Installing the DSG
Installing the DSG On-Premise or on Cloud Platforms
The Data Security Gateway (DSG) installation requires an existing ESA. It serves as a single point of management for the data security policy, rules configuration, and on-going monitoring of the system. This section provides information about the recommended order of the steps to install a DSG appliance.
Important: The DSG 4.1.0 release does not include installation media such as ISO, Cloud Images (AWS AMI, Azure, or GCP), or VMware images.
This release is supported only as an upgrade for existing DSG deployments.
Ensure that the following steps are followed to install DSG 4.1.0:
- Install DSG v4.0.0.
For more information about installing the DSG, refer to the section Installing the DSG. - Upgrade this DSG to v4.1.0 using the upgrade patch.
For more information about upgrading to DSG v4.1.0, refer to the section Upgrading to DSG 4.1.0.
1 - Installing the DSG patch on ESA
Installing the DSG patch on ESA
Steps to install the DSG patch (ESA_PAP-ALL-64_x86-64_10.2.2+MR.xxxx.DSGUP.4.1.0.xx.pty) on the ESA to extend its Web UI with the DSG menu.
Login to the ESA Web UI.
Navigate to Settings > System > File Upload.
Click Choose File to upload the DSG patch file.
Select the file and click Upload.
The uploaded patch appears on the Web UI.
On the ESA CLI Manager, navigate to Administration > Installation and Patches > Patch Management.
Enter the root password.
Select Install a Patch and press OK.
Select the uploaded patch.
Select Install.
The patch is successfully installed.
After the DSG patch is installed, the DSG component is visible on the ESA Web UI. The details of the DSG component can be verified from the About screen on the ESA. To verify the DSG installation, run the following steps.
- Login to the ESA Web UI.
- Click the
(Information) icon, and then click About. - Verify that the DSG version is reflected as DSG 4.1.0.
2 - Configuring the DSG Cluster
Create a DSG cluster.
Creating a DSG cluster
On the DSG Web UI, navigate to System > Trusted Appliances Cluster.
The Join Cluster screen appears.
Click Create a new Cluster to create a DSG cluster.
The Create Cluster screen appears.
Click Create and select a preferred communication method.
Click Save to create a cluster.
Adding DSG Nodes to an existing Cluster
This section outlines the steps to add additional DSG nodes to an existing cluster in which a DSG node is already part of the Trusted Appliance Cluster (TAC).
Before you begin
Ensure that the communication process between the DSG and the ESA is properly established.
For more information about communcication process, refer to the Set ESA Communication
Ensure that the DSG patch is applied on the ESA.
For more information about applying the DSG patch on the ESA, refer to the Installing the DSG patch on ESA
On the ESA Web UI, navigate to Cloud Gateway > {DSG build number} > Cluster > Monitoring.
The Cluster screen appears.
Select the Actions drop down list in the Cluster Health pane.
The following options appear:
- Apply Patch on Cluster
- Apply Patch on selected Nodes
- Change Groups on Entire Cluster
- Change Groups on Selected Nodes
- Add Node
Perform the following steps to add a node.
Click Add Node.
The Add new node to cluster screen appears.
Enter the FQDN or IP address of the DSG node to be added in the cluster in the Node IP field.
Caution: Make sure that the DSG host address matches the Subject Alternative Name(SAN) field or Common Name(CN) in the DSG server certificate.
For more information about checking the DSG host address, refer to the section Ascertaining the host address in the DSG server certificate
Enter the administrator user name for the ESA node user in the Node User Name field.
Enter the administrator password for the ESA node user in the Node Password field.
Enter the node group name in the Deployment Node Group field.
Note: If the deployment node group is not specified, by default it will get assigned to the default node group.
Click Submit.
Click Refresh Dropdown > Deploy or Deploy to Node Groups.
For more information about deploying the configurations to entire cluster or the node groups, refer to the section Deploying the Configurations to Entire Cluster and Deploying the Configurations to Node Groups.
The node is added to the cluster.
3 - Forward Logs to the Audit Store
Configure logs to reach Insight
After installing or upgrading to the DSG 4.1.0, you must configure the DSG to forward the DSG logs to the Audit Store on the ESA using the steps provided in this section.
Ensure that you have configured the Audit Store component on the ESA. Configuring this component allows the Audit Store to store and report the DSG appliance and audit logs.
For more information about Audit Store, refer to the section Logging Architecture.
Forwarding appliance logs to the Audit Store
The appliance logs (syslog), transaction metrics, error metrics, and usage metrics are forwarded through the td-agent service to the Audit Store on the ESA.
To forward appliance logs to the Audit Store:
Login to the DSG CLI Manager.
Navigate to Tools > PLUG - Forward logs to Audit Store.
Enter the password of the DSG root user and select OK.
Enter the username and password of the DSG administrator user and select OK.
Select OK .
Enter the IP address for the ESA and select OK. You can specify multiple IP addresses separated by comma.
Enter y to fetch certificates and select OK.
These certificates are used to validate and connect to the target node. It is required to authenticate with the Audit Store while forwarding logs to the target node.
If the certificates already exists on the system, then specify n in this screen.
Enter the username and password of the ESA administrator user and select OK.
The td-agent service is configured to send logs to the Audit Store and the CLI menu appears.
Repeat step 1 to step 8 on all the DSG nodes in the cluster.
Forwarding audit logs to the Audit Store
The audit logs include protect, reprotect, unprotect, RPP, and Pycore logs. The audit logs are forwarded through the Log Forwarder service to the Audit Store on the ESA, where they are stored.
To forward audit logs to the Audit Store:
Login to the DSG CLI Manager.
Navigate to Tools > ESA Communication.
Enter the password of the DSG root user and select OK.
Select the Logforwarder configuration option. Press Tab to select Set Location Now and press Enter.
Select the ESA that you want to connect with, and then press Tab to select OK and press ENTER.
Note: If you want to enter the ESA details manually, then select the Enter manually option. You will be asked to enter the ESA IP address or hostname when this option is selected.
Enter the ESA administrator username and password to establish communication between the ESA and the DSG. Press Tab to select OK and press Enter.
Enter the IP address or hostname for the ESA. Press Tab to select OK and press ENTER. You can specify multiple IP addresses separated by comma.
After successfully establishing the connection with the ESA, the following Summary dialog box appears. Press Tab to select OK and press Enter.
Repeat step 1 to step 8 on all the DSG nodes in the cluster.
4 - Registering the DSG node with ESA
Before you begin
Note: Ensure that only one DSG node is registered with the ESA.
On the ESA CLI Manager, navigate to Tools > Register DSG Details.
Enter the root password, press Tab to select OK and press Enter.
Enter the FQDN of the DSG and enter the DSG administrator credentials in the Username and Password text boxes. Press Tab to select OK and press Enter.
The DSG TAC Registration screen appears.
- After successfully registering the DSG with the ESA, the ESA communication is established successfully between the DSG and the ESA.
5 - Updating the host name or domain name of the DSG or ESA
Perform the following steps if the hostname or FQDN of a DSG node is changed.
Remove this DSG node from the DSG TAC.
On the DSG Web UI, navigate to System > Trusted Appliances CLuster.
Under the Management drop down, select Leave Cluster.
If the custom certificates are used, regenerate these certificates with the updated hostname.
If the custom certificates are not used, regenerate the certificate using the following command.
python3 -m ksa.cert.manager --installation-apply
Caution: Run this command only on the DSG node where the hostname or FQDN has changed.
Ensure that the TAC is created on ESA.
For more information about creating a TAC, refer to Create a TAC on ESA.
Run the ESA communication process.
For more information, refer to Setting up ESA communication.
If the current DSG node was registered with ESA, then re‑register the DSG node because the hostname has been updated.
For more information, refer to Registering the DSG.
If single DSG node was present in the DSG-DSG TAC, then re‑register the DSG node because the hostname has been updated.
For more information, refer to Registering the DSG.
If DSG node is not registered with the ESA and there are multiple DSG nodes present in DSG-DSG TAC, then add the DSG node to the cluster.
Adding a DSG node
Perform the following steps if the hostname or FQDN of a ESA node is changed.
If the custom certificates are used, regenerate these certificates with the updated hostname.
If the custom certificates are used, then to choose the latest certificates, run the following steps.
On the DSG Web UI, navigate to Settings > Network > Manage Certificates.
Under the Management area, select Change Certificates.
Under CA Certificate(s), unselect the CA certificate from ESA. Click Next.
Under Server Certificates, retain the default settings. Click Next.
Under Client Certificates, ensure that only the latest DSG System client certificate and key is selected.
Click Apply.
If the custom certificates are not used, regenerate the certificate using the following command.
python3 -m ksa.cert.manager --installation-apply
Caution: Run this command only on the ESA node where the hostname or FQDN has changed.
Update the ESA configuration after updating the host name or domain name of the ESA machine.
For more information, refer to Update the ESA configuration.
After updating the certificates, ensure that the set ESA communication steps are performed on each DSG node.
For more information about set ESA communication, refer to Set communication process.
Configure the DSG to forward the logs to Insight on the ESA.
For more information, refer to Forwarding Logs to Insight|