Black Box ET0100A, ET1000A, ET0010A manual Managing EncrypTight Users

Page 3

Table of Contents

Uninstalling EncrypTight Software

40

Starting EncrypTight

40

Exiting EncrypTight

41

Management Station Configuration

41

Securing the Management Interface

42

Enabling the Microsoft FTP Server

42

Configuring the Syslog Server

43

Installing ETKMSs

43

Configuring ETKMSs

43

Basic Configuration for Local ETKMSs

44

About Local ETKMSs

44

Adding a Local ETKMS

44

Launching and Stopping a Local ETKMS

45

Starting the Local ETKMS Automatically

45

Configuring External ETKMSs

46

Logging Into the ETKMS

47

Changing the Admin Password

47

Changing the Root Password

48

Configure the Network Connection

49

Configure Time and Date Properties

51

Check the Status of the Hardware Security Module

53

Starting and Stopping the ETKMS Service

53

Checking the Status of the ETKMS

54

Secure the Server with the Front Bezel

54

Configuring Syslog Reporting on the ETKMSs

54

Policy Enforcement Point Configuration

55

Default User Accounts and Passwords

56

Managing Licenses

56

Installing Licenses

57

Upgrading Licenses

58

Upgrading the EncrypTight License

58

Upgrading ETEP Licenses

58

Next Steps

58

Chapter 4: Managing EncrypTight Users

61

Working with EncrypTight User Accounts

61

Configuring EncrypTight User Authentication

62

Managing EncrypTight Accounts

65

Changing an EncrypTight User Password

66

How EncrypTight Users Work with ETEP Users

67

Chapter 5: Maintenance Tasks

69

Working with the EncrypTight Workspace

69

About the EncrypTight Workspace

69

Saving a Workspace to a New Location

70

Loading an Existing Workspace

71

Moving a Workspace to a New PC

72

Deleting a Workspace

72

Installing Software Updates

73

Step 1: Schedule the Upgrade

73

4

EncrypTight User Guide

Image 3
Contents EncrypTight User Guide Table of Contents Managing EncrypTight Users Provisioning Appliances Getting Started with EtemsManaging Appliances 117 Creating Vlan ID Ranges for Layer 2 Networks Managing Key Management SystemsManaging IP Networks Managing Network SetsPolicy Design Examples 211 Modifying the Etkms Properties File Using Enhanced Security FeaturesEtep Configuration 299 302 Index 343 About This Document PrefaceContacting Black Box Technical Support Part I EncrypTight Installation and Maintenance EncrypTight User Guide Distributed Key Topologies EncrypTight OverviewLayer 2 Ethernet topologies Network topologiesTopology Description Layer 3 IP topologiesRelated topics EncrypTight ElementsEncrypTight Element Management System Policy ManagerKey Management System Single Etkms for multiple sites Policy Enforcement PointShared keys Point-to-Point Negotiated TopologyLayer 2 Point-to-Point Deployment Security within EncrypTightSecure Key Storage within the Etkms Secure Communications Between DevicesEncrypTight Component Connections EncrypTight Deployment PlanningEtpm to Etkms Connections Management Station ConnectionsEtpm and Etkms on the Same Subnetwork Etpm and Etkms on Different SubnetworksEtpm and Etkms in Layer 3 IP Policies Out-of-band Etkms management in an Ethernet network External Etkms to Etkms Connections Connections for Backup ETKMSsEtkms to Etkms Connections in Ethernet Networks Connecting Multiple ETKMSs in an IP NetworkEtkms to PEP Connections in IP Networks Etkms to PEP ConnectionsIn-line Etkms to PEP communications in IP networks Etkms to PEP Connections in Ethernet NetworksIPv6 Address Support Network Clock SynchronizationCertificate Support IPv6 address representationsAddress Format Address Representation Network Addressing for IP Networks Network Addressing OptionsAddressing Method Description Related topics Before You Start Installation and ConfigurationThird party management station software Hardware RequirementsSoftware Requirements EncrypTight management station requirementsFirewall Ports EncrypTight Software InstallationInstalling EncrypTight Software for the First Time To install the EncrypTight softwareStarting EncrypTight Uninstalling EncrypTight SoftwareTo uninstall EncrypTight Upgrading to a New Version of EncrypTightRelated topic Management Station ConfigurationExiting EncrypTight To start EtemsEtems communications options To enable the Microsoft FTP Server serviceSecuring the Management Interface Enabling the Microsoft FTP ServerEtkms server connections Installing ETKMSsConfiguring ETKMSs Configuring the Syslog ServerBasic Configuration for Local ETKMSs About Local ETKMSsAdding a Local Etkms To launch a local Etkms Launching and Stopping a Local EtkmsStarting the Local Etkms Automatically To add a local EtkmsMaintaining the start.bat file Configuring External ETKMSsPrior to configuring the batch file do the following To configure the batch fileTo log into the Etkms Changing the Admin PasswordTo change the admin password Logging Into the EtkmsTo change the root password Changing the Root PasswordIPv4 Configure the Network ConnectionTo configure the network connection and hostname Static IP Netmask Default Gateway IP addressIPv6 To configure the network interfaceTo set the hostname and IPv6 default gateway address To set the default DNS server and configure the hosts fileConfigure Time and Date Properties To set up time synchronizationTo set the time zone Field Description Ntpq -p command outputTo restart the NTP daemon To check the time source connection statusCheck the Status of the Hardware Security Module Starting and Stopping the Etkms ServiceChecking the Status of the Etkms Configuring Syslog Reporting on the ETKMSsTo check the status of the Etkms service To configure syslog reporting on a EtkmsPolicy Enforcement Point Configuration Etep Throughput Speeds Default User Accounts and PasswordsPasswords to change Managing LicensesChoose Tools Put License Installing LicensesTo install a license on the Etep To enter EncrypTight licensesUpgrading Etep Licenses Next StepsUpgrading Licenses Upgrading the EncrypTight LicenseNext Steps Installation and Configuration EncrypTight User Guide Working with EncrypTight User Accounts Managing EncrypTight UsersConfiguring EncrypTight User Authentication Task Administrator UserEncrypTight account types and privileges Password Authentication and Expiration Login Session Inactivity TimerCommon Access Card Authentication DoD Login Banner Parameter User Name Password Login preferences default settingsEncrypTight user name and password conventions Preference SettingTo modify an EncrypTight user account Changing an EncrypTight User PasswordTo change a password To add an EncrypTight user accountRelationship between EncrypTight users and Etep users Example 1 Default EncrypTight user and default Etep userExample 2 Setting up new EncrypTight and Etep users How EncrypTight Users Work with Etep UsersExample 3 Adding a new Etep user to EncrypTight Maintenance Tasks Working with the EncrypTight WorkspaceAbout the EncrypTight Workspace Saving a Workspace to a New Location To save a workspace to a new locationOn the File menu, click Save Workspace To To load an existing workspace Loading an Existing WorkspaceTo delete a workspace Moving a Workspace to a New PCDeleting a Workspace To move a workspace to a new PCSchedule the Upgrade Installing Software UpdatesUpgrade the EncrypTight Software Prepare Etpm Status and Renew KeysVerify Etkms Status and Deploy Policies To deploy policies Upgrade PEP SoftwareTo upgrade software on the PEPs On the Tools menu, click Upgrade SoftwareFTP server site information for appliance software upgrades To check the status of the PEPs Click Edit Multiple Configurations Software VersionChange the PEP Software Version and Check Status To change the software version of the PEPsReturn Status Refresh and Key Renewal to Original Settings Upgrading External ETKMSsTo stop and remove the current Etkms software To start the Etkms software To install the new Etkms softwareTo configure the new Etkms software To mount the Cdrom driveMaintenance Tasks EncrypTight User Guide Etems Part II Working with Appliances usingEncrypTight User Guide Defining Appliance Configurations Getting Started with EtemsEtems Quick Tour Interface configuration for a new ET1000A appliance Pushing Configurations to AppliancesUpgrading Appliance Software Comparing ConfigurationsMaintenance and Troubleshooting Policy and Certificate Support Understanding the Etems WorkbenchEditors Appliance Manager perspective ViewsEtems toolbar ToolbarsPerspectives To open a perspectiveStatus Indicators Appliance Manager toolbarCertificate Manager toolbar EncrypTight User Types Appliance status indicatorsStatus Indicator Description Understanding RolesTo change communication preferences Function Administrator OpsModifying Communication Preferences Appliance roles for ETEPsStrict authentication communication preferences General communication preferencesPreference Description Policy Extensions Ignore CRL accessEnable Certificate CRL File LocationProvisioning Basics Provisioning AppliancesNew Appliance editor for the ET1000A To add a new appliance Adding a New ApplianceOn the Tools menu, click Put Configurations Saving an Appliance ConfigurationSaving appliance configurations To push Etems configurations to appliancesPut configuration status Viewing Appliance StatusResult Description Appliances view To configure automatic status checkingEtems To apply a filter to the appliances in the Appliances view Filtering Appliances Based on AddressEtep User Roles Rebooting AppliancesTo reboot appliances Appliance User ManagementAppliance roles for ETEPs v 1.4 and later Configuring the Password Enforcement PolicyDefault user names and passwords on the Etep Role Default user name Default passwordDefault Password Policy Conventions Strong Password Policy ConventionsUser Name Conventions Upgrading Software Removing ETEPs From ServiceOn the Tools menu, click Appliance User Add User Managing Appliance UsersAdding Etep Users To add a user to the EtepDefault password Strong password Parameter Policy Password policy valuesOn the Tools menu, click Appliance User Modify User Modifying Etep User CredentialsDeleting Etep Users To modify Etep user credentialsViewing Etep Users To delete a user from the EtepOn the Tools menu, click Appliance User Delete User On the Edit menu, click Default Configuration Working with Default ConfigurationsCustomizing the Default Configuration To customize the default configurationProvisioning Large Numbers of Appliances Restoring the Etems Default ConfigurationsTo return the default values to factory settings On the Edit menu, click Default ConfigurationsImporting Configurations from a CSV File Creating a Configuration TemplateAttribute Description To import appliance configurations to EtemsRemote and local keywords and attributes Importing Remote and Local Interface AddressesChanging Configuration Import Preferences To shut down the Etep Shutting Down AppliancesChecking the Time on New Appliances Shutdown operational codesManaging Appliances Editing ConfigurationsChanging the Management IP Address Changing the Address on the ApplianceTo change the management IP address on the appliance Change Management IP window Related topics Changing the Address in EtemsOperation failed message in response to management IP change Changing the Date and TimeTo change the date and time Changing Settings on a Single ApplianceChanging Settings on Multiple Appliances To edit the configuration of a single applianceDeleting Appliances To update an appliance setting on multiple appliancesTo delete appliances Connecting Directly to an ApplianceConnecting to the Command Line Interface Upgrading Appliance Software124 EncrypTight User Guide To upgrade software 126 EncrypTight User Guide Checking Upgrade Status Restoring the Backup File SystemCanceling an Upgrade What to do if an Upgrade is InterruptedTo restore the appliance file system from a backup copy Part III Using Etpm to Create Distributed Key Policies 130 EncrypTight User Guide To open Etpm Getting Started with EtpmOpening Etpm About the Etpm User InterfaceEtpm perspective Component Chapter EncrypTight Components ViewEditors To edit an element from the policy view Etpm Status IndicatorsStatus indicators Policy ViewSorting and Using Drag and Drop Etpm toolbar To enable or disable automatic status checkingEtpm Toolbar Etpm Status Refresh IntervalAbout Etpm Policies IP PoliciesEthernet Policies Policy generation and distribution Policy Generation and DistributionKey generation with one Etkms Key generation with multiple ETKMSs Creating a Policy An OverviewNetwork Set B Network aNetwork B Network Set aTo create a policy 144 EncrypTight User Guide EncrypTight User Guide 145 146 EncrypTight User Guide Provisioning PEPs Managing Policy Enforcement PointsEncrypTight PEP configuration Configuration DescriptionAdding a New PEP in Etems On the Advanced tab, select Enable Sntp Client On the Features tab, select Enable passing TLS trafficAdding a New PEP Using Etpm To add a new PEP using EtpmAdding Large Numbers of PEPs Editing PEPs Pushing the ConfigurationTo push Etems configurations to PEPs To edit a PEP’s configurationEditing PEPs From Etpm To change the NTP settings for multiple PEPsSelect Edit Multiple Configurations Sntp Client Editing Multiple PEPsTo change the IP address of a PEP Deleting PEPsChanging the IP Address of a PEP Changing the PEP from Layer 3 to Layer 2 EncryptionTo delete PEPs Etkms connections Managing Key Management SystemsTo add an Etkms Adding ETKMSsTo edit an existing Etkms Editing ETKMSsDeleting ETKMSs Etkms entriesTo delete an existing Etkms Adding Networks Managing IP NetworksAddress Network Mask To add a networkNetwork entries Network IPGrouping Networks into Supernets Advanced Uses for Networks in PoliciesUsing Non-contiguous Network Masks IP Address Network Mask Networks definitionsEditing Networks Deleting NetworksTo edit an existing network To delete a network Managing IP Networks 166 EncrypTight User Guide Network Sets Managing Network SetsTypes of Network Sets IP address Mask 40.32.21.0 255.255.255.0IP address Mask 40.55.11.0 255.255.255.0 IP address Mask Network set for a collection of networksAdding a Network Set To add a Network SetNetwork Set fields Mode Key ManagementSystem Network AddressingNetwork Set editor Importing Networks and Network SetsNetworks and network sets import document format in Excel To edit a Network Set Editing a Network SetDeleting a Network Set To import networks and network sets into EtpmTo delete an existing network set Managing Network Sets 176 EncrypTight User Guide Creating Vlan ID Ranges for Layer 2 Networks Adding a Vlan ID RangeTo add a new Vlan ID Range Vlan ID range entries Lower Vlan IDUpper Vlan ID To delete an existing Vlan ID range Editing a Vlan ID RangeDeleting a Vlan ID Range To edit a Vlan ID range180 EncrypTight User Guide Policy Concepts Creating Distributed Key PoliciesSchedule for Renewing Keys and Refreshing Policy Lifetime Policy PriorityPolicy Types and Encryption Methods EncapsulationLayer 2 Ethernet payload encryption Encryption and Authentication Algorithms Aria EncryptionTo use Aria in an encryption policy, do the following Addressing Mode Using Encrypt All Policies with ExceptionsKey Generation and ETKMSs Policy Size and Etep Operational Limits Encrypt all policy with exceptionsPolicy Policy Type Priority Action Protocol Covered Minimizing Policy Size To add a new Layer 2 mesh policy Adding Layer 2 Ethernet PoliciesLayer 2 Mesh policy entries Layer 2 Mesh policy editor Adding a Hub and Spoke Policy Adding Layer 3 IP PoliciesHub and spoke policy entries To add a new hub and spoke policySize IPSecAddressing Minimize PolicyHub and spoke policy editor To add a new mesh policy Adding a Mesh PolicyMesh policy entries Specifies a method for reducing the policy size Mesh policy editor Multicast network example Adding a Multicast PolicyMulticast policy entries To add a multicast policyNetwork MulticastMulticast policy editor To add a point-to-point policy Adding a Point-to-point PolicyPoint-to-point policy entries Point B Point aNetwork Set Point a PortsPoint-to-point policy editor Adding Layer 4 PoliciesPolicy Deployment Verifying Policy Rules Before DeploymentTo create a new Layer 4 policy To verify policies Setting Deployment Confirmation PreferencesTo enable or disable the deployment warning Deploying PoliciesEditing policies Editing a PolicyDeleting Policies To edit an existing policyTo delete an existing policy To delete all policiesSelect Tools Clear Policies Basic Layer 2 Point-to-Point Policy Example Policy Design ExamplesLayer 2 Ethernet Policy Using Vlan IDs Setting PEPPoint-to-point Layer 2 encryption policy Policy 3 Discard All Other Policy 2 Partner and Partner Portal ServerEncrypt Traffic Between Regional Centers Complex Layer 3 Policy ExampleEncrypt Traffic Between Regional Centers and Branches Network sets for mesh policyEncrypt all mesh policy Region a hub and spoke policy Network sets for the hub and spoke policiesField Region B hub and spoke policyRegion C hub and spoke policy Region D hub and spoke policyPass protocol 88 in the clear mesh policy Passing Routing ProtocolsEncrypTight User Guide 219 Policy Design Examples 220 EncrypTight User Guide Part IV Troubleshooting 222 EncrypTight User Guide Possible Problems and Solutions Etems TroubleshootingPreferences Symptom Explanation and possible solutionsConfig to Appliance Appliance UnreachableDisable-trusted-hosts CLI command Appliance ConfigurationPushing Configurations Appliance Tools RebootCompare Config to Appliance . Do one of the following To ping the management port Software UpgradesAbout upgrades show system-log and show upgrade Status Pinging the Management PortRetrieving Appliance Log Files Tools preferences To change the default ping toolTo retrieve log files from an appliance On the Tools menu, click Retrieve Appliance LogsFTP server site information for log retrieval Viewing Statistics Viewing Diagnostic DataStatistic Description Etep StatisticsExporting SAD and SPD Files Viewing Port and Discard StatusTo access the appliance CLI CLI Diagnostic CommandsWorking with the Application Log Viewing the Application Log from within EncrypTightTo view the log information Setting Log Filters Sending Application Log Events to a Syslog ServerExporting the Application Log Other Application Log Actions Log File ActionsIcon Description Etpm and Etkms Troubleshooting Learning About ProblemsMonitoring Status Etpm status problems and solutions Symptoms and SolutionsEtep PEPs, see the EncrypTight User Guide Policy ErrorsRenew Key Errors Status ErrorsViewing Log Files Etpm Log FilesEtkms Log Files Etkms Server Operation Etkms Troubleshooting ToolsLinux Commands Command DescriptionShutting Down or Restarting an External Etkms PEP Troubleshooting ToolsResetting the Admin Password Optimizing Time SynchronizationTo view statistics To disable the Sntp client on multiple PEPsStatistics Etep PEP Policy and Key InformationTo export SAD or SPD files from Etep PEPs Troubleshooting PoliciesReplacing Licensed ETEPs Checking Traffic and Encryption StatisticsSolving Policy Problems Placing PEPs in Bypass ModeViewing Policies on a PEP Expired Policies Allowing Local Site Exceptions to Distributed Key PoliciesCannot Add a Network Set to a Policy Solving Network Connectivity ProblemsCertificate Implementation Errors Modifying EncrypTight Timing ParametersCannot Communicate with PEP Etkms Boot Error Invalid Certificate ErrorInvalid Parameter in Function Call Enter strict-client-authentication disable To disable strict authentication on ETEPsEtpm and Etkms Troubleshooting 252 EncrypTight User Guide Part V Reference 254 EncrypTight User Guide About the Etkms Properties File Modifying the Etkms Properties FileHardware Security Module Configuration Digital Certificate ConfigurationLogging Setup Peer Etkms and Etpm Communications Timing Base Directory for Storing Operational State DataPEP Communications Timing Policy Refresh TimingPEP Communications Timing Page About Enhanced Security Features Using Enhanced Security FeaturesAbout Strict Authentication Order of Operations Prerequisites for Using Certificates with EncrypTightHow to Reference PrerequisitesSetting Description Certificate InformationDistinguished name information Usage, you type this string as follows Using Certificates in an EncrypTight SystemTo change the EncrypTight keystore password Changing the Keystore PasswordChanging the EncrypTight Keystore Password Changing the Etkms Keystore PasswordChanging the Keystore Password on a Etkms Restart the Etkms Service To start the Etkms service Changing the Keystore Password on a Etkms with an HSMChanging the Password Used in the Etkms Properties File To change the password listed in the Etkms properties fileConfiguring the Certificate Policies Extension To configure the certificate policies extension for ETEPsClick Enable Policy Extensions Parameter Description To configure certificate policy extensions for ETKMSsClick Enable Certificate Policy Extensions Etkms Certificate Policies EntriesEncrypTight User Guide 271 Generating a Key Pair Working with Certificates for EncrypTight and the ETKMSsTo create the certificate request Keytool genkeypair CommandRequesting a Certificate To generate a key pairKeytool Parameters for Importing a CA Certificate To install a CA certificateImporting a CA Certificate Importing a CA Certificate ReplyConfiguring the HSM for Keytool Working with Certificates and an HSMExporting a Certificate Generating a Key Pair for use with the HSM Importing CA Certificates into the HSMWorking with Certificates for the ETEPs Generating a Certificate Signing Request for the HSMImporting Signed Certificates into the HSM To start the Certificate Manager do one of the following Understanding the Certificate Manager PerspectiveCertificate Manager Workflow Working with External CertificatesObtaining External Certificates Installing an External Certificate To install an external certificateTo obtain a CA certificate from a CA Requesting a Certificate Working with Certificate Requests282 EncrypTight User Guide To view a pending certificate signing request Installing a Signed CertificateViewing a Pending Certificate Request Certificate usageTo set certificate request preferences Canceling a Pending Certificate RequestSetting Certificate Request Preferences To cancel a pending certificate requestCertificate request preference fields Managing Installed CertificatesTo export an installed certificate Viewing a CertificateExporting a Certificate To delete an external certificate Validating Certificates Using CRLsValidating Certificates Deleting a CertificateTo use CRLs with the Etkms Configuring CRL Usage in EncrypTight and the ETKMSsConfiguring CRL Usage on ETEPs To use CRLs with the EncrypTight softwareTo view CRLs Validating Certificates Using OcspTo install a CRL on the Etep Handling Revocation Check FailuresOptions Description To set up Ocsp in EncrypTightClick Enable Online Certificate Status Protocol Ocsp EncrypTight Ocsp OptionsOcsp Settings To set up Ocsp in the EtkmsTo set up Ocsp on the ETEPs Click Enable OcspTo enable strict authentication on PEPs Enabling and Disabling Strict AuthenticationTo enable strict authentication in the EncrypTight software To enable strict authentication on the EtkmsRemoving Certificates To disable strict authenticationClear the Enable Strict Client Authentication box To disable strict authentication from the command lineUsing a Common Access Card To remove certificatesSelect Tools Clear Certificates Configuring User Accounts for Use With Common Access Cards Enabling Common Access Card AuthenticationTo add common names to the Etkms To enable CAC Authentication in EncrypTight To enable CAC Authentication on the EtepClick XML-RPC Certificate Authentication To enable CAC Authentication on the EtkmsHandling Common Name Lookup Failures To specify how to handle common name failuresUsing Enhanced Security Features 298 EncrypTight User Guide Etep Configuration Identifying an Appliance Product Family and Software VersionAppliance Name Interface Configuration To configure appliance interfacesThroughput Speed Management Port Addressing ET0100A interfaces configuration Related topicsIPv4 management port addressing IPv4 AddressingIPv6 management port addressing IPv6 AddressingLink speeds on the management port Auto-negotiation All PortsRemote and Local Port Settings Transparent ModeLink speeds on the local and remote ports When to use transparent mode Policy Type Mode of operationLocal and Remote Port IP Addresses Transmitter Enable Default GatewayIP Address and Subnet Mask Dhcp Relay IP Address Transmitter Enable settings on the EtepIgnore DF Bit Reassembly ModeIgnore DF Bit settings Reassembly mode settingsTrusted host list Trusted HostsOutbound host Appliance Editor Tab Inbound trusted host protocols used by EncrypTightTo add a trusted host ProtocolSystem Information Snmp ConfigurationUnder Community Strings, click Add Community StringsSnmp system information To define a community nameTraps Traps reported on the EtepTrap Description To configure a trap host SNMPv2 Trap HostsSNMPv3 SNMPv3 Configuration Related topics Generating the Engine ID Retrieving and Exporting Engine IDsTo retrieve engine IDs Viewing SNMPv3 Engine IDs Related topics Configuring the SNMPv3 Trap Host UsersSNMPv3 trap host users SNMPv3 Trap Host configuration To configure a trap host userEtep Logging tab Logging ConfigurationLog Event Settings Log facilitiesFacility Description Under Syslog Servers, click Add Defining Syslog ServersLog priorities To define a syslog serverInternals logs Log File ManagementLog file sizes Log name File sizeLog files extracted from the Etep Related topics Advanced ConfigurationPacket Payload Size Layer 2 Etep Layer 3 Etep Path Maximum Transmission UnitValid Pmtu ranges on Etep appliances Pmtu and fragmentation behavior on the EtepNon IP Traffic Handling CLI Inactivity TimerPassword Strength Policy Non IP traffic handling configurationXML-RPC Certificate Authentication IKE Vlan Tags SSH Access to the EtepSntp Client Settings To configure the NTP clientIKE Vlan Tags Features ConfigurationOcsp Settings Certificate Policy ExtensionsEncryption algorithms Authentication algorithms Fips ModeEnabling Fips Mode Fips approved encryption and authentication algorithmsOperational Notes Policy Type Action upon entering Fips modeDisabling Fips Verifying Fips Status on the EtepEncrypTight Settings EncrypTight settingsSetting Definition Encryption Policy Settings Encryption policy settingsWorking with Policies Using EncrypTight Distributed Key Policies Creating Layer 2 Point-to-Point PoliciesTo launch Etpm from Etems Etep Policy tab Using Preshared Keys for IKE Authentication Using Group IDsSelecting a Role Parameter Value Selecting the Traffic Handling ModeHow the Etep Encrypts and Authenticates Traffic IKE Phase 2 ParametersInterfaces Factory DefaultsInterfaces defaults Interfaces Default SettingTrusted hosts defaults Snmp defaultsTrusted Hosts Logging PolicyAdvanced Features Default Setting FeaturesHard-coded Settings Features defaultsNumerics IndexIndex EncrypTight User Guide 345 Etpm See also HSM Https TLS 348 EncrypTight User Guide EncrypTight User Guide 349 350 EncrypTight User Guide See also TLS trap configuration 352 EncrypTight User Guide Black Box Tech Support FREE! Live /7
Related manuals
Manual 48 pages 53.09 Kb Manual 88 pages 24.35 Kb

EncrypTight, ET0100A, ET0010A, ET1000A specifications

The Black Box ET1000A, ET0010A, EncrypTight, and ET0100A are advanced solutions designed for secure data transmission and network management, catering to modern enterprise needs. These tools integrate cutting-edge technologies to enhance connectivity, security, and efficiency within various environments.

The Black Box ET1000A is primarily a high-performance Ethernet over Twisted Pair (EoTP) solution. It enables users to extend Ethernet signals over long distances using existing twisted-pair cabling without sacrificing speed or reliability. With support for speeds up to 100 Mbps, this device is ideal for organizations looking to upgrade their existing infrastructure without extensive rewiring. Key features include plug-and-play installation, which simplifies deployment, and versatile compatibility with both legacy and modern ethernet networks.

The ET0010A model takes connectivity a step further by providing seamless integration with fiber optics. This device supports transmission distances that far exceed traditional copper solutions, making it a perfect fit for larger facilities or multi-building campuses. Its built-in Ethernet switch enhances network efficiency by providing multiple ports for device connectivity, thus facilitating greater data flow.

EncrypTight technology is a notable feature across these Black Box models, offering advanced encryption capabilities to safeguard sensitive data during transmission. With military-grade encryption protocols, EncrypTight ensures that corporate information remains secure from potential eavesdroppers. This technology is essential for businesses operating in regulated industries or that handle confidential customer information.

The ET0100A model combines intelligence with monitoring features to provide users with comprehensive network insights. It boasts built-in diagnostic tools that enable IT professionals to troubleshoot issues quickly and efficiently. Additionally, it features real-time performance monitoring, allowing users to analyze bandwidth usage and optimize network performance accordingly.

In conclusion, the Black Box ET1000A, ET0010A, EncrypTight, and ET0100A are powerful tools that embody the latest in data transmission and network management technologies. With their unique features—including extended connectivity capabilities, robust encryption technologies, and real-time monitoring solutions—these devices cater to the growing demands of businesses seeking to enhance their network infrastructure while ensuring robust security and efficiency. Integrating these tools into any organization’s operations can fundamentally improve both performance and data protection, making them indispensable in today’s digital landscape.