PowerShell スクリプトを使用すると、すべての構成を設定した環境を準備できます。PowerShell スクリプトを実行して Unified Access Gateway をデプロイすると、初めてシステムを起動したときからこのソリューションを本番環境で利用できるようになります。
ただし、管理ユーザー インターフェイスのパスワードがデプロイ時に入力されないと、管理ユーザー インターフェイスと API のいずれも使用できません。デプロイ時に管理ユーザー インターフェイスのパスワードを入力しておかないと、後からユーザーを追加して管理ユーザー インターフェイスや API へのアクセスを有効にすることはできません。Unified Access Gateway を再デプロイする必要があります。
監視ロールを持つ、権限の低い管理者ユーザーを作成するために、INI ファイルにパラメータを含めることができます。スーパー ユーザー管理者ユーザーの作成はサポートされていません。root ユーザーと管理者ユーザーのパスワード ポリシーを構成してから、Unified Access Gateway インスタンスをデプロイできます。
パラメータ
パラメータの詳細については、同等の管理ユーザー インターフェイス パラメータが使用されているセクションを参照してください。
たとえば、一部のデプロイ パラメータについては、「PowerShell デプロイ パラメータ」と「OVF テンプレート ウィザードを使用した vSphere へのデプロイ」で説明しています。
システム構成、Syslog サーバ設定、ネットワーク設定などで使用されるパラメータの詳細については、「詳細設定」を参照してください。
Edge サービスで使用されるパラメータ、および Workspace ONE Intelligence や ID ブリッジなどの Unified Access Gateway のその他の使用事例については、「Edge サービスの設定」を参照してください。
前提条件
- Hyper-V デプロイで、静的 IP アドレスを使用して Unified Access Gateway をアップグレードする場合は、Unified Access Gateway の新しいインスタンスをデプロイする前に古いアプライアンスを削除します。
- システム要件を満たしており、利用可能であることを確認します。
手順
-
Omnissa Customer Connect ポータルからマシンに Unified Access Gateway OVA をダウンロードします。
-
uagdeploy-XXX.zip ファイルをマシンのフォルダにダウンロードします。
Unified Access Gateway の
ZIPファイルは、Omnissa Customer Connect ページにあります。 -
PowerShell スクリプトを開いて、ディレクトリをスクリプトの場所に変更します。
-
Unified Access Gateway 仮想アプライアンスの
INIファイルを開き、設定を適切に変更します。詳細については、「PowerShell デプロイ パラメータ」を参照してください。例:新しい Unified Access Gateway アプライアンス UAG1 をデプロイします。構成ファイルの名前は、uag1.ini です。このファイルには、UAG1 のすべての設定が含まれます。
uagdeploy.ZIPファイルにあるサンプルのINIファイルを使用してINIファイルを作成し、設定を適切に変更できます。
5. スクリプト実行が制限されないようにするには、PowerShell の set-executionpolicy コマンドを入力します。
```
set-executionpolicy -scope currentuser unrestricted
```
スクリプトの警告が表示される場合、次のコマンドを実行して、警告のブロックを解除します。
unblock-file -path .\uagdeploy.ps1
-
このコマンドを実行してデプロイを開始します。
.INIファイルを指定しない場合、スクリプトはデフォルトでap.iniを使用します。.\uagdeploy.ps1 -iniFile uag1.ini -
確認の画面が表示されたら、認証情報を入力し、スクリプトの実行を完了します。
Unified Access Gateway アプライアンスがデプロイされ、本番環境で利用できるようになります。
INI ファイルのサンプル
[General]
adminCertRolledBack=false
adminDisclaimerText=
adminMaxConcurrentSessions=5
adminPasswordExpirationDays=90
adminPasswordPolicyFailedLockoutCount=3
adminPasswordPolicyMinLen=8
adminPasswordPolicyUnlockTime=5
adminSessionIdleTimeoutMinutes=10
authenticationTimeout=300000
bodyReceiveTimeoutMsec=15000
ceipEnabled=true
cipherSuites=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384
clientConnectionIdleTimeout=180
cookiesToBeCached=none
defaultGateway=10.108.120.125
deploymentOption=threenic
diskMode=
dns=192.0.2.1 192.0.2.2
dnsSearch=example1.com example2.com
ds=
dsComplianceOS=false
eth0CustomConfig=DHCP^UseDNS=false
eth1CustomConfig=DHCP^UseDNS=false
extendedServerCertValidationEnabled=false
fallBackNtpServers=ipOrHostname1 ipOrHostname2
fipsEnabled=false
healthCheckUrl=/favicon.ico
hostClockSyncEnabled=false
httpConnectionTimeout=120
ip0=10.108.120.119
ipMode=DHCPV4_DHCPV6
ipModeforNIC2=DHCPV4_DHCPV6
ipModeforNIC3=DHCPV4_DHCPV6
isCiphersSetByUser=false
isTLS11SetByUser=false
locale=en_US
monitoringUsersPasswordExpirationDays=90
monitorInterval=60
name=
netBackendNetwork=
netInternet=
netManagementNetwork=
ntpServers=ipOrHostname1 ipOrHostname2
osLoginUsername=
osMaxLoginLimit=10
outboundCipherSuites=
passwordPolicyFailedLockout=3
passwordPolicyMinClass=1
passwordPolicyMinLen=6
passwordPolicyUnlockTime=900
quiesceMode=false
requestTimeoutMsec=10000
rootPasswordExpirationDays=365
rootSessionIdleTimeoutSeconds=300
secureRandomSource=
sessionTimeout=36000000
snmpEnabled= TRUE | FALSE
source=
sshEnabled=
sshInterface=eth0
sshKeyAccessEnabled=
sshLoginBannerText= EUC Unified Access Gateway
sshPasswordAccessEnabled=
sshPort=22
sshPublicKey1=
ssl30Enabled=false
sslprovider=
target=
tls10Enabled=false
tls11Enabled=false
tls12Enabled=true
tls13Enabled=true
tlsNamedGroups=
tlsPortSharingEnabled=true
tlsSignatureSchemes=
uagName=UAG1
unrecognizedSessionsMonitoringEnabled=true
gatewaySpec=
[WorkspaceOneIntelligenceSettings1]
encodedCredentialsFile=
name=TEST1
trustedCert1=
urlThumbprints=bed12345bf8546d15de2136f4c33f00f31d44e00
[WorkspaceOneIntelligenceSettings2]
encodedCredentialsFile=
name=RISK_SCORE
[SnmpSettings]
version= v3
usmUser=SAM_SNMP_V3
securityLevel=
authAlgorithm=
authPassword=
privacyAlgorithm=
privacyPassword=
engineID=uag1.example.com
[SnmpSettings]
version=V1+V2c
communityName=abc
[WebReverseProxy1]
proxyDestinationUrl=https://10.108.xx.xx
trustedCert1=
instanceId=view
healthCheckUrl=/favicon.ico
userNameHeader=AccessPoint-User-ID
proxyPattern=/(.*)
landingPagePath=/
hostEntry1=10.108.xx.xx HZNView.uag.com
[Horizon]
endpointComplianceCheckProvider=Workspace_ONE_Intelligence_Risk_Score
proxyDestinationUrl=https://enterViewConnectionServerUrl
trustedCert1=
gatewayLocation=external
blastExternalUrl=
additionalBlastExternalUrls=
tunnelExternalUrl=
additionalTunnelExternalUrls=
disableWebClient=true
healthCheckUrl=/favicon.ico
proxyDestinationIPSupport=IPV4
smartCardHintPrompt=false
queryBrokerInterval=300
proxyPattern=(/|/view-client(.*)|/portal(.*)|/appblast(.*))
matchWindowsUserName=false
windowsSSOEnabled=false
complianceCheckOnAuthentication=true
proxyDestinationUrlThumbprints=
proxyDestinationPreLoginMessageEnabled=true
customExecutable1=WEBEXVDIPLUGIN
enableAuthOnRedirectedSite=false
#Origin header details objects being used
originHeaderDetailsList=1,2,3
[OriginHeaderDetails1]
origin=userorigin.com
rewriteEnabled=true
autoGenerated=false
[OriginHeaderDetails2]
origin=tunnelurl.com
rewriteEnabled=false
autoGenerated=true
[OriginHeaderDetails3]
origin=https://uag-origin.test.com:443
rewriteEnabled=true
autoGenerated=false
[CustomExecutableSettings1]
name=OPSWAT2
osType=
trustedSigningCertificates1=
url=<<URL to custom executable file>>
urlResponseRefreshInterval=
isObtainedFromURL=
[Airwatch]
tunnelGatewayEnabled=true
disableAutoConfigUpdate=false
pacFilePath=
pacFileURL=
credentialFilePath=
apiServerUsername=domain\apiusername
apiServerPassword=*****
proxyDestinationUrl=https://null
ntlmAuthentication=false
healthCheckUrl=/favicon.ico
organizationGroupCode=
apiServerUrl=https://null
outboundProxyHost=1.2.3.4
outboundProxyPort=3128
outboundProxyUsername=proxyuser
outboundProxyPassword=****
reinitializeGatewayProcess=false
airwatchServerHostname=tunnel.acme.com
trustedCert1=c:\temp\CA-Cert-A.pem
hostEntry1=1.3.5.7 backend.acme.com
tunnelConfigurationId=
[AirwatchSecureEmailGateway]
memConfigurationId=abc123
apiServerUsername=domain\apiusername
healthCheckUrl=/favicon.ico
apiServerUrl=https://null
outboundProxyHost=1.2.3.4
outboundProxyPort=3128
outboundProxyUsername=proxyuser
outboundProxyPassword=****
reinitializeGatewayProcess=false
airwatchServerHostname=serverNameForSNI
apiServerPassword=****
trustedCert1=c:\temp\CA-Cert-A.pem
pfxCerts=C:\Users\admin\My Certs\mycacerts.pfx
hostEntry1=1.3.5.7 exchange.acme.com
[AirWatchContentGateway]
cgConfigId=abc123
apiServerUrl=https://null
apiServerUsername=domain\apiusername
apiServerPassword=*****
outboundProxyHost=
outboundProxyPort=
outboundProxyUsername=proxyuser
outboundProxyPassword=*****
hostEntry1=192.168.1.1 cgbackend.acme.com
trustedCert1=c:\temp\CA-Cert-A.pem
ntlmAuthentication=false
reinitializeGatewayProcess=false
airwatchServerHostname=cg.acme.com
[SSLCert]
pemPrivKey=
pemCerts=
pfxCerts=
pfxCertAlias=
[SSLCertAdmin]
pemPrivKey=resources\\test-key.pem
pemCerts=resources\\test-chain.pem
pfxCerts=
pfxCertAlias=
[SSLCert1]
identifier=cert1
defaultSSL=true
pemPrivKey=resources\\test-key1.pem
pemCerts=resources\\test-chain1.pem
[SSLCert2]
identifier=cert2
defaultSSL=false
pemPrivKey=resources\\test-key2.pem
pemCerts=resources\\test-chain2.pem
[RADIUSAuth]
authPort=
authPort_2=
authType=
authType_2=
directAuthChainedUsername=
enabledAux=
hostName=
name=
numAttempts=
radiusDisplayHint=
serverTimeout=
sharedSecret=
[SecurIDAuth]
accessKey=
authenticationTimeout=
hostname=
name=
pemCerts=
serverHostname=
serverPort=
[CertificateAuth]
caCertificatesDetails=
crlLocation=
enableCertCRL=
enableCertRevocation=
enableOCSP=
enableOCSPCRLFailover=
name=
pemCerts=
requestTimeout=
userIdSource=
validateUpn=
[WorkspaceONEIntelligenceRiskScoreEndpointComplianceCheckSettings]
allowLow=true
allowMedium=true
allowHigh=true
allowOthers=false
complianceCheckInterval=5
name=Workspace_ONE_Intelligence_Risk_Score
workspaceOneIntelligenceSettingsName=RISK_SCORE
[JWTSettings1]
publicKey1=
publicKey2=
publicKey3=
name=JWT_1
[JWTSettings2]
publicKey1=
publicKey2=
name=JWT_2
[JWTIssuerSettings1]
issuer=issuer-1
jwtType=PRODUCER
name=issuerJWT_1
pemPrivKey=
pemCerts=
pfxCerts=
pfxCertAlias=
[JWTIssuerSettings2]
issuer=issuer-2
jwtType=PRODUCER
name=issuerJWT_2
pemPrivKey=
pemCerts=
pfxCerts=
pfxCertAlias=
[AdminUser1]
enabled=true
name=monitoringUser1
[AdminUser2]
enabled=true
name=monitoringUser2
[OutboundProxySettings1]
proxyUrl=
name=
proxyType=HTTP
includedHosts1=
includedHosts2=
trustedCert1=
[OutboundProxySettings2]
proxyUrl=
name=
proxyType=HTTP
includedHosts1=
includedHosts2=
trustedCert1=
[adminSAMLSettings]
enable=true
entityId=https://www.entityid.com
[IDPExternalMetadata1]
allowUnencrypted=false
certChainPem=
encryptionCertificateType=
entityID=<entityID>
forceAuthN=false
metadataXmlFile=<Path of IDP metadata xml file>
privateKeyPem=
[OPSWATEndpointComplianceCheckSettings]
allowInCompliance=
allowEndpointUnknown=
complianceCheckFastInterval=
complianceCheckInitialDelay=
complianceCheckInterval=
allowNotInCompliance=
allowOutOfLicenseUsage=
allowAssessmentPending=
allowOthers=
hostName=
name=
clientSecret=
clientKey=
[PackageUpdates]
packageUpdatesScheme=OFF|ON_NEXT_BOOT|ON_EVERY_BOOT
packageUpdatesURL=
trustedCert1=
[OidcProviderSetting]
oidcClientId=
oidcConfigUrl=
oidcConfigurationId=
oidcForceAuthPrompt=
oidcTimeoutSeconds=
[SyslogServerSettings1]
sysLogType=TCP
syslogCategory=ALL
syslogFormat=TEXT
syslogSettingName=
syslogSystemMessagesEnabledV2=true
syslogUrl=
[SyslogServerSettings2]
hostname=
port=6515
sysLogType=TLS
syslogCategory=ALL
syslogClientCertKeyPemV2=
syslogClientCertPemV2=
syslogServerCACertPemV2=
syslogFormat=TEXT
syslogSettingName=
syslogSystemMessagesEnabledV2=false
[SyslogServerSettings3]
mqttClientCertCertPem=
mqttClientCertKeyPem=
mqttServerCACertPem=
mqttTopic=
sysLogType=MQTT
syslogCategory=ALL
syslogFormat=TEXT
syslogSettingName=
syslogSystemMessagesEnabledV2=true
syslogUrl=
次のタスク
既存の設定を保持したまま Unified Access Gateway をアップグレードする場合は、.ini ファイルを編集して、ソースの参照先を新しいバージョンに変更し、.ini ファイルを再実行します:uagdeploy.ps1 uag1.ini。このプロセスには、最大で 3 分かかることがあります。
[General]
name=UAG1
source=C:\temp\euc-unified-access-gateway-2512-xxxx_OVF10.ova
サービスを中断せずにアップグレードする方法については、「ダウンタイムなしのアップグレード」を参照してください。
このページは役に立ちましたか?