HAPTER Installing Secure Gateway This chapter contains instructions for installing the Secure Gateway and provides a diagram of the recommended configuration. Overview ................1-2 Recommended Secure Gateway configuration ....1-2 Installing the Secure Gateway ..........1-4 Setting up a Secure Gateway cluster ........1-7...
Installing Secure Gateway Overview Overview Your company policy may dictate how you deploy Nokia’s technology within your network configuration. There are several configuration options available; however, Nokia recommends the configuration described in this chapter using a demilitarized zone (DMZ), or screened subnet. The DMZ is a computer or small subnetwork that sits between a trusted internal network, such as a corporate private LAN, and an untrusted external network, such as the public Internet.
Installing Secure Gateway Installing the Secure Gateway The following table shows the default port settings. Your port settings may be different depending on your network configuration. Table 1: Default ports for communication from devices Communication Protocol Default Port HTTP 80 (configurable) Sync traffic Web tunneling HTTPS...
Page 8
Installing Secure Gateway Installing the Secure Gateway After the installation, you must specify the name of the Secure Gateway computer on the Intellisync Mobile Suite server. To do so, complete the following steps: 1. From the Windows Start menu on the Intellisync Mobile Suite server, choose Programs, Intellisync Mobile Suite, and then choose Admin Console.
Page 9
Installing Secure Gateway Installing the Secure Gateway 8. Enter the Secure Gateway server name in the following fields: Website Server Name Sync Server Name Network Push Server (this applies only to the IMS server) 9. Click OK. The Intellisync Mobile Suite Properties dialog box closes and the Secure Gateway Admin Console appears.
Installing Secure Gateway Setting up a Secure Gateway cluster Setting up a Secure Gateway cluster You can set up multiple Secure Gateways in a cluster. A Secure Gateway cluster can provide redundancy to decrease the probability of system downtime in case one Secure Gateway server should fail.
Page 11
Installing Secure Gateway Setting up a Secure Gateway cluster Adding Secure Gateway servers to the cluster To add the servers to the Secure Gateway cluster, complete the following steps: 1. From the shared properties path, open the sgsharedprop.properties file. 2. Define the Secure Gateway cluster servers by entering the following property fore each server: SecureGatewayAddress<1-N>=<DNS hostname or IP address>...
HAPTER Configuring the Secure Gateway This chapter offers information for configuring the Secure Gateway after installation. Using the Secure Gateway Admin Console ....2-2 Configuring the Secure Gateway properties file .....2-3 Configuring Secure Gateway to route HTTP requests ..2-6 Configuring Secure Gateway for SSL ......2-8...
Configuring the Secure Gateway Using the Secure Gateway Admin Console Using the Secure Gateway Admin Console The Secure Gateway Admin Console is a management utility located on the Secure Gateway server. To access the Secure Gateway Admin Console, enter the following URL or enter from a local server: sgadmin...
Configuring the Secure Gateway Configuring the Secure Gateway properties file Configuring the Secure Gateway properties file You can manage your Secure Gateway configuration using the securegateway.properties file. With this file, you can configure authentication, logging, HTTP server, Web tunneling, and properties. When you modify the securegateway.properties file, you must restart the Secure Gateway service for changes to take effect.
Configuring the Secure Gateway Configuring the Secure Gateway properties file Debugging and logging The following properties define and manage debugging and audit logging for Secure Gateway (default values shown): Property Description LoggingLevel=0 Sets debugging logging for Secure Gateway. Logging will appear in a file <secure_gateway_mm_dd_yyyy_n.log>...
Configuring the Secure Gateway Configuring the Secure Gateway properties file Secure Gateway cluster configuration The following properties define and manage settings for a Secure Gateway cluster configuration (default values shown): Property Description SecureGatewaySharedPropertiesPath= Defines the path of the sgsharedprops.properties file. Used for Secure Gateway clusters.
Configuring the Secure Gateway Configuring Secure Gateway to route HTTP requests Property Description SyncMLDenyAccess=0 Allows SyncML requests as unauthenticated. Set value to 1 to disallow SyncML requests. Used in conjunction with the SyncMLWebTunnelingSupported property. To block SyncML access, set value to 1 when SyncMLWebTunnelingSupported property value is set to 1.
Page 18
Configuring the Secure Gateway Configuring Secure Gateway to route HTTP requests Routing destinations can be defined two ways. The first is DNS-based, where each different destination has its own unique DNS name. The second is URL- based, where the request URL is examined and the request is routed based on the folder names in the URL.
Configuring the Secure Gateway Configuring Secure Gateway for SSL URL routing destinations WebURLRouting[uniqueNumber]=source,destination,flag is defined as the following: – is the first folder in the URL source – is defined as [protocol]address[:port] destination – is used for specifying this is a virtual folderName and the name flag should be stripped from the URL before being routed Examples:...
Page 20
Configuring the Secure Gateway Configuring Secure Gateway for SSL To configure Secure Gateway for SSL, complete the following steps: Create a keystore file 1. Generate the keystore file by running the keytool utility with the following parameters where <name>.key is a the keystore file you define: C:\Program Files\Secure Gateway\jre1.5.0_01\bin\keytool -genkey -keyalg RSA -alias <Web server name>...
Page 21
Configuring the Secure Gateway Configuring Secure Gateway for SSL Run the keytool utility with the following parameters Verify your certificate. where <name>.key is the filename you define: C:\Program Files\Secure Gateway\jre1.5.0_01\bin\keytool -list -v -alias <Web server name>-keystore <name>.key 4. Enter keystore password and verify the digital certificate, which includes owner, issuer, serial number, and certificate fingerprints.
Troubleshooting Secure Gateway Troubleshooting Secure Gateway issues Troubleshooting Secure Gateway issues This section provides steps to follow to help identify, isolate, and resolve sync or push related issues with Intellisync Mobile Suite and Secure Gateway. Verify server name values and connections 1.
Page 24
Troubleshooting Secure Gateway Troubleshooting Secure Gateway issues Verify network configuration on Secure Gateway server(s) 1. Add all IP addresses bound to all NICs to the hosts file, resolving to the hostname. 2. Remove all registered DNS server entries on all NICs. 3.
Need help?
Do you have a question about the INTELLISYNC MOBILE SUITE 7.0 - SECURE GATEWAY ADMINISTRATOR GUIDE 04-2006 and is the answer not in the manual?
Questions and answers