Manage U-Series Appliance Security Settings
Download a Crypto Key
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under Download Crypto Key Options, create an encryption password.
- Click Submit. The crypto key zip file is created and downloaded to your system.
Upload a Crypto Key
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under Upload Crypto Key Options, enter the encryption password.
- Drag and drop the crypto key zip file into the drop area or click the button to browse to the zip file.
- Click Generate the Uploaded Key.
Check FIPS Compliance
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under FIPS Compliance Checking, click the toggle to change it to FIPS State (Yes).
- Click Update FIPS Setting.
- You must reboot the U-Series Appliance for this setting to take effect.
Manage the U-Series Appliance API Key
The U-Series Appliance API manages the communication between U-Series Appliances when high availability is used in your environment. The API key enables U-Series Appliances to communicate with each other.
The API key is automatically generated and is available to copy from the Appliance API Keys page.
For security reasons, we recommend that you regenerate the key regularly. Remote appliances using the previous Registration Code to communicate with this appliance will be denied access until the new Registration Code is copied to that appliance and registered again.
To view this appliance's key details:
- On the sidebar menu, click Integrations, and then select Appliance API Keys.
- Ensure that the This Appliance tab is selected. The details appear in the Appliance Key Details section.
- To view the Registration Code, from the dropdown list, select an IP Address to Use in Configuration.
Regeneration and Settings
To create a new API key:
- Click Regenerate Registration Code. A new API key appears in the Appliance Key Details section on the left.
- From the dropdown list, select an IP Address to Use in Configuration. The associated registration code appears.
- At the right of the Registration Code field, click the Copy button.
You must copy the new registration code to the remote appliances that you want to communicate with this appliance.
Register a Remote Appliance
Communication between appliances requires both appliances to be registered with each other.
To register a remote appliance:
- Open the U-Series Appliance Console on the remote appliance first.
- On the sidebar menu, click Integrations and select Appliance API Keys.
- Click the Register Remote Appliance tab.
- Copy and paste in the registration code from the first appliance.
- (Optional). Enter a short Description for the appliance being registered.
- Click Register Remote Appliance.
- Click the This Appliance tab.
- To view that appliance's Registration Code, from the dropdown list, select an IP Address to Use in Configuration.
- At the right of the Registration Code field, click the Copy button.
- Go back to the first appliance's console, and go to the Appliance API Keys page again.
- Click the Register Remote Appliance tab.
- Paste the registration code from the remote appliance.
- (Optional). Enter a short Description for the appliance being registered.
- Click Register Remote Appliance.
The registered remote appliance now appears in the Registered Remote Appliance table at the bottom of the page. At any time, to refresh that list, click the Refresh button at the top right of the table.
To view more of the table, at the right of the Appliance API Keys section, click the down arrow to collapse that section.
Background Network Check Interval
In the Registered Remote Appliance table listing, you might see the word Communicating under the Status Ongoing and Status Incoming headings. You can adjust how often the connected appliances check with each other to make sure they are still connected.
To set the Background Network Check Interval:
- Under the This Appliance tab, in the Regeneration and Settings section, enter the number of minutes for the background network check interval.
- Click Save Settings.
Turn SSL Authentication Off or On
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under Event Service SSL Requirement, click the toggle to Event Service SSL/Certificate Required (No) to ignore SSL certificate authentication.
- Click Submit.
We do not recommend disabling SSL certificate authentication. SSL authentication should be disabled only in certain rare circumstances, such as during testing.
Analytics & Reporting Endpoints
If the BeyondInsight Analytics & Reporting website is unreachable, you can refresh the settings to establish the connection.
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under Analytics & Reporting Web Service Endpoints, clickRefresh.
Generate and Export Certificates
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- To regenerate the SSL certificate to match the U-Series Appliance network name, under Generate SSL Certificate, click Generate Certificate.
This certificate will not be trusted by the client browser.
- To export the client certificate, under Export Client Certificate, enter the password for the certificate, and then click Export Certificate.
Set a Security Protocol
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under Security Protocols (TLS), select the security protocol that applies to your environment.
- Click Update Security Protocols.
- KB2979597: https://support.microsoft.com/en-us/topic/kb2979597-sql-server-2008-r2-service-pack-3-release-information-25af206d-68ab-4be5-ddc9-4d2e69c7d2fb
- KB3144517: https://support.microsoft.com/en-us/topic/kb3144517-cumulative-update-package-13-for-sql-server-2014-f69a0087-2489-316b-2d83-944438f4e30b
Turn On HSTS
You can apply extra security to the U-Series Appliance website by using HTTP strict transport security (HSTS) technology.
- On the sidebar menu, click LA (if you are in the new environment only).
- On the Maintenance menu, click Security Settings.
- Under HTTP Strict Transport Security, toggle the switch to on.
- Click Update HSTS Setting.