Connect Secure 25.1.x Release

25.1.0.0 Release

25.1.1.0 Release

25.1.3.0 Release

25.1.0.0 Release

The upgrade process for hardware appliances involves uploading the 25.1.0.0 package, importing logs and configurations.

Note

  • For hardware appliances, upgrade is supported only on ISA6000/ISA8000 Hardware Appliances for ICS releases from 22.8R2 version.
  • Supports Rollback to Secure Boot 22.8R2 release.

  • Fresh deployment/upgrade of 25.1.0.0 is supported on VMware.
  • In 25.1.3.0 release, the legacy SCSI storage subsystem is replaced with a high-performance NVMe (Non-Volatile Memory Express) controller on VMware.

Upgrading from 22.8R2 Release to 25.1.0.0 Release

To upgrade from 22.8R2 release to 25.1.0.0 release:

1.Log into the Admin portal.

2.Upload the 25.1.0.0 package using standard upgrade process. For details, see ICS Administration Guide.

The system performs actions, which requires multiple reboots as part of the upgrade.

After the upgrade to the Secure Boot build (detailed above) is complete, the images on an ICS would look like the following:

Deploying Virtual ICS from OVF

ICS 25.1.0.0 needs vTPM to be enabled at the ESXi infrastructure. To enable vTPM, you need VMware vSphere and a key provider, such as Native Key Provider. vTPM and Native Key Provider are licensed for use in all vSphere versions. Supported ESXi versions are 7.0.x and 8.0.x.

vTPM is a VMware component, and for the latest documentation please refer to VMware product documentation.

To deploy Virtual ICS (vICS) from OVF:

1.Select Compute > vApps > New, and then select the Add vAPP From OVF option.

2.Select all three files (OVF, NVRAM, VMDK) required for deployment of vICS:

OVF file - Select the OVF file based on your deployment requirement.

For example:

ISA-V-VMWARE-ICS-25.1.0.0-<build-number>-VT-ISA8000-V.ovf

ISA-V-VMWARE-ICS-25.1.0.0-<build-number>-VT-ISA6000-V.ovf

ISA-V-VMWARE-ICS-25.1.0.0-<build-number>-VT-ISA4000-V.ovf

NVRAM file - example: ISA-V-VMWARE-ICS-25.1.0.0-<build-number>-VT-file1.nvram

VMDK file - example: ISA-V-VMWARE-ICS-25.1.0.0-<build-number>-VT-disk1.vmdk

3.Follow the wizard and configure the necessary details as per your requirement. Click Finish.

4.Click Start to power on vICS.

vTPM on ESXi 8.0.x

No additional steps are required to add vTPM when the ESXi itself is enabled with vTPM support.

Prerequisites

vCenter license

ESXi license

Key Management Server on vCenter

vTPM requirements as specified by Broadcom https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-automation/all/vtpm-overview.html

vTPM on ESXi 7.x

If ESXi 7.2 is used as hypervisor, then vTPM does not get attached automatically on deploying virtual ICS. Attach vTPM by selecting Settings > ADD NEW DEVICE > Trusted Platform Module.

Due to VMware limitations, sometimes Trusted Platform Module is not visible in ADD NEW DEVICE option. In such scenario, follow the below steps.

1.Navigate to Settings > VM Options > General Options.

2.Change Guest OS Family from Other to Linux.

3.Change Guest OS Version from Other (64-bit) to TPM supported version like Ubuntu Linux (64-bit).

4.Click OK.

5.Attach vTPM by selecting Settings > ADD NEW DEVICE > Trusted Platform Module.

6.Revert Guest OS Family from Linux to Other.

7.Revert Guest OS Version from TPM supported version like Ubuntu Linux (64-bit) to Other (64-bit).

Limitations

Removing vTPM from virtual ICS can make virtual ICS non recoverable.

Cloning virtual ICS with replace TPM option is not supported.

Exporting virtual ICS with vTPM to template is not supported by VMware.

25.1.1.0 Release

Deploying Ivanti Connect Secure Appliance on Hyper-V

Deploying Ivanti Connect Secure Appliance on OpenStack KVM

Deploying Ivanti Connect Secure Appliance on Azure

Deploying Ivanti Connect Secure Appliance on Hyper-V

Overview of ICS Hyper-V Enablement

Ivanti Security Appliance are now supported on Microsoft's Hyper-V hypervisor in addition to VMWare platform.

The following table contains data regarding the Number of cores to be allocated to each Hyper-V model:

Platform

Cores Per VM

RAM

Disk Space

ISA4000-V

4

8 GB

80 GB

ISA6000-V

8

16 GB

80 GB

ISA8000-V

12

32 GB

80 GB

Limitations

Hyper-V Deployment with secure boot is only qualified for ICS 25.1.1.0 release onwards.

Upgrade from 22.X to 25.X as well as rollback from 25.1.1.0 to any older release is not supported.

Only Fresh install is supported.

The image supports only IDE disks and will support only the ‘Generation 2’ type of Virtual machine in Hyper-V Manager because secure-boot is only supported on Gen2 onwards.

VM Cloning is no longer a valid scenario because for every VM we should store unique keys in TPM, hence we can’t use same TPM while cloning.

Deploying a Hyper-V ISA-V through the Hyper-V Manager

To deploy a Ivanti Security appliance through the Hyper-V Manager:

1.Copy the Hyper-V ISA-V Package to the Hyper-V Server.

2.Open Hyper-V Manager.

3.Deploy Hyper-V ISA-V.

4.On the Before you Begin screen, click Next.

5.Enter Specify Name and Location and click Next.

6.Select Generation 2 only as Hyper-V ISA-V does not support older Generation 1, and click Next.

7.Now assign the appropriate memory. Enter 8192 MB for ISA-V, and click Next.

8.The Configure Networking page opens. Select a virtual switch to be used by the network adapter, and click Next.

You should configure your own virtual switch (Hyper‑V Manager > Virtual Switch Manager).

9. The Connect Virtual Hard Disk page appears. Select the Use an existing virtual hard disk button and provide the location of the Hyper-V ISA-V package.vhdx (step 1).

10. Click on Finish. Hyper-V Server creates an entry under Virtual Machines.

11. Now, add number on vCPUs and network adapter for External Port and Management Port.

a. Right click on the VM Name, and click on Settings.

b. Enter Number of virtual processors required.

c. In the dialog box that opens, click on Add Hardware in the left pane.

d. On the right pane, select Network Adapter.

e. Click on Add.

It is important to add all the three network adapters to Hyper-V ISA-V before powering on the VM. Adding network adapters after powering-on the Hyper-V ISA-V may result in network connectivity issues. The following list indicates the order of virtual adapters:
1. Network Adapter: Internal
2. Network Adapter 2: External
3. Network Adapter 3: Management

12. Select the virtual switch for External Port, and click on Apply.

13. Now add network adapter for Management port.

a. Click on Add Hardware on the left pane. Select Network Adapter, click on Add.

b. Select the Virtual Switch for Management Port, and click on Apply.

14. Before starting the virtual machine, go to Settings > Security.

a. Change the Template to Microsoft UEFI Certificate Authority.

b. Clear the Enable Secure Boot option to disable it before the first boot.

c. Clear the Enable Trusted Platform Module option to disable TPM for the first boot.

15. Select Start to power on the virtual machine.

16. Virtual machine will boot, and it will automatically shut down when it detects Secure Boot is disabled. This step is very much needed, as it will install Ivanti Secure Boot certificate in this first boot. The following screenshot may or may not appear during the fast booting process and after the system is turned off.

17. Before starting the virtual machine again, go to Settings > Security.

a. Make sure the Template is Microsoft UEFI Certificate Authority.

b. Select the Enable Secure Boot option.

c. Select the Enable Trusted Platform Module option.

d. Optional step is to add a DVD drive with automatic initial configurations For details, see Deploying Connect Secure with Automatic Initial Configurations.

18. Select Start to power on the virtual machine.

Once Deployment is successful, the deployed VM Console is shown.

Deploying Connect Secure with Automatic Initial Configurations

1.Download the Hyper-V package file and find the hyperv_template.xml file.

2.Customize the required fields like IP address/Subnet Mask/Default Gateway for internal, external, and management ports and then convert to .iso image (hyperv.iso) using the following command.
Command Sample: mkisofs -l -o hyperv.iso hyperv_template.xml.

3.Under DVD Drive, click Browse and upload the .iso file and then start the VM.

4.You can add DVD Drive when the virtual machine is switched off automatically after the first.

Note:

When deploying a Hyper-V image using a script (.ps1 file), it is essential to use the file name hyperv_template.xml with the mkisofs command. If you use any other file name, the deployment will not recognize hyperv.iso as a drive.

For example, the following commands will not work:

mkisofs -l -o hyperv.iso hyperv_template-AP.xml

mkisofs -l -o hyperv.iso hyperv_template-AP1.xml

or
with any other file name in place of hyperv_template.xml.

Always use the file name hyperv_template.xml with the mkisofs command:

mkisofs -l -o hyperv.iso hyperv_template.xml

Deploying a Hyper-V ISA-V through Powershell cmdlets

To deploy a Hyper-V ISA-V through Powershell cmdlets:

either run the powershell commands manually from powershell script "hyperv-VMDeployVHDX.ps1".

or call the powershell script(Method1) with proper arguments to automate all the steps and directly get a running VM with secure boot enabled.

Launch Hyper-V ISA-V in an automated fashion with secure boot enabled.

1.Copy the Hyper-V ISA-V Package and hyperv-VMDeployVHDX.ps1 to the Hyper-V Server.

2.Open PowerShell as administrator.

3.PowerShell script takes the following inputs:

VMName: Name of the VM to create (mandatory)

VHDXPath: Path to the existing VHDX file (mandatory)

ISAVariant: ISA variant determining VM resources - "4K", "6K", or "8K" (mandatory)

4K: 8GB RAM, 4 vCPUs

6K: 16GB RAM, 8 vCPUs

8K: 32GB RAM, 12 vCPUs

IntSwitch: Name of the Hyper-V virtual switch for Internal network adapter (mandatory)

ExtSwitch: Name of the Hyper-V virtual switch for External network adapter (mandatory)

MgmtSwitch: Name of the Hyper-V virtual switch for Management network adapter (optional)

ConfigISOPath: Path to an ISO file to mount as a DVD drive for auto configuration (optional)

4.Keep the VMName, VHDXPath, ISAVariant, Internal Switch name, External Switch name ready.

5.Example deployment commands:

With all three network adapters:

With Internal and External adapters only:

Cloning of VM on Hyper-V

Cloning is no longer supported for Generation 2 VMs because of TPM (Trusted platform modules) limitations.

Increasing the Disk Size in Hyper-V

Fresh installation 80 GB disk space is available by default. You can modify or increase the disk size only once on fresh installation or upgrade of the ICS images, but not on rollback or factory reset images.

To increase the disk space:

1.Click IDE Controller > Hardware, click Edit.

2.Select Expand and click Next>.

3.Change the disk size in GB and click Finish.

ICS Provisioning Parameters

Provisioning parameters are those parameters which are required during the deployment of a virtual appliance. ICS accepts the following parameters as provisioning parameters in the XML format.

<PropertySection>

<Property oe:key="vaIPAddress" oe:value=""/>

<Property oe:key="vaNetmask" oe:value=""/>

<Property oe:key="vaGateway" oe:value=""/>

<Property oe:key="vaDefaultVlan" oe:value=""/>

<Property oe:key="vaExternalIPAddress" oe:value=""/>

<Property oe:key="vaExternalNetmask" oe:value=""/>

<Property oe:key="vaExternalGateway" oe:value=""/>

<Property oe:key="vaExternalDefaultVlan" oe:value=""/>

<Property oe:key="vaManagementIPAddress" oe:value=""/>

<Property oe:key="vaManagementNetmask" oe:value=""/>

<Property oe:key="vaManagementGateway" oe:value=""/>

<Property oe:key="vaManagementDefaultVlan" oe:value=""/>

<Property oe:key="vaPrimaryDNS" oe:value=""/>

<Property oe:key="vaSecondaryDNS" oe:value=""/>

<Property oe:key="vaWINSServer" oe:value="1.2.3.4"/>

<Property oe:key="vaDNSDomain" oe:value="ics.company.com"/>

<Property oe:key="vaAdminUsername" oe:value="admin"/>

<Property oe:key="vaAdminPassword" oe:value="Password123$"/>

<Property oe:key="vaCommonName" oe:value="ics-ext-port.company.com"/>

<Property oe:key="vaOrganization" oe:value="Ivanti"/>

<Property oe:key="vaRandomText" oe:value="randomtextrandomtextrandomtextrandomtext"/>

<Property oe:key="vaAcceptLicenseAgreement" oe:value="y"/>

<Property oe:key="vaEnableLicenseServer" oe:value="n"/>

<Property oe:key="vaAdminEnableREST" oe:value=""/>

<Property oe:key="vaAuthCodeLicense" oe:value=""/>

<Property oe:key="vaConfigURL" oe:value="http://a.b.c.d/ics_config.xml"/>

<Property oe:key="vaConfigServerCACertPEM" oe:value=""/>

<Property oe:key="vaConfigData" oe:value=""/>

<Property oe:key="vaInternalPortReconfigWithValueInVAppProperties" oe:value="1"/>

<Property oe:key="vaManagementPortReconfigWithValueInVAppProperties" oe:value="1"/>

<Property oe:key="vaExternalPortReconfigWithValueInVAppProperties" oe:value="1"/>

</PropertySection>

Parameter Name

Type

Description

vaIPAddress

IP address

Internal interface IP

vaNetmask

IP address

Internal interface subnet mask

vaGateway

IP address

Internal interface IP gateway

vaDefaultVlan

integer

VLAN number to assign to this interface

vaExternalIPAddress

IP address

External interface IP

vaExternalNetmask

IP address

External interface subnet mask

vaExternalGateway

IP address

External interface IP gateway

vaExternalDefaultVlan

integer

VLAN number to assign to this interface

vaManagementIPAddress

IP address

Management interface IP

vaManagementNetmask

IP address

Management interface subnet mask

vaManagementGateway

IP address

Management interface IP gateway

vaExternalDefaultVlan

integer

VLAN number to assign to this interface

vaPrimaryDNS

IP address

Primary DNS IP

vaSecondaryDNS

IP address

Secondary DNS IP

vaWINSServer

IP address

Windows server IP

vaDNSDomain

string

Windows domain name

VaAdminUsername

string

Admin username

vaAdminPassword

string

Admin password

vaCommonName

string

Common name

vaOrganization

string

Organization name

vaRandomText

string

Random text to generate self-signed certificate

vaAcceptLicenseAgreement

character

“y” to accept the license agreement

vaEnableLicenseServer

character

“y” to enable it as VLS server. “n” to bring it up as a ICS node.

vaAdminEnableREST

character

“y” to enable REST for administrator user

vaAuthCodeLicense

string

Authentication code that needs to be obtained from Ivanti.

vaConfigURL

string URL

Http based URL where XML based ICS configuration can be found.

vaConfigServerCACertPEM

string

PEM format of CA certificate.

vaConfigData

string

base64 encoded XML based ICS configuration.

vaInternalPortReconfigWithValueIn

VAppProperties

integer

The Internal port overwrite property. If set to 1, overwrites the virtual appliance’s internal port settings with the ones specified during deployment. Set this value as 1.

vaManagementPortReconfigWithValueIn

VAppProperties

integer

The Management port overwrite property. If set to 1, overwrites the management port-related parameters in the ICS with the ones defined here. Set this value as 1.

vaExternalPortReconfigWithValueIn

VAppProperties

integer

The External port overwrite property. If set to 1, overwrite the external port-related parameters in ICS/IPS with the ones defined here. Set this value as 1.

v6 Parameters

Parameter Type Description
vaNetworkStack IPv4 or IPv6 address

It indicates network address configured during deployment.

v4 : IPv4 addresses are allowed to configured.

v6 : IPv6 addresses are allowed to configured.

Both: IPv4 and IPv6 addresses are allowed to configured.

vaIPv6Address IPv6 address Internal interface IPv6 address

vaPrefix

IPv6 address

Internal interface IPv6 prefix length.

vaIPv6Gateway

IPv6 address

Internal interface IPv6 gateway address.

vaManagementIPv6Address

IPv6 address

Management interface IPv6 address

vaManagementPrefix

IPv6 address

Management interface IPv6 prefix length.

vaManagementIPv6Gateway

IPv6 address

Management interface IPv6 gateway address.

vaExternalIPv6Address

IPv6 address

External interface IPv6 address

vaExternalPrefix

IPv6 address

External interface IPv6 prefix length.

vaExternalIPv6Gateway

IPv6 address

External interface IPv6 gateway address.

ICS supports zero touch provisioning. This feature can detect and assign DHCP networking settings automatically at the ICS boot up. The following ICS parameters should be set to null in order to fetch the networking configuration automatically from the DHCP server.

vaIPAddress

vaExternalIPAddress

vaManagementIPAddress

vaNetworkStack

vaManagementIPv6Address

vaExternalPrefix

vaNetmask

vaExternalNetmask

vaManagementNetmask

vaIPv6Address

vaManagementPrefix

vaExternalIPv6Gateway

vaGateway

vaExternalGateway

vaManagementGateway

vaPrefix

vaManagementIPv6Gateway

 

vaPrimaryDNS

vaSecondaryDNS

vaDNSDomain

vaIPv6Gateway

vaExternalIPv6Address

 

Deploying Ivanti Connect Secure Appliance on OpenStack KVM

Overview

Assumptions

The basic understanding of deployment models of ICS on a data center and basic experience in using OpenStack is needed for the better understanding of this guide.

Prerequisites and System Requirements

The OpenStack Fabric has various components such as Controller, Compute, Identity, Image, Networking etc. that are separately installed. For details about these services,

To deploy the ICS VA on OpenStack, you need the following:

Access to the OpenStack Dashboard

An OpenStack account with deployment rights

ICS KVM Image

(Optional) ICS licenses

(Optional) ICS configuration in xml format, required only for zero touch deployment

Desired flavors of ISA-V (ISA4000-V, ISA6000-V, ISA8000-V).

Desired ICS KVM image on OpenStack

Internal, External and Management networks on OpenStack

Security Groups for Internal, External and Management Ports

Compute nodes should support vTPM.

Compute nodes should support secure boot for virtual machines.

Compute nodes should have Ivanti released OVMF firmware binary (OVMF_CODE.secboot.ivanti.fd) and NVRAM file (OVMF_VARS_4M.ivanti.fd) for secure boot.

Deploying ICS on OpenStack Using Horizon Dashboard

Before proceeding with the ICS deployment, ensure that the necessary prerequisites are set up. For details, see Appendix A: Setting Up Prerequisites

To deploy ICS on OpenStack, do the following:

1.Log in to the OpenStack.

2.In the OpenStack dashboard displayed, select Project > Compute > Imagesand then create an image. For more information, see Create Image.

3.From the list of images displayed, click on Launch corresponding to the ICS KVM image you want to launch.
Image selected must have following attributes for secure boot and vTPM supported ICS image.

hw_disk_bus='virtio'

hw_firmware_type='uefi'

hw_machine_type='q35'

hw_tpm_model='tpm-crb'

hw_tpm_version='2.0'

os_secure_boot='required'

The following figure depicts the ICS VA Images screen:

4.In the Launch Instance Details window, fill the following and then click Next.

Instance Name: Specify host name of the ICS Virtual instance

Description: Enter a brief description on this instance

Availability Zone: Select the zone where the instance is deployed

Count: Number of VM instances

The following figure depicts the Device Details screen:

5.The Source window displays the details of the image used. Click Next.

The following figure depicts the Source Selection screen.

6.In the Flavor window, select required flavors of ISA-V (ISA4000-V, ISA6000-V, ISA8000-V) from the list based on the memory and storage capacity of the instance. Click Next.

The following figure depicts the Flavor Selection screen.

7.In the Networks window, select networks from the list that specifies internal, external and management subnets. ICS supports VM with 2-NICs model and 3-NICs model for deployment. Click Next.

The following figure depicts the Network Selection screen:

8.(Optional) Network Ports window. Click Next.

The following figure depicts the Network Ports Selection screen:

9.In the Security Groups window, select the required network security groups from the list for internal, external and management ports. Click Next. To create new security groups, refer Creating Required Security Groups for Internal, External and Management Ports

The following figure depicts the Security Groups Selection screen:

10.Key Pair is not used. Click Next.

The following figure depicts the Key Pair screen:

11.Click Choose File and import the file that contains the provisioning parameters in XML format OR paste the Customization script and do the required modifications. Select the Configuration Drive check box. The template file is available for ISA-V instance and click Launch Instance upon selecting the Configuration Drive option.

The following figure depicts the Configuration Script screen:

12.The Instances window lists all the ICS VA instances. The blue bar in the Task column shows the status of creation of the instance. This will take a few minutes.

Open the created ICS VA instance by clicking on the Instance Name link.

The Interface tab shows the networks that are created.

The Log tab shows the log details of the device that is created.

The console tab provides the virtual console to view the device coming up.

13.Next, the Internal and External interfaces are configured by DHCP (Zero touch configuration).

The following figure depicts the Internal and External Interfaces Configuration by DHCP screen:

14.The Config URL is downloaded for initial configuration.

The following figure depicts the Download Config URL from Template screen:

ICS Provisioning Parameters

Provisioning parameters are those parameters which are required during the deployment of a virtual appliance. ICS accepts the following parameters as provisioning parameters in the XML format.

<PropertySection>

<Property oe:key="vaIPAddress" oe:value=""/>

<Property oe:key="vaNetmask" oe:value=""/>

<Property oe:key="vaGateway" oe:value=""/>

<Property oe:key="vaDefaultVlan" oe:value=""/>

<Property oe:key="vaExternalIPAddress" oe:value=""/>

<Property oe:key="vaExternalNetmask" oe:value=""/>

<Property oe:key="vaExternalGateway" oe:value=""/>

<Property oe:key="vaExternalDefaultVlan" oe:value=""/>

<Property oe:key="vaManagementIPAddress" oe:value=""/>

<Property oe:key="vaManagementNetmask" oe:value=""/>

<Property oe:key="vaManagementGateway" oe:value=""/>

<Property oe:key="vaManagementDefaultVlan" oe:value=""/>

<Property oe:key="vaPrimaryDNS" oe:value=""/>

<Property oe:key="vaSecondaryDNS" oe:value=""/>

<Property oe:key="vaWINSServer" oe:value="1.2.3.4"/>

<Property oe:key="vaDNSDomain" oe:value="ics.company.com"/>

<Property oe:key="vaAdminUsername" oe:value="admindb"/>

<Property oe:key="vaAdminPassword" oe:value="Password123$"/>

<Property oe:key="vaCommonName" oe:value="ics-ext-port.company.com"/>

<Property oe:key="vaOrganization" oe:value="Ivanti"/>

<Property oe:key="vaRandomText" oe:value="randomtextrandomtextrandomtextrandomtext"/>

<Property oe:key="vaAcceptLicenseAgreement" oe:value="y"/>

<Property oe:key="vaEnableLicenseServer" oe:value="n"/>

<Property oe:key="vaAdminEnableREST" oe:value=""/>

<Property oe:key="vaAuthCodeLicense" oe:value=""/>

<Property oe:key="vaConfigURL" oe:value="http://a.b.c.d/ics_config.xml"/>

<Property oe:key="vaConfigServerCACertPEM" oe:value=""/>

<Property oe:key="vaConfigData" oe:value=""/>

<Property oe:key="vaInternalPortReconfigWithValueInVAppProperties" oe:value="1"/>

<Property oe:key="vaManagementPortReconfigWithValueInVAppProperties" oe:value="1"/>

<Property oe:key="vaExternalPortReconfigWithValueInVAppProperties" oe:value="1"/>

</PropertySection>

 

Parameter Name

Type

Description

vaIPAddress

IP address

Internal interface IP

vaNetmask

IP address

Internal interface subnet mask

vaGateway

IP address

Internal interface IP gateway

vaDefaultVlan

integer

VLAN number to assign to this interface

vaExternalIPAddress

IP address

External interface IP

vaExternalNetmask

IP address

External interface subnet mask

vaExternalGateway

IP address

External interface IP gateway

vaExternalDefaultVlan

Integer

VLAN number to assign to this interface.

vaManagementIPAddress

IP address

Management interface IP

vaManagementNetmask

IP address

Management interface subnet mask

vaManagementGateway

IP address

Management interface IP gateway

vaManagementDefaultVlan

Integer

VLAN number to assign to this interface

vaPrimaryDNS

IP address

Primary DNS IP

vaSecondaryDNS

IP address

Secondary DNS IP

vaWINSServer

IP address

Windows server IP

vaDNSDomain

string

Windows domain name

VaAdminUsername

string

Admin username

vaAdminPassword

string

Admin password

vaCommonName

string

Common name

vaOrganization

string

Organization name

vaRandomText

string

Random text to generate self-signed certificate

vaAcceptLicenseAgreement

character

y” to accept the license agreement

vaEnableLicenseServer

character

y” to enable it as VLS server. “n” to bring it up as a ICS node.

vaAdminEnableREST

character

y” to enable REST for administrator user

vaAuthCodeLicense

string

Authentication code that needs to be obtained from Ivanti.

vaConfigURL

String URL

Http based URL where XML based ICS configuration can be found.

vaConfigServerCACertPEM

string

PEM format of CA certificate.

vaConfigData

string

base64 encoded XML based ICS configuration.

vaInternalPortReconfigWithValueIn
VAppProperties

integer

The Internal port overwrite property. If set to 1, overwrite the virtual appliance’s internal port settings with the ones specified during deployment. Set this value as 1.

vaManagementPortReconfigWithValueIn
VAppProperties

integer

The Management port overwrite property. If set to 1, overwrite the management port-related parameters in the ICS with the ones defined here. Set this value as 1.

vaExternalPortReconfigWithValueIn
VAppProperties

integer

The External port overwrite property. If set to 1, overwrite the external port-related parameters in ICS/IPS with the ones defined here. Set this value as 1.

IICS supports zero touch provisioning. This feature can detect and assign DHCP networking settings automatically at the ICS boot up. The following ICS parameters should be set to null in order to fetch the networking configuration automatically from the DHCP server.

vaIPAddress

vaExternalIPAddress

vaManagementIPAddress

vaNetmask

vaExternalNetmask

vaManagementNetmask

vaGateway

vaExternalGateway

vaManagementGateway

vaPrimaryDNS

vaSecondaryDNS

vaDNSDomain

Leased IP from DHCP server should be valid for a long time as ICS does not request for DHCP renewals.

vTPM and Secure Boot Support on OpenStack

This section provides guidance on enabling virtual Trusted Platform Module (vTPM) and Secure Boot features for Ivanti Connect Secure virtual appliances deployed on OpenStack. Implementing vTPM and Secure Boot improves data protection by supporting encrypted secrets and secure firmware validation.

vTPM Overview

This section describes the process and prerequisites for enabling vTPM (virtual Trusted Platform Module) and Secure Boot for Ivanti Connect Secure virtual appliances on OpenStack. Enabling these security features ensures that sensitive data such as encryption keys are stored securely and validates the integrity of the virtual appliance firmware during boot. The guidance provided here will help you configure a compliant and robust OpenStack environment for secure ICS deployments.

Enabling vTPM

To enable vTPM (virtual Trusted Platform Module) support on OpenStack for Ivanti Connect Secure virtual appliances, ensure the following requirements and steps are met on each compute host:

Prerequisites:

An OpenStack key manager service, such as Barbican, must be deployed and configured on the controller node. This service is required to store the secrets used for encrypting virtual device files at rest.

The user deploying the ICS virtual appliance must have the creator role in the corresponding OpenStack project to allow Barbican to create ICS secrets.

The swtpm binary and associated libraries must be installed on each compute node

/etc/nova/nova-compute.conf should have following configuration to support virtual TPM.

Set the config option to 'True' inof compute node. This will enable support for both TPM version 1.2 and 2.0.

With the above requirements satisfied, verify vTPM support by inspecting the traits on the compute node’s resource provider:

Enabling Secure Boot

To enable UEFI secure boot on OpenStack, follow steps as per OpenStack documentation.

You can verify UEFI Secure Boot support by inspecting the traits on the compute node’s resource provider:

In order to boot Ivanti virtual ICS in secure boot mode, perform following steps.

1.Extract Ivanti released OVMF firmware and VARS file from KVM ZIP artifact.

2.Ivanti released OVMF firmware and VARS file needs to be copied to /usr/share/OVMF directory of compute nodes.

Ivanti released VARS file has secure boot certificate required to boot virtual ICS in secure boot mode.

3.Copy 40-edk2-x86_64-secure-enrolled.json to 10-edk2-x86_64-secure-enrolled.json and modify 10-edk2-x86_64-secure-enrolled.json file in /usr/share/qemu/firmware directory to use Ivanti’s secure boot OVMF files.


b. Following contents need to be changed to use Ivanti’s released OVMF files.

4.Restart libvirtd and nova-compute on compute nodes

Setting Virtual ICS Image Attributes

Following attributes need to be set to enable secure boot for virtual ICS.

1.Select virtual ICS image.

2.Edit image.

3.Select Metadata section.

4.Update following attributes.

hw_disk_bus='virtio'

hw_firmware_type='uefi'

hw_machine_type='q35'

hw_tpm_model='tpm-crb'

hw_tpm_version='2.0'

os_secure_boot='required'

If above listed attributes are enabled then virtual ICS will boot with secure boot enabled and vTPM attached.

OpenStack Limitations

1.Snapshot and Restore functionality does not work in OpenStack for ICS with vTPM.
a. Source
b. Spawning from an image created by snapshotting a VM with a vTPM will result in a fresh, empty vTPM

2.Operations like “hard reboot” or “shut off/start” may fail to start ICS with vTPM. Refer Bug link

a. Above error may be seen.
b. OpenStack fix link is needed to solve this issue.
c. Alternately, following workaround can be added in your OpenStack environment.

 

Deploying Ivanti Connect Secure Appliance on Azure

Prerequisites and System Requirements on Azure

To deploy the Ivanti Connect Secure Virtual Appliance on Azure custom deployment, you need the following:

A Microsoft Azure account

Access to the Microsoft Azure portal (https://portal.azure.com)

Ivanti Connect Secure Virtual Appliance Image (.vhd file).

Azure Resource Manager template (ARM template)

Supported Platform Systems

This section helps you in choosing the instance types that should be deployed with Ivanti Connect Secure for Azure.

ISA4000-V

ISA6000-V

ISA8000-V

Create a Resource Group

To create a Resource group, do the following:

1.Log into Azure portal.

2.Navigate to Resource Groups. Enter unique resource group name.

3.Click Review + create to finalize and create resource group.

Create a Storage Account

To create a Storage Account, do the following:

1.Log in to the Azure portal.

2.Click New and create a Storage Account.

3.Choose the resource group you have already created.

4.Enter a unique name for the storage account name.

5.Click Review + create to create storage account.

Upload ICS Appliance Image to Storage Account

To upload Ivanti Connect Secure Virtual Appliance image to Stroage Account, do the following:

1.Download the Azure ICS image file (ics-azure-isa-v-<releaseno>-<buildno>-package.zip) which is in the zipped format.

The package contains the following components:

ISA-V-AZVA-ICS-<releaseno>-<buildno>-SERIAL-azure.vhd: VHD disk image for Ivanti Connect Secure VA, to upload to Azure

ivanticonnectsecure-gallery: Publish VHD as Shared Image Gallery image

ivanticonnectsecure-2-nics: Deploy ICS with 2 NICs (new VNet)

ivanticonnectsecure-2-nics-existing-vnet: Deploy ICS with 2 NICs (existing VNet)

ivanticonnectsecure-3-nics: Deploy ICS with 3 NICs (new VNet)

ivanticonnectsecure-3-nics-existing-vnet: Deploy ICS with 3 NICs (existing VNet)

azuredeploy.json: ARM deployment templates

Do not use old release templates. Always use the latest templates for gallery deployment and ICS VM deployment to ensure compatibility and proper functionality.

2.Unzip the file and look for the Ivanti Connect Secure Virtual Appliance vhd image.

3.Log in to the Azure portal.

4.In the Azure portal, search for storage accounts and select the Storage Account you have created.

5.To upload ICS Virtual Appliance image. Select Storage browser in the left menu.

6.Click Blob containers and select your target container.

7.Click Upload at the top, browse for your file and hit the final Upload button and upload.

8.Inside your Storage Account, go to the left menu and click Storage browser under Data storage.

9.Under Blob containers, find and select your container (e.g., az-images) where the VHD file is uploaded.

10.Inside the container, find your VHD file (e.g., ISA-V-AZVA-ICS-<releaseno>-<buildno>-SERIAL-azure.vhd). Click on the file to open its properties.

11.In the Overview or properties pane, look for the field named URL. Click the copy icon next to it.

The URL will be in this format: https://<name>.blob.core.windows.net/az-images/ISA-V-AZVA-ICS-<releaseno>-<buildno>-SERIAL-azure.vhd. This URL is need to deploy the Azure Gallery

Upload Azure Resource Manager Template to Gallery

1.Navigate to Custom Deployment.

2.Select Build your template in the editor.

3.Locate the Azure Gallery deployment template file in folder (ivanticonnectsecure-gallery/azure-gallery-deploy.json).

4.Open this file and Copy its content and paste the into the designated field.

5.Click Save to apply the template.

6.Fill or modify the following parameters:

Region (mandatory): place

ICS Location: Location of the Shared Image Gallery (Where Azrure Gallery image is deployed)

Resource Group (mandatory): A resource group is a collection of resources that share the same lifecycle, permissions, and policies, where ICS is getting deployed

ICS Storage Account Name: Storage account name where ICS image is uploaded

ICS Storage Account Resource Group Name: Resource group of the existing storage account where ICS image is uploaded

ICS Image Location URI: The is the URL to the location where ICS Azure vhd image is stored

Gallery Name: The name of the Shared Image Gallery (this value is from Azure Gallery image)

Image Definition Name: The name of the Image Definition (this value is from Azure Gallery image)

Publisher: The name of the VM image definition publisher

Offer: The name of the VM image definition offer

SKU: The name of the VM image definition SKU

Version Name: The VM image version name in semantic version pattern. The allowed characters are digit and period. For example: 0.0.1, 15.35.0. (this value is from Azure Gallery image)

1.Click Review+ create to review your selections.

2.Click Create. Deployment will take 10 to 15 Minutes.

After a successful deployment, the Azure Gallery image for ICS will be ready for deploying the ICS virtual appliance.

ICS Virtual Machine Deployment

1.Navigate to Custom Deployment.

2.Select Build your own template in the editor.

3.Download the Azure deployment template 2-NIC or 3-NIC from "Azure-template" folder (ivanticonnectsecure-3-nics/azuredeploy.json) to get azuredeploy.json.

ISA4000-V supports only 2-NIC deployment. ISA6000-V and ISA8000-V support 2-NIC and 3-NIC deployments.

Standard Model

vCPU

RAM(GiB)

Disk Space

NICs

ISA4000-V (Standard_D4s_v6) 4 16 GB 80 GB 2
ISA4000-V (Standard_D4ds_v6) 4 16 GB 80 GB 2
ISA6000-V (Standard_D8s_v6) 8 32 GB 80 GB 3

ISA6000-V (Standard_D8ds_v6)

8 32 GB 80 GB 3

ISA8000-V (Standard_D16ds_v6)

16

64 GB

80 GB

3

ISA4000-V (Standard_F4as_v6)

4

16 GB

80 GB

2

ISA6000-V (Standard_F8as_v6)

8 32 GB 80 GB 3

ISA8000-V (Standard_F16as_v6)

16

64 GB

80 GB

3

4.Copy and paste the azuredeploy.json into the designated field.

5.Edit Virtual Machine Standards - variables section "variables": ["VirtualMachineSize": "Standard_D8ds_v6",]

6.Click Save to apply the template.

You can modify the following parameters in the VM Template to suit your requirements:

Gallery name, Image Definition name, and Image Version number

Network Details

7.Fill or modify the following parameters:

ICS Storage Account Name: Storage account name where ICS image is uploaded

ICS Storage Account Resource Group Name: Resource group of the existing storage account where ICS image is uploaded

Gallery Name: The name of the Shared Image Gallery (This value is from Azure gallery image created)

Image Definition Name: The name of the Image Definition (This value is from Azure gallery image created)

Version Name: The VM image version name in semantic version pattern. The allowed characters are digit and period. For example: 0.0.1, 15.35.0 (This value is from Azure gallery image created)

ICS VM Name: This is the name given to ICS Virtual Appliance.

ICS Admin User: Ivanti Connect Secure Admin User, value must be 2-30 characters long.

ICS Admin Password: Ivanti Connect Secure Admin Password, value must be 12-128 characters long and no special characters.

SSH Public Key: This is an RSA public key that is used to access Ivanti Connect Secure via SSH.

ICS Config: This section contains provisioning parameters that are required during the deployment of a Virtual Appliance. An XML-based configuration file can be present in another Virtual Machine in Azure cloud or in the corporate network which is accessible for Ivanti Connect Secure through site-to-site VPN between Azure and the corporate data center.

Key pair name: The new ssh key pair name.

DNS Label Prefix Ext: This is the prefix for External Interface DNS label.

DNS Label Prefix Mgmt: This is the prefix for Management Interface DNS label.

In case of two NIC deployment, the management port would not be auto-populated and admin has to provide details for internal port manually.

VNet Address Space: This is a Virtual Network address space

Internal Subnet: Subnet from which Ivanti Connect Secure Internal Interface needs to lease IP.

External Subnet: Subnet from which Ivanti Connect Secure External Interface needs to lease IP.

Management Subnet: Subnet from which Ivanti Connect Secure Management Interface needs to lease IP.

Tunnel Subnet: Subnet which will be configured as Tunnel IP pool in Ivanti Connect Secure VPN profile.

8.Click Review + create to review your selections.

9.Click Create. A prompt will appear for generating new key pairs

10.Click "Download + Create" to download the PEM key and begin deploying the virtual appliance (VA).

This action will create all required network resources, routes, and deploy the VA.

11. Once the virtual appliance (VA) status shows as "Created," the VA will appear in the list of Virtual Machines.

The new ICS virtual appliance will boot with the following features enabled:

Secure Boot

vTPM (virtual Trusted Platform Module)

Disk controller type set to NVME

25.1.3.0 Release

ISA VA Platforms for 25.1.3.0

Deploying Ivanti Connect Secure Appliance on AWS

Deploying Ivanti Connect Secure Appliance on GCP

ISA VA Platforms for 25.1.3.0

Platform

Qualified

Qualified Cloud VM Types /Equivalent ISA-V

Microsoft Hyper-V Server 2022 Q (4 vCPUs / ISA4500-v), (8 vCPUs/ ISA6500-v), (12 vCPUs/ ISA8500-v)
Azure Q

• ISA4500-V (Standard_D4ds_v6)

• ISA4500-V (Standard_D4s_v6)

• ISA6500-V (Standard_D8ds_v6)

• ISA6500-V (Standard_D8s_v6)

• ISA8500-V (Standard_D16ds_v6)

• ISA4500-V (Standard_F4as_v6)

• ISA6500-V (Standard_F8as_v6)

• ISA8500-V (Standard_F16as_v6)

AWS Q

• ISA4500-V (c7i.xlarge)

• ISA6500-V (c7i.2xlarge)

• ISA8500-V (c7i.4xlarge)

• ISA4500-V (m7i.xlarge)

• ISA6500-V(m7i.2xlarge)

• ISA8500-V (m7i.4xlarge)

• ISA4500-V (c7i-flex.xlarge)

• ISA6500-V (c7i-flex.2xlarge)

• ISA8500-V (c7i-flex.4xlarge)

• ISA4500-V (m7i-flex.xlarge)

• ISA6500-V (m7i-flex.2xlarge)

• ISA8500-V (m7i-flex.4xlarge)

GCP Q

• ISA4500-V (n4-standard-4)

• ISA6500-V (n4-standard-8)

• ISA8500-V (n4-standard-16)

For the deployment details, see:

VMware: Deploying Virtual ICS from OVF

HyperV: Deploying Ivanti Connect Secure Appliance on Hyper-V

Azure: Deploying Ivanti Connect Secure Appliance on Azure

In 25.1.3.0 release, the legacy SCSI storage subsystem is replaced with a high-performance NVMe (Non-Volatile Memory Express) controller on VMware.

Deploying Ivanti Connect Secure Appliance on AWS

Prerequisites

SNAT End Point Tunnel IP

The packets transmitted from ICS Internal Interface are dropped by AWS Virtual Gateway in L3 traffic. This is because the source IP and MAC address are not matching and the transit routing is not supported.

Ivanti Connect Secure must be able to SNAT these packets to the Internal interface IP which belongs to a subnet within the VPC.

To NAT endpoint tunnel IP to Internal interface IP, do the following:

1.Log in to Ivanti Connect Secure admin console.

2.Navigate to System > Network > VPN Tunneling.

3.Enable Source NATTING. By default, Source NATTING is disabled.

Enabling SNAT on ICS would reduce the number of connections, since one IP will be handling the traffic for all the end user Ivanti client connections. So, it is recommended that you purchase a NAT gateway and assign it to ICS.

Deploying Ivati Connect Secure using AWS Marketplace

Ivati Connect Secure is made available in AWS Market Place. The CloudFormation templates are available at Amazon marketplace.

Prerequisites and System Requirements on AWS Marketplace

To deploy the Ivati Connect Secure Virtual Appliance on AWS Marketplace, you need the following:

An AWS account

Access to the AWS Marketplace (https://aws.amazon.com/marketplace)

Ivati Connect Secure licenses *

Deploying Ivati Connect Secure on AWS Marketplace

4.Launch AWS Marketplace using the URL: https://aws.amazon.com/marketplace and search with keyword Ivanti.

AWS Marketplace contains the following two Ivati Connect Secure SKUs:

Ivati Connect Secure - BYOL 2 NIC

Ivati Connect Secure - BYOL 3 NIC

5.Select either 3-NIC model or 2-NIC model based on your requirement. In the Product Subscription page displayed, click Continue to Subscribe. In this section, 3-NIC model is chosen as example.

6.After subscribing, proceed to configuration by clicking Continue to Configuration.

7.In Fulfillment Option, select either Existing VPC or New VPC that you want to deploy and click Continue to Launch. In the Launch page displayed, select Launch CloudFormation and click Launch.

Specify Template

1.In the Create stack wizard, in the Specify Template page choose the template that describes your stack’s resources and their properties and, click Next.

Specify Stack Details

1.In the Specify Stack Details page, specify a name for the stack.

2.In the Parameters section, use the default parameter values. These are defined in the CloudFormation template.

3.In the Ivati Connect Secure Configuration section:

Select Ivati Connect Secure VM size. By default it is set to m5.xlarge.

By default, ICS admin user name is configured. You can give any other user name if you want to.

Enter the Admin user password.

Config Data: This is pre-populated as part of AWS Cloudformation template. In order to customize the config parameters, see [[[Undefined variable Custom.ICS_long]]] Provisioning Parameters.

Select SSH Key Name of EC2 key pair. This key is used to access ICS via SSH. The SSH keys are generated using ssh-keygen on Linux and OS X, or PuTTyGen on Windows. For details about generating the SSH key pairs, refer http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html.

Without providing the SSH key, an error is displayed during deployment.

Accessing the ICS using SSH will work on releases prior to 22.4R2 and all FIPS releases.

In the Security Configuration section, enter Remote Access CIDR IP range that permits end user access to Ivati Connect Secure instance.

Review

1.In the Review page, verify the details and click Create.

2.Wait for a few minutes while it creates all the resources. This completes deploying ICS on AWS Marketplace.

To access Ivati Connect Secure Virtual Appliance, see Accessing the [[[Undefined variable Custom.ICS_long]]] Virtual Appliance

Resizing a Disk Volume in the AWS portal

From 22.6R2 release, On fresh installation, 80 GB disk space is available by default. You can modify or increase the disk size only once on fresh installation or upgrade of the ICS images, but not on rollback or factory reset images.

If the user is upgrading to 22.6R2 or later, then the disk size change from 40 GB to 80 GB have to be done prior to upgrade on AWS cloud platform.

Disk Size Allocation is supported from 22.6R2 and later releases.

1.To increase the data volume size, in the navigation pane, choose Instances.

2.Under the Storage tab, select the Volume ID of your data volume.

3.Click Modify volume.

4.The Modify volume screen displays the volume ID and the volume’s current configuration, including type, size, input/output operations per second (IOPS), and throughput. Change the Size to 80 GB.

5.Choose Modify, and when prompted for confirmation choose Modify again. You are charged for the new volume configuration after volume modification starts.

Custom Ivati Connect Secure Deployment on AWS Portal

Prerequisites and System Requirements on AWS

To deploy the Ivati Connect Secure Virtual Appliance on AWS, you need the following:

An AWS account

Access to the AWS portal (https://console.aws.amazon.com/)*

Ivati Connect Secure Virtual Appliance AMI ID

AWS CloudFormation template

Ivati Connect Secure licenses **

Site-to-Site VPN between AWS and the corporate network (optional)

Note: This is needed only if the Ivati Connect Secure users need to access corporate resources.

Ivanti License Server (optional)**

Located at corporate network, accessible through site-to-site VPN

Ivati Connect Secure configuration in XML format (optional)

Ivati Connect Secure Virtual Appliance can be deployed only through AWS CloudFormation style.

Deploying Ivati Connect Secure on Amazon Web Services

As depicted in the below diagram, a remote user can use Ivati Connect Secure to securely access cloud resources as well as corporate resources. To access corporate resources, the Ivati Connect Secure administrator needs to ensure that site-to-site VPN is already established between AWS and the corporate network.

Supported Platform Systems

From 25.1.3.0 release, ICS supports Secure Boot and Nitro TPM, and new instance types which are powered by 4th gen Intel Xenon Scalable processors and have support of DDR5 memory.

ISA4500-V (xlarge)

ISA6500-V (2xlarge)

ISA8500-V (4xlarge)

Model

vCPU

Memory

Diskspace

c7i.xlarge 4 8 80 GB
c7i.2xlarge 8 16 80 GB
c7i.4xlarge 16 32 80 GB
m7i.xlarge 4 16 80 GB

m7i.2xlarge

8

32

80 GB

m7i.4xlarge

16

64

80 GB

c7i-flex.xlarge

4

8

80 GB

c7i-flex.2xlarge

8

16

80 GB

c7i-flex.4xlarge

16

32

80 GB

m7i-flex.xlarge

4

16

80 GB

m7i-flex.2xlarge

8

32

80 GB

m7i-flex.4xlarge

16

64

80 GB

Customs Templates

To deploy 2-NIC or 3-NIC in an existing VPC respectively using the links below:

To deploy 2-NIC or 3-NIC in a new VPC respectively using the links below:

Registering the AMI

This section describes the steps to register the AMI. This is the one-time activity to be followed to deploy Ivati Connect Secure on AWS.

To register AMI, do the following:

1.Login to AWS Portal.

2.Search for the AMI name in the Public images: ISA-V-NITRO-ICS-22.2R1-657.1-SERIAL-nitro.img. Images can be searched under public AMI section and copy AMI ID for custom deployment using custom templates. To determine AMI for 2 NIC and 3 NIC based on the AMI name or AMI ID, refer to the KB article.

To deploy 2-NIC or 3-NIC in an existing VPC and new VPC respectively using the links above.

ICS gateway AMIs are available in all AWS regions (except China).

Deploying AWS Cloud ICS using Terraform Template

This section describes how to install terraform template, and deploy ICS on aws with 2 NICs and 3 NICs.

Installing Terraform Template

1.Go to the Terraform website and install Terraform on a Linux VM of your choice at usr/local/bin.

2.Install AWS CLI.

3.Configure AWS Access key and AWS Secret key under .bashrc directory.

Example: AWS_ACCESS_KEY="XXXXXXXX"; export AWS_ACCESS_KEY

AWS_SECRET_KEY="YYYYYYYY"; export AWS_SECRET_KEY

4.Deploy the ICS using the Terraform Template. To download the Cloud Templates, see product-downloads.

Beginning with Release 22.7R2.3, the default password has been removed from the terraform template file and the Admin's are required to configure the password as needed.

To configure the required password:

1.Locate pulse-config within the .tf file.

2.Assign the desired value to the admin-password field.

Configuring Base Setup

1.Customize and set the variables in variables.tf file based on the requirement.

Example: Region, AMI-id, VPC name, subnet IP address details, instance name etc.

2.Create a directory base_setup.

3.Copy the files variables.tf and base_setup.tf into the base_setup directory.

4.Change the key based on your requirement.

5.Change the files permission with +x .

linux# chmod +x *.*

6.Run the following commands creating base setup.:

linux# terraform init

linux# terraform apply

7.When prompted for admin input for deployment, type "yes".

The Base setup will create VPC, Subnets, Security Groups, Internet Gateway and Route Table.

Deploying ICS with 2 NICs

1.Customize and set the variables in variables.tf file based on the requirement.

2.Change directory to ics_2_nics.

3.Copy the files variables.tf and ics_2_nics.tf into the ics-2nic directory.

4.Run the following commands:

linux# terraform init

linux# terraform apply

This terraform will deploy 2 NIC ICS.

Deploying ICS with 3 NICs

1.Customize and set the variables in variables.tf file based on the requirement.

2.Change directory to ics_3_nics.

3.Copy the files variables.tf and ics_3_nics.tf into the ics-3nic directory.

4.Run the following commands:

linux# terraform init

linux# terraform apply

This terraform will deploy 3 NIC ICS.

Ivati Connect Secure Provisioning Parameters

Provisioning parameters are those parameters which are required during the deployment of a virtual appliance. Ivati Connect Secure accepts the following parameters as provisioning parameters in the XML format.

<pulse-config>

<primary-dns><value></primary-dns>

<secondary-dns><value></secondary-dns>

<wins-server><value></wins-server>

<dns-domain><value></dns-domain>

<admin-username><value></admin-username>

<admin-password><value></admin-password>

<cert-common-name><value></cert-common-name>

<cert-random-text><value></cert-random-text>

<cert-organisation><value></cert-organisation>

<config-download-url><value></config-download-url>

<config-data><value></config-data>

<auth-code-license><value></auth-code-license>

<enable-license-server><value></enable-license-server>

<accept-license-agreement><value></accept-license-agreement >

<enable-rest><value></enable-rest>

<registration-code> 1grkL2Xbr </registration-code>

<registration-fqdn>auto.toad.pzt.dev.perfsec.com</registration-fqdn>

<enable-proxy>n</enable-proxy>

<proxy-host></proxy-host>

<proxy-port></proxy-port>

<proxy-username></proxy-username>

<proxy-password></proxy-password>

<register-network-interface>external</register-network-interface>

</pulse-config>

The below table depicts the details of the xml file.

#

Parameter Name

Type

Description

1

wins-server

IP address

Wins server for Ivati Connect Secure

2

dns-domain

string

DNS domain of Ivati Connect Secure

3

cert-common-name

string

Common name for the self-signed certificate generation. This certificate is used as the device certificate of Ivati Connect Secure

Random text for the self-certificate generation

Organization name for the self-signed certificate generation

4

cert-random-text

string

5

cert-organization

string

6

config-download-url

String URL

Http based URL where XML based Ivati Connect Secure configuration can be found. During provisioning, Ivati Connect Secure fetches this file and comes up with preloaded configuration. XML based configuration can be present in another VM in AWS cloud or at corporate network which is accessible for Ivati Connect Secure through site to site VPN between AWS and corporate data center

7

config-data

string

base64 encoded XML based Ivati Connect Secure configuration

8

auth-code-license

string

Authentication code that needs to be obtained from Ivanti

9

enable-license-server

string

If set to ‘y’, ICS will be deployed as a License server.

If set to ‘n, ICS will be deployed as a normal server.

10

accept-license-agreement

string

This value is passed to the instance for configuration at the boot time. By default, this value is set to “n”. This value must be set to “y”.

11

enable-rest

string

If set to ‘y’, REST API access for the administrator user is enabled.

  • In the above list of parameters, primary dns, dns domain, admin username, admin password, cert-random name, cert-random text, cert-organization and accept-license-agreement are mandatory parameters. The other parameters are optional parameters.
  • The XML parsing fails if the following characters are used in the strings:
    • "
    • <
    • >
    • &
  • Ivanti Connect Secure supports zero touch provisioning. This feature can detect and assign DHCP networking settings automatically at the Ivanti Connect Secure boot up. The Ivanti Connect Secure parameters should be set to null in order to fetch the networking configuration automatically from the DHCP server.

The below table describes the new parameters that are added in the XML file and these are applicable only for nSA-managed 9.x and ICS 21.x versions.

Parameter

Type

Description

registrationCode

string

The registration code, which is generated during the ICS gateway registration on nSA. Example: KyZR6YDL8

registrationFQDN

string

The registration FQDN name, which is generated during the ICS gateway registration on nSA. Example: sample.domain.com

enableproxy

string

Default is set to n.

proxyHost

string

The proxy server name.

proxyPort

integer

The port number of the proxy server. Example: 8080

proxyUsername

string

The username of the proxy server. Example,:usr

proxyPassword

string

The password of the proxy server. Example: pxx124

registerNetworkInterface

string

The interface through which the gateway registers with nSA. Example: external

Provisioning Ivati Connect Secure with Predefined Configuration

The Ivati Connect Secure Virtual Appliance can be provisioned on AWS with a predefined Ivati Connect Secure configuration. The provisioning can be done in the following two ways:

Ivati Connect Secure administrator needs to provide the location of the XML-based configuration as a provisioning parameter. Refer [[[Undefined variable Custom.ICS_long]]] Provisioning Parameters for details about the Ivati Connect Secure specific provisioning parameters.

Ivati Connect Secureconfiguration can be kept on AWS or on a machine located in the corporate network. If it is in the corporate network, the Ivati Connect Secure administrator needs to ensure that site-to-site VPN between AWS to corporate network is already established so that Ivati Connect Secure can access the machine located in the corporate network.

Ivati Connect Secure administrator provides the configuration data encoded in the base64 encoded xml in the CloudFormation template.

Configuring Licenses on the Ivati Connect Secure Appliance

Evaluation licenses are provided, to add more licenses, the Ivati Connect Secure administrator needs to leverage the Ivanti License server.

Ivanti License Server in Corporate Network

Ivanti License Server in Cloud Network

Ivati Connect Secure virtual machines (VM) are enabled to provision licenses through the Ivanti Cloud Licensing Service. For this, administrator needs to obtain an Authentication code from Ivanti Support and apply it in Download Licenses page of ICS admin console. The ICS also periodically sends heartbeat messages to CLS for auditing purposes.

The Authentication code can also be specified in the CloudFormation template. When ICS comes up, it automatically fetches the Authentication code.

Adding Authentication Code in ICS Admin Console

Including Authentication Code in CloudFormation Template

Adding Authentication Code in ICS Admin Console

To add Authentication code:

5.Go to System > Configuration > Licensing > Download Licenses.

6.Under On demand license downloads, enter the Authentication code in the text box.

7.Click on Download and Install. For more info see Gateway Licensing.

Including Authentication Code in CloudFormation Template

To include Authentication code in the CloudFormation template:

In the CloudFormation template, go to the ICSConfig section.

For the element <auth-code-license>, enter the Authentication code as the content.

Save the template.

For details about the license configuration, refer to License Configuration Guide.

System Operations

The AWS portal provides Start, Restart Stop and Terminate operations to control the Virtual Appliance connection.

On the AWS portal, select AWS Services > Launch Instance. From the Actions menu, select Instance State.

Click Start to start a VM

Click Stop to stop the VM

Click Restart to restart the VM

Click Terminate to terminate the VM

Network Configuration

IP Address Assignment for Internal, External and Management Interfaces

Each interface in AWS can have private and public IP addresses. Sample CloudFormation Templates provided by Ivati Connect Secure creates the Ivati Connect Secure Virtual Appliance with public and private IP addresses for external and management interfaces and only private IP address for internal interface. More details about IP address types on AWS can be seen at: https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/vpc-ip-addressing.html

IP Addressing Modes

When Ivati Connect Secure gets deployed by using the sample templates provided by Ivanti, Ivati Connect Secure comes up with multiple interfaces. If you take an example of a template “pulsesecure-ICS-3-nics.zip” provided by Ivanti, you notice the following things.

ICS external interface and ICS management interface have both Elastic and Private IP addresses.

Modifying Network Parameters After Deployment

Since Networking Infrastructure is provided by AWS, a ICS admin cannot change Networking configuration after deployment. Hence, both admin UI and ssh do not support changing network configuration.

Controlling the Selection of Internal, External and Management Interfaces

Sample CloudFormation template, provided by Ivanti, requests AWS fabric to create three Network Interfaces. While running this template, AWS fabric creates interfaces named eth0, eth1 and eth2 and attaches them to ICS Virtual Interface.

So, the question is, among eth0, eth1 and eth2 which network interface will become external, internal or management interface? Below table answers this question.

Interface Name

ICS Interface

eth0

internal interface

eth1

external interface

eth2

management interface

Then, question is how you can control the order of network interfaces named eth0, eth1 and eth2 created through CloudFormation template?

The Ivati Connect Secure Virtual Appliance is qualified with internal interface as primary and other two are secondary. In the following code snippet, three network interfaces get assigned to VM. These three NICs with ID “nic1”, “nic2” and “nic3” are internally mapped to ‘eth0’, ‘eth1’, and ‘eth2’ respectively.

"EC2Instance": {

"Type": "AWS::EC2::Instance",

"DependsOn": [

"EIPAssoc0",

"EIPAssoc1"

],

"Properties": {

"ImageId": {

"Fn::FindInMap": [

"ICSAMI",

{

"Ref": "AWS::Region"

},

"img"

]

},

"KeyName": {

"Ref": "KeyName"

},

"InstanceType": {

"Ref": "InstanceType"

},

"NetworkInterfaces": [

{

"NetworkInterfaceId": {

"Ref": "Eth0"

},

"DeviceIndex": "0"

},

{

"NetworkInterfaceId": {

"Ref": "Eth1"

},

"DeviceIndex": "1"

}

],

ICS converts eth0 to int0, eth1 to ext0 and eth2 to mgmt0. This means, the network interface with ID nic1 will be internal interface, nic2 will be external interface and nic3 will be management interface.

The below table depicts this scenario well:

Interface Name

ICS Interface

Network ID

eth0

internal interface

nic1

eth1

external interface

nic2

eth2

management interface

nic3

Accessing the Ivati Connect Secure Virtual Appliance

Accessing the Ivati Connect Secure Virtual Appliance as an Administrator

In the AWS portal, navigate to CloudFormation section. Select the stack where ICS is deployed and then click on the ‘Outputs’ tab. Note down the ICS management, internal and external address from the table as shown in figure.

Use the credentials provided in the provisioning parameters to log in as the administrator in the ICS Admin interface with URL https://<PCS-IP>/admin. The default ICS Admin UI user configured in the CloudFormation config file is: user ‘admin’ and password ‘password1234’.

The administrator can configure Active Directory located in the corporate network for user authentication. The Ivati Connect Secure Virtual Appliance administrator can check troubleshooting tools provided in the Ivati Connect Secure admin UI (System > Maintenance > Troubleshooting), to verify whether Ivati Connect Secure is able to reach other cloud resources as well as corporate resources. For this, AWS network administrator needs to ensure that all other resources have Ivati Connect Secure Internal interface as its default gateway.

Accessing the Ivati Connect Secure Virtual Appliance as an End User

After successfully deploying ICS on AWS, go to the Outputs section and copy the Ivanti External Interface details.

Seamless Migration of ICS configuration on AWS

Overview

This section describes the seamless migration of the ICS configuration on Amazon Web Services.

Process

The process for seamless migration of the ICS configuration on AWS marketplace is as follows:

1.Setting up and deploying a new VM, refer [[[Undefined variable Custom.ICS_long]]] on Amazon Web Services.

2.ICS configuration migration, refer Provisioning Ivati Connect Secure with Predefined Configuration.

3.License migration, refer Configuring Licenses on the [[[Undefined variable Custom.ICS_long]]] Appliance.

4.Network IP address migration.

Before You Begin

1.Deploy a ICS in AWS environment with new software version, possibly with existing Virtual Private Cloud instance. Note down the private and public IP addresses.

2.Check the reachability of the ICS using public IP address for newly deployed ICS.

3.Perform a cleanup of the appliance before exporting the user.cfg to reduce the size of the user configuration file.

Disable any debug logging

Delete logs

Delete any old snapshots

Clear event logs

Delete old ESAP

Delete old Ivanti Clients

Clean up external user records

Network IP address Migration

To change IP address of the ICS instance on AWS for internal and external ports:

1.In the AWS environment, navigate to Elastic IP dashboard of port network settings. Select the public IP address entry and select Disassociate Elastic IP address under Actions.

2.Select the private IP address entry and select Disassociate address under Actions.

3.For external port interface, select the entry and select Delete under Actions.

Internal port is associated as primary interface of the ICS deployed earlier. For internal port IP address migration, AWS console does not allow to delete the specific interface. Admin needs to delete the instance and then associate the internal port.

4.Navigate to the port interface of the newly deployed ICS, click Actions and select Manage IP addresses.

5.Enter the IP address of the ICS instance and select Assign new IP address.

6.Select the public IP entry again and select Associate Elastic IP address under Actions.

7.Select the private IP address of the newly deployed ICS. Select Network interface, enter the interface ID in Network Interface field.

8.The list of configured IPs automatically populates under Private IP address field. Select the IP address as configured in ICS and click Associate.

9.In the port network interface for the newly deployed ICS, select the Elastic IP address and navigate to Actions  View Details. View and verify the elastic IP address associated to the secondary IP address.

10. Login to newly deployed ICS and modify the external port IP address to older ICS external port address.

11.Login as end user using the elastic IP address (assigned for secondary private IP address) and verify that end user login is successful.

Troubleshooting

Ivati Connect Secure emits booting logs at a specified storage. You can check the storage details of the boot diagnostic logs as shown below:

1.Select AWS Services > Instances > Launch Instance.

2.From the list displayed, select Instance Settings > Get System Log.

The system logs window is displayed.

Deploying Ivanti Connect Secure Appliance on GCP

Prerequisites and System Requirements

To deploy the Ivanti Connect Secure Virtual Appliance on GCP, you need the following:

Google Cloud Platform account

Access to the GCP portal (https://cloud.google.com/ )*

Ivanti Connect Secure Virtual Appliance Image

Ivanti Connect Secure licenses **

Ensure that you have enough IP address in your region

Ensure that you have already created VPC network for each interface, as this is required while you deploy VM instances.

Before you Begin

Before you start, make sure you have the following information and files:

Signature database file : https://pulsezta.blob.core.windows.net/gateway/nsa/db.der

To create a GCP image : https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/<package name>/ivanti-ics-image.zip

Downloading the GCP Virtual Machine Image

Download ICS image which is in zip format from Ivanti support site. Unzip the file to a location that is accessible from Google Cloud Platform.

Uploading the GCP Virtual Machine Image onto the Google Cloud Platform

To upload a GCP Gateway virtual machine image into Google Cloud Platform:

1.Access the Google Cloud Platform Management Portal, either from a client or a web browser, and log in using your Google Cloud Platform credentials.

2. In the Google Cloud Platform console, select your required project from the pull-down list on the title bar. For example:

3.Click the Navigation menu, and then select Cloud Storage > Browser.

A list of GCP storage buckets appears.

4.Select the bucket into which you wish to place the GCP image.

A page listing the current contents of the bucket appears.

5.(Optional) Navigate to the required folder within the bucket.

6.Click Upload Files. For example:

An upload dialog appears.

7.Select the ICS Gateway GCP virtual machine image .tar file from your local workstation (see Before you begin), and click Open.

If you want to use the provided YAML templates to automate the creation of the GCP image (see Creating a VM Instance of the Uploaded GCP Image Using a Script/Template), select these in addition to the image archive.

The image archive and any selected template files are added to the bucket.

8.Wait until the upload completes. This may take several minutes.

9.Start a command line session from the title bar. For example:

A command line session starts.

10.Navigate to the project folder.

11.Copy the db.der file extracted from the ICS image .zip file, to the current project directory.

12.Create an image using the following command using GCP CLI:

gcloud compute images create <image_name> --source-uri=gs://<bucket_name>/<optional_path>/<image_name>.tar.gz --signature-database-file=db.der --guest-os-features MULTI_IP_SUBNET,UEFI_COMPATIBLE,GVNIC

For example:

gcloud compute images create pcs109 --source-uri=gs://bucket-california/pcs_images/ICS-25.13R1-25.13R1-145.1.tar.gz --signature-database-file=db.der --guest-os-features MULTI_IP_SUBNET,UEFI_COMPATIBLE,GVNIC

13.You can also create an image using a script/template (see Creating a GCP Image Using a Script/Template)

14.You can now create a VM instance of the uploaded GCP image. To do this, either:

Perform the task manually, see Creating a VM Instance of the Uploaded GCP Image Manually.

Perform the task with a script/template, see Creating a VM Instance of the Uploaded GCP Image Using a Script/Template.

Creating a GCP Image Using a Script/Template

1.Download the required template archive file to your local workstation. https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/21-12-145/ivanti-ics-image.zip

2.Unpack the downloaded archive file to a location that is accessible from Google Cloud Platform. Each archive contains three files present in one respective directory, i.e.:

ivanti-ics-image.jinja

ivanti-ics-image.scheme

ivanti-ics-image.yaml

3.Edit the YAML file properties section to reflect your project requirements.

An example of an existing VPC YAML file is provided here:

imports:

- path: ivanti-ics-image.jinja

 

resources:

- name: ivanti-custom-secure-image

type: ivanti-ics-image.jinja

properties:

image_name: icsgcp123

bucket_name: bucket-california

image_file: ICS-25.13R1-25.13R1-145.1.tar.gz

# Paste your Base64 encoded file lines directly here:

db_content: <BASE64_STRING_FROM_DB.DER>

4.Save the YAML file.

5.On the Google Cloud Platform, start a command line session from the title bar. For example:

A command line session starts.

6.Within the project folder, change to deploymentmanager folder.

7.Create a new folder and change to the new folder and copy the three script files to this folder.

8.Select the required project:

gcloud config set project <project-name>

9.Create the GCP image using the following command:

gcloud deployment-manager deployments create <image-name> --config <yaml_file>

For example:

gcloud deployment-manager deployments create icsgcp123 --config ivanti-ics-image.yaml

 

Creating a VM Instance of the Uploaded GCP Image Manually

This section describes how to manually create a virtual machine instance of the ICS Gateway image inside Google Cloud Platform. You can also perform this process automatically using a script/template, see Creating a VM Instance of the Uploaded GCP Image Using a Script/Template.

1.Click the Navigation menu, and then select Compute Engine > Images.

The Images page appears. For example:

2.Locate the new image in the list of images.

3.At the end of the image entry, click the action menu and select Create Instance.

The Create Instance page appears. For example:

4.On the Create Instance page:
For more information, see table below.

General-Purpose

CPUs / Memory

ISA Model

Disk Space

N4 (5th Gen Intel Xeon Scalable processor)

n4-standard-4 (4 vCPU, 16 GB)

ISA4500V

80 GB

n4-standard-8 (8 vCPU, 32 GB)

ISA6500V

80 GB
n4-standard-16 (16 vCPU, 64 GB)

ISA8500V

80 GB

Enter a Name for the new instance.

Select a Region and Zone.

Under Machine configuration:

For Series, select n4-standard-4.

For Machine Type, select a minimum of n4-standard-4.

For Boot Disk, confirm that the correct image is already selected.

For Firewall, select the required HTTP/HTTPS options.

Under Security → Shielded VM

Select Turn on Secure Boot

Select Turn on vTPM

Deselect Turn on Integrity Monitoring

Expand the Management, security, disks, networking, sole tenancy options.

Select the Management tab.

Under Metadata:

For Key, enter pulse-config.

For Value, paste the text of the metadata file, see Provisioning Parameters.

Select the Networking tab.

Under Network interfaces, click the Edit icon to change the default network interface selection.

The Network interface options appear.

Under Network interface, specify a private (internal) network interface:

For Network, select the required private VPC.

For Subnetwork, select the required subnetwork.

Click Done to confirm the settings for the private network interface.

Under Network interfaces, click Add network interface.

The Network interface options appear.

Under Network interface, specify a public (external) network interface:

For Network, select the required public VPC.

For Subnetwork, select the required subnetwork.

Click Done to confirm the settings for the public network interface.

(Optional) Click Add network interface and specify a management network interface.

Click Create to confirm the settings and instantiate a VM instance of the image.

The VM Instances page appears. This page shows the new VM instance of the image. For example:

5.On the VM Instances page, wait until the creation of the VM instance completes. This may take several minutes.

6.After the VM instance is created, click on it in the list of VM instances.

The VM instance details page appears for the instance.

7.Confirm the details for the VM instance, including the number of network interfaces.

8.Make a note of the public IP address of the EXT interface (typically, this is nic1. This is required inside nSA.

9.Under Network interfaces, confirm that the firewall settings from your VPCs are present for your specified network interfaces:

Click nic0. A summary page for this network interface appears.

Under Firewall and route details, click the Firewall Rules tab and confirm that the following firewall rules are defined.

Click nic1. A summary page for this network interface appears.

Under Firewall and route details, click the Firewall Rules tab and confirm that the following firewall rules are defined.

(Optional) Click nic2. A summary page for this optional network interface appears.

Under Firewall and route details, click the Firewall Rules tab and confirm that the following firewall rules are defined.

10.The VM instance details* page, click Connect to serial console

A console monitor view (in a separate browser tab) shows the ongoing boot-up process for the instance.

11.Wait until the instance boot up is complete, and shows a screen similar to the following:

You can then complete this process by updating the Gateway details on the nSA Controller, see Completing the Configuration of the nSA Controller.

Creating a VM Instance of the Uploaded GCP Image Using a Script/Template

This section describes how to automatically create a virtual machine instance of the ICS Gateway image inside Google Cloud Platform using a script/template. You can also perform this process manually, see Creating a VM Instance of the Uploaded GCP Image Manually.

Ivanti provides YAML-based templates to create an instance of the ICS Gateway image in the following configurations:

Two network interfaces in an existing VPC.

Three network interfaces in an existing VPC.

Download:

https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/21-12-145/ivanti-ics-2-nics-existing-vpc.zip

https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/21-12-145/ivanti-ics-3-nics-existing-vpc.zip

Two network interfaces in a new VPC.

Three network interfaces in a new VPC.

Download:

https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/21-12-145/ivanti-ics-2-nics-new-vpc.zip

https://pulsezta.blob.core.windows.net/gateway/nsa/templates/GCP/21-12-145/ivanti-ics-3-nics-new-vpc.zip

To use a template:

1.Download the required template archive file to your local workstation.

2.Unpack the downloaded archive file to a location that is accessible from Google Cloud Platform. Each archive contains three files. These files should be present in one respective directory. For example, for the three-interface (existing VPC) version of the archive:

ivanti-ics-2-nics-existing-vpc.jinja

ivanti-ics-2-nics-existing-vpc.scheme

ivanti-ics-2-nics-existing-vpc.yaml

3.Edit the YAML file properties section to reflect your project and instance requirements, including the user_data property.

An example of an existing VPC YAML file is provided here:

imports:

- path: ivanti-ics-3-nics-existing-vpc.jinja

resources:

- name: my-vm

properties:

project: ics-project

email: [email protected]

machinetype: n2-standard-4

region: asia-south1

zone: asia-south1-b

image: icsgcp123

int_network: vpc-network-private-abcdef

ext_network: vpc-network-public-abcdef

mgmt_network: vpc-network-mgmt-abcdef

int_subnetwork: vpc-asia-south1-b-ics-int-port

ext_subnetwork: vpc-asia-south1-b-ics-ext-port

mgmt_subnetwork: vpc-asia-south1-b-ics-mgmt-port

user_data: <pulse-config><primary-dns>8.8.8.8<\primary-dns> ...

type: ivanti-ics-3-nics-existing-vpc.jinja

enableSecureBoot: true

enableVtpm: true

enableIntegrityMonitoring: false

The following table lists all possible template properties and their meaning:

Property

Description

project

Name of the Project

email

Registered service account email address

region

The name of the region in which you want to deploy your VM instance

zone

The name of the zone in which you want to deploy your VM instance

image

Virtual machine image name

machine_type

N2-standard machine type

int_network

VPC network name for internal network

ext_network

VPC network name for external network

mgmt_network

VPC network name for management network

int_subnetwork

Subnet name for internal VPC

ext_subnetwork

Subnet name for external VPC

mgmt_subnetwork

Subnet name for management VPC

user_data

The Gateway config file downloaded.

In User data, <networkConnection>v4</networkConnection> parameter can be configured as follows:

v4 : IPv4 addresses are allowed to configured (Default).

4. Save the YAML file.

5.On the Google Cloud Platform, start a command line session from the title bar. For example:

A command line session starts.

6.Within the project folder, change to deploymentmanager folder.

7.Create a new folder and change to the new folder and copy the three script files to this folder.

8. Select the required project:

gcloud config set project <project-name>

9.Deploy the VM using the following command:

gcloud deployment-manager deployments create <vm-name> --config <yaml_file>

For example:

gcloud deployment-manager deployments create vm-gcp-123 --config ivanti-ics-3-nics-existing-vpc.yaml

10.Wait until the command completes.

11.On the VM Instances page, click on the new VM in the list of VM instances.

The VM instance details page appears for the instance.

Increasing the Disk Space in GCP

From 22.6R2 release , on fresh installation 80 GB disk space is available by default. You can modify or increase the disk size only once on fresh installation or upgrade of the ICS images, but not on rollback or factory reset images.

If the user is upgrading to 22.6R2 or later, then the disk size change from 40 GB to 80 GB have to be done prior to upgrade on Google cloud platform.

Disk Size Allocation is supported from 22.6R2 and later releases.

1.On the Google Cloud console, go to the Disks page. Go to Disks.

2.In the list of persistent disks in your project, click the name of the disk that you want to resize.

3.On the disk details page, click Edit. You might need to click the ⋮> More actions menu and then click Edit.

4.In the Size field, enter the new size for your disk.

5.Click Save to apply your changes to the disk.

Deploying ICS using Terraform Template

This section describes how to install terraform template and deploy ICS on GCP with 2 NICs and 3 NICs.

1.Copy variables, base_setup_tf and ics_deploy scripts to a linux m/c installed with terraform. Go to the Terraform website to install Terraform on a Linux VM of your choice at usr/local/bin.

2.Create base_setup directory and copy base_setup.tf and variables.tf to it. Customize and set the variables in variables.tf file based on the requirement.

Example: Region, AMI-id, VPC name, subnet IP address details, instance name etc.

3.cd to base_setup directory and run terraform apply.

linux# terraform apply

4.Create ics_deploy directory and copy ics_deploy and variables.tf to it

5.Run following command:

terraform apply -input=false -auto-approve -var "instance_name=gcp-test-instance-1" -var "image_name=icsgcp386"

Before running the script, user has to create an image in the GCP cloud in the name of icsgcp386 (as shown above)

Downloading Terraform Template File

To download Terraform Template zip file:

1.Log in to https://portal.ivanti.com/customer/product-downloads

2.Navigate to Security> Ivanti Connect Secure (ICS, Pulse Connect Secure) > Downloads > Pulse Secure > Pulse Connect Secure > Cloud Templates.

3.Under Current and Supported Releases, select the Template file and Download. For example, ps-ics-terraform_templates-9.1Rx_22.Rx-2.0.zip.

Adding ICS Gateway to nSA

To add ICS Gateway, perform the following steps:

1.From the Ivanti Connect Secure menu, click the Gateways icon, then select Gateways > Gateways List.

The All Gateways page is displayed.

2.In the All Gateways page, click the Add drop-down list.

3.From the Gateway types list, select ICS Gateway.

The Register ICS Gateway page is displayed.

4.Enter a unique name for ICS gateway.

5.Enter your Location details such as Country, State/Region, City, and then click Register.

The Registration Summary page contains the FQDN URL and Registration Key, which you need to enter in the ICS Gateway to complete the registration. See Completing Registration of a ICS Appliance.

6.Click Close.

The newly added ICS Gateway gets listed as “Unregistered” under ICS Gateways list.

Completing Registration with ICS

We recommend you use NTP server to ensure the clocks are synchronized and features on Ivanti Neurons for Secure Access work properly.

To complete registration with ICS:

1.Log in to the ICS as an Admin.

2.Select the System > Configuration > Ivanti Neurons for Secure Access > Settings tab.

3.Enter the Registration FQDN and Registration Code.

4.Click Save Changes.

The Status Information displays the Registration Status in green.

Checking a Current Gateway Version

To check the current version for a Gateway, and to apply an update:

1.Log into the nSA Controller as a Tenant Admin.

2.From the Ivanti Connect Secure menu, click the Gateways icon, then select Gateways > Gateway List.

The All Gateways page appears, showing the full list of Gateway Groups and standalone Gateways currently configured on the Controller.

3.Select the required Gateway from the list.

The Gateways Overview page appears. The summary at the top of the page displays details pertaining to this Gateway, including the current version:

4.Click the context menu icon at the top-right to access the Edit options applicable to the selected Gateway:

FAQ

Q: I am unable to connect to my backend resources through L3 VPN.

Solution: SNAT these packets to the Internal interface IP which belongs to a subnet within the VPC.

To NAT endpoint tunnel IP to Internal interface IP, do the following:

1.Log in to Ivanti Connect Secure admin console.

2.Navigate to System > Network > VPN Tunneling.

3.Enable Source NATTING. By default, Source NATTING is disabled.

Q: User not able to access ICS after installation.

Solution: Ensure that the port 443 is opened for ICS