...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
...
Note |
---|
This topic only applies to Armor Complete Enterprise Cloud users who are account administrators and new to the Armor Management Portal (AMP). |
As a first-time user in AMP, you must:
Complete the onboarding / invitation process
Access AMP
Invite users
Set up your
infrastructureinfrastructure
Note |
---|
Before you begin, Armor recommends that you review pre-installation/pre-deployment information, such as virtual machine offerings and supported browsers. To learn more, see Pre-deployment considerations for Armor CompleteEnterprise Cloud. |
Expand | ||
---|---|---|
| ||
|
Expand | ||||
---|---|---|---|---|
| ||||
| ||||
Expand | ||||
| ||||
Option 1: Credit card
|
Expand | ||
---|---|---|
| ||
Option 1: Credit card
Option 2: ACH Bank Debit
Option 2: ACH Bank Debit | ||
Expand | ||
| ||
Insert excerpt | ESLP:Workloads and tiers (snippet) | ESLP:Workloads and tiers (snippet) |
nopanel | true | |
Tier | Number of virtual machines | |
1 | 1 - 10 | |
2 | 11 - 25 | |
3 | 26 - 100 | |
4 | 101- 250 | |
5 | 251 - 500 | |
6 | 500 + | |
Expand | ||
|
Note |
---|
If you run Ubuntu 16.x, then please review Install SSL VPN for Ubuntu 16.x. If you run Ubuntu 18.x, then please review Install SSL VPN for Ubuntu 18.x. If you run Mac OS 10.11 or higher, then please review Install SSL VPN for Mac OS 10.11+. |
Note |
---|
For Account Administrators only. |
In the field, enter and select the name of the user, or their email address.
Mark the desired data center or data centers that the user can connect to.
Click Submit.
- The newly added user will appear in the table; the table is organized in alphabetical order, based on the first name of the user.
- AMP will automatically detect your operating system; however, you can click Download for another platform to view other operating system options.
- When you open the client, follow the on-screen installation instructions.
For Windows users, the client will download as a .zip file.
- Extract the installation files to your local hard drive.
- Launch the installer.exe file to begin the installation.
For Mac OS users, the client will download as a .tgzfile.
- Extract the installation files to your local hard drive.
- Access the mac_phat_client folder, and then run the naclient.pkg installer.
- When you run the installer, you will see an error regarding the certificate. Click Continue. (In a future release, Armor will resolve the issue.)
- To launch the SSL VPN client, in your Applications folder, search for naclient.
- If you run Mac OS 10.11 or higher, then please review Install SSL VPN Client for Mac OS, version 10.11 and higher.
- Extract the installation files to your local hard drive.
Click Settings.To add a new connection, you must enter a Connection Alias, Hostname/IP Address, and Port, which you can find in AMP.
- Your SSL VPN login credentials are the same credentials you use to access the Armor Management Portal (AMP).
title | Step 6: Create a Firewall Rule with a New IP Address Group |
---|
Step 1: Create an IP Group
In the Firewall screenExpand | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||||
|
Expand | ||
---|---|---|
| ||
|
Expand | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||
Step 1: Create an IP GroupIn the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several IP addresses or just a single IP address. You can combine related IP addresses into a single IP Group. For example, if you want to block traffic from three separate IP address, you do not have to create three separate firewall rules. Instead, you can combine the three separate IP addresses into a single, configurable IP Group. Then, when you create a firewall rule, you can pick the newly created IP Group as your Source or Destination IP addresses.
Step 2: Create a Service GroupIn the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several IP addresses or just a single IP address. protocols (and ports). You can combine related IP addresses protocols (and ports)into a single IP Service Group. For example, if you want to create a firewall rule to block traffic from three separate IP addressthree types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three separate IP addresses types of traffic (protocols and ports) into a single, configurable IP configurable Service Group. Then, when you create a firewall rule, you can pick the newly created IP Group as your Source or Destination IP addressescreated Service Group.
Step 2: Create a Service GroupIn the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several protocols (and ports). You can combine related protocols (and ports) into a Service Group. For example, if you want to create a firewall rule to block three types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three types of traffic (protocols and ports) into a single, configurable Service Group. Then, when you create a firewall rule, you can pick the newly created Service Group. In the Armor
For a complete list of supported services and sub-protocol, see Review supported services and sub-protocols. Step 3: Create a Firewall Rule
Service or sub-protocol Notes Example | |||||||||||||||
Services (TCP, UDP, etc.) | You must enter a port number. These services are not case-sensitive. |
| |||||||||||||
Additional services (AARP, AH, etc.) | These additional services are not case-sensitive. Do not enter a port number with these additional services. |
| |||||||||||||
Sub-protocols (echo-reply, redirect, etc.) | You must enter icmp, followed by the specific sub-protocol. You must enter the sub-protocol in lower-case letters. Do not enter a port number. |
|
Note |
---|
If you are not familiar with ordering rules, contact Armor Support to help you properly order your firewall rules. It is extremely important to order rules in order to receive desired traffic. To learn how to send a support ticket, see Armor Support. |
- Under Rule, in the numbered fields, enter a number to move the rule to a different position.
- If you have more than 25 rules, the additional rules will be placed in a secondary section within the Firewallscreen. To reorder and move these additional rules into a higher position, enter a number under the Ordercolumn, and then press Enter on your keyboard.
- In the top menu that appears, click Save.
title | Step 7: Create a Role and Add Permissions |
---|
In the Armor Management Portal (AMP), roles are similar to job titles that you can create and assign to your users. You can populate these roles with certain permissions. For example, you can create an Audit role, and then you can add specific permissions that will give the assigned user permission to access audit-related features.
By default, a new administrator account contains an Admin role with all the available permissions selected.
When you create a new user account, you must assign that user a role. You can assign a default role or create a new role.
Note |
---|
There are three default permissions in AMP:
If you want to use a default role, then you can skip to Step 8: Create An User and Assign A Role. |
title | Step 8: Create a User and Assign a Role |
---|
Note |
---|
Repeat Step 8: Create An User and Assign A Role for every user you want to invite. |
title | Step 9: Enable SSL/VPN Access for Your Users |
---|
title | Step 10: Subscribe to Data Center Notifications |
---|
title | Step 11: Configure Your Notification Preferences |
---|
Armor recommends that you configure your account to receive notifications for Account, Billing, and Technical events.
Note |
---|
These notification preferences do not relate to support tickets. To update your notification preferences for support tickets, see Notification Preferences. |
You will receive a notification when:
- A password expires in 14 days.
- A password expires in 7 days.
- A password expires in 24 hours.
- A password has expired.
You will receive a notification when:
- An invoice has posted.
- An invoice is past due (2, 10, 15, 25, and 30 days).
- A payment method will soon expire (1, 15, and 30 days).
You can configure a user to become the primary billing contact for an account. This user will receive billing notifications. Additionally, this user will be listed in the Bill to field in an invoice.
- In the Armor Management Portal (AMP), in the left-side navigation, click Account.
- Click Users.
- Locate and hover over the desired user.
- Click the vertical ellipses.
- Select Set as Primary Billing Contact.
- Click OK.
You will receive a notification when:
- A virtual machine will be deleted or downgraded.
- CPU, disk, and memory utilization is at more than 90% for 5 minutes.
- Ping, SSH (Linux), or RDP (Windows) fails for 5 minutes.
Note |
---|
You can only change the notification preferences for your own account. You cannot change the notification preferences for other user accounts. |
- Select Alert to receive notifications in the top bar in the Armor Management Portal (AMP).
- Select Email to receive notifications through email.
- You can select both notification options.
Expand | ||
---|---|---|
| ||
An organization allows you to specify when a group of users should be added to a specific support ticket, based on the subject matter of the ticket. For instance, for a billing-related ticket, you can indicate that members of the Billing organization should be notified. When a support ticket is shared with an organization, all users within the organization will receive an initial email notification.
|
...
After you create a rule, Armor recommends that you place the rule in the correct order.
|
Expand | ||
---|---|---|
| ||
In the Armor Management Portal (AMP), roles are similar to job titles that you can create and assign to your users. You can populate these roles with certain permissions. For example, you can create an Audit role, and then you can add specific permissions that will give the assigned user permission to access audit-related features. By default, a new administrator account contains an Admin role with all the available permissions selected. When you create a new user account, you must assign that user a role. You can assign a default role or create a new role.
|
Expand | ||
---|---|---|
| ||
|
Expand | ||
---|---|---|
| ||
Before an invited user can download and install their SSL VPN, the account administrator must add the following permissions to their account:
Additionally, the account administrator must enable the account to access the SSL VPN client:
|
Expand | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||
|
Expand | ||||||||||
---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||
Armor recommends that you configure your account to receive notifications for Account, Billing, and Technical events.
|
Expand | ||
---|---|---|
| ||
An organization allows you to specify when a group of users should be added to a specific support ticket, based on the subject matter of the ticket. For instance, for a billing-related ticket, you can indicate that members of the Billing organization should be notified. When a support ticket is shared with an organization, all users within the organization will receive an initial email notification.
|
Excerpt | ||||
---|---|---|---|---|
| ||||
You can use Armor's StatusHub page to review the status of Armor's infrastructure, as well as other Armor services, such as the Armor Management Portal (AMP). Additionally, you can use StatusHub to receive notifications and updates regarding infrastructure outages.
|