本文档介绍将安全网络设备(SWA)集成到安全管理设备(SMA)的过程。
建议掌握下列主题的相关知识:
本文档不限于特定的软件和硬件版本。
本文档中的信息都是基于特定实验室环境中的设备编写的。本文档中使用的所有设备最初均采用原始(默认)配置。如果您的网络处于活动状态,请确保您了解所有命令的潜在影响。
1.确保SMA和SWA均已获得许可。
2.检查SWA和SMA的兼容性矩阵,请使用此链接:SWA-SMA-ESA兼容性矩阵。
映像 — 取消调配的版本
步骤1.从SWA导出配置文件 |
1.1.在GUI中,导航到System Administration并选择Configuration File。 1.2.确保选择了“下载文件到本地计算机以查看或保存”。 1.3.在“配置文件”中选择“加密密码”。 1.4.(可选)选择配置文件的名称。 1.5.单击提交。
|
步骤2.创建配置管理器 |
2.1.在SMA GUI中,单击Web选项卡。 2.2.从实用程序选择Configuration Manager。 2.3.如果配置管理器尚未初始化,请点击所需配置管理器的Initialize链接,否则跳至步骤2.5。 2.4.选择使用默认设置,然后点击Initialize。 2.5.单击Import Configuration(导入配置)作为所需的Configuration Manager。
2.6.从Select Configuration Source中选择Web Configuration File。 2.7.选择您在第1步中导出的配置文件。
2.8.单击导入。 2.9.确定更改。 |
步骤3.配置管理器设置 |
3.1.在SMA GUI中,单击Web选项卡。 3.2.从Utilities中选择Security Services Display。 3.3.确保所需的功能配置正确,您可以从“编辑显示设置”中启用或禁用这些功能。 3.4.如果进行了任何更改,请提交并提交。
|
步骤4.添加Web设备 |
4.1.从SMA GUI中单击Management Appliance选项卡。 4.2.从Centralized Services(集中服务)选择Security Appliances。 4.3.单击添加Web设备
4.4.输入设备名称和IP地址或主机名。 4.5.单击Establish Connection。 4.6.输入Username和Passphrase,然后单击Establish Connection。 4.7.分配配置管理器。
4.8.提交并提交更改。 |
步骤5.验证集成 |
5.1.在SMA GUI中,单击Web选项卡卡。 5.2.从Utilities中,选择Web Appliance Status。 5.3.如果您看到“需要注意”警告消息。点击设备名称了解详细信息,点击SWA的名称,然后查看详细信息。
|
当您尝试选择集中服务时,如果复选框处于非活动状态,请点击问号(?),指南将引导您通过路径来启用该服务。
映像 — 集中服务已禁用
如果您收到此错误,请将SWA集成到SMA时,请确保IP地址或主机名以及凭证正确。
映像 — 身份验证失败
如果SMA配置了集中网络报告,并且您在“第4步”中将SWA集成到SMA时将该功能分配给SWA,则需要启用Cisco Centralized Web Reporting:
图像 — 在SWA中禁用集中网络报告
要解决此问题,请从CLI连接到SWA并键入reportingconfig并选择CENTRALIZED,完成向导以启用集中报告并提交更改。
SWA_CLI> reportingconfig
Choose the operation you want to perform:
- COUNTERS - Limit counters recorded by the reporting system.
- WEBTRACKINGQUERYTIMEOUT - Timeout value for Webtracking Queries.
- AVERAGEOBJECTSIZE - Average HTTP Object Size used for Bandwidth Savings Calculation.
- WEBEVENTBUCKETING - Enable or Disable web transaction event bucketing.
- CTROBSERVABLE - Enable or Disable CTR observable based indexing.
- CENTRALIZED - Enable/Disable Centralized Reporting for this Secure Web Appliance.
[]> CENTRALIZED
Reporting service status: Local Reporting enabled. (Show usernames in reports.)
Do you want to enable Centralized Reporting for this appliance? [N]> Y
Do you want to anonymize usernames in reports? [N]> N
Reporting service status: Centralized Reporting enabled. (Show usernames in reports.)
Choose the operation you want to perform:
- COUNTERS - Limit counters recorded by the reporting system.
- WEBTRACKINGQUERYTIMEOUT - Timeout value for Webtracking Queries.
- AVERAGEOBJECTSIZE - Average HTTP Object Size used for Bandwidth Savings Calculation.
- WEBEVENTBUCKETING - Enable or Disable web transaction event bucketing.
- CTROBSERVABLE - Enable or Disable CTR observable based indexing.
- CENTRALIZED - Enable/Disable Centralized Reporting for this Secure Web Appliance.
[]>
SWA_CLI> commit
如果您将配置发布到SWA并收到Error(错误)指示SWA和SMA中的URL类别列表不同,请确保两个设备均可连接到Cisco Update Server,并且updater_logs中没有Errors(错误):
图像 — URL类别列表不匹配
要强制SWA或SMA下载更新,请从CLI键入updatenow。
要查看与更新相关的SMA或SMA日志,请从CLI键入grep并选择与updater_logs关联的编号并完成向导
如果您将SWA集成到SMA并收到“Error that the host key has been changed”(主机密钥已更改),这是因为SMA在其密钥存储中存储了同一IP地址的不同主机密钥。
图像 — 主机密钥似乎已更改
要解决此错误,请登录SMA的CLI,运行logconfig并输入HOSTKEYCONFIG。键入DELETE,然后按Enter。然后,选择与SWA关联的编号,然后按Enter直到完成向导。
提交更改:
SMA_CLI> logconfig
Currently configured logs:
Log Name Log Type Retrieval Interval
---------------------------------------------------------------------------------
1. aggregatord_logs Aggregatord Logs Manual Download None
2. authentication Authentication Logs Manual Download None
...
Choose the operation you want to perform:
- NEW - Create a new log.
- EDIT - Modify a log subscription.
- DELETE - Remove a log subscription.
- DELETELOGFILE - Delete log files
- SETUP - General settings.
- LOGHEADERS - Configure headers to log.
- HOSTKEYCONFIG - Configure SSH host keys.
[]> HOSTKEYCONFIG
Currently installed host keys:
1. 10.48.48.182 ssh-rsa AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...ZhW4gEXWE=
2. 10.48.48.181 ssh-rsa BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBb...4p74b9Q9k=
Choose the operation you want to perform:
- NEW - Add a new key.
- EDIT - Modify a key.
- DELETE - Remove a key.
- SCAN - Automatically download a host key.
- PRINT - Display a key.
- HOST - Display system host keys.
- FINGERPRINT - Display system host key fingerprints.
- USER - Display system user keys.
- REGENERATESCPKEYS - Regenerate SSH Keys for SCP Log Subscription Retrieval.
[]> DELETE
Enter the number of the key you wish to delete.
[]> 2
Currently installed host keys:
1. 10.62.131.143 ssh-rsa AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA...ZhW4gEXWE=
...
SMA_CLI> commit
| 版本 | 发布日期 | 备注 |
|---|---|---|
2.0 |
29-Jul-2026
|
首次公开发布 |
1.0 |
24-Mar-2026
|
初始版本 |