Installing and Configuring DSG
Before you begin
Before you begin installing and configuring DSG, consider the following.
Assumptions
This section assumes that
There is no prior installation of DSG. Installation of DSG is happening from the beginning..
GTM and LTM are provisioned and installed. For information about prescribed configurations for GTM or LTM, refer to Recommended Traffic Manager.
Prerequisites
Ensure there is good network connectivity between the machine where DSG is going to be installed and all the ESAs, and they can communicate with each other.
Ensure ESAs in both the Primary site, ESA P1, S1, S2, and the DR site, ESA S3, S4, S5, are up and running.
Ensure that ESAs in both sites are in a TAC.
Ensure that PIM is initialized on all the ESAs.
Ensure that ESAs in Primary site are in an Audit Store Cluster and ESAs in DR site are in a separate Audit Store Cluster.
Ensure all ESAs and DSGs are in the cluster, and that they themselves are reachable using hostname or FQDN.
Installing and Configuring the DSGs.
Install DSGs v4.0.0.
For more information about installing DSG v4.0.0, refer to Installing the DSG.
Create a TAC. Create a TAC in one of the DSGs installed in the previous step.
Join DSGs to the TAC. Join the rest of the DSGs to the TAC created in the previous step.
Upload and Install DSG Management Server Certificates. Upload and install DSG Management Server certificates in each of the DSGs individually. Ensure the SAN field in each of the certificates has the hostname and FQDN of the DSG node it is going to be installed in.
Perform ESA Communication.
Perform ESA communication from all the DSGs. For all the options in ESA communication, provide GTM IP, hostname, or FQDN as applicable.
For more information about performing set ESA communication, refer to Setting up ESA communication.
Install DSG patch on all the ESAs in the Primary and DR site.
Install DSG v4.0.0 patch on all ESAs in both sites, that is, ESA P1, S1, S2 in the primary site and ESA S3, S4, S5 in the DR site.
Register DSG with ESA.
During the prompt for DSG details during DSG registration, provide any of the DSG’s FQDN/hostname in TAC. Ensure the same DSG FQDN or hostname is provided during DSG registration in all other ESAs.
Upload and apply DSG Admin Tunnel Certificates.
Upload and apply DSG Admin tunnel certificates from Web UI in ESA P1.
For more information regarding uploading and applying DSG Admin tunnel certificates, refer to Upload Certificate/Keys.
Create and Deploy DSG Tunnels and Ruleset.
Create Tunnels and Ruleset.
Create tunnels and rulesets from the Web UI in ESA P1.
For more information related to creating tunnels, refer to Tunnels.
For more information related to creating rulesets, refer to Ruleset Reference.
Deploy Rulesets.
Click on the Deploy button from the DSG’s Cluster page in ESA P1 to deploy rulesets in all the DSGs present in the TAC.
For more information related to deploying rulesets, refer to Deploying configurations to the cluster.
Check Health Status of DSGs under Cluster Page.
After the deployment of rulesets is successful, check the health status of DSGs in TAC from the DSG’s Cluster page in ESA P1. All the DSGs should show health status as green.
Ensure TAC Replication Job includes DSG configuration.
Ensure that the TAC replication job also includes the DSG configuration. This configuration must be replicated from the Primary ESA P1 to all Secondary ESAs, S1, S2, S3, S4, and S5.
Make sure to follow these steps meticulously to ensure a seamless installation and configuration process.
Feedback
Was this page helpful?