inserted too quickly or at the wrong angle.
1 Go to the SG8100 home page: open a browser and enter your SG8100 IP
address followed by a colon and port number (for example: https://ProxySG_ip_address:8082). Click Yes in the Security Alert dialog, enter your username and password and click OK in the Enter Network Password dialog.
2 Click the Management Console link in the SG8100 home page that appears. 3 Select the Maintenance tab, then click System and Disks and select
Environment.
72
P/N 231-02940
1 Disconnect the power cord to the faulty power supply that will be
replaced. Power Supply 1 is below Power Supply 2 (see Check for a Faulty Power Supply, above, to determine which power supply is faulty).
P/N 231-02940
73
3 Push the power supply tab in toward the left and at the same time grasp
the power supply handle and slowly pull out the power supply.
Pull out the handle
4 Insert the new power supply and tighten the power supply screw.
74
P/N 231-02940
WARNING! You must connect the grounding wire included with the SG8100 from the DC power supply to an electrically neutral ground (described in Step 1, below). You must also use a 20A circuit breaker to connect to your DC power source as an over-current protection device.
P/N 231-02940
75
2 Disconnect the DC power connector to the faulty power supply that will
be replaced (see Check for a Faulty Power Supply on page 72 to determine which power supply is faulty).
3 Push in the DC power supply latch to the right until it aligns with the
power supply handle and pull the power supply out slowly.
Push the power supply latch toward the power supply handle
76
P/N 231-02940
WARNING! If you use the cables supplied by Blue Coat to reconnect the DC power connections to a DC power source, ALWAYS connect the yellow DC power cord to a negative DC outlet, and connect the black DC power cord to a positive DC outlet.
ALWAYS plug the yellow cord to a negative outlet
P/N 231-02940
77
NIC slot 2
SSL slot 5
The following option upgrade cards are available for installation into the SG8100: Dual GigE Copper Card Quad GigE Copper Card with Pass-Through Quad GigE Fiber LX Card SSL Accelerator Card: Note that the SG8100 supports only one SSL card. If the system shipped with an SSL accelerator card, you cannot add a second.
78
P/N 231-02940
Chapter 6: Troubleshooting
This chapter describes how to locate and solve common problems.
1 Go to the SG8100 home page: open a browser and enter your SG8100
HTTPS IP address followed by a colon and port number 8082, as follows: https://ProxySG_ip_address:8082. Click Yes in the Security Alert dialog, enter your username and password and click OK in the Enter Network Password dialog.
2 Click the Management Console link in the SG8100 home page that appears. 3 Select the Maintenance tab, then click System and Disks and select
Environment.
P/N 231-02940
79
80
P/N 231-02940
If you created a serial console password and forgot it, you must restore the SG8100 to factory defaults and re-do the initial setup. All settings will be lost.
SGOS# restore-defaults factory-defaults
P/N 231-02940
81
If you are accessing a SG8100 located on a remote network (any segment other than the segment where your workstation is attached), verify that other servers on that network are accessible. Try pinging the IP address to verify that the SG8100 is accessible from the workstation. If the SG8100 does not respond to the ping, verify that it is operational, as described earlier.
82
P/N 231-02940
Verify that both interfaces have established a network link. Ping the ProxySG or have the ProxySG ping other devices on the network, such as its gateway. If you are using a bridged deployment, verify that you entered the correct initial configuration URL: https://proxysg_IP.bluecoat.com:8083/ where, proxysg_IP is the IP address you configured for this ProxySG using the front panel or the serial console. Verify that the browser is not proxied. To change or check the browser settings, complete one of the following steps: In a Windows browser, select Tools>Internet Options > Connections. Click LAN Settings and deselect Proxy server if it is selected. In a Firefox browser, select Tools > Options > General. Click the Connection Settings button and deselect Manual or Automatic Proxy Configuration if one of them is selected (select Direct Connection to the Internet). In a Netscape Communicator browser, select Edit > Preferences > Advanced > Proxies and deselect Manual or Automatic Proxy Configuration if one of them is selected (select Direct Connection to the Internet).
Restore the appliance to its factory defaults (the Initial Configuration page is not accessible to an appliance that has already been configured). See Resetting the ProxySG to Factory Defaults on page 88. Use another method, such as the serial console.
P/N 231-02940
83
To Isolate Client Request Failures If the SG8100 is used to access the Internet, and the SG8100 has been working properly, the most likely cause of failed requests is the route between the SG8100 and the Internet or intranet. Before you spend time troubleshooting the SG8100, verify your connection to the Internet by using the ping and traceroute commands from the CLI. If you can ping the destination from the SG8100, use the test http get command to verify that the device can get the object. For information on the ping, traceroute, and test commands, refer to <Emphasis>Blue Coat ProxySG Command Line Interface Reference. If the request fails, try other HTML requests to verify that all requests fail. The SG8100 can be configured to deny access to address groups. If the SG8100 is configured for forwarding or filtering, verify that the requested address does not match a denied subnet and mask. For information on configuring deny settings in the Web interface, refer to Volume 6: The Visual Policy Manager and Advanced Policy.
84
P/N 231-02940
If your network is not configured for transparency, check the Web browser to see if it is using a Proxy Auto-Configuration (PAC) file for auto-configuration. If the browser is configured to use a PAC file, verify that the address of the PAC file is correct and that the file is accessible. If auto-configuration is not being used, check the browser's proxy configuration. If you are not using transparency, the Web browser must be configured for the SG8100's IP address and port. Refer to Volume 1: Getting Started for more information. If the ProxySG responds to the ping, verify that the SG8100's configuration is valid. If it is configured to forward requests, verify that the machine that receives requests SG8100 is working. If the SG8100 is not forwarding requests, check the default gateway address and DNS address. If the SG8100's default gateway address and DNS address are correct, try pinging each address from the CLI to verify that the servers are running. Be sure to ping the gateway and DNS server from the same network segment where the SG8100 is connected. If the default gateway is accessible, the problem most likely lies outside the local network. To verify that the problem is not associated with the SG8100, configure your workstation for the same gateway address as the SG8100, and configure the Web browser not to use a proxy server for HTTP requests.
P/N 231-02940
85
Check the Web browser's proxy address and port. The Web browser must be configured for the SG8100's IP address and port. Refer to Volume 2: Proxies and Proxy Services for information on configuring the clients. If the address or port is not correct, the Web browser might attempt to access the SG8100, then wait for a timeout before retrieving the object directly. If the correct IP address and port for the proxy server is specified in the Web browser, try pinging the IP address to verify that the SG8100 is accessible from the workstation. If the SG8100 does not respond to the ping, verify that it is operational.
1 Open an active session on the terminal server, noting any traffic being
output.
86
P/N 231-02940
P/N 231-02940
87
2 Select Maintenance>General.
88
P/N 231-02940
3 In the Tasks panel, click Restore the configuration to defaults. 4 Click Apply.
The appliance does a soft restart. The power LED turns amber during the restart. Wait until the reset is complete (about one minute) before trying to complete the initial configuration.
P/N 231-02940
89
90
P/N 231-02940
Appendix A: Specifications
Enclosure (Einschlieung) Height (Hhe) Width (Breite) Depth (Lnge) Weight (Gewicht)
Operating Environment
19 in (48.3 cm) rack-mountable 6.95 in (17.652 cm); 4 rack units 17.4 in (44.2 cm) 23.3 in (60.2 cm) 68 lbs (30.8 kg) maximum 100-240V, 50-60Hz, 525 Watts (1+1 redundancy) -36 VDC to -72 VDC, 650 Watts (n+1 redundancy) Operating: 41 to 104 F (+5 to 40 C) Non-operating: -40 to 158 F (-5 to 70 C) Less than 90% (non-condensing) Operating: Up to 9,400 ft (3.0 Km) Non-operating: Up to 15,000 ft (4.6 Km) Two to eight Ultra 320 10,000 RPM or 15,000 RPM SCSI Disk Drives. Up to two Dual Core AMD64 Opteron 1 to 8 GB Two 10/100/1000BaseT on-board ports and two or four 10/100/1000BaseT ports (depending on the add-in card). Hot-swappable SCSI Ultra 320 SGOS v5
Power Input, AC (Stromversorgung) Power Input, DC (Optional) Temperature (Betriebstemperatur) Relative Humidity (Relative Luftfeuchte) Maximum Altitude (Maximale Hhe)
System
Disk Drives (Festplatte) Processors (Prozessor) RAM (Speicher) Network Interfaces (Netzwerk) Backplane
Operating System
P/N 231-02940
91
Regulations
CSA C22.2 No. 950 M95, UL 60950 3rd Edition, EN60950, TUV-GS, TUV-S, CCC, BMSI FCC Class A, EN55022 Class A, VCCI Class A No. 1706609, BSMI, CCC, C-Tick UL/CSA, TUV-S, BSMI, CCC, C-Tick, CE
Lasers
Location of the laser apertures if any (Par. 6.1 3). Example: connectors for fiberoptic component.
Connector
The port on the Gigabit-LX Module transmits at 850 nm wavelength, and is compatible with the IEEE 802.3z Gigabit-LX standard. It accepts multi-mode.
92
P/N 231-02940
Important: Any modification to this product, unless expressly approved by Blue Coat Systems, Inc., could void the users warranty.
P/N 231-02940
93
Mechanical LoadingMounting of the equipment in the rack should be such that a hazardous condition is not achieved due to uneven mechanical loading. Circuit OverloadingConsideration should be given to the connection of the equipment to the supply circuit and the effect that overloading of the circuits might have on overcurrent protection and supply wiring. Appropriate consideration of equipment nameplate ratings should be used when addressing this concern. Reliable Earthing Reliable earthing of rack-mounted equipment should be maintained. Particular attention should be given to supply connections other than direct connections to the branch circuit (for example, use of power strips).
94
P/N 231-02940
P/N 231-02940
95
General Warning
Connection to ports not defined for normal operation, according to this manual, might result in excessive radiated emissions. The user is then responsible for all corrective action in the event of any problem.
96
P/N 231-02940
Declaration of Conformity
Declaration of Conformity We, Blue Coat Systems 420 North Mary Avenue Sunnyvale, CA 94085 Declare under our sole responsibility that the products Blue Coat Systems model 8100 to which this declaration relates is in conformity with the following standards: EN 60950-1: 2001+A11 EN 55022: 1998+A1:2000+A2:2003 EN 55024: 1998+A1:2001+A2:2003 Following the provisions of the 73/23/EEC and 89/336/EEC Directives, including the Amending Directive 93/68/EEC. Blue Coat Systems model 8100 is also in conformity with the following standard: Directive 2002/95/EC, Restriction of Hazardous Substances (RoHS).
420 North Mary Avenue Sunnyvale, CA 94085-4121 USA 866.30.BCOAT Toll Free 408.220.2200 Direct 408.220.2250 Fax www.bluecoat.com
P/N 231-02940
97
98
P/N 231-02940
Index
A
AC power supply about 7 hot-swapping 73 activate license 65 adapter port LEDs 23
B
Blue Coat, technical support 6
C
certificate troubleshooting 86 CLI limited to four sessions 81 logging on to using a direct serial connection 49, 54 logging on using a direct serial connection 58 logging on using an SSH client 5960 session times out 81 client HTML, see HTML 85 configuring the SG8100 using the Setup Wizard 35 connection ports 7 control buttons accessing 10 using for first-time configuration 3031 copyrights document ii
disk drives aligning with guide rails 17, 18 hot-swapping 6971 installing in the ProxySG 17 preparing for insertion 17 removing and replacing 71 taking offline 6971 verifying successful insertion 23 disk lever orientation into drive bay 17 using to lock disk in place 19 DNS server, setting and changing 32 drive bays guide rails 17 inserting disk drives 18 numbered one - eight 17 dual fiber SX upgrade cards 7
E
equipment rack installing the ProxySG into 1113 safety instructions 11, 93
F
first-time configuration overview 25 security warning dialog 36, 82 using a direct serial connection 50 terminal emulator parameters 40 using a Web browser conditions required 35 front panel bezel tabs 17 opening 10, 16 front-panel PIN configuring 61
D
DC power supply 7 hot-swapping 75 declaration of conformity 97 diagnosing system malfunction 79
P/N 231-02940
99
G
gigabit Ethernet ports 7
H
hot-swapping AC power supply 73 DC power supply 75 disk drives 6971 power supplies 7277 HTML requests fail 84 responses slow 85
N
network cables attaching 13 network interfaces 7 network upgrade slots 7
O
option card kits 66
I
IP address, setting and changing 32 IP gateway, setting and changing 32 IP subnet mask, setting and changing 32
P
packing list 6 password auto-configuration of 32 CLI 58 configuring using the front panel 33 failure 83 PC connection problems 39 PCI card slots 7 ping command 80 ports gigabit Ethernet 7 serial console 7 power button accessing 10 power cords attaching 14 power supplies AC and/or DC 7 hot-swapping 7277 insertion warning 16, 72, 75, 77 powering on and off 20 ProxySG CLI passwords for 58 CLI username for 58 diagnosing system malfunction 79
J
Java errors 84
L
LAN connector LEDs 23 LCD cursor in 2930 modes reflected in 2930 LEDs checking system status with 21 description of color and flash rate 23 disk drive 22 LAN 22 power 22 system warning 22 system warning diagnostic 79 license, activation 65 logging on using a direct serial connection 49, 54
M
Management Console cannot access 81 logging on to 5657
100
P/N 231-02940
disk drives, installing 17 equipment rack, installing into 1113 front panel, opening 10, 16 logging on to 5660 modes in 2930 packing list 6 powering on and off 20 testing 80
environmental and electrical 91 lasers 92 regulatory statements 9396 SSL accelerator upgrade cards 7 system malfunction diagnosing 79
T
technical support 6 terminal emulator direct serial connection parameters 39
S
safety instructions equipment rack 11, 93 security configuring a front-panel PIN 61 security warning dialog at first-time configuration 36, 82 serial console port 7 port password, securing 44 SG8100, using with 39 SG8100,using with 49 troubleshooting 80 SG8100, configuring configuring network settings 32, 34 connection ports 7 control button functions 30 control buttons 3031 control buttons, accessing 10 disk drives, accessing 10 instructions 25 using a serial terminal or PC 39 using a Web browser 35, 38 using Director registration, problems 87 using front panel LCD and buttons 28, 34 using the Setup Wizard 35, 52 viewing modes in the LCD 2930 SG8100, invalid certificate, troubleshooting 86 specifications connector 92 declaration of conformity 97
U
upgrade cards dual fiber SX 7 insertion slots for 78 SSL accelerator 7 upgrade kit 67 username CLI 58 default 32 failure 83
W
Web interface, see Management Console Web setup wizard not accessible 82
P/N 231-02940
101
102
P/N 231-02940