Deployment and Installation Center
Websense TRITON Enterprise v7.6.x

Go to the table of contents Go to the previous page Go to the next page Go to the index
Email Security Gateway (V10000 G2) > Setting up the appliance

Note 
If you have already completed the appliance set up steps provided in the Websense V-Series Getting Started guide, skip to
The Quick Start poster, which comes in the shipping box with your appliance, shows you all items included in each Websense appliance shipping box. The 2-page Quick Start explains how to set up the hardware and shows how to connect the cables to the appliance and to your network.
Network interfaces C, E1, and E2 (if used) must be able to access a DNS server. These interfaces typically have continuous access to the Internet once the appliance is operational. Essential databases are downloaded from Websense servers through these interfaces.
*
Make sure that this address is permitted by all firewalls, proxy servers, routers, or host files that control the URLs that the C, E1, and E2 interfaces can access.
After hardware setup, connect directly to the appliance through the serial port or the monitor and keyboard ports. For serial port activation, use:
Continue on to the next section to complete the initial configuration.
The first time you start a Websense appliance, a brief script (firstboot) prompts you to supply settings for the network interface labeled C and a few other general items. You can run the script again if you want to examine your settings or change settings. You can also change settings through the Appliance Manager (user interface) after firstboot has been executed.
Gather the following information before running the script. Some of this information may have been written down on the Quick Start during hardware setup.
                                       
*
E1 or P1 to download antispam and antivirus database updates from Websense (Email Security mode)
Configuring these interfaces to access the Internet for database downloads is done through the Appliance Manager and through the TRITON Unified Security Center. See the Appliance Manager Help for information about configuring the interfaces. See the TRTION - Email Security Help for information about configuring database downloads.
Note 
To configure the appliance, connect through the serial port or the keyboard/video ports and complete the firstboot script. For serial port activation, use:
3.
When asked if you want to begin, enter yes to launch the firstboot activation script.
4.
At the first prompt, select Email Security only mode.
After the activation script has been completed successfully, access the Appliance Manager. Open a supported browser, and enter this URL in the address bar:
The Appliance Manager is the Web-based configuration interface for the appliance. Through it you can view system status, configure network and communication settings, and perform general appliance administration tasks.
After completing the initial configuration required by the firstboot script, use the Appliance Manager to configure important settings for network interfaces E1, E2, P1, and P2 (E2, P1, and P2 are optional). Interfaces P1 and P2 can be bonded to E1 and E2, respectively, either for load balancing or active/standby.
Gather the following information before running the Appliance Manager. Some of this information may have been written on the Quick Start during hardware setup.
Be sure that interface C can access the NTP server. If interface C does not have Internet access, you can install an NTP server locally on a subnet that can be accessed by interface C.
If you use both E1 and E2, the default gateway and DNS configuration are shared by both.
Follow these steps to configure basic system and network interface settings. See the Appliance Manager Help for detailed instructions on any field or area, or for information about other available settings.
2.
Log on with the user name admin and the password set during initial appliance configuration.
3.
In the left navigation pane, click Configuration > System.
4.
Under Time and Date:
*
Automatically synchronize with an NTP server: select this option to use a Network Time Protocol server. Specify up to three NTP servers. Use of an NTP server is recommended, to ensure that database downloads and time-based policies are handled precisely.
*
Manually set time and date: select this option to enter a system time and date yourself.
c.
Click Save in the Time and Date area.
5.
In the left navigation pane, click Configuration > Network Interfaces.
6.
Under Websense Email Security Gateway Interfaces (E1 and E2), configure the E1 and E2 (optional) interfaces.
a.
Select whether E1 only or both E1 and E2 are used.
If you choose E1 only, enter configuration information (IP address, subnet mask, default gateway, DNS IP addresses) under E1.
If you choose E1 and E2, enter configuration information under both E1 and E2. Note that default gateway and DNS configuration (under Shared Setting) are shared between both E1 and E2.
b.
Click Save in the Websense Email Security Gateway Interfaces (E1 and E2) area when you are done.
7.
Under Expansion Interfaces (P1 and P2), choose whether to bond to P1 and P2 to E1 and E2.
Interfaces P1 and P2 can be cabled to your network and then bonded through software configuration to E1 and E2. If you choose to bond the interfaces, P1 must be bonded to E1 and P2 to E2. No other pairing is possible.
You can choose to bond or not bond E1 and E2 independently. You do not have to bond both. Also, you can choose different bonding modes for E1 and E2 (e.g., E1/P1 could be Active/Standby while E2/P2 could be Load balancing).
a.
Under P1, select the check box for Bond to E1 interface.
*
Active/Standby: Select this for failover. E1 is active, and P1 is in standby mode. Only if the primary interface fails would its bonded interface (P1) become active.
*
Load balancing: Select this for load balancing. If your switch or router supports load balancing, then traffic to and from the primary interface is balanced between the primary interface (E1) and its bonded interface (P1).
c.
Click Save in the Expansion Interfaces (P1 and P2) area.
Follow the instruction above for bonding E1 to P1, substituting E2 in place of E1 and P2 in place of P1. Make sure E2 is enabled. Otherwise the P2 options will be inactive. (See Step 6 for instructions on activating E2.)
a.
In the left navigation pane, click Configuration > Routing.
b.
Under Static Routes, use the Add/Import button to specify customized, static routes.
c.
Under Module Routes, use the Add button to specify non-management Web Security or Email Security traffic through the C interface.
d.
For either static or module routes, use the Delete button to remove existing routes, if necessary.
Note 
An existing route cannot be edited. If you want to edit a route, delete it and then use the Add/Import (static) or Add (module) button to specify the route with the changes you want.
9.
Click Log Off, at the top right, when you are ready to log off Appliance Manager.


Go to the table of contents Go to the previous page Go to the next page Go to the index
Email Security Gateway (V10000 G2) > Setting up the appliance