EasyManua.ls Logo

Thales V6000 - User Manual

Thales V6000
181 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Loading...
Data Security Manager
DSM Installation and Configuration Guide
6.4.2
Document Version 2
06/18/2020

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Thales V6000 and is the answer not in the manual?

Summary

Preface

Documentation Version History

Tracks changes made to document versions.

Assumptions

Lists prerequisites and knowledge assumed for the document.

DSM Hypervisor Support

Details supported hypervisors for virtual DSM deployment.

Document Conventions

Typographical Conventions

Explains common text and formatting conventions used in the manual.

Notes, Tips, Cautions, and Warnings

Describes different types of informational and cautionary statements used.

Hardware-Related Warnings

Provides specific warnings related to electrostatic discharge and hazardous voltages.

Sales and Support

Offers contact information and resources for sales and technical support.

Chapter 1: The Data Security Manager

DSM Overview

Introduces the Data Security Manager component and its functions.

DSM Deployment

Explains the DSM's role in a VTE environment and its architecture.

Chapter 2: DSM V6100 Hardware Appliance

DSM V6100 Overview

Describes the V6100 appliance and its FIPS 140-2 Level 3 HSM.

Remote HSM Administration

Explains the benefits and requirements for remote management of the V6100 HSM.

Administrator Card Set (ACS)

Details the ACS, its creation, and its importance for securing the HSM.

V6100 Operations that require the ACS

Lists administrative operations that necessitate the use of the ACS.

Configuring a V6100 Appliance

Guides through the setup and configuration of the V6100 appliance.

DSM Installation Checklist

A checklist to gather required information for DSM installation.

Pre-configuration tasks

Outlines essential tasks to perform before DSM installation.

Chapter 3: DSM V6000 Hardware Appliance

Overview

Introduces the V6000 appliance and its capabilities, including HSM integration.

Configuring a V6000 Appliance

High-level steps for installing and configuring the V6000 hardware appliance.

DSM Installation Checklist

A checklist for gathering installation requirements for the V6000 appliance.

Pre-configuration tasks

Outlines essential tasks before V6000 DSM installation.

Configuration Tasks

Lists the main configuration steps for the DSM appliance.

Connect to the V6000 appliance

Instructions for connecting to the V6000 appliance via serial console.

Access the DSM Command Line Interface (CLI)

Steps to access the DSM CLI for configuration.

Configure network settings

Guides on setting up network interfaces, IP addresses, and gateways.

Configure a bonded NIC device

Explains aggregating NICs for load balancing and fault tolerance on the V6000.

Bonding driver modes

Describes different bonding policies for NIC aggregation.

Enable DHCP on bond0 interface

Instructions to enable DHCP for the bonded interface on the V6000.

Configure NTP, time zone, date, time

Setting time and date on the V6000 for system operations.

Configure the hostname

Steps to set the hostname for the V6000 appliance.

Generate DSM Certificate Authority and create ACS

Process for creating CA and ACS for the V6000 appliance.

Configuring IPMI

Explains IPMI configuration for the V6000 appliance.

Verify Web Access

Verifies access to the DSM Management Console via a web browser.

Upload a license file

Guides on uploading the license file to enable functionality.

Full Disk Encryption

Details the security feature of automatic root filesystem encryption.

nShield Connect Integration

Explains integrating nShield Connect HSMs with DSM appliances.

DSM Installation on bare metal using IBM Cloud

Steps for installing DSM on bare metal via IBM Cloud.

Chapter 4: Installing and Configuring a DSM

Overview

Introduces virtual DSM deployment options and features like encryption and DHCP.

Configuring a Virtual Appliance

High-level steps for installing and configuring virtual DSM appliances.

Virtual DSM Installation Checklist

A checklist for virtual DSM installation requirements.

Pre-Configuration tasks

Essential tasks before installing a virtual DSM.

Access the Command Line Interface (CLI)

Steps to access the DSM CLI for virtual appliance configuration.

Virtual Appliance Setup

Detailed procedure for deploying the DSM OVA file.

Disk Re-encryption for DSM Fastboot Image

Process for re-encrypting the root disk for fastboot images.

Disk Re-encryption after initial setup

Steps to re-encrypt the disk and create a master key post-setup.

Virtual Appliance Configuration

Guides on configuring network settings and hostnames for virtual appliances.

Configure network settings

Detailed steps for configuring network interfaces and addresses.

Configure a bonded NIC device

Explains aggregating NICs for load balancing and fault tolerance.

Bonding driver modes

Describes different bonding policies for NIC aggregation.

Enable DHCP on bond0 interface

Instructions to enable DHCP for the bonded interface.

Configure NTP, time zone, date, time

Setting time and date for system operations.

Configure the hostname

Steps to set the FQDN for the virtual DSM.

Generate DSM Certificate Authority and create ACS

Process for creating CA and ACS for virtual appliances.

Verify Web Access

Verifies access to the DSM Management Console via browser.

Upload a license file

Guides on uploading the license file to enable functionality.

Full Disk Encryption

Details the security feature of automatic root filesystem encryption.

DSM Installation on bare metal using IBM Cloud

Steps for installing DSM on bare metal via IBM Cloud.

Deploying a DSM Azure Image

Instructions for deploying the DSM image on Azure.

Configure the Hostname

Steps to configure the hostname for the DSM on Azure.

Generating the CA

Process to generate the DSM certificate authority on Azure.

Ping the DSM in Azure

Explains how to ping DSM instances in Azure for connectivity checks.

Enabling Ping

How to enable ping for legacy Vormetric products in Azure.

Configuring an HA Cluster

General guidance on configuring HA clusters.

Deploying a DSM AWS image

Instructions for deploying the DSM AMI on AWS.

Installing DSM

Steps to install the DSM AMI on AWS EC2.

Configuring HA

Steps to set up an HA cluster in multiple regions for AWS.

Deploying a DSM in the Google Cloud platform

Guides on deploying virtual DSM on Google Cloud Platform.

Obtain the DSM image for GCP Deployment

How to download the DSM TAR file for GCP.

Upload DSM Image to GCP Storage

Steps to upload the DSM image to GCP Cloud Storage.

Create a GCP Image

Process for converting the DSM tar image into a GCP image.

Creating a GCP Instance of DSM

Steps to create a GCP VM instance for DSM.

Deploying a DSM to GCP through the GCP CLI

Alternative CLI method for deploying DSM on GCP.

Create the GCP Instance in the CLI

CLI commands to create a GCP instance.

KVM Deployment

Guides on deploying KVM images using virt-manager and virsh.

Deploying on a Xen Hypervisor

Instructions for deploying DSM on a Xen hypervisor.

High Availability (HA) Configuration for Virtual Appliances

Procedures for configuring HA for virtual appliances.

Chapter 5: Luna SA HSM

Luna Compatibility

Lists DSM compatibility with Luna HSM models and versions.

Add a Luna SA HSM to an HA Cluster

Steps to integrate a Luna SA HSM into an HA cluster.

Configuring an HA Cluster with a Luna SA HSM

Details on creating partitions and registering HSMs in an HA cluster.

Configure for Redundancy and Load Balancing

Explains how to add multiple Lunas for redundancy and load balancing.

Creating a Partition on the Password-authenticated Luna

Steps to create a partition on a password-authenticated Luna.

Creating a Partition on the PED-authenticated Luna

Steps to create a partition on a PED-authenticated Luna.

Backup your Configuration

Emphasizes the importance of backing up system configuration before attaching Luna.

Break Apart the Cluster

Instructions to break apart an HA cluster before adding Luna.

Add a Luna to the Initial Node of the HA Cluster

Steps to add a Luna HSM to the initial node of an HA cluster.

Verifying the Luna status

How to confirm that the Luna HSM is properly connected.

Add DSM Nodes to a Luna-enabled HA Cluster

Steps to add subsequent DSM nodes to a Luna-enabled HA cluster.

Join a (missing or bad snippet) Node to an HA Cluster

Procedure to join a DSM node to an existing HA cluster with Luna.

Monitoring the Luna

How to monitor the status and health of the Luna HSM.

HSM Slots

Information on monitoring HSM slots on the Luna SA.

Upgrading a DSM attached to a Luna

Procedures for upgrading a DSM attached to a Luna HSM.

Registering Again

Steps to re-register the cluster with the Luna SA.

Troubleshooting

Troubleshooting common issues related to Luna HSM integration.

Chapter 6: Upgrade and Migration

Overview

Introduces DSM software upgrades and hardware migrations.

Supported Upgrade Paths

Details valid paths for upgrading DSM software versions.

Migrating from DSM v6.1.0.9229 to DSM 6.4.2

Specific steps for migrating to DSM v6.4.2 due to database improvements.

Prerequisites

Essential steps before performing a migration or upgrade.

Best Practices for Migration

Recommendations for ensuring data integrity during migration.

Upgrading the DSM

General instructions for upgrading DSM software.

Migrating from V5 appliances to V6 x00 appliances

Procedures for migrating from older V5 appliances to V6x00.

Restore backup

Steps to restore a DSM backup.

Migrating from V5 appliances to V6 x00 appliance (KMIP)

Migration process for V5 appliances using KMIP.

Enabling Remote Administration for Upgraded V6100 Appliances

How to enable remote HSM administration post-upgrade.

Replacing the ACS

Steps to replace the Administrator Card Set.

ACS replacement guidelines

Best practices and considerations for replacing the ACS.

Enabling remote administration for an HA configuration

Steps to enable remote administration in an HA deployment.

Appendix A: Specifications, Racking, and Cabling for the V6000 and V6100

Hardware Appliance Diagrams

Visual representations of the DSM hardware appliance.

DSM Hardware Appliance Specifications

Detailed technical specifications for the V6000/V6100 appliances.

Space, Network, and Power Requirements

Requirements for installing the appliance in a data center environment.

Appliance Rack Mount Safety Instructions

Safety guidelines for rack-mounting the DSM appliance.

Rack Mounting the Appliance

Practical steps and considerations for physically installing the appliance in a rack.

General server precautions

General safety guidelines for server installation.

Rack mounting considerations

Factors to consider for optimal rack mounting.

Rack Mounting Instructions

Step-by-step guide for mounting the chassis in a rack.

Locking tabs

Describes the function of locking tabs on chassis rails.

The Inner Rail Extension (Optional)

Information on optional inner rail extensions for chassis stabilization.

Installing the inner rails

Detailed steps for installing inner rail extensions.

Outer rack rails

Information on attaching outer rack rails to the server rack.

Installing the outer rails to the rack

Steps for attaching outer rails to the rack.

Installing the chassis into a rack

Procedure for sliding the chassis into the rack rails.

Installing the chassis into a mid-mount position (telco) rack

Specific instructions for telco rack installations.

Installing and Connecting Cables

Guidance on connecting power and console cables.

Connecting to the network

Instructions for connecting the DSM appliance to the network.

Appendix B: HA for V6 x00 and Virtual Appliances

HA Overview

Introduces High Availability concepts for DSMs.

Supported HA Deployments

Details requirements and limitations for HA deployments.

V6100

Specific HA cluster requirements for V6100 appliances.

V6000 and Virtual Appliances

HA cluster configuration for V6000 and virtual appliances.

Configuring HA for V6 x00 and Virtual Appliances

General steps to configure HA for V6x00 and virtual appliances.

Prerequisites

Essential setup steps before configuring HA.

Network Latency

Factors affecting HA replication and recommendations for latency.

Configuring the Hardware

Hardware requirements for HA configuration.

Adding Nodes to an HA Cluster

Steps to add new nodes to an existing HA cluster.

Join a Node to an HA Cluster

Procedure to join a node into an HA cluster.

Configuring High Availability for Network HSM-enabled Nodes

HA configuration for DSMs using network HSMs.

Configure HA with standalone nodes

Method to configure HA using standalone nodes with network HSMs.

Configure an HA cluster with HSM-enabled nodes

Alternative method for creating an HSM-enabled HA cluster.

Adding a Host to a new HA node

Manually moving hosts to a different HA node if a failure occurs.

Upgrading an HA Cluster

Steps for upgrading nodes within an HA cluster.

Optimize the Upgrading of Nodes in the HA Cluster

Strategies to optimize the upgrading process for HA nodes.

Deleting a Node from a Cluster

Procedures for removing nodes from an HA cluster.

Deleting a Node from a Cluster with Hosts assigned

Steps to delete a node with assigned hosts and reassign them.

Moving a Host to a different Node with the CLI

CLI method for moving hosts between nodes.

Moving a Host to a different Node with the UI

UI method for moving hosts between nodes.

Appendix C: IPMI

IPMI Overview

Introduction to IPMI features and security best practices.

Configuring and Accessing IPMI on the DSM

Steps to configure and access the IPMI management console.

Configuring IPMI Network Settings

Guides on setting up IPMI network configuration.

Configuring Date and Time Settings with NTP Enabled

Setting date/time using NTP server.

Configuring Users Settings

Managing user accounts and privileges for IPMI.

Configuring IPMI GUI Port Settings

Configuring IPMI ports for access.

Configuring Fan Settings

Adjusting fan speed based on system load.

Remote Control

Options for remote server management through IPMI.

Using Active Directory with IPMI GUI

Integrating IPMI with Active Directory for authentication.

Maintenance Firmware Update

Procedures for updating IPMI firmware.

Upgrading the firmware

Step-by-step guide to upgrade IPMI firmware.

Reset the Firmware

Restoring IPMI to factory default settings.

Server Health

Monitoring system health via sensor readings and event logs.

Best Practices after IPMI is Configured

Security recommendations after IPMI configuration.

DSM IPMI CLI Commands

Reference for IPMI commands available via the DSM CLI.

Appendix D: Ports

Ports to Configure

Table listing required ports for appliance communication.

IPMI Ports

Lists IPMI ports that can be configured.

Appendix E: Bonding Driver Modes

Appendix F: Troubleshooting

Loss of Connection

Troubleshooting steps for appliance connectivity issues.

Reset DSM Appliance and Remove All Data

Procedures to reset the DSM appliance to factory defaults.

Create New Security World with New ACS

Process to create a new Security World and ACS.

Chassis Issues

Troubleshooting chassis intrusion messages.

Indicator Definitions

Explanation of LED status indicators.

Boot-Up Messages

Interpretation of common boot-up messages.

Boot-up Issues

Troubleshooting steps for DSM boot failures.

Thales V6000 Specifications

General IconGeneral
BrandThales
ModelV6000
CategorySecurity System
LanguageEnglish

Related product manuals