Jump to:navigation, search
Wiki

































De.png
En.png
Fr.png






Start web sessions via USC
Last adaptation to the version: Portal v1.23 / UTM v12.5.2
New:
Last updated: 
02.2024
notempty
This article refers to a Resellerpreview

Access: portal.securepoint.cloud  Unified Security Console UTMs / Select UTM / Tab  Websession



Requirements

Enabling the control via the Unified Security Console

The Unified Security Console must be enabled in the UTM


UTM v12.6.2 USC aktivieren-en.png

Access by then Unified Security Console must first be enabled in the UTM itself in the menu USC .
The UTM reports to the license server after the update. Here, the availability of the service is indicated and the menu is activated.

notempty
Attention: It usually takes a few minutes, in unfavorable cases up to an hour, before the menu is displayed for the first time.

The process can be shortened by executing the command system restrictions update on the CLI after a few minutes of runtime (the UTM must have had the opportunity to report to the license server!).

Caption Value Description UTM v12.6.2 USC synchronisiert-en.png
Privacy Policy: Yes The privacy policy must be accepted
Activated: Yes This activates the Unified Security Console - and thus the display, configuration and access via the Securepoint Unified Security portal.
Authentication method:

PIN (recommended) Login mask

  • Authentication method for a web session
  • PIN: •••••••• As authentication for a web session, a 6-digit PIN can be selected instead of the login mask with access data.
    After 5 incorrect entries in a row, access is blocked.
    The block is only lifted again after correct login directly at the admin interface.
      
    Displays the Websession PIN
    Creates a new PIN

    IP address

    • UTM up to v.12.2.2.8: Update required
      The UTM uses an older procedure for the web session, which is only available until 30.11.2023
      • The UTM is directly accessible via a local network
      • Access data (user name and password) are required
        or
      • The UTM has a public IP
        If no public IPv4 is available because the UTM is behind a NAT router, a public IPv6 can be assigned via IPv6 prefix delegation.
          
    • UTM up to v12.4.4.1 An update to the latest version is recommended
      • The UTM is directly accessible via a local network
      • Access data (user name and password) are required
        or
      • The UTM has a public IP
        If no public IPv4 is available because the UTM is behind a NAT router, a public IPv6 can be assigned via IPv6 prefix delegation.
          
    • UTM v12.5.0
      • The UTM is directly accessible via a local network
      • Access data (user name and password) are required
        or
      • The UTM has a public IP
        If no public IPv4 is available because the UTM is behind a NAT router, a public IPv6 can be assigned via IPv6 prefix delegation.
          
      • A PIN is additionally required
        Deposited on the UTM in the menu USC / box Unified Security Console
          






























    Example configuration with a Fritzbox





  • Note
    This section includes descriptions of third-party software and is based on the status at the time this page was created.
    Changes to the user interface on the part of the manufacturer are possible at any time and must be taken into account accordingly in the implementation.
    All information without warranty.
    • Login to the configuration interface (in the default settings at https://192.168.178.1)
    • In the network settings for IPv6, the option Enable DHCPv6 server in FRITZ!Box for home network must be selected
    • Select suboption Assign DNS server, prefix (IA_PD) and IPv6 address (IA_NA)

    Configuration on the UTM:
    Edit interfaces
    UTM v12.4 externe Schnittstelle IPv6.png
    External interface
    Typically A0, LAN1 or eth0 - depending on the hardware used
      
    connected to the Internet via NAT router

    Menu → Network →Network ConfigurationTab Network Interfaces / Edit External Interface / Tab General

    DHCP Client IPv4 & IPv6
    Router Advertisement: Off
    IPv6 Prefix Delegation On

    UTM v12.4 interne Schnittstelle IPv6.png
    Internal interface
    E.g. A1, LAN2 or eth1 - depending on the used hardware
      
    (must be configured for all internal interfaces that are to distribute a public IPv6 address to clients (and thus also receive one themselves).

    Menu → Network →Network ConfigurationTab Network Interfaces / Edit Internal Interface / Tab General

    DHCP Client Off
    Router Advertisement: On
    IPv6 Prefix Delegation Off

    UTM v12.4 Routing Default IPv6.png
    Add default route

    Gateway interface: LAN1
    IPv6: On

    In order for the IPv6 addresses to be routed, a default route must be added under → Network →Network ConfigurationTab Routing with Button Add Default Route.
    Save

    UTM v12.4 Netzwerkkonfiguration mit IPv6 Prefix-Delegation.png
    Network configuration with IPv6 prefix delegation

    • The external interface should get a dynamic after a short moment. .../64 IPv6 address
      If there is a 128 address here, the settings in the Fritzbox must be verified
        












    Create network objects and portfilter rules
    UTM v12.4 Netzwerkobjekt internal v6.png
    Network object internal_v6
    → Firewall →PortfilterTab Network Objects Button Add Object

    Name: internal_network_v6

    Type: Network (interface)
    Adresse: LAN2
    Zone: internal

    For systems set up before v12.4: internal_v6

    UTM v12.4 Netzwerkobjekt Internet v6.png
    Network object Internet_v6

    Name: Internet_v6
    Type: Network (address)
    Adresse:    ⸬/0 
    Zone: external
    For systems set up before v12.4: external_v6

    UTM v12.4 Portfilterregel IPv6.png
    Possible portfilter rule

    Source: Network.svg internal_network_v6

    Target: World.svg internet_v6
    Service: Service-group.svg default-internet
    Action: Accept
    NAT

    Type:
    NONE No NAT!













    The UTM can now be reached via a public IPv6.
    After a few minutes, this address is displayed in the selection box for IP addresses in the USC.
    • UTM from v.12.5.1:
      • The UTM is directly accessible via a local network
      • Access data (user name and password) are required
        or
      • A web session from remote networks is also possible if the UTM does not have a public IP
      • The connection is established via the interface on which the default route of the UTM is set up.
      • Login with PIN or access data possible
        Deposited on the UTM in the menu USC / box Unified Security Console
          

    Websession

    Websession

    Action: Description USC Reiter Websession-en.png


     Start new websession Opens the dialog to start the administrative web interface of the UTM
    Websession with UTM up to v12.5.0

    notempty

    An update to the latest version is recommended

    IP address All interfaces with IP addresses on the UTM are offered in the drop-down menu.
    It is also indicated whether the IP addresses are public or local.

    Interface with a public IP address

    203.0.113.203 (A0) [Public]

  • A Websession PIN is required (see below)
  • If the first login 'after the first update of the UTM to a version 12.5.x via a web session, the initial PIN 000000 is valid.
    The PIN must be changed at the first login.
  • Interface with private IP address

    192.168.12.50 (A1) [Local]

    • A link to the local administration web interface will be provided
  • User credentials with administrator rights for the UTM are required
  • The own IP must be registered as manager IP on the UTM
  • A connection in the local network to the UTM is required
  • USC 1.17 Websession PIN-en.png
    Web session with PIN (UTM up to v12.5.0)
    Port 11115
    Port through which the admin interface of the UTM can be reached (is read from the settings of the UTM under Network Server Settings )
    PIN: ••••••••
    Websession PIN (Configured on the UTM in the USC menu in the Unified Security Console section
    The entered PIN is incorrect
    After 5 incorrect entries in a row, access is blocked.
    The block is only lifted again after correct login directly at the admin interface.
    Version Version
    Currently used firmware version
     Start new websession PIN Opens the admin interface of the UTM in a new tab of the used browser
  • Pop-ups may need to be allowed for portal.securepoint.cloud in the browser used!
  • Web session with PIN
    notempty
    Websession with PIN (UTM from v12.5.1)
    The connection is established via the interface on which the default route of the UTM is set up.
    User admin
    If there is no user with the name admin, a user with admin rights can be selected here with whom the web session connection is to be started.
    USC v1.23 Websession PIN-en.png
    Web session with PIN (UTM as of v12.5.1)
    PIN:
    _ _ _ _ _ _
    Websession PIN (Configured on the UTM in the USC menu in the Unified Security Console section
    After entering the PIN, the web session can be started directly using ↵ Enter.
    The entered PIN is incorrect
    After 5 incorrect entries in a row, access is blocked.
    The block is only lifted again after correct login directly at the admin interface.
     Start new websession Opens the admin interface of the UTM in a new tab of the used browser
  • Pop-ups may need to be allowed for portal.securepoint.cloud in the browser used!
  • Web session with login screen
    notempty
    Web session with login screen (UTM from v12.5.1)
    The connection is established via the interface on which the default route of the UTM is set up. UTM 12.5.1 Websession Loginmaske.png
    Web session with login screen (as of UTM v12.5.1)
    As the web session PIN is deactivated, no automatic login can take place. Access data (user name and password) are required.
     Start new websession Opens the admin interface of the UTM in a new tab of the used browser
  • Pop-ups may need to be allowed for portal.securepoint.cloud in the browser used!