Title
Create new category
Edit page index title
Edit category
Edit link
Microsoft Hyper-V Startup Guide
Includes Installation Instructions for loading MetaAccess NAC into your Hyper-V Gen2 environment from an VHDX file.
Overview
This document is intended to be used as a guide to install a Virtual Machine (VM) version of the MetaAccess NAC Policy Enforcer appliance within a Hyper-V virtual environment. You should be familiar with the Hyper-V Manager Console prior to attempting this task. If technical support is required during the installation, please use the contact information below for assistance.
Installation
To add the new machine to your inventory, launch your Hyper-V Manager Console. The image uses Hyper-V Generation 2.
Click New > Virtual Machine
Specify Name and Location:
Enter a name for your MetaAccess NAC virtual machine and a storage location, if applicable.
Specify Generation:
Select Generation 2 as the version
Assign Memory:
Assign Memory to 16000 MB
Configure Network:
Select the Connection type from the Connection drop down
Connect Virtual Hard Disk:
Select Use an existing virtual hard disk and browse to your MetaAccess NAC vhdx.
Click Next
When finished you may then click: “ Finish ” to close the dialogue window.
Once VM is created you will need to verify 2 virtual processors are assigned to the VM. You can do this by right clicking on the virtual machine and selecting Processor. Under ‘Number of virtual processors’ ensure there are 2.
Once complete click OK and start the MetaAccess NAC virtual machine.
The Impulse Policy Enforcer Hyper-V Template is now successfully deployed within your virtual environment.
IP Reconfiguration
Once the virtual appliance is powered on, connect to the console and login with the username “admin” and the password “admin”. After logging in, the consoled configuration utility will be launched. The resulting pages will prompt the user to update the admin password, configure the IP address settings, and enter a MetaAccess license key. An OPSWAT representative will need enable the NAC feature for the associated MetaAccess account prior to the activation step. If you are not sure your account has this feature enabled, please contact opswat-support@opswat.com .
Reset Admin Password
Configure Appliance Network Settings
Enter License Key
Write down the Web Login URL. The console utility displays formats for the default hostname and the IP address of the appliance. If this is a brand new installation, the IP address format will likely need to be used as DNS may not yet be configured.
Exit Appliance Basic System Configuration. Further configuration can be completed by opening https://portal.myweblogon.com:8443/manage (alternatively https://<appliance_IP>:8443/manage) in your web browser.
Remote Access Requirements
The Access Requirements below are used to facilitate installation, testing, training, support, monitoring, backups and upgrades of your MetaAccess NAC Appliance(s) which is included as part of your Managed Service.
Allow outbound ssh (port 22) to below resources from host x.x.x.x (MetaAccess NAC Appliance Private IP):
FQDN: nac-ca1.opswat.com
- IP Address: 52.1.227.222/32
FQDN: nac-ca2.opswat.com
- IP Address: 52.4.162.8/32
FQDN: nac-downloads.opswat.com
- IP Address: 34.192.23.191/32
Allow outbound https (port 443) to below resources from host x.x.x.x (MetaAccess NAC Appliance Private IP):
- FQDN: gears.opswat.com
- IP/FQDN Address: For a full list of FQDN/IPs see: https://help.salesforce.com/articleView?id=000003652&type=1
Allow outbound HTTP (port 80) to below resources from host x.x.x.x (MetaAccess NAC Appliance Private IP):
- Service Name: Squid (Used for proxying remediation resources)
- Service: HTTP
Allow outbound HTTP/HTTPS (port 80 and 443) to below resources from host x.x.x.x (MetaAccess NAC Appliance Private IP):
- Service Name: Amazon Web Services (Appliance Configuration Backups)
- Resources:
- 52.92.16.0/20
- 52.216.0.0/15
- 54.231.0.0/17
Allow outbound for following services from host x.x.x.x (MetaAccess NAC Appliance Private IP):
- Services: HTTPS, DNS, NTP
If any questions arise please contact your OPSWAT Deployment Engineer or OPSWAT Support.