Networking Worksheet: Ironport Email Security Appliance Technical Support: 1-877-641-Iron (4766)
Networking Worksheet: Ironport Email Security Appliance Technical Support: 1-877-641-Iron (4766)
Networking Worksheet: Ironport Email Security Appliance Technical Support: 1-877-641-Iron (4766)
Network Integration
Gateway: DNS (Internet or Specify Own):
Interfaces
Data 1 Port IP Address: Network Mask: Fully Qualified Hostname: Accept Incoming Mail: Relay Outgoing Mail: Domain Destination System
Data 2 Port IP Address: Network Mask: Fully Qualified Hostname: Accept Incoming Mail: Relay Outgoing Mail: Domain Destination System
Management Port IP Address: Network Mask: Fully Qualified Hostname: Accept Incoming Mail: Relay Outgoing Mail: Domain Destination System
Message Security
SenderBase Reputation Filtering: Enable IronPort Anti-Spam Scanning Engine McAfee Anti-Virus Scanning Engine Sophos Anti-Virus Scanning Engine Virus Outbreak Filters
Copyright 2000-2009 Cisco Systems, Inc. All rights reserved. IronPort, the IronPort logo and SenderBase are registered trademarks of Cisco Systems, Inc. or its affiliates. All other trademarks are the property of Cisco Systems, Inc., its affiliates or their respective owners. While every effort is made to ensure the information given is accurate, Cisco does not accept liability for any errors or mistakes which may arise. Specifications and other information in this document may be subject to change without notice. PN 421-0135(A)
Enable / Disable Enable / Disable Enable / Disable Enable / Disable Enable / Disable
IronPort C360
These simple-to-follow steps will allow you to install, congure, and start using your IronPort Email Security appliance right away.
Before you start, be sure you have the following: Rack cabinet enclosure Dell 9G Combination Rails Rapid/Versa Combination Rails and adaptor kits (optional) 10/100/Gigabit BaseT TCP/IP local area network (LAN) Web browser software (or SSH and terminal software) Network cable(s) for connecting to your network
PLAN THE INSTALLATION WITHIN YOUR NETWORK Your IronPort appliance is designed to serve as your SMTP email gateway at your network perimeter that is, the rst machine with an IP address that is directly accessible to the Internet for sending and receiving email. Many of the features (including Email Security Monitor, Reputation Filtering, Content Scanning, Spam Detection, and Virus Protection) require you to install the IronPort appliance into your existing network infrastructure in the following way.
DATA The IronPort appliance requires at least one IP address to send and receive email. Ideally, two IP addresses should be used: Connect the Data 1 network port to your public network Connect the Data 2 network port to your private network Alternately, you can receive and deliver email from a single connection to either network port, if your network topology dictates it. Multiple IP addresses can be congured on one network interface.
Turn on the system power by pressing the On/Off switch on the front panel of the the appliance. You must wait ve minutes for the system to initialize the very rst time you power up before moving to Step 5.
Wait 5 minutes
Firewall
IronPort Email Security appliance Public Network Groupware Server (Microsoft Exchange, Lotus Notes, SunONE Messaging)
OR
Private Network
OR
Public and Private Networks
Check to make sure the following items are present in the IronPort Email Security appliance system box: IronPort C360 Email Security appliance Dual-head power cable Straight power cables (2) Null modem serial cable IronPort C360 Quickstart Guide (this guide) IronPort AsyncOS Documentation CD Safety and Compliance Guide
Clients
Depending on your network conguration, your rewall may need to be congured to allow access on the following ports. SMTP and DNS services must have access to the Internet. For other system functions, the following services may be required: SMTP: port 25 DNS: port 53 HTTP: port 80 HTTPS: port 443 SSH: port 22 Telnet: port 23 LDAP: port 389 or 3268 NTP: port 123 LDAP over SSL: port 636 LDAP with SSL for Global Catalog queries: port 3269 FTP: port 21, data port TCP 1024 and higher
SETUP AND MANAGEMENT For access by Ethernet, connect to the Management Network Port. Use a browser to access the web-based interface on the default IP address 192.168.42.42. You can also access the command line interface by SSH or terminal emulation software on the same IP address. (The netmask is /24.) Or, for Serial access, connect to the Serial Port. Access the command line interface by a terminal emulator using 9600 bits, 8 bits, no parity, 1 stop bit (9600, 8, N, 1), owcontrol = Hardware.
Fill out the Networking Worksheet on the back of this Quickstart Guide. Contact your network administrator if you need assistance. Use a browser to connect to the following URL:
http://192.168.42.42
Log in as: Username: admin Password: ironport The System Setup Wizard begins and the end user license agreement is displayed. Please read and accept the license agreement to continue. Use the information from the Networking Worksheet to complete the System Setup Wizard.
Note: You can download the AsyncOS Release Notes from the IronPort Customer Support Portal located at www.support.ironport.com.
OR
See the appendix, Firewall Information in the AsyncOS For Email User Guide for more information. INSTALL IN RACK Install the IronPort appliance into your rack cabinet. Ensure the ambient temperature around the system is within the specied limits. Ensure there is sufcient airow around the unit.
IRONPORT C160
(Or, you may connect using SSH or terminal emulation software. Initiate a session to the IP address 192.168.42.42. Log in as admin with the password ironport and, at the prompt, run the systemsetup command.) Record critical information from the Networking Worksheet to assist in completing the System Setup Wizard.
POWER Plug the female end of each straight power cable into the redundant power supplies on the back panel of the appliance. Or, plug the female ends of the dual-headed power cable into the redundant power supplies on the back panel of the appliance.
Choose an Injector Name (e.g. OutboundMail): * IP Interface Name (from above, e.g. PrivateNet): *
NTP
Documentation CD
Quickstart Guide
OR
OR