IBM Guardium

IBM Guardium

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Guardium Managed Units IP address Change

  • 1.  Guardium Managed Units IP address Change

    Posted Mon October 19, 2020 10:10 PM
    hi,

    Guardium Central Manager contains Some Collectors and aggregators those are managed units, if we need to change the IP address of collectors and aggregators in the current setup, do we need to unregister and change the ip address, then only we should make it as managed unit to CM.? May I know the process of this scenario?

    Thanks,
    Panendar Rao.C

    ------------------------------
    PHANENDRA RAO CHAVANA
    ------------------------------


  • 2.  RE: Guardium Managed Units IP address Change

    Posted Tue October 20, 2020 05:29 AM
    Hello Phanendra,

    I did this in my Client's environment a few months ago. I experienced some issues. Based on this experience, here are some recommendations.

    As a prerequisite, if your appliances are moving VLANs, make sure that the necessary firewall rules are open.

    1) Unregister the appliances before proceeding with the changes. Check in your Central Manager that the Managed Units are correctly unregistered.

    2) If you use GIM and your GIM agents connect to the Central Manager, you should push new GIM_URL/GIM_FAILOVER_URL settings through GIM to your agents. If you use S-TAP enterprise load balancing, you should push new STAP_LOAD_BALANCER_IP value to your S-TAP agents. I would advise to reconfigure your GIM/S-TAP clients immediately before step 3 below.

    3) Proceed with re-configuring the network on your appliances

    4) Make sure that connectivity is OK:
        * From each MU to the CM : run these commands on each MU :
                support show port open IP.address.of.CM 22
                support show port open IP.address.of.CM 8443
        * From the CM to each MU : run these commands on the CM :
                support show port open IP.address.of.MU 22
                support show port open IP.address.of.MU 8443

    5) Now register each appliance to the CM.

    I hope that helps!

    ------------------------------
    Sylvain Randier
    ------------------------------