Deployment for Network Proxy in Simpana Environment There are multiple ways you can use the proxy for Simpana communication. 1. Use proxy to communicate for CommNet DataCenter CS will also have CommNet installed on it. You can register all the remote CS (remote1, remote2 from above diagram) to the data center CS after proxy configuration is done. 2. Use Proxy to configure GRC Setup You can setup GRC CommCell migration feature between multiple remote CS and data center CS once the proxy configuration is done.
Setup Configuration on Datacenter CS 1. On Datacenter CS CommCell GUI, right Click on Client Computers node and select New Client. 2. Select Windows from list and provide proxy machine client name and hostname. 3. Again, Right Click on Client Computers node and select New Client 4. Select Windows from list and provide remote commcell client name and hostname. Now you have created 2 pseudo clients on Datacenter CS, Start the firewall configuration now. 1. Right click on Proxy client node and go to Properties, Firewall Configuration Tab. 2. On Incoming Connections tab, a. Click Add, select CommServe and state as RESTRICTED. Click OK b. Click Add, select remotecs and state as RESTRICTED. Click OK 3. On Incoming Ports tab, In Tunnel HTTP\HTTPS Section : Check Listen for tunnel connections on port: checkbox and enter port number on which the Simpana proxy will listen from the CommServe. 4. On Options Tab, Check This computer is in DMZ and will work as a proxy checkbox. These are default values, but you can change according to your requirements. Keep Alive Interval, Seconds: 300 Tunnel Init interval, Seconds: 1 Incoming Tunnel Protocol: Accept HTTP and HTTPS 5. Right click on CommServe client node and go to Properties, Firewall Configuration Tab. 6. On Incoming Connections tab, c. Click Add, select proxy and state as BLOCKED. Click OK d. Click Add, select remotecs and state as BLOCKED. Click OK
7. On Outgoing Routes tab, a. Click Add, b. Click Add, Select Remote Group / Client: remotecs 8. Right click on remotecs client node and go to Properties, Firewall Configuration Tab. Check Configure Firewall Settings checkbox. 9. On Incoming Connections tab, e. Click Add, select proxy and state as BLOCKED. Click OK f. Click Add, select CommServe and state as BLOCKED. Click OK 10. On Outgoing Routes tab, c. Click Add, d. Click Add, Select Remote Group / Client: CommServe
INSTALL THE SIMPANA PROXY Install a CommCell client Proxy (e.g., File System idataagent) in the DMZ pointing to the Datacenter CommServe. This will operate as the Simpana proxy. Since DMZ always receives connections from outside, the Simpana proxy in DMZ must communicate to the CommServe through tunnel connections initiated by the CommServe. If firewall is enabled on the computer where the Simpana proxy will be installed, ensure there are open connections for the CommServe and client computers. During the installation, use one of the following firewall configuration sequences: This machine can open connection to CommServe on a tunnel port After the installation is completed, open the CommCell Console, right-click the proxy, CommServe computer and click All Tasks Push Firewall Configuration. Note : This is not exactly the firewall but saving and deploying the proxy network configuration, you will have to push the firewall configuration from Simpana GUI.
Setup Configuration on Remote CS 1. On Remote CS CommCell GUI, right Click on Client Computers node and select New Client. 2. Select Windows from list and provide proxy machine client name and hostname. 3. Again, Right Click on Client Computers node and select New Client 4. Select Windows from list and provide CommServe (Datacenter CS) client name and hostname. Now you have created 2 pseudo clients on remote CS, let s do the firewall configuration now. 1. Right click on Proxy client node and go to Properties, Firewall Configuration Tab. 2. On Incoming Connections tab, g. Click Add, select CommServe and state as RESTRICTED. Click OK h. Click Add, select remotecs and state as RESTRICTED. Click OK 3. On Incoming Ports tab, In Tunnel HTTP\HTTPS Section : Check Listen for tunnel connections on port: checkbox and enter port number on which the Simpana proxy will listen from the CommServe. 4. On Options Tab, Check This computer is in DMZ and will work as a proxy checkbox. These are default values, but you can change according to your requirements. Keep Alive Interval, Seconds: 300 Tunnel Init interval, Seconds: 1 Incoming Tunnel Protocol: Accept HTTP and HTTPS 5. Right click on remotecs client node and go to Properties, Firewall Configuration Tab. Check Configure Firewall Settings checkbox. 6. On Incoming Connections tab, a. Click Add, select proxy and state as BLOCKED. Click OK b. Click Add, select CommServe and state as BLOCKED. Click OK
7. On Outgoing Routes tab, a. Click Add, b. Click Add, Select Remote Group / Client: CommServe 8. Right click on CommServe client node and go to Properties, Firewall Configuration Tab. 9. On Incoming Connections tab, a. Click Add, select proxy and state as BLOCKED. Click OK b. Click Add, select remotecs and state as BLOCKED. Click OK 10. On Outgoing Routes tab, a. Click Add, b. Click Add, Select Remote Group / Client: remotecs 11. Right-click the remotecs computer and click All Tasks Push Firewall Configuration