Trustix™ Xsentry Firewall Hardware Enterprise Firewall Hardware

Trustix™ Xsentry™ Frequently Asked Questions

1. List the items for which the statistics can be displayed on the LCD panel.
  • Load Average
  • Memory Usage
  • Firewall Uptime
  • Last Reconfiguration Time
  • Firewall Model Number
  • Firewall Version / date / time information
  • Restore Base Configuration
2. Specify the option used to reset the root user password to 'trustix'?
Reset System Password to 'trustix'
3. List the steps that should be followed to successfully setup and connect to Xsentry.
  • Install the Xsentry hardware
  • Install the Xsentry client software
  • Change the pre-configured parameters to your requirements
4. How to unblock traffic?
For any of your internal network to connect through the firewall you must set Block Traffic to no. Using the keys select 'Block Traffic?' press key to select, use keys to highlight '[No]' press to enter. This will unblock traffic.
5. How to configure Xsentry Client?

First, locate the machine with the IP address and then insert the Firewall CD into the CD-ROM drive. The Firewall Xsentry Client should begin the installation automatically (under Windows). Once installed, launch the Client program.

The Client program should then prompt you with a login box. Enter the IP address of the Firewall, the username and the password. The default Username/Password should be used in order to login in to the firewall. Trustix encourages you to alter the password after the client installation process has been completed. Choose a password that is secure and known only to users who you wish to have administrative access to the firewall. The client will then login to the Firewall.

6. How to change the default gateway?
To set the default gateway to that provided by your ISP, use the keys to select 'Set Default Gateway?' and press key to select. Then, use the keys to select a number and the key to enter. When the last digit is entered 'Select Gateway Device: ETH0' will be displayed on the LCD display. Press to accept the default interface (ETH0). The display will then return to 'Trustix Xsentry T1000' in the LCD panel.
7. How to change the WAN (ETH0) interface address?
When the display reads 'Trustix Xsentry T1000' change the IP address for the WAN interface (ETH0, port labeled 1 on the front of the box) to those provided by you ISP. Use the keys to select 'Configure Networks', press the key to enter. Use the keys to select ETH0 press key to edit. To change the IP address use keys to change the number displayed in each LCD segment, when the correct number is displayed press key to move to the next number. Repeat for the Netmask which appears after the ETH0 IP address is complete and the key is used whilst on the right most digit. When 'Configure which Interface: ETH0' is displayed again press to return to the main menu.
8. I cannot connect from the Xsentry Client to the Firewall, what can cause this?
If the gateway is not set to be the firewall, or if an aliased (or secondary) IP address is used on the client PC, it is quite possible to ping the firewall from the client and to ssh into the firewall from the client, however the Xsentry client software will still not connect unless BOTH the gateway address is set correctly (to be the IP address of the NIC on the firewall to which the client is connected) and the primary IP address of the client is the IP set on the firewall to be allowed to login as the user.
9. How do I set up PING service in the Xsentry client?
Add the PING service in the internet zone, and drag a rule from LAN to this service. Remember to transfer the rules.
10. Is there a second Admin possible on the Xsentry firewall?
There can be several Admin's on the Xsentry firewall. They can be connected through the Internet as well as on the LAN. They must however have a static IP address. Also the same user cannot be connected from more than one client computer at a time. And no more than one user may be connected at a time from a client computer.
11. Can I install Xsentry firewall on other Linux-distributions?
No, the Xsentry firewall has a special secure Trustix Operating System included.
12. Can I use ISA network cards on Xsentry firewall?
No, we have decided not to support ISA network cards anymore.
13. Which ports needs to be opened to administer an Xsentry Firewall from outside of your own Firewall?
If you want to remotely administer an Xsentry Firewall, you will have to open port 1976 in your own Firewall to be able to access the remote firewall with the Xsentry client.
14. I cannot connect to the Xsentry firewall server from the client?
Check that the IP-address for the eth1(Lan-node) is used as the default gateway on the pc that you are running the client from.
15. Which Windows versions do you recommend for the Xsentry client?
Windows 2000 or higher, NT4 (with SP6)