Loading...

Configuring the Client for One-Way Firewall (Client to CommServe)

You must configure the client to initiate connections with the CommServe computer and MediaAgent. This configuration is necessary to enable backup and restore operations on the clients.

During the firewall configuration, you will set incoming connections from the CommServe and MediaAgent computers as Blocked.

Before You Begin

You must have configured the CommServe computer and MediaAgents to receive communications from the client.

Procedure

  1. From the CommCell Browser, right-click the client, then click Properties and Network.
  2. On the Firewall Configuration tab, select Configure Firewall Settings, then the Advanced option. Click OK to acknowledge the warning and continue.
  3. Set the incoming connection to the client from the CommServe computer:
    1. Click Add.
    2. In From, select the name of the CommServe computer.
    3. In State, select BLOCKED, since the CommServe does not need to open connections to the Client.
    4. Click OK.
  4. Set the incoming connection to the client from the MediaAgent:
    1. Click Add.
    2. In From, select the name of the MediaAgent computer.
    3. In the State field, select BLOCKED, since the MediaAgent does not need to open connections to the Client.
    4. Click OK.
  5. Set the outgoing route from the client to the CommServe computer:
    1. Click the Outgoing Routes tab.
    2. Select the CommServe name from the Remote Group/Client list.
    3. For Tunnel Connection Protocol, select Encrypted, to enable authentication and encryption for tunnel connections.
    4. The Force all data (along with control) traffic into the tunnel option is not required, as this route is not toward the MediaAgent.
    5. Click OK repeatedly until all dialog boxes are closed.
  6. Under Client Computers, right-click the client, then click All Tasks > Push Firewall Configuration.
  7. Click Continue.
  8. Click OK. The client is configured to communicate with the CommServe and MediaAgent.
  9. Verify that your firewall configuration was pushed successfully by checking the Event Viewer window.

Note: Outgoing routes are automatically created for direct connections. However, you might want to set up outgoing routes to enable HTTPS encryption for data traffic, or to encrypt data connections by forcing connections into the tunnel. To set up outgoing routes from any host, see Configuring Outgoing Tunnel Connections.

Result

The client has been configured to open tunnel connections with the CommServe computer and MediaAgent.