tufin T-800 User manual

T-800/1200 Quick Start Guide
Version 13.11

Table of Contents
Table of Contents 2
Chapter 1: Introduction 3
Welcome 3
Overview 3
Chapter 2: The T-800/1200 Front and Rear Panels 4
Front Panel 4
Front Panel LEDs and Buttons 4
Rear Panel 6
Chapter 3: Setting Up The T-800/1200 7
Power up and Connect to the Network 7
Advanced CLI Configuration 7
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic 8
Install Tufin Orchestration Suite Classic 8
Configure SecureTrack 8
Configure SecureChange 11
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora 13
Network Requirements for Tufin Orchestration Suite Aurora 13
Install Tufin Orchestration Suite Aurora 13
Configure SecureTrack 15
Configure SecureChange 16
Chapter 6: Setting up the Remote Management Module 18
Prerequisites for Remote Computer 18
Ports 18
Configure RMM Using BIOS 18
Configure RMM Using SSH or a Console 19
Installing TufinOS 20
Chapter 7: Restoring Factory Defaults 21
The Next Step 22
Support 22
Tufin at a Glance 22
Trademarks 22
T-800/1200 Quick Start Guide
Table of Contents
Copyright 2003-2021, Tufin Software Technologies Ltd. 2

Chapter 1: Introduction
Welcome
Congratulations on choosing the T-800/1200 Appliance from Tufin Technologies, the industry’s most comprehensive Security Policy Orchestration
solution. Our worldwide technical services team is available to you through the web, email, or telephone. See http://www.tufin.com/support for your
preferred mode of communication. We look forward to supporting all of your current and future firewall operation’s needs.
Overview
Information in this guide applies to the T-800 and the T-1200 appliances.
The new T-Series Appliances are a Tufin-in-a-box solution that provides IT organizations with a quick, robust installation that lowers total cost of
ownership. T-Series Appliances are designed to support both Tufin Orchestration Suite Classic (default) and Aurora. You can choose which
product to install.
Using distributed deployment architecture, Tufin’s T-Series Appliances enable virtually unlimited scalability – multiple appliances can be connected
on-demand at multiple sites, according to network needs. With enterprise-grade memory and SSD drives, the T-Series combines power and
flexibility in several models to scale to the needs of mid-size to large enterprises and ensure optimal performance for your organization.
The T-Series Appliances come pre-installed with TufinOS and are designed to support both Tufin Orchestration Suite Classic (default) and Aurora.
You will need to choose the desired Tufin Orchestration Suite product and install it using the instructions provided in this document.
When setting up the appliance, we recommend that you also configure the Remote Management Module (RMM). With this module you can install
newer versions of TufinOS on the appliance without having to physically access the server.
All Tufin Appliances are rigorously lab-tested by our network security experts.
This document provides:
lShipping container contents, and descriptions of the appliance panels
lA step by step guide to getting the appliance and software up and running
lInstructions for restoring factory defaults
To set up device monitoring by SecureTrack, to configure SecureChange, or for more information about the Tufin Orchestration Suite, see the
Tufin Knowledge Center at https://forum.tufin.com/support/kc/latest (for Classic) or https://forum.tufin.com/support/kc/aurora (for Aurora).
Shipping Container Contents
Item Description
Appliance T-800/1200 appliance
Cables 2 power cables
1 RJ-45 (CAT 5e) network cable
1 DB9 console cable
USB flash drive USB flash drive for appliance recovery
Documentation This Quick Start Guide
Other hardware Rack mounting kit
Appliance front bezel
T-800/1200 Quick Start Guide
Chapter 1: Introduction
Copyright 2003-2021, Tufin Software Technologies Ltd. 3

Chapter 2: The T-800/1200 Front and Rear Panels
These sections describe the different elements in the front and rear panels.
Front Panel
Item Description
A Service/Asset Tag
B Hard drive bay 0
C Hard drive bay 1
D Hard drive bay 2
E Hard drive bay 3
F Hard drive bay 4
G Hard drive bay 5
H Hard drive bay 6
I Hard drive bay 7
J Front panel LEDs and buttons
K 2 USB 3.0 Ports
Front Panel LEDs and Buttons
All control buttons and status LEDs are located on the front of the appliance.
Item Feature Description
A Information
LED
Indicates system status as follows:
lContinuously on and red: An overheat condition has occurred (which may be caused by cable
congestion).
lBlinking red (1Hz): Fan failure, check for an inoperative fan.
lBlinking red (0.25Hz): Power failure, check for a non-operational power supply.
lSolid blue: UID has been activated locally to locate the server in a rack environment.
lBlinking blue: UID has been activated using IPMI to locate the server in a rack environment.
T-800/1200 Quick Start Guide
Chapter 2: The T-800/1200 Front and Rear Panels
Copyright 2003-2021, Tufin Software Technologies Ltd. 4

Item Feature Description
B NIC LED When flashing, indicates network activity on LAN1.
C NIC LED When flashing, indicates network activity on LAN2.
D HDD When flashing, indicates activity on the hard drive.
E Power LED Indicates power is being supplied to the system power supply units. This
LED is illuminated when the system is operating normally.
F UID
button/LED
The unit identification (UID) button turns on or off the blue light function of the Information LED and a blue LED
on the rear of the chassis. These are used to locate the server in large racks.
PWR Power button The main power switch applies or removes primary power from the power supply to the server but maintains
standby power.
T-800/1200 Quick Start Guide
Chapter 2: The T-800/1200 Front and Rear Panels
Copyright 2003-2021, Tufin Software Technologies Ltd. 5

Rear Panel
Item Description Notes
A Power supply 1
B Power supply 2
C LAN 10GB ethernet port 1
D LAN 10GB ethernet port 2
E LAN 10GB ethernet port 3
F LAN 10GB ethernet port 4
G 2 USB 3.0 ports
H IPMI LAN Dedicated IPMI management interface that gives you remote management (“lights-out
management”) of the system.
I Serial port Standard serial port that gives you serial access to the system via console redirection.
J VGA port
K 1 PCI-E 3.0 low profile slot
L 2 PCI-E 3.0, full height, full
length slots
Note: For Tufin Orchestration Suite 2.0 (Aurora), you must use only LAN Ethernet port 1 (C in the figure) for all network
connections.
T-800/1200 Quick Start Guide
Chapter 2: The T-800/1200 Front and Rear Panels
Copyright 2003-2021, Tufin Software Technologies Ltd. 6

Chapter 3: Setting Up The T-800/1200
Power up and Connect to the Network
Note: The appliances have a predefined IP address. Before racking the appliances, make sure to change the IP address either
in the first-time wizard (as described Chapter 4: Configure SecureTrack), or using a console connection (see Advanced CLI
Configuration) in CLI. For CLI instructions, see https://forum.tufin.com/support/kc/latest/Content/Suite/1584.htm.
To power up the appliance and connect it to the network:
1. Connect the power cable.
2. Boot up the appliance by pressing the Power button on the front panel.
3. Connect a network cable to the ethernet port 1 (Chapter 2: Rear Panel, item C) and to a PC (with a crossover cable), or to a local network
that is in the same subnet as the eth0 port. If you have not changed it, the default is 192.168.1.100/24.
Advanced CLI Configuration
You can achieve CLI access using a console connection or SSH access. To use a console connection, configure the terminal to match the
following appliance console port settings:
l57600 bits per second
l8 Data bits
lParity: None
lStop bit: 1
lFlow Control: None
T-800/1200 Quick Start Guide
Chapter 3: Setting Up The T-800/1200
Copyright 2003-2021, Tufin Software Technologies Ltd. 7

Chapter 4: Installing and Configuring Tufin Orchestration
Suite Classic
This section includes instructions to install and configure Tufin Orchestration Suite Classic R21-1 and above running on TufinOS 3.60.
Install Tufin Orchestration Suite Classic
1. Install Tufin Orchestration Suite Classic (SecureTrack and SecureChange/SecureApp):
a. Open a command line via SSH to the IP address of eth0 (if you have not changed it: 192.168.1.100).
b. Log in as tufin-admin with password admin.
You are prompted to change the default password when you first log in.
c. To install Tufin Orchestration Suite Classic, run the following commands:
screen -S install
sudo su –
cd /opt/tufin/data/classic
sh <filename>
The installation file is in /opt/tufin/data/classic.
d. Follow the installation instructions in the command line.
If you disabled SecureTrack and will not be using it on this appliance, skip to Configure SecureChange.
2. (SecureTrack only) Log into SecureTrack:
a. To access SecureTrack with Mozilla Firefox or Google Chrome, browse with HTTPS to the IP address of eth0. If you have not
changed the IP address, browse to: https://192.168.1.100.
b. Accept the certificate.
The login window appears.
c. Log in with these credentials (admin/admin) and click Login.
Configure SecureTrack
After logging into SecureTrack for the first time, the SecureTrack Setup Wizard opens. The wizard includes the following pages:
T-800/1200 Quick Start Guide
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic
Copyright 2003-2021, Tufin Software Technologies Ltd. 8

lLogin: For security reasons, change the admin password.
lEULA: Read and accept the End User License Agreement.
lPassword: Type system for the Old Password of the TufinOS root user, and change the password.
T-800/1200 Quick Start Guide
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic
Copyright 2003-2021, Tufin Software Technologies Ltd. 9

lNetworking (optional): Configure networking (DNS settings can also be configured later from SecureTrack's web interface)
lTime: Configure date and time settings.
lUser Details: Configure the admin user’s details. Username and password cannot be changed in this page.
T-800/1200 Quick Start Guide
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic
Copyright 2003-2021, Tufin Software Technologies Ltd. 10

lNotifications: Configure the SMTP settings for SecureTrack email notifications.
lLicense: Installing a license is optional at this stage. To receive a license, please contact your Tufin reseller.
lFinish: Click Save to complete the installation wizard:
Configure SecureChange
1. Configure SecureChange for the first time:
If SecureTrack is disabled, and you have not gone through the SecureTrack Setup Wizard, use standard Linux commands in TufinOS to
do the following:
lConfigure interface settings according to your networking needs (eth0 may still have the preconfigured IP address of
192.168.1.100). For instructions, see https://forum.tufin.com/support/kc/latest/Content/Suite/1584.htm.
lChange the root password. For instructions, see https://forum.tufin.com/support/kc/latest/Content/Suite/1585.htm.
lSet the time, time zone, and date. For instructions, see https://forum.tufin.com/support/kc/latest/Content/Suite/1024.htm.
l(Optional) Configure NTP. For instructions, see https://forum.tufin.com/support/kc/latest/Content/Suite/chrony.htm.
2. Log into SecureChange:
T-800/1200 Quick Start Guide
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic
Copyright 2003-2021, Tufin Software Technologies Ltd. 11

a. To access the SecureChange Administration Console, browse to https://<host>/securechangeworkflow
where <host> is the IP address or resolvable name of the T-series appliance.
b. Log in as tufin-admin, with password admin.
To further configure SecureChange, see the https://forum.tufin.com/support/kc/latest/Content/Suite/2353.htm.
To add devices to be monitored, see the https://forum.tufin.com/support/kc/latest/Content/Suite/4034.htm.
To add SecureTrack on this appliance to a distributed deployment, see https://forum.tufin.com/support/kc/latest/Content/Suite/2456.htm.
T-800/1200 Quick Start Guide
Chapter 4: Installing and Configuring Tufin Orchestration Suite Classic
Copyright 2003-2021, Tufin Software Technologies Ltd. 12

Chapter 5: Installing and Configuring Tufin Orchestration
Suite Aurora
This section includes instructions to install and configure Tufin Orchestration Suite Aurora R21-1 and above running on TufinOS 3.60.
Note: After you install Tufin Orchestration Aurora on the appliance, you will be unable to revert it to Tufin Orchestration Suite
Classic.
Network Requirements for Tufin Orchestration Suite Aurora
If you are installing Tufin Orchestration Suite Aurora on the appliance, you need to do the following:
lAllow access to the requiredports and services. For more information, see
https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/PortsAndServices.htm.
lDedicate a 24-bit CIDR subnet on your network to Tufin Orchestration Suite Aurorafor internal use. It must not overlap with
CIDR10.244.0.0/16or with the physical and VIP (Virtual IP) network addresses of yourSecureTrack Auroraservers.
lDedicate two different IP addresses to Tufin Orchestration Suite Aurora:
lThe virtual IP(VIP) that will serve as the external IPaddress used to accessTufin Orchestration Suite Aurorafrom your browser
and from devices that send it data. The VIP will not be needed in the installation, except in the last step - the installation
command.
lThe physical network IP that will serve as the internal IPaddress used by the administrator for CLI commands and this is the one
you will use in all other steps of the installation.
lIf additional nodes are subsequently added to the cluster, each node will require an additional dedicated physical network IP. The
VIP and all the physical network IPs must be on the same subnet.
Install Tufin Orchestration Suite Aurora
1. Reconfigure TufinOS
a. Open a command line via SSH to the IP address of eth0 (if you have not changed it: 192.168.1.100).
b. Log in as tufin-admin with password admin
You are prompted to change the default password when you first log in.
c. Run the following commands:
screen -S switch
switch-tos-mainstream
d. When prompted to reconfigure TufinOS, select yes. This process can run about five minutes.
e. Reboot the appliance.
f. Reconnect to the appliance (steps 2-3).
g. To install Tufin Orchestration Suite Aurora, run the following commands:
screen -S install
cd /opt/tufin/data/aurora
sudo sh <filename>
The installation file is in /opt/tufin/data/aurora.
2. Configure the appliance for Tufin Orchestration Suite Aurora
a. To access the appliance with Mozilla Firefox or Google Chrome, browse with https to the IP address of eth0. If you have not
changed the IP address, browse to https://192.168.1.100.
b. Accept the certificate.
T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora
Copyright 2003-2021, Tufin Software Technologies Ltd. 13

c. The login window appears. Log in as admin with password admin, and click Login.
You are prompted to set a new password.
d. Configure the IP address and DNS, where <Interface Name> is the name of the interface you are using. For example: ens33.
e. Do one of the following:
l(Recommended) Run the commandsudo nmtui edit <Interface Name>.
In the window, set the parameters as follows:
lSet IPv4 CONFIGURATION to Manual.
lSet Addresses to the internal machine IP together with the chosen subnet.
lSet Gateway and DNS Servers to the IPs used by your organization.
l(or) Edit the configuration files directly:
1. Edit the file /etc/sysconfig/network-scripts/ifcfg-eno1.
2. Change line BOOTPROTO=dhcp to BOOTPROTO=static.
3. Add entries at the end of the file:
IPADDR=<NEWIP>
NETMASK=<MyNetmask>
GATEWAY=<MyGateway>
DNS1=<DNS_IP1>
DNS2=<DNS_IP2>
where
<NEWIP> is the internal machine IP.
<MyNetmask> ,<MyGateway>,<DNS_IP1>,<DNS_IP2> are the appropriate values for your network.
f. Restart the network service.
service network restart
3. Installing Tufin Orchestration Suite Aurora
T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora
Copyright 2003-2021, Tufin Software Technologies Ltd. 14

a. Run the screen command:
screen -S install
b. Run the install command, replacing the parameters:
l<VIP>with the external IP that you will use to accessTOS Aurora
l<SERVICE-CIDR>with the CIDR that you wantTOS Aurorato use
l<MODULE-TYPE>with one of the following values:
lSTforSecureTrackonly
lST,SCfor bothSecureTrackandSecureChange
lRCfor a remote collector
sudo tos install --modules=<MODULE-TYPE> --loadbalancer-ip=<VIP> --services-
network=<SERVICE-CIDR>
Example:
sudo tos install --modules=ST,SC --loadbalancer-ip=192.168.1.2--services-
network=10.10.10.0/24
The End User License Agreement (EULA) appears.
c. After reading, enter qto exit the document and then enter yto accept the EULA and continue until the commands completes.
d. Type Exit to leave the CLI.
e. Log in as admin with password admin, and click Login.
You are prompted to set a new password.
Configure SecureTrack
1. Activate your SecureTrack license: Relevant only for central clusters. Skip for remote collectors.
For complete instructions, see https://forum.tufin.com/support/kc/aurora/Content/Suite/2258.htm#activate.
T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora
Copyright 2003-2021, Tufin Software Technologies Ltd. 15

2. Set the Time Zone: TheTOS Auroraapplication has its own timezone, independent of your host node and the default is UTC. If UTC is
not the timezone you want to use,see https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/SetTimeZone.htm.
3. Set up your IP Addresses: To set up your Syslog VIP address, see
https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/VIP-syslog.htm.
Primary and VIP addresses can be changed if needed. For more information, see
https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/ChangingIPAddress.htm.
4. Add Nodes to your cluster: TOS Aurora is deployed by default as a single node Kubernetes cluster. See
https://forum.tufin.com/support/kc/aurora/Content/ST2/ManagingTOS/MultiNodeProcessing.htm for more information about adding
additional nodes.
Configure SecureChange
1. Create a SecureTrack Administrator User:
a. Go to at https://<IP> where IP is the cluster VIP.
b. Log in to SecureTrack as tufin-admin with password admin.
c. Create a new SecureTrack Administrator user.
Note: If you are going to configure SecureChange for multi-domain management, make the user either a
super administrator or multi-domain administrator, depending on whether you want to restrict the
administrator to selected domains.
For more information, see https://forum.tufin.com/support/kc/aurora/Content/Suite/1073.htm.
2. Log in to SecureChange:
a. Go to https://<IP>/securechangeworkflow where<IP>is thecluster VIP.
b. Log in to SecureChange as tufin-admin with password admin.
You are prompted to change the password.SecureChangeusers are separate fromSecureTrackusers; there is no connection
between aSecureTrackuser anda SecureChangeuser with the same name.
On the prompt window, you can also enter an email address for administrative email notifications. We recommend using the
address of an email list so you can edit the list of recipients easily.
3. Configure the SecureChange Settings
a. Go to Settings>Miscellaneous.
b. Enter a value for Server DNS name. The DNS server is used for links in email notifications. This can be an IP address in the
format 11.22.33.44 or a FQDN in the format https://mydomain.com.
The SecureChange DNS name is published bySecureChangeso it can be accessed from external sources. For example, it is
embedded in notification mails sent bySecureChange, which include a link to a ticket, such as an email notifying a handler
assigned with a task, or informing a requester that the ticket has been successfully resolved.
T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora
Copyright 2003-2021, Tufin Software Technologies Ltd. 16

c. Go to Settings>SecureTrack.
d. Enter the SecureTrack administrator username, which was created previously.
e. If you want a link to SecureTrack to be available in the SecureChange applications icon, select Show link to SecureTrack.
f. If you want to change how often SecureChange tests its connectivity to SecureTrack, change the value of the Connection check
interval.
g. Click Test connection to verify that SecureChange has a connection to SecureTrack.
h. Click Save.
4. Additional SecureChange Configurations
These tasks can be done now or at a later stage.
lConnect to a mail server. For instructions, see https://forum.tufin.com/support/kc/aurora/Content/Suite/1794.htm.
l(optional) Connect to an LDAP directory to use LDAP user accounts. For instructions, see
https://forum.tufin.com/support/kc/aurora/Content/Suite/2386.htm.
lCreate local users and user roles. For instructions, see https://forum.tufin.com/support/kc/aurora/Content/Suite/2287.htm.
If you need to reset the password of the initial Administrator (username: admin), see
https://forum.tufin.com/support/kc/aurora/Content/Suite/1922.htm.
T-800/1200 Quick Start Guide
Chapter 5: Installing and Configuring Tufin Orchestration Suite Aurora
Copyright 2003-2021, Tufin Software Technologies Ltd. 17

Chapter 6: Setting up the Remote Management Module
The remote management module (RMM) or IPMI port in Tufin appliances lets you connect to an administration web interface for the appliance. You
can configureRMMvia BIOS or via SSH or a Console. With this module you will be install newer versions of TufinOS on the appliance without
having to access the server physically.
Prerequisites for Remote Computer
lTo avoid latency issues, we recommend that the remote computer be on the same local network as the appliance.
lWeb browser.We recommend Internet Explorer with anti-virus enforcement and browser protection disabled.
lJava version 8 or later.
Ports
The following ports must be open between the appliance and the TufinOS remote installation computer:
Use Port
HTTP 80 (TCP)
HTTPS 443 (TCP)
IPMI Virtual Media 623 (UDP/TCP)
Remote Console 5900, 5901 (TCP)
SSH 22 (TCP)
WS-MAN 5985 (TCP)
Configure RMM Using BIOS
1. Reboot or start the appliance and pressDELto enter BIOS setup.
2. SelectIPMI>BMC Network Configuration.
3. Set Update IPMI LAN Configuration to Yes.
T-800/1200 Quick Start Guide
Chapter 6: Setting up the Remote Management Module
Copyright 2003-2021, Tufin Software Technologies Ltd. 18

4. Edit the settings as required.
5. SetUpdate IPMI LAN Configurationback toNo.
6. Save settings and reboot the appliance.
Configure RMM Using SSH or a Console
1. Make sure that the MGMT port for the appliance is connected to the network.
2. Connect the appliance using SSH or a console and set the following network settings:
ipmitool lan set 1 ipaddr <RMM IP Address>
ipmitool lan set 1 netmask <Subnet Netmask>
ipmitool lan set 1 defgw ipaddr <Default Gateway IP Address>
3. Verify the configuration:
ipmitool lan print 1
4. Ping theRMMIP address to confirm connectivity:
ping <RMMIPAddress>
5. Configure the user settings:
a.a. Check the existing user list:
ipmitool user list 1
b. Create or modify users. This command will create a new user or overwrite settings for an existing User ID.
ipmitool user set name <user_id> <username>
ipmitool user set password <user_id>
T-800/1200 Quick Start Guide
Chapter 6: Setting up the Remote Management Module
Copyright 2003-2021, Tufin Software Technologies Ltd. 19

ipmitool channel setaccess <channel number> <user id> [callin=on|off] [ipmi=on|off]
[link=on|off] [privilege=level]
For example:
ipmitool user set name 3 myuser
ipmitool user set password 3
ipmitool channel setaccess 1 3 callin=on ipmi=on link=on privilege=4
c. Enable the new user:
ipmitool user enable <user_id>
6. In a browser, log into the Web Interface and confirm that you are able connect using the username and password defined in the previous
step.
https://<RMMIPAddress>
Now you can securely connect to theRMMto do remote administration tasks. For more about using theRMM, refer to theIntel® Remote
Management Module 4 (Intel®RMM4) User Guide at http://www.intel.com/support/motherboards/server/sb/CS-032371.htm.
Installing TufinOS
To install TufinOS using RMM, see https://forum.tufin.com/support/kc/latest/Content/Suite/TufinOS_RMM.htm.
T-800/1200 Quick Start Guide
Chapter 6: Setting up the Remote Management Module
Copyright 2003-2021, Tufin Software Technologies Ltd. 20
Other manuals for T-800
1
This manual suits for next models
1
Table of contents
Other tufin Firewall manuals
Popular Firewall manuals by other brands

Juniper
Juniper NetScreen-5GT Wireless user guide

Neoware
Neoware Neoware c50 - Thin Client user manual

Fortinet
Fortinet FortiGate ASM-FX2 quick start guide

PaloAlto Networks
PaloAlto Networks Prisma SD-WAN ION 2000 Hardware reference

Cisco
Cisco RV120W Administration guide

PaloAlto Networks
PaloAlto Networks PA-1400 Series quick start guide

Intel
Intel McAfee Data Loss Prevention Prevent quick start guide

Fortinet
Fortinet FortiGate 240D quick start guide

Juniper
Juniper NetScreen-204 user guide

Fortinet
Fortinet FortiGate 5001A-DW user guide

Pulse Secure
Pulse Secure PSA3000 Hardware guide

Fortinet
Fortinet FortiGate FortiGate-300 installation guide