Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Changing the TRITON management server IP address or name : Migrating the Web Security manager off of a Websense appliance
Migrating the Web Security manager off of a Websense appliance
Topic 50625 | Management Server Location Change | Web Security Solutions | v7.7.x, 7.8.x
In version 7.8, the Web Security manager cannot reside on an appliance. Before upgrading, disable the v7.7 on-appliance TRITON console and create a Windows-based TRITON management server.
Use the following instructions to complete the process:
*
*
*
Step 1: Disable the on-appliance TRITON console
When you disable the TRITON console on the appliance, you are prompted to back up your existing configuration. You can then use the backup file to restore your configuration to the new management server machine.
1.
https://<C_interface>:9447/appmng
2.
Under Configuration, select Web Security Components.
3.
Under TRITON - Web Security, select Disabled.
4.
Click Save.
The disabling process may take several minutes. Wait for it to complete.
5.
When the process completes successfully, a TRITON Configuration link appears below the Disabled option. Use this link to create a backup of TRITON settings that can be restored to the off-appliance TRITON Unified Security Center:
a.
b.
c.
Save the TRITON backup file (EIP_bak.tgz) in a convenient location.
Step 2: Create a new TRITON management server
Getting started
Install TRITON management components on a Windows Server 2008 R2 machine that meets or exceeds the v7.8 system requirements. (Note that while v7.8.x components can also run on Windows Server 2012, v7.7 components cannot.)
1.
2.
Right-click WebsenseTRITON77xSetup.exe and select Run as administrator to launch the installer. After a few seconds, a progress dialog box appears, as files are extracted.
3.
4.
On the Subscription Agreement screen, select I accept this agreement, then click Next.
5.
On the Installation Type screen, select TRITON Unified Security Center, then mark the Web Security check box and click Next.
6.
On the Summary screen, click Next to continue the installation.
TRITON Infrastructure Setup launches.
Install TRITON infrastructure components
The TRITON infrastructure includes data storage and common components for the management modules of the TRITON console.
1.
2.
*
*
 
Important 
3.
On the SQL Server screen, select Use existing SQL Server on another machine, then specify the location and connection credentials for a database server located elsewhere in the network.
a.
Enter the Hostname or IP address of the SQL Server machine, including the instance name, if any, and the Port to use for SQL Server communication.
If you are using a named instance, the instance must already exist.
If you are using SQL Server clustering, enter the virtual IP address of the cluster.
b.
Specify whether to use SQL Server Authentication (a SQL Server account) or Windows Authentication (a Windows trusted connection), then provide the User Name or Account and its Password.
If you use a trusted account, an additional configuration step is required after installation to ensure that reporting data can be displayed in the Web Security manager. See Configuring Websense Apache services to use a trusted connection.
c.
Click Next.
The installer verifies the connection to the database engine. If the connection test is successful, the next installer screen appears.
If the test is unsuccessful, click OK to dismiss the message, verify the information you entered, and click Next to try again.
4.
*
Select an IP address for this machine. If this machine has a single network interface card (NIC), only one address is listed.
Administrators will use this address to access the TRITON console (via a web browser), and Websense component on other machines will use it to connect to the TRITON management server.
*
Specify the Server or domain of the user account to be used by TRITON Infrastructure and TRITON Unified Security Center. The name cannot exceed 15 characters.
*
Specify the User name of the account to be used by TRITON Unified Security Center.
*
Enter the Password for the specified account.
5.
On the Administrator Account screen, enter an email address and password for the default TRITON console administration account: admin. When you are finished, click Next.
System notification and password reset information is sent to the email address specified (once SMTP configuration is done; see next step).
6.
On the Email Settings screen, enter information about the SMTP server to be used for system notifications and then click Next. You can also configure these settings after installation in the TRITON console.
 
Important 
If you do not configure an SMTP server now and you lose the admin account password (set on previous screen) before the setup is done in the TRITON console, the "Forgot my password" link on the logon page does not provide password recovery information. SMTP server configuration must be completed before password recovery email can be sent.
*
IP address or hostname: IP address or host name of the SMTP server through which email alerts should be sent. In most cases, the default Port (25) should be used. If the specified SMTP server is configured to use a different port, enter it here.
*
Sender email address: Originator email address appearing in notification email.
*
Sender name: Optional descriptive name that can appear in notification email. This is can help recipients identify this as a notification email from the TRITON Unified Security Center.
7.
8.
If an Error 1920 message appears, check to see if port 9443 is already in use on this machine.
If port 9443 is in use, release it and then click Retry to continue installation.
9.
You are returned to the Installer Dashboard and, after a few seconds, the Web Security component installer launches.
Install Web Security management components
1.
*
*
2.
When prompted, supply the IP address and port used by Policy Broker (on the full policy source appliance or Policy Broker machine) in your deployment.
3.
4.
5.
6.
This completes the management server installation process.
Step 3: Restore your TRITON console backup
1.
Copy the EIP_bak.tgz file created when you disabled your on-appliance Web Security manager to the new TRITON management server machine.
2.
When the process is complete, you should have a directory called EIP_bak that contains, among other files, EIP.db and httpd-data.txt, as well as apache and tomcat folders.
3.
4.
*
*
*
5.
Open the Windows Control Panel and select Programs > Programs and Features, then select Websense TRITON Infrastructure.
6.
Click Uninstall/Change.
7.
When asked if you want to modify, repair, or remove the TRITON Infrastructure, select Modify, then click Next until you get to the Restore Data from Backup screen.
8.
Mark the Use backup data box and click the Browse button to locate the backup folder, then click Next until you begin the restore process.
 
Note 
9.
Click Finish to complete the restore wizard.
10.
Go back to the Services window and click Refresh. If the Websense TRITON Unified Security Center service (or any other service that you stopped manually) has not restarted, right-click it and select Start.
Once the restore process is complete, a file named DataRestore.log is created in the date-stamped backup folder that was used for the restore.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Changing the TRITON management server IP address or name : Migrating the Web Security manager off of a Websense appliance
Copyright 2016 Forcepoint LLC. All rights reserved.