Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 95

Manually Restarting the CAM/CAS Configuration Utility, Step 7

Page 95 highlights

Chapter 3 Installing the Clean Access Manager and Clean Access Server Installing the Clean Access Server Note If this prompt does not appear after you install the Cisco NAC Appliance software and restart the CAS, refer to Manually Restarting the CAM/CAS Configuration Utility, page 3-46. Step 3 If your CAS is a FIPS-compliant platform (NAC-3315 or NAC-3355) the first prompt asks if you want to initialize the on-board FIPS card (used to ensure FIPS compliant functions on the appliance). Otherwise, skip to Step 7. Do you want to initialize the fips cards? (y/n)? [y] Step 4 Choose y to enable FIPS on your appliance. The appliance automatically initializes the FIPS card and attempts to establish the security world. -- Running startup script 45drivers -- Running startup script 46exard -- Running startup script 50hardserver Security world not found Creating the security world and initializing the smart cards Next, the FIPS setup process prompts you to specify how many Smart Cards (from 1-6) you want to initialize to enable FIPS compliance on the CAS. How many cards do you want to initialize (1-6)? [1] Set ncipher card switch in i mode and press Return to continue Step 5 Enter the number of Smart Cards you want to initialize, ensure that the FIPS card operation switch on the back of the CAS is switched to "I" (for "initialize"), and press Return. Module 1, command ClearUnit: OK Create Security World: Module 1: 0 cards of 1 written Module 1 slot 0: unknown card Module 1 slot 0: - no passphrase specified - overwriting card Module #1 Slot #0: Processing ... Card writing complete. security world generated on module #1; hknso = 65cc642b8d38a1f99b58c8afa560f4d94 522d2ad Set ncipher card switch in o mode and press Return to continue Step 6 Switch the FIPS card switch back to "O" (for "operational") and press Return. Module 1, command ClearUnit: OK Card(s) check passed Do you want to continue with the rest of the NAC Server Configuration? (y/n)? [y] Step 7 When prompted, enter an IP address for the eth0 (trusted) interface of the CAS. Confirm the value when prompted, or type n and press Enter to correct the entry. Configuring the network interfaces: Please enter the IP address for the interface eth0 []: 10.201.1.20 You entered 10.201.1.20 Is this correct? (y/n)? [y] OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 3-25

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

3-25
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 3
Installing the Clean Access Manager and Clean Access Server
Installing the Clean Access Server
Note
If this prompt does not appear after you install the Cisco NAC Appliance software and restart the CAS,
refer to
Manually Restarting the CAM/CAS Configuration Utility, page 3-46
.
Step 3
If your CAS is a FIPS-compliant platform (NAC-3315 or NAC-3355) the first prompt asks if you want
to initialize the on-board FIPS card (used to ensure FIPS compliant functions on the appliance).
Otherwise, skip to
Step 7
.
Do you want to initialize the fips cards? (y/n)? [y]
Step 4
Choose
y
to enable FIPS on your appliance. The appliance automatically initializes the FIPS card and
attempts to establish the security world.
-- Running startup script 45drivers
-- Running startup script 46exard
-- Running startup script 50hardserver
Security world not found
Creating the security world and initializing the smart cards
Next, the FIPS setup process prompts you to specify how many Smart Cards (from 1-6) you want to
initialize to enable FIPS compliance on the CAS.
How many cards do you want to initialize (1-6)? [1]
Set ncipher card switch in i mode and press Return to continue
Step 5
Enter the number of Smart Cards you want to initialize, ensure that the FIPS card operation switch on
the back of the CAS is switched to “I” (for “initialize”), and press Return.
Module 1, command ClearUnit: OK
Create Security World:
Module 1: 0 cards of 1 written
Module 1 slot 0: unknown card
Module 1 slot 0: - no passphrase specified - overwriting card
Module #1 Slot #0: Processing ...
Card writing complete.
security world generated on module #1; hknso = 65cc642b8d38a1f99b58c8afa560f4d94
522d2ad
Set ncipher card switch in o mode and press Return to continue
Step 6
Switch the FIPS card switch back to “O” (for “operational”) and press Return.
Module 1, command ClearUnit: OK
Card(s) check passed
Do you want to continue with the rest of the NAC Server Configuration?
(y/n)? [y]
Step 7
When prompted, enter an IP address for the eth0 (trusted) interface of the CAS. Confirm the value when
prompted, or type
n
and press Enter to correct the entry.
Configuring the network interfaces:
Please enter the IP address for the interface eth0 []: 10.201.1.20
You entered 10.201.1.20 Is this correct? (y/n)? [y]