Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.


Note

This topic only applies to Armor 's private cloud Enterprise Cloud users who are account administrators and new to the Armor Management Portal (AMP).

...

  • Complete the onboarding / invitation process

  • Access AMP

  • Invite users

  • Set up your infrastructure

Note

Before you begin, Armor recommends that you review pre-installation/pre-deployment information, such as virtual machine offerings and supported browsers.

To learn more, see Pre-deployment considerations for Armor 's private cloudEnterprise Cloud.

Expand
titleStep 1: Open the Account Signup Email
  1. In the email from Armor, click the link.

    • You will be redirected to enter your account security information, including payment information.

      • If you already coordinated your payment process with Armor, then you will not see the payment screen.

...

Expand
titleStep 5: Enable and Install Your SSL/VPN Access
Note

For Account Administrators only.

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.

  2. Click SSL VPN.

  3. Click Members.

  4. Click the plus ( + ) icon.

  5. In the field, enter and select the name of the user, or their email address.

  6. Mark the desired data center or data centers that the user can connect to.

  7. Click Submit.

    • The newly added user will appear in the table; the table is organized in alphabetical order, based on the first name of the user.

  8. Click Client.

  9. Click Download SSL VPN client.

    • AMP will automatically detect your operating system; however, you can click Download for another platform to view other operating system options.

    • When you open the client, follow the on-screen installation instructions.

    • For Windows users, the client will download as a .zip file.

      • Extract the installation files to your local hard drive.

      • Launch the installer.exe file to begin the installation.

      For Mac OS users, the client will download as a .tgzfile.

      • Extract the installation files to your local hard drive.

      • Access the mac_phat_client folder, and then run the naclient.pkg installer.

      • When you run the installer, you will see an error regarding the certificate. Click Continue. (In a future release, Armor will resolve the issue.)

      • To launch the SSL VPN client, in your Applications folder, search for naclient.

      • If you run Mac OS 10.11 or higher, then please review Install SSL VPN Client.

  10. After installation, open the client.

    • In the drop-down menu, default will be listed.


  11. Click Settings.

    • To add a new connection, you must enter a Connection Alias, Hostname/IP Address, and Port, which you can find in AMP.


  12. Return to AMP, specifically to the Client section of the SSL VPNscreen.

  13. Use the Client Configuration table to locate the data center and corresponding information to add to the client.


  14. Under Client Configuration, copy the Location information, and then paste that information into Connection Alias.

  15. Under Client Configuration, copy the HOST/FQDN information, and then paste that information into Hostname/IP Address.

  16. Under Client Configuration, copy the Port information, and then paste that information into Port.

  17. Click Add.

  18. Click OK.

  19. In the drop-down menu, select the newly created connection.

  20. Log into the client.

    • Your SSL VPN login credentials are the same credentials you use to access the Armor Management Portal (AMP).

...

Expand
titleStep 6: Create a Firewall Rule with a New IP Address Group
Step 1: Create an IP Group

In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several IP addresses or just a single IP address.

You can combine related IP addresses into a single IP Group. For example, if you want to block traffic from three separate IP address, you do not have to create three separate firewall rules. Instead, you can combine the three separate IP addresses into a single, configurable IP Group. Then, when you create a firewall rule, you can pick the newly created IP Group as your Source or Destination IP addresses.

  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click IP Groups.

  5. Click Actions, and then click New Group.

  6. In IP Group Name, enter a descriptive name.

    • Armor recommends that you add Source or Destination into the name of the IP Group to help you identify the IP Group as the Source or Destination IP group.

  7. In Add Members To Group, enter a member, and then click the plus icon.

    • You can enter:

      • A single IP address

      • A range of IP addresses

      • CIDR

    • You must add at least one member.

    • You can add multiple members to a service group.

  8. Click Apply.

    • The newly created IP group will appear at the bottom of the table.

Step 2: Create a Service Group

In the Firewall screen, each entry in the table represents a single firewall rule; however, each firewall rule can contain several protocols (and ports).

You can combine related protocols (and ports)into a Service Group. For example, if you want to create a firewall rule to block three types of traffic, you do not have to create three separate firewall rules. Instead, you can combine the three types of traffic (protocols and ports) into a single, configurable Service Group. Then, when you create a firewall rule, you can pick the newly created Service Group.

  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top drop-down menu, select the desired data center.

  4. Click Service Groups.

  5. Click Actions, and then click New Group.

  6. In Service Group Name, enter a descriptive name.

  7. In Add Members To Group, enter the service or sub-protocol, and then click the plus ( + ) icon.

    • You must add at least one member.

    • You can add multiple members to a service group.

      Service or sub-protocol

      Notes

      Example

      Services (TCP, UDP, etc.)

      You must enter a port number.

      These services are not case-sensitive.

      • tcp/80
      • TCP/80
      • Tcp/80
      • tCp/80
      Additional services (AARP, AH, etc.)

      These additional services are not case-sensitive.

      Do not enter a port number with these additional services.

      • ATALK
      • igmp
      • Gre
      Sub-protocols (echo-reply, redirect, etc.)

      You must enter icmp, followed by the specific sub-protocol.

      You must enter the sub-protocol in lower-case letters.

      Do not enter a port number.

      • icmp/source-host-isolated
      • icmp/time-exceeded
  8. Click Apply.

    • The newly created service group will appear at the bottom of the table.

For a complete list of supported services and sub-protocol, see Review supported services and sub-protocols.

Step 3: Create a Firewall Rule
  1. In the Armor Management Portal (AMP), on the left-side navigation, click Security.

  2. Click Firewall.

  3. If you have virtual machines in various data centers, then in the top menu, click the corresponding data center.

  4. Click Actions, and then click New Rule.

    • If you do not see Actions, then click Create a Firewall Rule.

  5. In Name, enter a descriptive name.

  6. In Action, select Allow to allow specified traffic to access your virtual machine or Block to block specified traffic.

  7. Under Service, enter and select the name of the desired Service Group.

  8. Under Source, enter and select the name of the desired IP Group.

  9. Under Destinations, in the field, enter and select the name of the desired IP Group.

  10. Click Save Rule.

After you create a rule, Armor recommends that you place the rule in the correct order.

Note

If you are not familiar with ordering rules, contact Armor Support to help you properly order your firewall rules. It is extremely important to order rules in order to receive desired traffic.

To learn how to send a support ticket, see Armor Support.


Reorder a Rule:

  1. Under Rule, in the numbered fields, enter a number to move the rule to a different position.

    • If you have more than 25 rules, the additional rules will be placed in a secondary section within the Firewall screen. To reorder and move these additional rules into a higher position, enter a number under the Order column, and then press Enter on your keyboard.

  2. In the top menu that appears, click Save.


Disable a Rule:

  1. Locate and hover over the desired rule.

  2. Click the vertical ellipses.

  3. Click Disable Rule.

  4. Click Disable Rule again.

  5. In the top menu that appears, click Save.


Expand
titleStep 7: Create a Role and Add Permissions

In the Armor Management Portal (AMP), roles are similar to job titles that you can create and assign to your users. You can populate these roles with certain permissions. For example, you can create an Audit role, and then you can add specific permissions that will give the assigned user permission to access audit-related features.

By default, a new administrator account contains an Admin role with all the available permissions selected.

When you create a new user account, you must assign that user a role. You can assign a default role or create a new role.

Note

There are three default permissions in AMP:

  • Admin contains every permission in AMP.

  • Technical contains mostly write-only permissions.

  • Billing contains mostly read-only permissions.

If you want to use a default role, then you can skip to Step 8: Create An User and Assign A Role.

...

Expand
titleStep 9: Enable SSL/VPN Access for Your Users

Before an invited user can download and install their SSL VPN, the account administrator must add the following permissions to their account: 

  • Write SSL VPN Devices and Users 

  • Read SSL VPN Devices and Users

  • Read Virtual Data Centers 

Additionally, the account administrator must enable the account to access the SSL VPN client:

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure

  2. Click SSL VPN

  3. Click Members.

  4. In the top bar, select the data center that corresponds to your virtual machine. 

    • If you have virtual machines in multiple data centers, then you must configure the user for each data center. (Also, you must download the client for every data center you use.)

  5. Under Active Members, type and select the desired username.

    • The user can now access to AMP to download their SSL VPN client. 

Expand
titleStep 10: Subscribe to Data Center Notifications

...

You can use Armor's StatusHub page to review the status of Armor's infrastructure, as well as other Armor services, such as the Armor Management Portal (AMP).

Additionally, you can use StatusHub to receive notifications and updates regarding infrastructure outages.

  1. Access Armor's StatusHub page

  2. In the top menu, click Subscribe

  3. Select your desired notification method (EmailSMSSlack, or Webhook), and then enter the corresponding information, such as your email address for the Email tab. 

  4. Select a notification type. There are two options.  

    1. To receive information about every Armor service, click All services. This option will send you information about: 

      1. All data centers

      2. Armor API

      3. Armor Management Portal

    2. To receive information about specific Armor services, click Selected Services

      1. Next to Choose services, click Select.   

      2. Click the desired data center, and then click Select to receive information for every infrastructure component for that data center.  

  5. During an unexpected outage (or incident), you may receive multiple updates regarding the status of an outage.

    • To receive multiple updates during an outage, select OFF for Do not notify on intermediate incident updates.

    • To simply receive one notification regarding the beginning of an outage, and then one notification regarding the completion of an outage, select ON for Do not notify on intermediate incident updates.

  6. Click Subscribe

...

titleStep 11: Configure Your Notification Preferences

Armor recommends that you configure your account to receive notifications for Account, Billing, and Technical events.

Note

These notification preferences do not relate to support tickets.

To update your notification preferences for support tickets, see Notification Preferences.

...

Insert excerpt
Account Administrators
Account Administrators
nameSubscribe to Data Center Notifications
nopaneltrue

Expand
titleStep 11: Configure Your Notification Preferences

Armor recommends that you configure your account to receive notifications for Account, Billing, and Technical events.

Note

These notification preferences do not relate to support tickets.

To update your notification preferences for support tickets, see Notification Preferences.

Account

You will receive a notification when:

  • A password expires in 14 days.

  • A password expires in 7 days.

  • A password expires in 24 hours.

  • A password has expired.

Billing

You will receive a notification when:

  • An invoice has posted.

  • An invoice is past due (2, 10, 15, 25, and 30 days).

  • A payment method will soon expire (1, 15, and 30 days).

You can configure a user to become the primary billing contact for an account. This user will receive billing notifications. Additionally, this user will be listed in the Bill to field in an invoice.

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Account.

  2. Click Users.

  3. Locate and hover over the desired user.

  4. Click the vertical ellipses.

  5. Select Set as Primary Billing Contact.

  6. Click OK.

Technical

You will receive a notification when:

  • A

...

A password expires in 7 days.

...

A password expires in 24 hours.

...

A password has expired.

...

Billing

You will receive a notification when:

  • An invoice has posted.

  • An invoice is past due (2, 10, 15, 25, and 30 days).

  • A payment method will soon expire (1, 15, and 30 days).

...

  • virtual machine will be deleted or downgraded.

  • CPU, disk, and memory utilization is at more than 90% for 5 minutes.

  • Ping, SSH (Linux), or RDP (Windows) fails for 5 minutes.


Note

You can only change the notification preferences for your own account. You cannot change the notification preferences for other user accounts.

  1. In the Armor Management Portal (AMP), in the

...

  1. top, right corner, click the vertical ellipses.

  2. Click Settings.

  3. Click

...

  1. Notification Preferences.

...

Locate and hover over the desired user.

...

Click the vertical ellipses.

...

Select Set as Primary Billing Contact.

...

Click OK.

...

Technical

...

You will receive a notification when:

  • A virtual machine will be deleted or downgraded.

  • CPU, disk, and memory utilization is at more than 90% for 5 minutes.

  • Ping, SSH (Linux), or RDP (Windows) fails for 5 minutes.

...

  1. Use the slider to make your desired changes.

    • Select Alert to receive notifications in the top bar in the Armor Management Portal (AMP).

    • Select Email to receive notifications through email.

    • You can select both notification options.

  2. Click Update Notification Preference to save your changes.


For more information on setting up access to Support Tickets, see Organizations.
  1. In the Armor Management Portal (AMP), in the top, right cornerleft-side navigation, click the vertical ellipsesSupport.

  2. Click SettingsTickets.

  3. Click Notification PreferencesManage Organizations or Organizations.

  4. Use Select the slider to make your desired changesorganization.

    • Select Alert to receive notifications in the top bar in the Armor Management Portal (AMP).

    • Select Email to receive notifications through email.

    • You can select both notification options.

    Click Update Notification Preference to save your changes.
Expand
titleStep 12: Add a User to an Organization

An organization allows you to specify when a group of users should be added to a specific support ticket, based on the subject matter of the ticket. For instance, for a billing-related ticket, you can indicate that members of the Billing organization should be notified. When a support ticket is shared with an organization, all users within the organization will receive an initial email notification.

An organization allows you to specify when a group of users should be added to a specific support ticket, based on the subject matter of the ticket. For instance, for a billing-related ticket, you can indicate that members of the Billing organization should be notified. When a support ticket is shared with an organization, all users within the organization will receive an initial email notification.

  • n the Armor Management Portal (AMP), in the left-side navigation, click Support.

  • Click Tickets.

  • Click Manage Organizations or Organizations.
  • Select the desired organization.

  • To add a user, enter and select the name of the user.

    • The change will be automatically saved.

  • Note
    Expand
    titleStep 12: Add a User to an Organization
    1. To add a user, enter and select the name of the user.

      • The change will be automatically saved.

    Note

    For more information on setting up access to Support Tickets, see Organizations.


    Excerpt
    hiddentrue
    nameSubscribe to Data Center Notifications

    You can use Armor's StatusHub page to review the status of Armor's infrastructure, as well as other Armor services, such as the Armor Management Portal (AMP).

    Additionally, you can use StatusHub to receive notifications and updates regarding infrastructure outages.

    1. Access Armor's StatusHub page

    2. In the top menu, click Subscribe

    3. Select your desired notification method (EmailSMSSlack, or Webhook), and then enter the corresponding information, such as your email address for the Email tab. 

    4. Select a notification type. There are two options.  

      1. To receive information about every Armor service, click All services. This option will send you information about: 

        1. All data centers

        2. Armor API

        3. Armor Management Portal

      2. To receive information about specific Armor services, click Selected Services

        1. Next to Choose services, click Select.   

        2. Click the desired data center, and then click Select to receive information for every infrastructure component for that data center.  

    5. During an unexpected outage (or incident), you may receive multiple updates regarding the status of an outage.

      • To receive multiple updates during an outage, select OFF for Do not notify on intermediate incident updates.

      • To simply receive one notification regarding the beginning of an outage, and then one notification regarding the completion of an outage, select ON for Do not notify on intermediate incident updates.

    6. Click Subscribe