SteelHead™ Management Console User’s Guide
Preface
About This Guide
Audience
Document Conventions
Documentation and Release Notes
Contacting Riverbed
Overview of the Management Console
Prerequisites
Hardware and Software Dependencies
SCC Compatibility
Ethernet Network Compatibility
SNMP-Based Management Compatibility
Using the Management Console
Connecting to the Management Console
The Dashboard
Navigating in the Management Console
Saving Your Configuration
Restarting the Optimization Service
Signing Out
Printing Pages and Reports
Getting Help
Displaying Online Help
Downloading Documentation
Next Steps
Working with the Virtual Services Platform
Overview of VSP
Supported Features
VSP Architecture
Setting Up the Virtual Services Platform
Before You Begin
Configuring VSP
Using the ESXi Installation Wizard
Managing ESXi and Virtual Machines with vSphere
Creating and Configuring Virtual Machines
Managing Virtual Machines Using VNC
Using the VNC Client
Adding SteelFusion Edge as an ESXi Datastore
Before You Begin
Provisioning a LUN from Remote Storage
Provisioning a LUN from Local Storage
Creating a Datastore on the LUN
VSP High Availability Overview
VSP HA Deployment Considerations
VSP HA Supported Port Configurations
Supported Port Uses for Integrated Mode Deployments
Supported Port Uses for Dedicated Mode Deployments
VSP HA Recommended Port Configurations
Recommended Port Uses for Integrated Mode Deployments
Recommended Port Uses for Dedicated Mode Deployments
Deploying VSP HA in Integrated Mode
Deploying VSP HA in Dedicated Mode
Modifying Host and Network Interface Settings
Modifying General Host Settings
Viewing the Test Result
Modifying Base Interfaces
IPv6 Support
Features Not Supported with IPv6
Modifying In-Path Interfaces
Modifying Data Interfaces
Configuring SteelFusion Storage
Configuring SteelFusion Edge Connectivity
Traffic Routing Options
Configuring Edge High Availability
Viewing Configuration Information
Viewing High Availability Status
Viewing Blockstore Allocation
Viewing SteelFusion Core Connections
Viewing Target Details
Viewing Initiators
Viewing Initiator Groups
Viewing Connected iSCSI and Local LUNs
Viewing the Interfaces Used with Multi-Path I/O (MPIO)
Configuring Branch Services
Enabling DNS Caching
Configuring In-Path Rules
In-Path Rules Overview
Creating In-Path Rules for Packet-Mode Optimization
Upgrade Consideration
Packet-Mode Optimization Rule Characteristics
Default In-Path Rules
Configuring In-Path Rules
Configuring Optimization Features
Configuring General Service Settings
Enabling Basic Deployment Options
Enabling Failover
Physical In-Path Failover Deployment
Out-of-Path Failover Deployment
Synchronizing Master and Backup Failover Pairs
Configuring General Service Settings
Enabling Peering and Configuring Peering Rules
About Regular and Enhanced Automatic Discovery
Extending the Number of Peers
Configuring Peering
Peering Rules
Configuring NAT IP Address Mapping
Configuring Discovery Service
Configuring the RiOS Data Store
Encrypting the RiOS Data Store
Synchronizing Peer RiOS Data Stores
RiOS Data Store Synchronization Requirements
Clearing the RiOS Data Store
Improving SteelHead Mobile Performance
Requirements
Receiving a Notification When the RiOS Data Store Wraps
Improving Performance
Selecting a RiOS Data Store Segment Replacement Policy
Optimizing the RiOS Data Store for High-Throughput Environments
Setting an Adaptive Streamlining Mode
Configuring CPU Settings
Configuring the SteelHead Cloud Accelerator
Prerequisites
Configuring CIFS Prepopulation
Editing a Prepopulation Share
Performing CIFS Prepopulation Share Operations
Viewing CIFS Prepopulation Share Logs
Configuring TCP, Satellite Optimization, and High-Speed TCP
Optimizing TCP and Satellite WANs
Optimizing SCPS with SkipWare
SCPS Connection Types
Configuring Buffer Settings
Adding Single-Ended Connection Rules
High-Speed TCP Optimization
HS-TCP Basic Steps
Configuring Service Ports
Configuring Domain Labels
When to Use
Dependencies
Creating a Domain Label
Modifying Domains in a Domain Label
Configuring Host Labels
When to Use
Configuring a Host Label
Resolving Hostnames
Viewing the Hostname Resolution Summary
Modifying Hostnames or Subnets in a Host Label
Configuring Port Labels
Creating a Port Label
Modifying Ports in a Port Label
Configuring CIFS Optimization
CIFS Enhancements by Version
SMB Dialects by Windows Version
Optimizing CIFS SMB1
Optimizing SMB2/3
SMB3 Support
SMB2 Support
Configuring SMB Signing
Domain Security
Authentication
SMB Signing Prerequisites
Verifying the Domain Functional Level and Host Settings
Enabling SMB Signing
Encrypting SMB3
Viewing SMB Traffic on the Current Connections Report
Configuring HTTP Optimization
About HTTP Optimization
Configuring HTTP Optimization Feature Settings
Configuring Oracle Forms Optimization
Determining the Deployment Mode
Enabling Oracle Forms Optimization
Configuring MAPI Optimization
Optimizing MAPI Exchange in Out-of-Path Deployments
Deploying SteelHeads with Exchange Servers Behind Load Balancers
Configuring NFS Optimization
Configuring Lotus Notes Optimization
Encryption Optimization Servers Table
Unoptimized IP Address Table
Configuring an Alternate Port
Configuring Citrix Optimization
Citrix Enhancements by RiOS Version
Citrix Version Support
Citrix Traffic Fallback Behavior
Backward Compatibility
Configuring FCIP Optimization
Viewing FCIP Connections
FCIP Rules (VMAX-to-VMAX Traffic Only)
FCIP Default Rule
Configuring SRDF Optimization
Viewing SRDF Connections
Setting a Custom Data Reduction Level for an RDF Group
Creating SRDF Rules (VMAX-to-VMAX Traffic Only)
SRDF Default Rule
Configuring SnapMirror Optimization
How a SteelHead Optimizes SnapMirror Traffic
Viewing SnapMirror Connections
Adding or Modifying a Filer
Windows Domain Authentication
Configuring Domain Authentication Automatically
Easy Domain Authentication Configuration
Configuring Domain Authentication for Delegation
Replication
Delegation (deprecated)
Configuring the Delegation Account (deprecated)
Configuring the Replication Account
Adding the Delegation Servers (deprecated)
Removing the Delegation Servers
Status and Logging
Configuring Domain Authentication Manually
Delegation (deprecated)
Autodelegation Mode (deprecated)
Configuring Replication Users (Kerberos)
Granting Replication User Privileges on the DC
Verifying the Domain Functional Level
Configuring PRP on the DC
Enabling Kerberos in a Restricted Trust Environment
Configuring Hybrid Networking, QoS, and Path Selection
Where Do I Start?
Best Practices for QoS Configuration
Best Practices for Path Selection Configuration
Defining a Hybrid Network Topology
Topology Properties
Defining a Network
Defining a Site
Defining Uplinks
Defining Tunneled Uplinks
Defining Applications
Applying QoS Policies
QoS Overview
QoS Enhancements by Version
Traffic Classification
WeQoS EX xx60 Series Limits
Bypassing LAN Traffic
QoS Classification for the FTP Data Channel
QoS Classification for Citrix Traffic
Configuring QoS
Overview
Migrating from RiOS 8.6.x and Earlier to RiOS 9.x
Creating QoS Profiles
Enabling MX-TCP Queue Policies
Adding a QoS Rule to a Profile
Verifying and Saving a QoS Configuration
Modifying QoS Profiles
Classifying and Prioritizing OOB Traffic Using DSCP Marking
Inbound QoS
How a SteelHead Identifies and Shapes Inbound Traffic
Inbound QoS Limitations
Path Selection
Using Paths to Steer Packets
Validating the Path Selection Design
Path Selection Use Cases
Using an Interface and Next Hop IP Address to Select an Uplink
Path Selection Limits
Configuring Path Selection in a SteelHead Interceptor Cluster
Path Selection in Interceptor Cluster Deployment Options
Configuring Path Selection on a SteelHead in an Interceptor Cluster
Path Selection Limitations for SteelHeads in an Interceptor Cluster
Configuring SSL and a Secure Inner Channel
Configuring SSL Server Certificates and Certificate Authorities
How Does SSL Work?
Prerequisite Tasks
Verifying SSL and Secure Inner Channel Optimization
Configuring SSL Main Settings
Configuring SSL Server Certificates
Preventing the Export of SSL Server Certificates and Private Keys
Configuring SSL Certificate Authorities
Modifying SSL Server Certificate Settings
Removing or Changing an SSL Server Certificate
Exporting an SSL Server Certificate
Generating a CSR
Adding a Chain Certificate
Configuring CRL Management
Managing CRL Distribution Points (CDPs)
Configuring Secure Peers
Secure Inner Channel Overview
Enabling Secure Peers
Configuring Peer Trust
Verifying the Secure Inner Channel Connections
Configuring Advanced and SSL Cipher Settings
Setting Advanced SSL Options
Configuring SSL Cipher Settings
Performing Bulk Imports and Exports
Configuring Network Integration Features
Configuring Asymmetric Routing Features
Troubleshooting Asymmetric Routes
Configuring Connection Forwarding Features
Configuring IPSec Encryption
Configuring Subnet Side Rules
Configuring Flow Statistics
Enabling Flow Export
Flow Export in Virtual In-Path Deployments
Troubleshooting
Joining a Windows Domain or Workgroup
Domain and Local Workgroup Settings
Domain Mode
Local Workgroup Mode
Troubleshooting a Domain Join Failure
Configuring Simplified Routing Features
Configuring WCCP
Verifying a Multiple In-Path Interface Configuration
Modifying WCCP Group Settings
Configuring Hardware-Assist Rules
Managing SteelHeads
Starting and Stopping the Optimization Service
Configuring Scheduled Jobs
Upgrading Your Software
Rebooting and Shutting Down the SteelHead
Managing Licenses and Model Upgrades
Flexible Licensing Overview
For More Information
Installing a License
Upgrading an Appliance Model
Removing a License
Viewing Permissions
Managing Configuration Files
Configuring General Security Settings
Managing User Permissions
Accounts
Combining Permissions By Feature
Managing Password Policy
Selecting a Password Policy
Unlocking an Account
Resetting an Expired Password
Setting RADIUS Servers
Configuring TACACS+ Access
Unlocking the Secure Vault
Configuring a Management ACL
ACL Management Rules
Usage Notes
Configuring Web Settings
Managing Web SSL Certificates
Enabling REST API Access
Configuring System Administrator Settings
Configuring Alarm Settings
Setting Announcements
Configuring Email Settings
Configuring Log Settings
Filtering Logs by Application or Process
Configuring the Date and Time
Current NTP Server Status
NTP Authentication
NTP Servers
NTP Authentication Keys
Configuring Monitored Ports
Configuring SNMP Settings
Configuring SNMPv3
Basic Steps
SNMP Authentication and Access Control
Configuring Disk Management
Before You Begin
Switching the Disk Layout
Viewing Reports and Logs
Overview
Navigating the Report Layout
Plot Area
Control Panel
Navigator
Setting User Preferences
Viewing Current Connection Reports
What This Report Tells You
Connections Summary
Query Area
Connections Table
Viewing the Current Connection Details
Connection Details
Tools
Network Topology
LAN/WAN Table
Viewing Connection History Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Connection Forwarding Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Outbound QoS Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Inbound QoS Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Secure Transport Reports
What This Report Tells You
Viewing Top Talkers Reports
What This Report Tells You
About Report Data
Viewing Traffic Summary Reports
What This Report Tells You
About Report Data
Viewing WAN Throughput Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Application Statistics Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Application Visibility Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Interface Counter Reports
What This Report Tells You
Viewing TCP Statistics Reports
What This Report Tells You
Viewing Optimized Throughput Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Bandwidth Optimization Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Peer Reports
What This Report Tells You
Viewing CIFS Prepopulation Share Log Reports
Viewing HTTP Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Live Video Stream Splitting Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing NFS Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SRDF Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SnapMirror Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SSL Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SharePoint Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Data Store Status Reports
What This Report Tells You
Viewing Data Store SDR-Adaptive Reports
What This Report Tells You
Viewing Data Store Disk Load Reports
What This Report Tells You
Viewing DNS Cache Hit Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing DNS Cache Utilization Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing LUN I/O Reports
What This Report Tells You
About Report Data
About Report Graphs
Viewing Initiator I/O Reports
What This Report Tells You
About Report Data
About Report Graphs
Viewing SteelFusion Core I/O Reports
What This Report Tells You
About Report Data
About Report Graphs
Viewing Blockstore Metrics Reports
What This Report Tells You
About Report Data
About Report Graphs
Viewing Blockstore SSD Read Cache Reports
What This Report Tells You
About Report Data
About Report Graphs
Viewing Alarm Status Reports
What This Report Tells You
Viewing CPU Utilization Reports
What This Report Tells You
About Report Graphs
Viewing Memory Paging Reports
What This Report Tells You
About Report Graphs
Viewing TCP Memory Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing System Details Reports
What This Report Tells You
Viewing Disk Status Reports
What This Report Tells You
Checking Network Health Status
Viewing the Test Status
Viewing the Test Results
Checking Domain Health
Viewing the Test Status
Viewing the Test Results
Common Domain Health Errors
Verifying Hardware Capabilities of a SteelHead-v
Viewing the Test Status and Results
Viewing Logs
Viewing User Logs
Viewing System Logs
Downloading Log Files
Downloading User Log Files
Downloading System Log Files
Generating System Dumps
Viewing Process Dumps
Capturing and Uploading TCP Dump Files
Troubleshooting
Custom Flag Use Examples
IPv6 Custom Flag Use Examples
Stopping a TCP Dump After an Event Occurs
Stop Trigger Limitations
Viewing a TCP Dump
Uploading a TCP Dump
Exporting Performance Statistics
SteelHead MIB
Accessing the SteelHead Enterprise MIB
Different OID Branches for Steelhead EX Appliances
Retrieving Optimized Traffic Statistics by Port
SNMP Traps
SteelHead Ports
SteelFusion Ports
Default Ports
Commonly Excluded Ports
Interactive Ports Forwarded by the SteelHead
Secure Ports Forwarded by the SteelHead
Application Signatures for AFE
List of Recognized Applications
SteelHead™ Management Console User’s Guide
List of Recognized Applications