SteelCentral™ Controller for SteelHead™ User’s Guide
Preface
About This Guide
Audience
Document Conventions
Documentation and Release Notes
Contacting Riverbed
Product Overview
Hardware and Software Dependencies
Hardware and Software Requirements
SCC Compatibility
SteelHead CX
SteelHead EX
SteelHead Interceptor
SteelHead Mobile
SteelFusion Core
SteelFusion Edge
Legacy Policy Push Restrictions
Firewall Requirements
Upgrading the SCC
Upgrade Considerations
Recommended Upgrade Paths
Upgrading the SCC Software Version
Migration Procedures
SteelHead Autoregistration
HTTPS Communication Channel
Connecting SteelHeads When the SCC Is Behind a Firewall
Connecting to the SCC Management Console
The Dashboard
The Dashboard
Viewing Appliance Status
Summary for Global Group
Appliance Status Tabs
Navigating in the SCC
Intelligent Search Bar
Saving Your Configuration
Printing Pages and Reports
Getting Help
Displaying Online Help
Downloading Documentation
Logging Out
SCC Best Practices
Best Practices for Configuring Hybrid Networking
Network Topology
Application Performance
Hybrid Network Path Selection Probing Techniques
Subset Probing on SteelHeads
Rate Limited Bandwidth Probing
Path Selection Rule Aware Probing
Hybrid Networking Workflow
Best Practices for SCC Features
Autonegotiation of Multi-stream ICA
HTTPS Communication Channel
MAPI over HTTP Optimization
Migrating Appliances to Sites
Order of Migration to 9.0 and Later
Pushing Hybrid Networking Features
QoS Migration
SteelCentral AppResponse Support
Web Proxy
Configuring Web Proxy on the Client-Side SteelHead
Configuring the Certificate Authority on the SCC
Configuring Web Proxy on the SCC
In-Path Rules Requirements for HTTP Caching
Configuring In-Path Rules on the SCC
Configuring Administration Settings
Configuring Networking Settings
Configuring General Host Settings
Configuring Base Interfaces
IPv6 Support
Configuring System Settings
Setting Announcements
Configuring Alarm Parameters
Configuring the Date and Time
NTP Authentication and Servers
Current NTP Server Status
NTP Authentication Keys
Configuring Monitored Ports
Configuring SNMP Basic Settings
Configuring SNMPv3
Basic Steps
Configuring SNMP Authentication and Access Control
Configuring Email Notification
Configuring Log Settings
Configuring Per-Process Logging
Changing the Account Password
Managing Configuration Files
Configuring Security Settings
Configuring General Security Settings
Configuring SCC Security
Enabling or Disabling a Certificate Authority
Managing User Permissions
Combining Permissions by Feature
SCC Roles and Permissions
Group Roles and Permissions
Configuring Password Policy
Selecting a Password Policy
Unlocking an Account
Resetting an Expired Password
Setting RADIUS Servers
Configuring TACACS+ Access
Unlocking the Secure Vault
Configuring a Management ACL
Adding ACL Management Rules
Configuring Web Settings
Enabling REST API Access
Configuring Maintenance Settings
Managing External Backups
Configuring External SCC Backups
Configuring External SCC Backups Using an RSA Public Key
Scheduling External Backups
Viewing Backup Operations
Setting Daily Maintenance Window Settings
Displaying Scheduled Jobs
Managing Licenses
Managing SCC Licenses
Removing a License
Upgrading Your Software
Rebooting and Shutting Down the SCC
Managing Your Network
Managing Sites and Networks
How Is a Site Different from an Appliance?
Before You Begin
Defining Networks
Traffic Aware Backoff Probing
Defining Sites
Custom Probe IP Addresses
Troubleshooting
Defining Site Connectivity Templates
Defining Site Types
Defining Site Regions
Creating a Secure Transport Concentrator
Best Practices for Creating a Secure Transport Concentrator
Viewing Site Details
Defining Uplinks
Defining Uplink Types
Managing Appliances
Migrating Appliances to Sites
Managing Appliance Groups
Adding Appliances
Filtering the Display of Appliances
Managing Appliance Settings
Managing Appliance Operations
Pushing Policies to Selected Appliances or Appliance Groups
Replacing (Generating) Peering Certificates
Updating Licenses
Starting and Stopping Appliances
Shutting Down Appliances
Setting the Password for Appliances
Unlocking the Secure Vault
Changing the Secure Vault Password
Sending CLI Commands
Starting or Stopping SteelCentral NetShark Service
Disabling SSL Server Certificate Export
Removing SteelFusion Core
Joining or Leaving a Windows Domain
Fetching Appliance-Specific Configurations
Performing Global Policy Pushes
Trusting Appliances Using Security Keys
Managing Appliance Pages
Managing Host Settings
Managing Base Interfaces
Managing In-Path Interface Settings
Managing Subnet Side Rules
Managing SSL Settings
Displaying the Certificate PEM
Replacing the SSL Certificate
Generating the Certificate Signing Request (CSR)
Managing Licenses
Managing Web Settings and Web Certificates
Managing Web Certificates
Managing Outbound QoS Interfaces
Managing Legacy Inbound QoS Interfaces
Managing Path Selection
Managing Connection Forwarding
Managing SteelFusion Core Settings
Managing Virtual Services Platform
Managing Data Interfaces
Managing Policies
Policy Types
Basic Steps to Create and Push a Policy
Adding Policies
Configuring Policy Pages
Copying an Existing Policy
Importing Polices from Appliance Configurations
Merging Policies
Editing Policies
Overriding Policy Settings from a Parent Group
Policy Page Conflicts
Assigning Policies to Appliances and Groups
Managing Interceptor Clusters
Adding a Cluster Using the Wizard
Configuring Cluster In-Path Rules
Configuring Cluster Load Balancing Rules
Overview of Load-Balancing Rules
Configuring Path Selection on Interceptor Clusters
Configuring Path Selection in Cluster Deployments
Path Selection Push Prerequisites
Configuring Channels on Interceptor Clusters
Improving Performance for Interceptor Path Selection Clusters
Editing Clusters
Fetching Cluster Configurations from Remote Appliances
Pushing Cluster Configuration Settings
Removing Clusters
Managing Hybrid Network Services
Managing Path Selection
Configuring Application Groups Using the Path Selection Wizard
Configuring Path Selection Rules
Pushing Your Settings and Viewing Push Status
Viewing Push Status
Managing Secure Transport
Overview of Secure Transport
Common Network Deployment Models for Secure Transport
Typical Workflow for Configuring Secure Transport
Configuring the Secure Transport Controller on the SteelHead
Disconnected Mode
Activating the Secure Transport Controller on the SCC
Adding Appliances to the Secure Transport Group
Configuring Secure Transport Group Settings
Viewing Active Secure Transport Status
Viewing Group Traffic Information
Viewing Secure Group Members
Managing QoS
QoS Overview
Enabling and Disabling QoS
Adding a QoS Profile
Adding Classes and Rules to QoS Profiles
Modifying QoS Profiles
Adding a Class to a QoS Profile
Adding Rules to a QoS Profile
Pushing Your Settings and Viewing Push Status
Viewing Push Status
Migrating Legacy QoS Policies
Managing Application Policies
Defining Applications
Viewing Application Details and Statistics
Enabling Statistics Collection for Applications
Managing Optimization
Managing Web Proxies
Configuring HTTP Web Proxy
Enabling HTTPS Web Proxy
Prerequisites
YouTube Caching
In-Path Pass-Through Rule
Adding Domains to the Whitelist for HTTPS
Pushing Your Settings and Viewing Push Status
Viewing Push Status
Viewing the Cache Hit Ratio
Managing Appliance Operations and Upgrades
Managing Appliance Operation History
Managing Backups and Restores
Assigning Rollover Strategy
Restoring a Backup Snapshot to an Appliance
Migrating the Current State of a Source Appliance
Removing Backup Configurations
Upgrading Appliances
Downgrading Appliances
Uploading Local Software Images
Viewing Remote Software Images
Rebooting Appliances
Managing Virtual Appliances
Managing Virtual Appliances
Managing Virtualization Services
Managing RSP and VSP Packages and Slots
Managing the Package Library
Managing the Image Library
Viewing Reports
Overview
Navigating the Report Layout
Plot Area (1)
Control Panel (2)
Navigator (3)
Setting User Preferences
Browser Recommendation
Data Grouping
Grouping and Approximation
Exporting Statistics
Viewing Connection History Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Connection Forwarding Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Connection Pooling Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Outbound QoS Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Inbound QoS Report
What This Report Tells You
About Report Graphs
About Report Data
Viewing Optimized Throughput Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Bandwidth Optimization Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Traffic Summary Reports
What This Report Tells You
About Report Data
Viewing Performance Details Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing DNS Cache Hits Reports
What This Report Tells You?
About Report Graphs
About Report Data
Viewing DNS Cache Utilization Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing HTTP Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing NFS Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SnapMirror Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SRDF Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SSL Servers Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Data Store Status Reports
Viewing Data Store SDR-Adaptive Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Data Store Disk Load Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Appliance PFS Data Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing LUN I/O Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Initiator I/O Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Network I/O Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Blockstore Metrics Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing Appliance Status
Viewing Diagnostic Reports and Logs
Viewing SCC Alarm Status Reports
What This Report Tells You
About Report Data
Viewing SCC CPU Utilization Reports
What This Report Tells You
About Report Graphs
About Report Data
Viewing SCC Memory Paging Reports
What This Report Tells You
About Report Graphs
Viewing SCC User and System Logs
Viewing User Logs Reports
Viewing System Logs Reports
Downloading SCC User and System Logs
Downloading User Logs Reports
Downloading System Log Files Reports
Generating SCC System Dumps
Viewing SCC Process Dump Files
Viewing SCC TCP Dumps Files
Viewing Appliance Details Reports
What This Report Tells You
About Report Data
Viewing Health Check Details Reports
What This Report Tells You
About Report Data
Viewing Appliance CPU Utilization Reports
What This Report Tells You
About Report Graphs
Viewing Appliance Memory Paging Reports
What This Report Tells You
About Report Graphs
Viewing Appliance TCP Memory Reports
What This Report Tells You
About Report Graphs
Downloading Appliance Logs
About Report Data
Generating Appliance System Dumps
Viewing Appliance TCP Dumps
Troubleshooting
Custom Flag Use Examples
Stopping a TCP Dump After an Event Occurs
Stop Trigger Limitations
Viewing a TCP Dump
Uploading a TCP Dump
Viewing Appliance Expiring Certificates
What This Report Tells You
About Report Data
Policy Pages Reference
Networking Policy Settings
Host Settings
DNS Settings
Hosts
Proxies
WCCP
WCCP Service Groups
Adding a New Service Group
Hardware Assist Rules
10-G NIC Hardware Assist Rules Settings
TCP Hardware Assist Rules
Simplified Routing
Mapping Data Collection Setting
Asymmetric Routing
Asymmetric Routing Settings
Flow Statistics
Flow Statistics Settings
Flow Export Settings
Enable Interfaces
Flow Collectors
Outbound QoS (Basic)
QoS Settings
Sites
Applications
Service Policies
Outbound QoS (Advanced)
QoS Settings
QoS Classes
QoS Sites and Rules
Outbound QoS Interfaces
Outbound QoS (Basic) WAN Link
Outbound QoS (Advanced) WAN Link
Inbound QoS
WAN Link
Inbound QoS Classes
Inbound QoS Rules
Inbound QoS Interfaces
WAN Link
Path Selection
Port Labels
Host Labels
When to Use
Domain Labels
When to Use
Dependencies
Adding a Domain Label
Optimization Policy Settings
General Service Settings
General Service Settings
In-Path Rules
General Settings (SteelHead Interceptor)
Peering Rules
Settings
Add Peering Rules
XBridge
Transport Rules
Enabling Congestion Control Algorithm
Configuring Buffer Settings
Enabling and Adding Single-Ended Connection Rules
Adding Single-Ended Connection Rules
Service Ports
Service Port Settings
Service Ports
RiOS Data Store
General Settings
Performance
Data Store
Adaptive Data Streamlining
CPU Settings
CIFS (SMB1)
Settings
Overlapping Open Optimization (Advanced)
SMB Settings
SMB2/3
SMB2 Support
Optimization
Signing
Down Negotiation
CIFS Prepopulation
Prepopulation
HTTP
Settings
HTTP Per-Host Autoconfiguration Settings
HTML Tags to Prefetch
Server Subnet an Host Settings
Oracle Forms
MAPI
NFS
Settings
Override NFS Protocol Settings
Lotus Notes
Settings
Encryption Optimization Servers
Citrix
Settings
FCIP
FCIP Settings
SRDF
Symmetrix IDs and Group Override Policies
Rules
SnapMirror
Windows Domain Authentication
NTLM
Delegation Mode
Kerberos
SSL Main Settings
General SSL Settings
Secure Peering (SSL)
SSL Secure Peering Settings
Trusted Peer Certificates and Peer CAs
Mobile Trust
Trusted Peers
Certificate Authorities (SSL)
CRL Management (SSL)
Advanced Settings (SSL)
Chain Discovery
SteelHead Mobile Security Mode
Client Side Session Reuse
Client Authentication
Proxies
Midsession SSL
TLS Extensions
Peer Ciphers
Client Ciphers
Server Ciphers
Effective Overall Cipher List
Secure Peering (IPSEC)
General Settings
Secure Peers
Cloud Accelerator
Branch Services Settings
Caching DNS
General Settings
DNS Forwarding Name Servers
Advanced Cache
Advanced Name Servers
RSP/VSP Slots
RSP/VSP Data Flow
Common Branch Storage Settings
Common VSP Settings
System Settings Policies
Alarms
Announcements
Email
Logging
Logging Configuration
Adding a New Log Server
Adding a New Process Logging Filter
Monitored Ports
SNMP ACLs
Security Names
Groups
Views
Access Policies
SNMP Basic
SNMP Server Settings
Adding a New Trap Receiver
SNMP v3
NTP Settings
Time Zone
Security Policy Settings
General Security Settings
User Permissions
Capability-Based Accounts
Adding a New User
Password Policy
RADIUS
Default RADIUS Settings
RADIUS Servers
TACACS+
Default TACACS+ Settings
TACACS+ Servers
Management ACL
Management ACL Settings
Adding a New Rule
REST API Access
Riverbed System Ports
Default Ports
SteelFusion Ports
Commonly Excluded Ports
Interactive Ports Forwarded by the SteelHead
Secure Ports Forwarded by the SteelHead
SCC Management Information Base (MIB)
Accessing MIB Files
SNMP Traps
Alarms
SteelHead
SteelHead Interceptor
SteelHead Mobile
SteelHead EX
SteelFusion Core
SteelCentral™ Controller for SteelHead™ User’s Guide
SCC Management Information Base (MIB)