1. Cyberoam Central Console
1.1. Virtual CCC
1.1.1. How can I obtain a Virtual CCC Appliance?

You can obtain a Virtual CCC Appliance by following the steps below:

1.     Place an order with your reseller/distributor.

2.     Reseller/Distributor provides you with an Appliance Key for the Virtual CCC Appliance.

3.     Once you receive the Appliance Key, logon to customer.cyberoam.com.
 
        -         If you do not already have an account with Cyberoam, click Register Your Appliance. Fill the Customer Registration form, which 
      registers you as a Cyberoam customer as well as your Appliance Key.
 
-         In case of existing customers, log into your account and register your newly acquired Appliance Key.

For details on how you can register your appliance, refer to CCC Registration and Subscription Guide.

4.     Once you have registered your Appliance, you receive an email which acknowledges your registration and intimates you that your Virtual CCC Appliance image, in other words, the OVF Package, is being processed. This process takes a few minutes.

5.     Once the process completes, you receive a second email which informs you that your OVF Package is ready.

6.     Login to your customer account and download the OVF Package by clicking the download link against the mentioned Virtual CCC Appliance model name. 
 
 
 
 
                                                                                                                                                                       Document Version: 1.1 – 22/03/2012
1.2. CCC Visio Stencil
1.3. How To
1.3.1. Configure L2TP VPN Connection for Multiple Managed Appliances

Overview
 
CCC allows administrator to configure L2TP VPN connections for several Managed Cyberoam Appliances in one shot by using Dynamic Objects. Dynamic Objects in CCC are used to map single objects in CCC to respective objects in multiple or all Managed Cyberoam Appliances. For example, One (1) Dynamic Host in CCC for a Mail Server can represent corresponding Mail Server hosts in multiple Managed Appliances, if mapped accordingly.
 

Scenario

Configure L2TP VPN connection in CCC and push it down to all Managed Cyberoam Appliances.
 

Configuration

You can configure an L2TP connection in CCC to push down to Managed Appliances by following the steps given below. Configuration is to be done from CCC Web Admin Console using Administrator profile.
 

Step 1: Create Dynamic Objects for BO Interfaces

Dynamic Interface for WAN Interfaces

Go to Management Console à Appliance Management à Dynamic Objects à Interface and click Add to add a Dynamic Interface using following parameters.

 
 
Parameter Description
 
Parameter
Value
Description
Name
WAN_Interface
Name to identify the Host.
Type
Route Interface
Zone
WAN
Appliance-Interface Mapping
Appliance
Boston
New_Jersey
Select the appliance.
Host
PortB
PortB

 
 

Click OK to save the interface.
 

Dynamic Interface for LAN Interfaces

Go to Management Console à Appliance Management à Dynamic Objects à Interface and click Add to add a Dynamic Interface using following parameters.

 
 
 
Parameter Description
 
Parameter
Value
Description
Name
LAN_Interface
Name to identify the Host.
Type
Route Interface
Select Interface Type – Route or Bridge
Zone
LAN
For Route interface type, select Zone type
Appliance-Interface Mapping
Appliance
Boston
New_Jersey
Select the appliance.
Host
PortA
PortA
Select the Interface which is to be mapped.

 
 
 
Click OK to save the interface.
 
Step 2: Configure L2TP Settings
 
Go to Policy Configuration à Appliance Group and select the Cyberoam Appliance Group. Once Group is selected, go to Policy ConfigurationàPolicyàVPNàL2TP à Configuration and check Enable L2TP. Configure L2TP VPN Settings according to parameters given below.
 
 
Parameter Description
 
 
Parameter
Value
Description
Enable L2TP
Enable
General Settings
Local IP Address
LAN_Interface (Dynamic Interface created in step 1)
Select the Local IP address on which connection is to be established.
Assign IP from
192.168.2.10 – 192.168.2.20
Client Information
Primary DNS Server
Other
4.2.2.2
Secondary DNS Server
Other
8.8.8.8
Select Secondary DNS Server from the list.  
Alternately, you can also specify DNS Server by choosing ‘Other’ from the list.

 

Click Apply. On clicking Apply, the Set Schedule Screen appears. Set the schedule at which the configuration is to be pushed to Managed Appliances and click OK to save the configuration.
 

Step 3: Configure L2TP Connection

Go to Policy Configuration à Policy à VPN à L2TP à Connection and click Add to add a new connection using parameters given below.

 
 
 
Parameter Description
 
Parameter
Value
Description
General Settings
L2TP_Connection
Policy
DefaultL2TP
Select policy to be used for connection
Action on VPN Restart
Respond Only
Authentication Details
Authentication Type
Preshared Key
Select the type of authentication used while establishing a connection.
Preshared Key
hr5xb84l6aa9r6
Specify the Preshared Key to be used during authentication
Local Network Details
Local WAN Port
WAN_Interfaces
(Dynamic Interface created in step 1)
Remote Network Details
Remote Host
*
Allow NAT Traversal
Enable
Remote LAN Network
Any

 


Click OK. On clicking OK, the Set Schedule Screen appears. Set the schedule at which the configuration is to be pushed to Managed Appliances and click OK to save the configuration.





                                                                                                                                                                                                Document Version: 1.0 – 27/04/2013
1.3.2. Establish IPSec Connection between HO and Multiple BO

Overview
 
CCC allows administrator to configure VPN connections between Head Office (HO) and multiple Branch Offices (BOs) in one shot by using Dynamic Objects. Dynamic Objects in CCC are used to map single objects in CCC to respective objects in multiple or all Managed Cyberoam Appliances. For example, One (1) Dynamic Host in CCC for a Mail Server can represent corresponding Mail Server hosts in multiple Managed Appliances, if mapped accordingly.

Scenario

Configure IPSec connection between HO and BOs in CCC and push it down to all BOs.

 
 
 

Configuration

You can configure an IPSec connection in CCC to push down to Managed Appliances by following the steps given below. Configuration is to be done from CCC Web Admin Console using Administrator profile.
 

Step 1: Create Dynamic Objects for BO LANs and BO WAN Interfaces

Dynamic Host for BO LANs

Go to Management Console à Appliance Management à Dynamic Objects à Host and click Add to add a Dynamic Host for BO LANs using following parameters.
 
 

 
 
Parameter Description
 
Parameter
Value
Description
Name
BO_LANs
Type
Network
Select the type of host.
Appliance-Host Mapping
Default
None
BO1
BO2
BO3
Host
BO1_LAN
BO2_LAN
BO3_LAN

 
 

Click OK to save the host.
 

Dynamic Interface for BO WAN Interfaces

Go to Management Console à Appliance Management à Dynamic Objects à Interface and click Add to add a Dynamic Interface using following parameters.
 
 

 
 
Parameter Description
 
Parameter
Value
Description
Name
BO_WAN_Interface
Name to identify the Host.
Type
Route Interface
Zone
WAN
Appliance-Interface Mapping
Appliance
BO1
BO2
BO3
Select the appliance.
Host
PortB
PortB
PortB

 
 

Click OK to save the interface.
 

Step 2: Configure IPSec Connection on HO Cyberoam

Go to Policy Configuration à Appliance Group and select the HO Cyberoam Appliance in which IPSec configuration is to be done. Once Appliance is selected, configure IPSec connection with BO according to the article How To - Establish Site-to-Site IPSec Connection using Preshared key.
 

Step 3: Configure IPSec Connection on all BO Cyberoam

Go to Policy Configuration à Appliance Group and select the BO Cyberoam Appliance Group. Once Group is selected, go to Policy ConfigurationàPolicyàVPNàIPSec and click Add to add a new IPSec connection using parameters given below.
 
 

 
 
Parameter Description
 
 
Parameter
Value
Description
General Settings
BO_to_HO
Connection Type
Site to Site
Select the type of connection
Policy
DefaultBranchOffice
Action on VPN Restart
Initiate
Select action when VPN services are restarted.
Authentication Details
Authentication Type
Preshared Key
Select the type of authentication used while establishing a connection.
Preshared Key
hr5xb84l6aa9r6
Specify the Preshared Key to be used during authentication
Local Network Details
Local WAN Port
BO_WAN_Interfaces
(Dynamic Interface created in step 1)
Local Subnet
BO_LANs
(Dynamic Host created in step 1)
Specify Local Subnet. Multiple Subnets can be added.
Remote Network Details
Remote VPN Server
*
Allow NAT Traversal
Disable
Remote Subnet
HO_LAN
Select IP addresses and netmask of remote network(s) with which connection is to be made.

 

Click OK to save configuration.

The above configuration establishes an IPSec connection between HO Cyberoam and all BO Cyberoam.
 





                                                                                                                                                                                          Document Version: 1.0 – 27/04/2013
1.3.3. Apply Anti Virus Policies on Managed Appliance from CCC

Overview
 
CCC allows you to push various policies, such as Anti Virus policies, to Managed Appliances. You can push these policies immediately or at a later date and time. This enables centralized management of the Managed Appliances.


Scenario
 
Create an Anti Virus policy wherein all SMTP, POP3 and IMAP mails are scanned and oversized SMTP mails are accepted. Push this policy to Managed Appliance Group ‘Sales’.
 

Configuration

You can create an Anti Virus policy and push it down to Managed Appliance(s) by following the steps below. All configurations are to be done from Web Admin Console using ‘Administrator’ profile.

Step 1: Configure Anti Virus Settings for Selected Managed Appliances

·         Go to Policy Configuration à Appliance Group to select the Managed Appliance/Appliance Group to which policy is to be pushed. Here we have selected all Managed Appliances.
 
 
 
 
·         Go to Policy Configuration à Policy à Anti Virus à Mail à Configuration to configure Anti Virus settings. Set parameters as given below.
 
 
Parameter
Value
Description
0
Specify maximum size (in KB) of the file to be scanned. Files exceeding this size received through SMTP will not be scanned. Specify 0 for default size restriction of 51200 KB i.e. files exceeding 51200 KB will not be scanned if 0 is configured.
Accept
0
Specify maximum size (in KB) of the file to be scanned. Files exceeding this size received through POP/IMAP will not be scanned and forwarded to the recipient without scanning. By default, Specify 0 for default size restriction of 10240 KB and files exceeding 10240 KB will not be scanned of 0 is configured.

 
 

Step 2: Create Firewall Rule to enable Anti Virus scanning

Go to Policy Configuration à Policy à Firewall à Rule à Rule and click Add to create a new Firewall Rule.
 
 
 
 
Enable Anti Virus Scanning for SMTP, POP3 and IMAP in the rule, as shown below.
 
 
 

Set Schedule
 
Set schedule at which the Rule is to be pushed to the desired appliance group with the following parameters.
 

Parameter Description
 
 
Parameter
Value
Description
Schedule
Immediate
Select the time when the Rule is pushed down to managed appliance group.
Override Configuration
Yes
Select ‘Yes’ if you want to override configuration of a Firewall Rule with the same name already present in the managed appliance, else select ‘No’.
Appliance
All Appliance
Select the managed appliance(s) in the group to which the Rule is pushed.

 
 
 
Click OK to create the Rule.
 
The above configuration enables Anti Virus scanning for emails in SMTP, POP3 and IMAP.




                                                                                                                                                                                 Document Version: 1.0 – 05/04/2013
1.3.4. CCC Registration and Subscription Guide

Overview
 
This document provides an overview of the Customer My Account (CMA) portal and how it can be used to:

Before you begin configuring and customizing features, register your CCC Appliance from the Customer My Account (CMA) portal, https://customer.cyberoam.com.

Many Cyberoam customer services, like firmware upgrades, technical support and other services available through Subscription modules, require product registration.

Note:

CCC Appliances are pre-subscribed with the 8 X 5 Support for one month. For continued support, you need to avail subscription of that module. Register your appliance if you want to avail 8 X 5 or 24 x 7 Support
 

Register Customer Account and Appliance

To avail subscriptions, you need to register your CCC Appliance. Following are details about how you can register:
 
-         Hardware Appliance
-         Virtual CCC Appliance

Registration of Hardware Appliance

Step 1: Browse to https://customer.cyberoam.com and click Register your Appliance.
 
 
 

Fill up the registration form and click
I Agree to register your appliance as well as for a customer account.
 
 
 
 
Note:
 
Supplier details are mandatory for each new appliance being registered.
 
 
 
 
This creates your customer account with the username as specified in Email ID and also registers your Appliance.

Step 2: Browse to http://<LAN IP address of CCC>

Go to Management Console à System Management à Maintenance à Licensing and click Synchronize. It fetches the licensing details from the registration server and shows the details on Web Admin console.
 
 
 
 
 

Registration of Virtual CCC Appliance 

You can register your Virtual CCC Appliance by following the steps below. 

Step 1: Browse to https://customer.cyberoam.com and click Register your Appliance
 
 
 

Fill up the registration form and click
I Agree to register your appliance as well as for a customer account.
 
 
 

On clicking I Agree you receive an email confirming your registration.

It takes a few minutes for the OVF file, corresponding to your registered key, to be generated. Once the file is generated, you receive a second email indicating that your file is ready to be downloaded from your customer account.
 
Step 2: Login to your Customer Account to download OVF
 
 
 

Under Model section, select the Platform where the virtual appliance is to be mounted and click Download.
 
 
 
 
On clicking Download, the Virtual CCC Download screen is displayed where you Select Virtualization Platform. Here, we have selected VMWare. Click Download to download the OVF file specific to the selected platform.
 
 
 
 
Once the file is downloaded, install it onto your hypervisor. For installation details, refer to the Virtual CCC Installation Guides.
 

Subscribe Module with License Keys
 
You can subscribe to any subscription-based modules by following the steps below. The appliance should already be registered to subscribe to any license.

Step 1
: Browse to https://customer.cyberoam.com and login with your credentials – Email id and password, provided at the time of registering customer account.
 
 
 
 
Step 2: Page displays the list of appliances registered. Click Subscribe to view the list of subscriptions available for the appliance.
 
 

Step 3: Click Subscribe to subscribe to any module.
 
 
 
 
Step 4: Enter the subscription key and Click Verify to verify the key.
 
 
 
 
Step 5: On clicking Verify the key you entered is verified and then, if the key is found valid, you can subscribe to the module. Click Subscribe to subscribe to the module.
 
 
 
 

Step 5: Browse to http://<LAN IP address of Cyberoam>

Go to System à Maintenance à Licensing and click Synchronize. It fetches the licensing details from the registration server and shows the details on Web Admin console.

 

Register Appliance with the existing Customer Account

Step 1: Browse to https://customer.cyberoam.com and login with the credentials – Email id and password, provided at the time of registering customer account.
 
 
 
 
Step 2: Page displays the list of appliances registered. Click Register Appliance to register additional appliance.
 
 
 

Fill in details of the additional appliance in the Register Appliance Form and click
Register.
 
 
 
 
 
 
 
 
 
 
                                                                       Document Version: 1.0 – 22/03/2013
 
 
 
1.3.5. Schedule a Task in CCC


Overview

CCC allows you to schedule the pushing of any configuration changes done on managed appliances. The changes can be pushed down either immediately or be scheduled for a later date and time.

Scenario

In this article, we have created a Firewall Rule in which Cyberoam drops all SMTP traffic from LAN to WAN. We then schedule the Rule to be pushed down to all Managed Appliances at the next day after creation.

Configuration

The configuration is to be done from the Web Admin Console using “Administrator” Profile.

Step 1: Create Firewall Rule for Selected Managed Appliances

·         Go to Policy Configuration à Appliance Group to select the Appliance or Appliance Group to which Rule is to be pushed. Here we have selected all Managed Appliances.
 
 
 
 
·         Go to Policy Configuration à Policy à Firewall à Rule à Rule and click Add to create a firewall rule using the given parameters.
 
  
 
Parameter Description
 
 

Parameter

Value

Description

Name

SMTP_Deny

Specify name to identify the Firewall Rule.

Zone

Source: LAN

Destination: WAN

Specify source and destination zone to which the rule applies.

Attach Identity

Disabled

Check to attach the user identity.

Network/Host

Source: Any

Destination: Any

Specify source and destination host or network address to which the rule applies.

Services

SMTP

Services represent types of Internet data transmitted via particular protocols or applications. Select service/service group to which the rule applies.

Schedule

All the time

Select schedule for the rule

Action

Drop

Select rule action  

Available Options:

-       Accept: Allow access
-       Drop: Silently discards
-       Reject: Denies access and ‘ICMP port unreachable’ message will be sent to the source
 
 

 
Click OK to create the Firewall Rule.
 

Step 2: Set Schedule for pushing Firewall Rule to Managed Appliances

On clicking OK, the Set Schedule screen appears which allows you to set the schedule when Firewall Rule is to be pushed down to Managed Appliances. Here, we have set schedule for the next day after creation of firewall rule.
 
 
 
 
Click OK to set appropriate schedule and create the Firewall Rule.

Step 3: Manage Scheduled Task from Scheduler Queue

All Scheduled Tasks in CCC are added to a Scheduler Queue. You can manage this Queue from Management Console à Appliance Management à Scheduled Task
à Scheduled Task.
 
The Scheduler Queue allows you to Delete or Reschedule the tasks in queue.
 
·         To delete a task, select the task(s) and click Delete.
 
 
 
 
·         To change the schedule of a task, select the task, click Reschedule and set the new schedule.
 
 
 
 
 
 
                                                                                                                                                                                Document Version: 1.0 – 09/03/2012
1.3.6. Change Default Ports to Access CCC

This article describes how the default ports through which CCC Web Admin Console is accessed can be customized. The default ports are port 80 for HTTP and port 443 for HTTPS.

Note:

Ports for SSH and Telnet access cannot be customized.


To customize the ports through which CCC Web Admin Console is accessed, follow the steps given below.
 
1.     Login to CCC using Administrator profile.
 
2.     Go to Management Console à CCC Management à System à Settings.
 
 
 
 
You can see the default ports configured as shown in the screen above. It is advised to take a backup of the CCC configuration before changing access ports. To know how to take backup of CCC configuration, refer to the article "Backup and Restore CCC Configuration" in the Related Articles section at the end of this article.
 
3.     Customize ports for HTTP, HTTPS or both. Here, we have set HTTP Port as 8080 and HTTPS Port as 4433.
 
 
 
 
Note:
 
Prefer using ports above 1024. Those below 1024 are often reserved by the operating system for internal use.
 
4.     Click Apply to customize the ports.
 
Connectivity to the Web Admin Console may be lost once the changes are applied. It can be accessed by browsing to http://<CCC IP address>:<HTTP port number> or https://<CCC IP address>:<HTTPS port number>. E.g., http://192.168.2.1:8080.     

                                                                                                                                                                                          Document Version: 1.0 – 31/01/2012
1.3.7. Push Firewall Rule to Cyberoam Appliance from CCC

Overview

This article describes how a Firewall Rule, created in CCC, can be pushed down to a group of managed Cyberoam Appliances.

Scenario

Create a Firewall Rule named “LANtoWANHTTPAllow” which allows all HTTP traffic from LAN to WAN. This rule is pushed down to a group of managed appliances.

Solution

All configurations are to be done from Web Admin Console using “Administrator” profile.

To create and push down a Firewall Rule, follow the steps given below.

Step 1: Create Firewall Rule

Add Rule

Go to Policy Configuration à Appliance Group and select the Appliance Group to which the Firewall rule is to be added. Once group is selected, go to Policy à Firewall à Rule and click “Add” to create a new Firewall Rule with the following parameters.
 
 
 
 
 
Parameter Description
 
 

Parameter

Value

Description

Name

LANtoWANHTTPAllow

Name to identify the Rule. Duplicate names are not allowed.

Zone

Source: LAN
Destination: WAN

Specify source and destination zone to which the rule applies.

Network/Host

Source: Any
Destination: Any

Specify source and destination host or network address to which the rule applies. 

You can also define a new IP host, MAC host, host group and virtual host directly from this page.

Service/Service group

HTTP

Select service/service group to which the rule applies.

Services represent types of Internet data transmitted via particular protocols or applications. You can also add a custom service or service group from this page itself.

Schedule

All the time

Select Schedule for the rule. You can also add a new schedule directly from this page.

Action

Accept

Select rule action

Apply NAT (Only if Action is ‘ACCEPT’)

MASQ

Select the NAT policy to be applied 

Note: 

This option is not available if Cyberoam is deployed as Bridge

 
 
 
 
Set Schedule

Set schedule at which the Rule is to be pushed to the desired appliance group with the following parameters.

Parameter Description


Parameter

Value

Description

Schedule

Immediate

Select the time when the Rule is pushed down to managed appliance group.

Override Configuration

Yes

Select ‘Yes’ if you want to override configuration of a Firewall Rule with the same name already present in the managed appliance, else select ‘No’.

Appliance

All Appliance

Select the managed appliance(s) in the group to which the Rule is pushed.

 
 
 
 
 
Click OK to create the Rule.
 
 
 
 

Step 2: Check Event Viewer Log

The event of creation of the Rule can be checked in CCC Event Viewer by going to Management Console à CCC Event Viewer. It displays whether the rule is created and applied to the managed appliance.
 
 
 
                                                                                                                                                                                   Document Version: 1.0 – 30/01/2012
 
1.3.8. Push Web Filter Policy to Cyberoam Appliance from CCC

Overview

This article describes how a Web Filter Policy, created in CCC, can be pushed down to a group of managed Cyberoam Appliances.

Scenario

Create a Web Filter Policy named “Block_Gaming_Sites” which blocks access to gaming websites. This policy is pushed down to a group of managed appliances.

Solution

All configurations are to be done from Web Admin Console using “Administrator” profile.

To create and push down a Web Filter Policy, follow the steps given below.

Step 1: Create Web Filter Policy

Add Policy

Go to Policy Configuration à Appliance Group and select the Appliance Group to which the Web Filter policy is to be added. Once group is selected, go to Policy à Web Filter à Policy and click “Add” to create a new Web Filter Policy with the following parameters.
 
 
 
 
Note:
 
Appliance comes with the following predefined policies:
 
-       Allow All
-       Deny All
-       CIPA

Parameter Description
 
 

Parameter

Value

Description

Name

Block_Gaming_Sites

Name to identify the Policy. Duplicate names are not allowed.

Template

Allow All

Select a template based on which the policy is to be made.

Available Options:

-       Allow All

-       Deny All

-       CIPA

Enable Reporting

Enabled (Default)

Enables generation of Internet Usage reports for all users. Disable it if you do not want the reports generated for all users.

Download File Size Restriction

0 (No Restriction)

Specify maximum allowed file download size. User will not be allowed to download file greater than the configured size.

 
 
 
 
Set Schedule

Set schedule at which the policy is to be pushed to the desired appliance group with the following parameters.

Parameter Description
 
 

Parameter

Value

Description

Schedule

Immediate

Select the time when the policy is pushed down to managed appliance group.

Override Configuration

Yes

Select ‘Yes’ if you want to override configuration of a web filter policy with the same name already present in the managed appliance, else select ‘No’.

Appliance

All Appliance

Select the managed appliance(s) in the group to which the policy is pushed.

 
 
 
 
Click OK to create the policy.
 
 
 
 
 

Step 2: Add Web Filter Policy Rules

Rules are added to Web Filter Policy to define what web traffic is blocked or allowed through that policy.

Add Rule

Select the Web Filter Policy to which rule is to be added. In our case, select Block_Gaming_Sites. Click Add to add a rule with following parameters.
 
 
 
 

Parameter Description
 
 

Parameter

Value

Description

Category Type

Web Category

Select Category Type for which the rule is to be added.

Category

Games

Select Category for which the rule is to be added. Multiple categories can also be selected. You can also search the category name from the search text box provided.

HTTP Action

HTTPS Action

HTTP Action: Deny

HTTPS Action: Deny

Specify action Allow OR Deny for HTTP and HTTPS traffic.

Schedule

All the time

Select the Schedule for categories selected.

 
 
 
 
Click OK to create the Rule. The Set Schedule screen appears again where you can schedule the time when rule is applied to the managed appliances. 


Step 3: Check Event Viewer Log

The event of creation of the Policy can be checked in CCC Event Viewer by going to Management Console
à CCC Event Viewer. It displays whether the policy is created and applied to the managed appliance.
 
 
 
 
                                                                                                                                                                                Document Version: 1.0 – 28/01/2012
1.3.9. Upgrade Firmware of CCC

This article describes the method of upgrading CCC to the latest firmware. Upgrading of CCC is done in two steps:
 

Download the Latest Firmware 

Go to http://download.cyberoam.com/ccc to download the latest firmware onto your local system.
 
 
 
 
Upload the Firmware on CCC
 
To upload the firmware onto CCC, follow the steps given below.
 
1.     Log in to CCC using Administrator profile.
 
2.     Go to Management Console à CCC Management à Maintenance à Firmware.
 
 
 
 
3.     Click  to upload the latest firmware that you have downloaded.
 
 
 
 
4.   Click Upload & Boot. The following warning message appears. Click OK.
 
 
 
 
      CCC will boot with the uploaded firmware.

                                                                                                                                          Document Version: 1.0 – 17/01/2012
1.3.10. Upgrade Firmware of Managed Appliance from CCC

CCC allows the administrator to upgrade firmware of one or more managed appliances from CCC itself rather than upgrading each appliance manually.
CCC downloads copies of firmware images from the Upgrade server, and stores and applies those firmware images to managed Cyberoam appliances.

This article describes how you can upgrade the firmware of a managed appliance from CCC. In this article, as an example, we have considered a managed Cyberoam Appliance CR 25wi named “Cyberoam” with current firmware version 10.01.0 build 739 which will be upgraded to firmware version 10.01.1 build 023 from CCC.

To upgrade firmware of managed appliance from CCC, follow the steps given below.
 
1.     Login to CCC using Administrator Profile.
 
2.     Go to Management Console à Appliance Management à Firmware.
 
 
 
 
3.     Click “Check for Latest Firmware”. Click OK in the warning message that appears. CCC fetches all Latest Firmware information and displays it as shown
     below.
 
 
 
 
4.     Click “Download” against the appliance(s) that need to be upgraded to download the corresponding firmware image(s).
 
 
 
 
     The status field reflects the In Progress status of the download. Once the firmware is downloaded, you are given the option to apply the firmware as shown below.
 
 
 
 
5.     Click Apply to apply the downloaded firmware. The Select Appliances screen appears where you can select the appliances to which the firmware is to be
     applied. Here, we have selected “Cyberoam”.
 
 
 
 
 
 
    Click OK to apply the downloaded firmware to the managed appliance.
 
The event of download of latest firmware and upgrade of managed appliance can be checked in CCC Event Viewer by going to Management Console à CCC Event Viewer.
 
 
 
                                                                                    
                                                                                                                                                                         Document Version – 1.0 – 29/12/2011
1.3.11. Push Application Filter Policy to Cyberoam Appliance from CCC

This article describes how an Application Filter Policy created in CCC can be pushed down to a managed Cyberoam Appliance.

Prerequisite:

There should be synchronized connectivity between Cyberoam Appliance and CCC.

In this article, as an example, we have created an Application Filter Policy named “Block_Facebook_Chat” in which we have blocked chat and video chat in Facebook. This policy is pushed down to the managed appliance called “Cyberoam”.

To create and push down an Application Filter Policy, follow the steps given below.
 
1.     Logon to CCC with Administrator Profile.
 
2.     Go to Policy Configuration à Policy à Application Filter à Policy.
 
 
 
 
3.     Click Add to create a policy. Set parameter values according to the table given below.
 
 
Parameter

Value

Name

Block_Facebook_Chat

Name to identify the Policy. Duplicate names are not allowed.

Description

Specify Policy Description. Add rule after policy is created successfully.

Template

Allow All

Select the template for the policy.

Available options:

·         Allow All
 
·         Deny All
Table 1
 
 
 
 
4.     Set the schedule at which the policy is to be pushed to the desired appliance in the Set Schedule screen. Set parameter values according 
       to the table given below.
 
 
Parameter

Value

Schedule

Selected Immediate 

Select the time at which the policy is to be pushed down to managed appliance

Available options:

·         Immediate
·         At the scheduled time. Specify the date and time.

Override Configuration

Selected Yes 

Select ‘Yes’ if you want to override configuration of an application filter policy with the same name already present in the managed appliance, else select ‘No’.

Appliance

Select All 

Select the managed appliance to which the policy is to be pushed.

Appliance Filter:

Model: CR 25wi

Firmware: All Firmware

You can use the “Appliance Filter” to search through specific appliance(s) based on certain criteria like:

·         Model
·         Firmware
·         AntiVirus
·         IPS
·         Web Category
·         Company
·         Country
·         State
·         City
·         Appliance Name
Table 2
 
 
 
 
5.     Click OK to create the policy.
 
 
 
 
6.     Select the policy to add rules. The following screen appears in which click Add to add a rule.
 
 
 
 
7.     Create Rule according to parameter values given in the table below.
 
 

Parameter

Value

Select Categories

All Categories

Select Application Category from the list of available categories.

Select Application

Facebook Chat

Facebook Video Chat

Select the Applications under the Category selected. You can also select more than one application using the checkbox.  

You can search for the application using the Search textbox.

Action

Selected Deny

Select the Action: Allow OR Deny

Schedule

Work Hours ( 5 day Week)

Select the Schedule from the list of schedules available.

Table 3
 
 
 
 
8.     Click OK to create the Rule. The Set Schedule screen appears again where you can schedule the time when you want to apply the rule in the
     managed appliance. Here, set the same parameter values as given in Table 2 given above.
 
 
 
 
9.     Click OK to add the rule to the policy.
 
 
 
 
The event of creation of the Policy can be checked in CCC Event Viewer by going to Management Console à CCC Event Viewer. It displays whether the policy is created and applied to the managed appliance.
 
 
 
 
                                                                                                                                                 Document Version – 1.0 – 01/12/2011
1.3.12. Create Alert Profiles in CCC

To create Alert Profile, follow the steps given below.
 
1.     Login to CCC using Administrator Profile.
 
2.     Go to Management Console à Appliance Monitoring à Alerts à Profile.
 
 
 
 
3.     Click Add to add a new Alert Profile. Set parameter values according to the table given below. Here, we have taken an example of an alert profile named
     “IPSandWebVirusAlert” which sends alerts to administrator in case IPS and Web Virus threat counts exceed set limits in all appliances associated with CCC.
 
 

Parameter

Value

Profile Name

IPSandWebVirusAlert

Name to identify the Profile

Send Email alert to

administrator@elitecore.com

Specify recipient email address(s), separated by commas, to send alert notification through email.

You need to configure email server from Management Consoleà CCC Management à System à Notification to send email alerts on specified email address(s). If any mail server is not configured, then the created alert will be displayed under Alerts tab.

Appliance

All Appliance

Select the appliance

Alert Criteria

Checked IPS Threats count exceeds

Checked Web virus count exceeds

Configure alert criteria. Select checkbox against criterion to be configured and specify value for the criterion. 

Available criteria:

·         Any subscription module expires

·         CPU usage exceeds

·         Memory usage exceeds

·         Disk usage exceeds

·         IPS Threats count exceeds

·         Web virus count exceeds

·         Mail Virus count exceeds

·         Total virus count exceeds

·         Spam Mail count exceeds

·         Unhealthy Surfing hits

·         Appliance Connection Status

·         Gateway status change

·         VPN connection status change

Description

Description of the alert profile.

Only one Profile can be associated with a single appliance.

 
 
 
 
4.     Click OK to create the alert profile.
 
 
 
 
     To modify any settings in the profile, click  against the required alert profile.
 
The event of creation of the Alert Profile can be checked in CCC Event Viewer by going to Management Console à CCC Event Viewer.
 
 
 
 
                                                                                                                                                                       Document Version - 1.0 - 30/11/2011
1.3.13. Backup and Restore CCC Configuration

Backups play an essential role in Data Protection. They enable us to recover critical data in the event of disk failures, accidental deletion or corruption of files, or system crashes.
 

This article describes how to take backup and restore configuration of CCC. It is advisable to take backup of CCC configuration on a regular basis to ensure that, should the system fail, you can quickly get the system back to its original state with minimal effect to the network. Also, taking backup before making any changes to the configuration of CCC or settings that affect managed appliances, is a good practice.

This article is divided into 2 sections:

·         Backup
·        
Restore
Backup
Backup of CCC Configuration can be taken in two ways:
 
·         Manual Backup – taken manually when required
 
·         Scheduled Backup – taken automatically after regular intervals of time
Manual Backup
To take backup manually, follow the steps given below.
 
1.     Logon to the CCC whose backup is to be taken using “Administrator” profile.
 
2.     Go to Management Console à CCC Management à Maintenance à Backup & Restore.
 
3.     Click Backup Now in the Backup Restore section.
 
 
 
 
 
Scheduled Backup
To configure scheduled backup, follow the steps given below.
 
1.     Logon to the CCC whose backup is to be taken using “Administrator” profile.
 
2.     Go to Management Console à CCC Management à Maintenance à Backup & Restore.
 
3.     Configure backup from the “Schedule Backup” section. Here, we will schedule a weekly backup which will be taken every Monday 
     at 11 a.m.
 
 
 
Parameter
Value
 
Available options:
Daily – Configure time at which the backup should be taken.
Weekly – Configure day and time of week at which the backup should be taken.
Monthly – Configure day and time of month at which the backup should be taken.
 
 
Select how and to whom backup files should be sent.
 
FTP – If backup is to be stored on FTP server, configure FTP server IP address, username and password to be used.
 
Mail– If back up is to be mailed, configure email address on which backup is to be mailed.
 
 

 
 

Backup files contain information about 
 
-       CCC configuration
 
-       Connectivity with Cyberoam Appliances, i.e., their IPs, Keys, Username/Password, etc.
 
All backup files stored in the appliance can be seen in the Manage Backup section.They can be downloaded to the local system at any time by clicking the corresponding Download Button.
 
 
 
 
A maximum of 5 backups can be stored. As new backups are taken, older backup files are automatically purged from the table.

Restore

Configuration data in any backup file can be restored in the CCC Appliance. Restoring data older than the current data will lead to the loss of current data.

Restoration can be done from backup files that are stored
 
·         On Appliance

·        
In Local System
 
Backup Stored On Appliance
If you want to restore a backup file stored in the appliance, follow the steps given below.
 
1.     Logon to the CCC where backup is to be restored using “Administrator” profile.
 
2.     Go to Management Console à CCC Management à Maintenance à Backup & Restore.
 
3.     A list of the last 5 backups can be seen in the Manage Backup section. Click Restore against the backup file that needs to be
     restored.
 
 
 
 

Backup Stored in Local System

If the backup file is stored in any local system, follow the steps given below.
 
1.     Logon to the CCC where backup is to be restored using “Administrator” profile.
 
2.     Go to Management Console à CCC Management à Maintenance à Backup & Restore.
 
3.     Upload the backup file to be restored in the Restore Configuration field and click Upload and Restore.
 
 
 

The restoration process reboots the appliance during which access to CCC GUI and connectivity with Managed Cyberoam Appliances is suspended. After reboot, CCC initiates a re-synchronization with the Cyberoam Appliances restoring connectivity.

                                                                                                                         Document Version – 1.0 – 21/10/2011
1.3.14. Take Backup of Managed Appliance

This article describes how to take backup of a managed Cyberoam appliance and store it on CCC. CCC acts as a Backup Repository
for the managed Cyberoam appliances.
 
Backups can be taken in two ways:
 
·         Automated or Scheduled Backup – taken automatically after regular intervals of time.

·         
Manual Backup – taken manually.
Automated or Scheduled Backup
To configure scheduled backup of a managed appliance, follow the steps given below.
 
1.     Logon to CCC with “Administrator” profile.
 
2.     Go to Management Console à Appliance Management à Maintenance à Backup & Restore.
 
3.     Configure backup from the “Schedule Backup” section. In this article, we will schedule a weekly backup of the appliance named 
     “Cyberoam” which will be taken every Monday at 11 a.m.
 
 

Parameter

Value

Backup Frequency

Selected Weekly

Available options:

Daily – Configure time at which the backup should be taken.

Weekly – Configure day and time of week at which the backup should be taken. 

Monthly – Configure day and time of month at which the backup should be taken.

Select Appliances

Cyberoam

Select the appliances whose backup is to be taken at the configured schedule.

 
 


4.     Click Apply. The following Warning Message appears.
 
 
 
 
5.     Click OK to configure scheduled backup.
 
Manual Backup
To take backup manually, follow the steps given below.
1.     Logon to CCC with “Administrator” profile.
 
2.     Go to Management Console à Appliance Management à Maintenance à Backup & Restore.
 
3.     Configure backup from the “Manage Backup” section. In this article, we will take manual backup of the appliance named
     “Cyberoam”.
 
     Select “Cyberoam” in the Select Appliance field and click “Take Backup”.
 
 
 
 
The table displays list of backups of the selected Appliance. The parameters of the table and their descriptions are given below.
 
 
 
You can take maximum five backups including ‘Last Good Backup’. Older backup files are automatically purged from the table.
The Last Good Backup is preserved all the time.
 
                                                                                                                                    Document Version – 1.0 – 14/09/2011
 
 
1.3.15. Create Role-based Administrator Profile

This feature is very useful when you have special-purpose administrators like VPN Administrator, Security Administrator, Audit Administrator, etc. and each needs to be assigned permissions according to his role in the organization.
 
This article describes how to create a role-based administrator profile. Here, we will create the Profile of a VPN Administrator as an example.

To create an Administrator Profile, follow the steps given below.
 
1.     Logon to CCC using “Administrator” profile.
 
2.     Go to Management Console à CCC Management à Administration à Profile.
 
 

3.     Click Add and set the parameters in “Add Profile” screen according to requirement. In this example, a profile VPN Administrator has 
     been created that has Read-Write Access to VPN Configuration only and No Access to Console access from GUI. For all the rest, 
     there is Read-Only Access.
 
 
 

 

Parameter

 

 

Value

 

Profile Name

VPN Administrator 

Name to identify the profile 

Configuration

VPN à Read-Write  

Console access from GUI à None 

All the rest à Read-Only  

Select the access level for each Configuration.

Available Options are:

  • None – No access to any page
  • Read-Only – View the pages
  • Read-Write – Add or Modify the details

Access levels can be set for individual menus as well. You can either set a common access level for all the menus or individually access level for each of the menu.

Click on  icon against a menu to view the items under that menu.

 
 
 
 
 
4.     Click OK to create Administrator Profile.
 
Once an Administrator Profile is created, it needs to be assigned to an Administrative User. Here, we will assign VPN Administrator Profile to user John Smith.
 
To assign an administrator profile to a user, follow the steps given below.

1.    
Go to Management Console à CCC Management à Administration à User.
 
 
 
 
2.     Click on the required user, i.e., john.smith.
 
 
 
 
3.     Change the “Access Profile” to VPN Administrator and Click OK to assign the Profile to john.smith.

                                                                                                                                               Document Version – 1.0 – 12/09/2011
 
1.3.16. Add Cyberoam Appliance to CCC Appliance

Cyberoam Appliance can be monitored and managed with the help of Cyberoam Central Console (CCC). Integration of a Cyberoam Appliance with CCC is done in two phases.
 
1.     Configuration in Cyberoam: Configure CCC Appliance in Cyberoam.

2.     Configuration in CCC: Integrate Cyberoam Appliance with CCC. 

In this article, we have used an example to explain the procedure.

Note:

The firmware version of Cyberoam Appliance should be compatible with the CCC Appliance to which it is being added. You can check the “Compatible Cyberoam Version” in System Information section on CCC Dashboard.
 
Cyberoam Configuration
 
To manage Cyberoam from CCC, the CCC Appliance has to be configured in Cyberoam. This can be done from Web Admin Console using “Administrator” profile.
 
To configure CCC in Cyberoam, follow the steps given below.
 
1.     Go to System à Administration à Central Console.
 
2.     Click “Manage this appliance using CCC” to activate the rest of the controls and specify CCC settings.
 
 

Parameters

Values

Manage this appliance using CCC

Enabled 

Enable if you want to manage appliance through Central Console. 

CCC IP Address

203.88.135.194

Specify CCC IP address

Heartbeat Protocol

HTTP

Specify Heartbeat protocol. Heartbeat protocol specifies how information will be provided to CCC i.e. by HTTP request or syslog.
 
Appliance will send information at specific interval to CCC. CCC will analyze the information received from the appliance periodically and send alerts if configured in CCC. Refer to CCC Guide for details on alerts. 

Heartbeat Port

80
 
Specify the port on which CCC can receive heartbeat information.
 
Make sure, CCC can receive heartbeat information on Port 514 for Syslog and Port 80 for HTTP.

AV, IPS & Web Category Signature Updates

From Update Server

Specify whether AV, IPS and Web category update are to be taken from online Update Server or CCC.
Table 1 - Cyberoam CCC Settings Parameters
 
 
 
 
3.     Click “Apply” to enable appliance management through CCC.

Note
:
 
Make sure that the CCC Appliance to which Cyberoam is added is listening on the same heartbeat port number as configured in Cyberoam.
 
CCC Configuration
 
After CCC is configured in Cyberoam, the Cyberoam Appliance has to be added to CCC. There are 2 ways to add a Cyberoam Appliance to CCC.
 
·     Through Auto Discovery

·     
Manually 
 
The entire configuration is to be done from Web Admin Console.
 
Addition of Cyberoam Appliance through Auto Discovery
 
To add Cyberoam through Auto Discovery, follow the steps given below.
 
1.     Logon to CCC using “Administrator” profile.

2.    Click on Appliance Discovery icon    . This icon on the upper right corner of the Dashboard indicates the addition of a Cyberoam Appliance
     (as shown in the image below) if it has already been configured to listen to the CCC Appliance.
 
 
 
     
On clicking the icon, the list of all Cyberoam Appliances waiting to be added appears.
 
 
 
 
3.     Click on Add Appliance icon  corresponding to the Cyberoam that you want to add. The “Add Appliance” screen appears. Specify the
     details of the Cyberoam to be added.
 
 
 
 
 
4.     Click “Test Connection”to check if the connection between CCC and Cyberoam is made.
 
     If connection is successful, a message acknowledging the same appears. Otherwise an error message is displayed.
 
5.    After successful connection, click “OK” to add Cyberoam Appliance to the CCC Appliance.
 
Addition of Cyberoam Manually
 
To add Cyberoam manually, follow the steps given below.
 
1.     Logon to CCC using “Administrator” profile.

2.    Go to Management Console à Appliance Management à Appliance(s)
 
 

 
3.     Click “Add” to add Cyberoam. The “Add Appliance” Screen appears. Specify the details of the Cyberoam to be added. Refer to Table 2 
     given above for details of parameters.
 
 
 
4.     Click “Test Connection”to check if the connection between CCC and Cyberoam is made.
 
      If connection is successful, a message acknowledging the same appears. Otherwise an error message is displayed.
 
5.     After successful connection, click “OK” to add Cyberoam Appliance to the CCC Appliance.

                                                                                                                                             Document Version – 1.0 – 08/09/2011
 
 
 
1.4. FAQ
1.4.1. In what ways does CCC communicate with its Managed Cyberoam Appliances?

Applicable Version: 02.01.4 Build 057 onwards
 
There are Two (2) Communication Modes available between CCC and its Managed Appliances:
 
-       CCC pushes updates to Managed Appliance
-       Managed Appliance fetches updates from CCC

The following diagram explains the modes mentioned above.
 
 
 
Appliance A is configured with CCC pushes updates to Managed Appliance. Hence, whatever updates are done in CCC are pushed down to the Managed Appliance immediately, or as scheduled.

Since Appliance B is placed behind a Router (or any NATting device), it is configured with Managed Appliance fetches updates from CCC. Since the Managed Appliance is not directly visible to CCC, because of the presence of the NATting device, CCC cannot push down updates to the Appliance directly.

When Managed Appliance fetches updates from CCC is configured, the Managed Appliance sends a polling request to CCC every One (1) minute requesting information about updates, if any. If there are updates available, Appliance itself fetches them from CCC.



                                                                                                                                                                  Document Version: 1.0 – 04/01/2012
1.4.2. How can I view logs of a particular Managed Appliance from CCC?

You can view logs of a Managed appliance in CCC by following the steps below.

1.     Logon to Web Admin Console using Administrator profile.

2.     Go to Management Console à Appliance Monitoring à Event Viewer à Event Viewer.

3.     Specify the log date and time, appliance and log type and click Go to display the archived files containing logs of selected appliance. Here,
as an example, we have shown Audit Logs of the appliance Cyberoam on 5th July, 2012.
 
 
 
 
4.     Under Action column, click View Data to view the required logs. The logs are available in Formatted as well as Raw form as shown below.
 
 
 
 
 
 
 

                                                                                 Document Version: 1.0 – 28/07/2012
1.4.3. Is it possible to use the Configuration of one CCC appliance on another CCC appliance?
 
Yes, it is possible to use the CCC Configuration among appliances, irrespective of their Model. For example, the configuration of CCC 50 can be used in CCC 100.
 
 
                                                                                                   



                                                                                                                                                                                  Document Version - 1.0 - 08/06/2012
1.4.4. How do I assign IP Address to a CCC Interface?

You can assign IP address to a CCC Interface by following the steps below.
 
1.     Logon to CCC Web Admin Console using Administrator profile.
 
2.     Go to Management Console à CCC Management à Network à Interface.
 
3.     Select the required Interface and set the desired IP address and Netmask.

                                                                                                                                                                                    Document Version: 1.0 – 30/01/2012

1.4.5. How do I find which Cyberoam firmware is supported by CCC?
 
Every CCC firmware can support specific Cyberoam versions. You can find out which Cyberoam versions are supported by CCC by checking the Compatible Cyberoam Version(s) in the System Information section on CCC Dashboard.
 
 
 
 
CCC cannot manage any other version of Cyberoam apart from those mentioned in its Compatible Cyberoam Versions list.
 
                                                                                                                                                                                       Document Version: 1.0 – 28/01/2012
1.4.6. How to check if CCC is able to reach to a specific CR?
 
To check connectivity between CCC and a specific Cyberoam Appliance, go to Management Console àCCC Managementà Diagnostics à Tools and use any of the following tools. 
1.4.7. Would changes be reflected in CCC if I make changes in an associated Cyberoam Appliance?

Yes, changes made to a Cyberoam Appliance are reflected in the CCC to which it is associated after synchronization.

                                                                                                                             Document Version – 1.0 – 08/09/2011