Skip to main content

Outbound Server Installation and Configuration Guide


1) System Requirements

The hardware and software requirements to operate the SHIELD Edge Outbound Server are as follows.

divisionApplicable Specifications
CPUIntel(R) Xeon(R) E-2234 3.6GHz / E-2134 3.5GHz / Silver 4112 3.0GHz or Similar Products
RAM1TB X 2(Raid)
HDD16GB or more
HypervisorProxmox 8.0 or higher

2) Preparation Items

Assuming that the hypervisor is already installed

NodivisionDescriptionNote
1Outbound Server installation OVA fileSdEdgeLink.mf
SdEdgeLink.ovf
SdEdgeLink-disk1.vmdk
Outbound Server Latest Release Version
2Public IPIP for SFS Relay Server

3) SHIELD Edge Outbound Server Installation

This document explains the installation of the SHIELD Edge OutBound Server (OVA) based on Proxmox.

  • Connect to the corresponding node of Proxmox via ftp.

  • Upload the OVF file to /root.

TABLE

3)-2. SHIELD Edge Outbound Server OVF File Import

  • Move to the folder where the OVF is uploaded and enter the command below (administrator privileges)

    • Command example) qm importovf 206 SHIELDEdgelink.ovf local-zfs

텍스트, 스크린샷, 폰트이(가) 표시된 사진 자동 생성된 설명

  • Once the import is successfully completed, the VM of SHIELD EdgeLink will be displayed as follows. This completes the installation.

텍스트, 폰트, 번호, 라인이(가) 표시된 사진 자동 생성된 설명

4) SHIELD Edge Outbound Server Booting, Network Settings, and Console (Settings) Screen Display

This document explains everything from execution to configuration after installation is complete.

4)-1. SHIELD Edge Outbound Server VM Booting

  • Clicking on VM 206 (SdEdgeLink) will display the Start Now button as shown in the image on the right.

  • Clicking the Start Now button will display the default OS, Ubuntu 22.04 Linux screen.

  • The booting of the SHIELD Edge Outbound Server begins. (Takes about 10 minutes)

텍스트, 스크린샷, 멀티미디어 소프트웨어, 소프트웨어이(가) 표시된 사진 자동 생성된 설명

4)-2. Network settings for running the console screen of SHIELD Edge OutBound Server

  • Set the local IP. Click the icon like '?' in the upper right corner and click 'Wired Connected' > 'Wired Setting'.

  • Click the gear icon in the Wired section to open the Wired popup, then navigate to IPV4 and click Manual. Enter the internal IP information (e.g., 192.168.40.10), Netmask, and Gateway.

  • Click the Apply button to reboot Ubuntu 22.04 Linux, and it will connect to the network. (Refer to the icon in the right image)

텍스트, 스크린샷, 소프트웨어, 디자인이(가) 표시된 사진 자동 생성된 설명

4)-3. SHIELD Edge OutBound Server Console Screen Display

  • Click the Chrome icon on the left side of the main screen of Ubuntu 22.04 Linux. Then, 'Authentication required' will be displayed, and enter 'SOFTCAMP1!"' in the password input field and click Unlock.

  • Type 'localhost/network-list' in the Chrome browser's address bar and press Enter. Then, the SHIELD EdgeLink console will be displayed.

스크린샷, 텍스트, 소프트웨어이(가) 표시된 사진 자동 생성된 설명

5) SHIELD Edge Outbound Server console screen display, default values, and operations

5)-1. SHIELD Edge Outbound Server console screen's initial settings when first displayed.

  • Config NetWorks initial settings

    텍스트, 스크린샷, 번호, 소프트웨어이(가) 표시된 사진 자동 생성된 설명

  • The External URL and Internal IP required to access SHIELDGate are displayed.

  • Internal IP and External URL can be changed/deleted.

    • External URL item: Register the external site you want to connect to.

    • Internal IP : Register the IP to access internally.

  • SFS Relay Server Initial Configuration Values

    텍스트, 스크린샷, 폰트, 라인이(가) 표시된 사진 자동 생성된 설명

    • The initial value is not set.

    • Enter the Public IP as the preparation item, then click the Run button.

    ※SHIELDEX Remote Browser management console requires Public IP settings.

    ① Access the SHIELDEX Remote Browser admin website. (https://elinkadmin.security365.com) Contact the administrator for ID/PW.

    ② Select the "Policy" button in the LNB.

    ③ Select the "Edit" button on the right side of the "rbrowser" item in the list.

    ④ Among the settings, enter the "ICE server URL" item as follows.

    • Setting Example{iceServers:\[{urls: 'turn:211.175.134.237:19001', username: ‘e\*\*\*\*\*\*', credential: ‘e\*\*\*\*\*\*\*\*\*'}\]}
  • DNS Settings Initial Configuration Values

    텍스트, 스크린샷, 폰트이(가) 표시된 사진 자동 생성된 설명

    • The initial value is 8.8.8.8.

    • It can be configured according to the network environment of the target for introduction.

  • Firewall Status Initial Settings

    텍스트, 폰트, 번호, 스크린샷이(가) 표시된 사진 자동 생성된 설명

    • The initial value is "Anywhere ALLOW IN 192.168.40.0/24".

    • You can add or delete rules according to the network environment of the target for introduction.

  • Initial Settings for Toggle Host Display

    텍스트, 스크린샷, 폰트, 번호이(가) 표시된 사진 자동 생성된 설명

    • The Internal IP and External URL set in Config Networks are displayed.

6) Network Environment Configuration for the Target Introduction

  • In order for the SHIELDGate screen to be displayed correctly, it is necessary to configure the network environment of the target for implementation (e.g., FireWall settings, etc.). Since various network environments exist depending on the implementation site, you can refer to the following examples.

  • Firewall Configuration Example - pfsense

    • Port Forward

텍스트, 스크린샷, 폰트, 소프트웨어이(가) 표시된 사진 자동 생성된 설명

  • Outbound

텍스트, 스크린샷, 소프트웨어이(가) 표시된 사진 자동 생성된 설명

7) Hosts file configuration on user PC

  • Enter the Internal IP and External URL set in Config Networks into the hosts file of the user's PC.

    • Location: C:\Windows\System32\drivers\etc\hosts (configuration example)

텍스트, 스크린샷, 폰트, 번호이(가) 표시된 사진 자동 생성된 설명

  • If managed with internal DNS at the introduction site, this Hosts file modification is unnecessary.

  • Initial Settings for Toggle Host Display