Synchronizing a master CC with one or more slave CCs requires an exchange of public keys from slave and master, and to copy the node information from the node property window on the slave CC to the master CC. In the following example, first all required slave CCs are configured on the master. After this, the node information is copied from a slave to the master.
Before You Begin
Step 1. Get the Private Key Information from the Slave CC
- Log into your Control Center that will serve as a slave CC.
- Go to CONFIGURATION > Configuration Tree > Multi Range > Global Settings > CC Identity.
- In the left menu, click Trust Chain.
- In the Trust Chain Configuration section, click Ex/Import for CC Private Key.
- From the list, click Export Public to Clipboard:
Step 2. Configure the Identity of the Slave CC on the Master CC
- Log into your Control Center that will serve as your master CC.
- Go to CONFIGURATION > Configuration Tree > CC Parameters.
- In the left menu, click Switch to Advanced view.
- In the left menu, click Split Control Center.
- Configure the CC to work as a master:
- Note Type – Select Master.
- Slave Control Centers – Click + to configure a new slave CC with its synchronisztion nodes.
- The Slave Control Centers window displays.
- Enter a name for the Control Center.
- Click OK.
- Enter the IP address for Slave Control Center IP.
- Click Ex/Import for Slave Public Key.
- From the list, select Import from Clipboard:
- Click OK.
- Click Send Changes.
- Click Activate.
Step 3. Get the Private Key Information from the Master CC
- Go to CONFIGURATION > Configuration Tree > Multi Range > Global Settings > CC Identity.
- In the left menu, click Trust Chain.
- In the Trust Chain Configuration section, click Ex/Import for CC Private Key.
- From the list, click Export Public to Clipboard:
Step 4. Configure the Identity of the Master CC on the Slave CC
- Log back into your Control Center that will serve as your slave CC.
- Go to CONFIGURATION > Configuration Tree > CC Parameters.
- For Node Type, select Slave.
- In the left menu, click Switch to Advanced view.
- In the left menu, click Split Control Center.
- For Master CC Public Key, click Ex/Import.
- Click Import from Clipboard:
- Click Send Changes.
- Click Activate.
Allow Traffic from the Master CC to the related Slave CC
For a proper communication between the Master and Slave CC, a firewall rule must be created on the Slave CC. This firewall rule must allow traffic from the Master CC to the Slave CC with the following options:
- Go to CONFIGURATION > Configuration Tree > Virtual Servers > your virtual server > Assigned Services > NGFW (Firewall) > Forwarding Rules.
- Click Lock.
- Click + to add an access rule.
- For the access rule type, select Pass.
- Enter a name for the access rule.
- Source – IP address from the Master CC
- Services
- NGF-MGMT-STATUS: service port UDP 801
- NGF-MGMT-CONF: service port TCP 809
- Destination – IP address from the local Slave CC
- Connection Method – Dynamic NAT
Configure the Synchronization Nodes
The following example assumes that a user wants to synchronize the Administrative Roles node.
Repeat the following steps for all paths of each slave CC that you want to synchronize with the master CC.
Step 1. Get the Node Information from the Slave CC
- Log into your slave CC.
- Go to CONFIGURATION > Configuration Tree > Multi Range > Global Settings.
- Right-click Administrative Roles in the Control Center configuration tree.
- From the list, select the Properties node.
- The Node Properties window opens.
- Locate the line that holds Configuration Node Path.
- Using your cursor, highlight the string in the Configuration Node Path field:
- Right-click the marked string.
- A small menu displays.
- From the list, select Copy:
Step 2. Configure the Node Information of the Slave CC on the Master CC
- Log into your Control Center that will serve as your master CC.
- Go to CONFIGURATION > Configuration Tree > CC Parameters.
- In the left menu, click Switch to Advanced view.
- In the left menu, click Split Control Center.
- From the list of Slave Control Centers, double-click the slave CC you want to configure the synchronization node for.
- For Synced Configuration Nodes, click + to add a new configuration node.
- The Synced Configuration Nodes window displays.
- Right-click into the edit field for Source Node Path.
- From the list, select Paste.
- In the edit field for Source Node Path, delete everything beginning with the last '/' to the end of the string, for example, '/roles'. The edit-field now displays the string '0settings'.
- Right-click into the edit field for Source Node Name.
- From the list, select Paste.
- From the string in the edit field—for example, 0setting/roles—delete everything from the beginning up to the last '/', for example, 0settings/. The edit-field now displays the string 'roles':
- Click OK.
- Click Send Changes.
- Click Activate.
Your master CC is now configured to synchronize the node 'Administrator Roles' with the slave CC of your choice. If you make any changes on the master CC to one of the configured synchronization paths, this path is automatically pushed to the CC if it is reachable and if the sync node is not locked on the slave CC.
Create an Access Rule on Both Control Centers
In order that the master and slave CC can communicate to each other, you must create an access rule on the host firewall for port 810 UDP. Execute the following steps on both the master and slave CC.
- Log into your CC on box level.
- Go to CONFIGURATION > Configuration Tree > Box > Infrastructure Service > Host Firewall.
- At the top of the list, ensure that Inbound is selected.
- Click + to add a new access rule.
- The Edit Rule window opens.
- For the action type, select Pass.
- For the name of the access rule, enter MGMT-ACCESS-SLAVE-CC.
- For Source, enter the network address where the other Control Center is in.
- For Service, select <explicit> from the list.
- Double-click the first line in the service list.
- The Edit/Create Service Object window opens.
- Click on New Object... .
- The Service Entry Parameters window opens.
- For IP Protocol, select 017 UDP.
- For Port Range, enter 810.
- Click OK.
- For Destination, enter the box level IP address of your current Control Center.
- For Connection Method, select <explicit-conn> and Original Source IP
- Click OK.
- Click Send Changes.
- Click Activate.
Status Map on Master CC and Slave CC
On a master CC, you can see in the status map information about configured slave CCs. The column Slave CC lists all slave CCs synched from the master CC. In the horizontal line, the status map displays the name of the slave Control Center:
Because a slave CC is only passively listening on sync commands sent by its master CC, no information is available in the status map: