Page tree

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 7 Next »

This topic only applies to Armor Complete - Secure Hosting account administrators who have been notified by Armor that their account has been fully upgraded to Generation 4.

Before you begin, to better understand the upgrade process, Armor recommends that you review the Frequently Asked Questions for Generation 4 documentation.

Overview

After the upgrade process is complete, you will receive a notification from Armor.

Use this document to complete the post-upgrade tasks and to confirm a successful upgrade. 


Step 1: Review your virtual machines

To ensure a successful upgrade, Armor recommends that you review your virtual machines. 
  1. In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure
  2. Click Virtual Machines
  3. Review the listed virtual machines. 
    • If you have any questions, contact Armor Support. For more information, see Support Tickets
    • To learn how to create a virtual machine, see Virtual Machines

      If you add or update a virtual machine in Generation 4, those changes will be priced according to the updated pricing structure for Generation 4.


Step 2: Enable SSL/VPN access for your users

If you run Ubuntu 16.x, see Install SSL / VPN Client for Ubuntu 16.x

Before an invited user can download and install their SSL VPN, the account administrator must add the following permissions to their account: 

  • Write SSL VPN Devices and Users 
  • Read SSL VPN Devices and Users
  • Read Virtual Data Centers 

Additionally, the account administrator must enable the account to access the SSL VPN client:

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure
  2. Click SSL VPN
  3. Click Members.
  4. In the top bar, select the data center that corresponds to your virtual machine. 
    • If you have virtual machines in multiple data centers, then you must configure the user for each data center. (Also, you must download the client for every data center you use.)
  5. Under Active Members, type and select the desired username.
    • The user can now access to AMP to download their SSL VPN client. 


Step 3: Enable and install your SSL/VPN access 

If you have accounts in multiple virtual data centers, you must install the SSL/VPN client for each data center. 

If you have accounts in multiple virtual data centers, then you must install SSL/VPN for each data center. 
  1. (For Account Administrators only) In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure
  2. (For Account Administrators only) Click SSL VPN
  3. (For Account Administrators only) Click Members.
  4. (For Account Administrators only) In the top bar, select the data center that corresponds to your virtual machine. 
  5. (For Account Administrators only) Under Active Members, type and select your username or the username of your user.
  6. Click Client.
  7. In the top bar, select the data center that corresponds to your virtual machine. 
  8. Click Download SSL VPN client
    • AMP will automatically detect your operating system; however, you can click Download for another platform to view other operating system options.
    • When you open the client, follow the on-screen installation instructions. 
    • For Windows users, the client will download as a .zip file.

      • Extract the installation files to your local hard drive.
      • Launch the installer.exe file to begin the installation. 

      For Mac OS users, the client will download as a .tgz file.

      • Extract the installation files to your local hard drive.
      • Access the mac_phat_client folder, and then run the naclient.pkg installer.
      • When you run the installer, you will see an error regarding the certificate. Click Continue. (In a future release, Armor will resolve the issue.)
      • To launch the SSL VPN client, in your Applications folder, search for naclient.
      • If you run Mac OS 10.11 or higher, then please review Install SSL VPN Client for Mac OS, version 10.11 and higher.
  9. After installation, open the client.
    • In the drop-down menu, default will be listed.
  10. Click Settings.
    • To add a new connection, you must enter a Connection Alias, Hostname/IP Address, and Port, which you can find in AMP.
  11. Return to AMP, specifically to the Client section of the SSL VPN screen.
  12. Use the Client Configuration table to locate the data center and corresponding information to add to the client.


    If you see two entries for the same data center, then you must verify that you are using the non-recovery data center. To determine the correct data center: 1. In the left-side navigation, click IP Addresses. 2. In the top, drop-down menu, select the data center that does not contain the Recovery tag. 3. Take note of the displayed public IP address. 4. In the left-side navigation, click SSL VPN. 5. Under HOST/FQDN, verify the data center that contains the matching public IP address.
  13. Under Client Configuration, copy the Location information, and then paste that information into Connection Alias.
  14. Under Client Configuration, copy the HOST/FQDN information, and then paste that information into Hostname/IP Address.
    • Remove .vpc.armor.com.
    • Replace dashes / hyphens ( - ) with periods ( . ).
    • Remove any zero ( 0 ) that begins a section, such as 085 or 067.
    • For example, if you see in AMP 122-087-074-072, then in the client, you should enter 122.87.74.72.
    • In another example, if you see in AMP 122-087-074-702, then in the client, you should enter 122.87.74.702.
    • OriginalCorrectIncorrect
      122-087-074-072.vpc.armor.com122.87.74.72

      122-087-074-072

      122-87-74-72

      122-087-074-702.vpc.armor.com122.87.74.702

      122-087-074-702

      122-87-74-72

  15. Under Client Configuration, copy the Port information, and then paste that information into Port.
  16. Click Add.
  17. Click OK.
  18. In the drop-down menu, select the newly created connection.
  19. Log into the client.
    • Your SSL VPN login credentials are the same credentials you use to access the Armor Management Portal (AMP). 
  20. If you have virtual machines in other data centers, then you must download the client for every data center you use. Repeat these steps for additional data centers.


Step 4: Review your firewall rules

To ensure a successful upgrade, Armor recommends that you review your firewall rules.
  1. In the Armor Management Portal (AMP), in the left-side navigation, click Security
  2. Click Firewall
  3. Review the listed firewall rules. 
    • If you have any questions, contact Armor Support. For more information, see Support Tickets
    • To learn how to create a firewall rule, see Firewall Rules

(Optional) Step 5: Create additional roles 

Before the upgrade process began, you had assigned roles and permissions to your users from a list of default roles.

Now, you can assign and customize additional roles to your users.  

You can assign multiple roles to a user.

To learn more about Roles and Permissions, see Roles and Permissions.

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Account
  2. Click Roles + Permissions
  3. Click the plus ( + ) icon. 
  4. In the top, right corner of the screen, hover over the gear icon. 
  5. Click the blue pencil (Rename) icon.
  6. In the window that appears, enter a descriptive name, and then click Rename Role.
  7. In the top menu, click Members
  8. In the field, enter and select the user (or users) to assign to the role. 
  9. In the top menu, click Permissions
  10. Mark the permissions to add to your role. 
  11. At the bottom of the screen, click Save Role


(Optional) Step 6: Assign roles to existing users

This step only applies if you created additional roles for your users.

  1. In the Armor Management Portal (AMP), in the left-side navigation, click Account
  2. Click Roles + Permissions
  3. Locate and select the desired role. 
  4. Under the name of the role, click Members
  5. Click Edit Members
  6. Select and drag the desired user to the Chosen column. 
  7. Click the X at the top, right corner.  

Step 7: Contact your users

Upgraded users who are not account administrators must also complete the account signup process

Similar to an account administrator, upgraded users also received an email invitation to complete the account signup. 

You can share the following document to help your users complete this process: Complete the onboarding process and create a virtual machine




In this topic



Have a suggestion for the Armor Knowledge Base? Send a message to kb@armor.com.