Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

SubjectAction
Supported operating system

Verify that your operation system is one of the supported operating systems described in System Requirements. You may use the following command:

cat /etc/redhat-release

Resources allocation

Ensure to select the correct architecture type, and that all resources listed in System Requirements are available. You may use the following commands:

free -h
lscpu

Network card

Ensure you have at least one network card installed and configured with full access to network services such as DNS and NTP (the same as your Gateways).

See Network Preparation for more details.

Root access

Installation must be performed by a root user.

You cannot use sudo instead. However, you may run it after running the command: su -

Disks, mount points / file systems and logical volumes

DPOD Standard Edition requires 3 disks (LUNs / physical / virtual) to support throughput, for both production and non-production installations.

Please allocate the mount points / file systems on the different disks, as described in Table 1 below.

It is strongly recommended to use logical volume manager (LVM) - particularly for the data disks.


Once configured, you may verify there are 3 disks using the following command:

lsblk


Tip: to create the mount points / file systems during RHEL installation:

  • Choose Installation Destination option.
  • Select all Local Standard drives and choose option "I will configure partitioning" under the "Other Storage Options" section.
  • Follow the table below and add all mount points with required definitions using the "+" button.
  • To create a volume group (sys, app, data) open the "Volume Group" listbox and choose "create new volume group ...".
Store service dedicated OS user and group

The Store service requires a dedicated OS user and group to run.

Consider executing the following command:

groupadd storeadms && useradd -g storeadms -md /home/storeadm -s /bin/bash storeadm

OS locale

The supported OS locale is en_US.UTF-8. Check the OS Locale Configuration and change it if necessary.

Installation file and environment

Ensure your /tmp directory has at least 1GB of free space.

Installation from a different directory is possible. If you opt to run the install from a directory other than /tmp, ensure that this directory:

    • Has at least 1GB of free space.
    • Is NOT one of these folders: /app, /logs, /data, /shared, /installs.

Download the CEF file and transfer it to the installation directory (e.g. /tmp) on the pre-installed OS server.

Execute the following command from the pre-installed OS server terminal:

chmod 755 ./<File Name>

Setup your network (consult your network admin)

Setup DNS - your network admin may need to assist you with this action. Make sure you can ping to your LDAP, Mail/SMTP Server, NTP Server.


Setup NTP - it has to be the same used for your IBM DataPower Gateways.

  • Consult your Linux and network admin about the proper way to configure this service.
  • Ensure the NTP RPM is installed. Consider executing the following commands:

    Info

    For RedHat: before using yum for the first time, you may need to execute:
    subscription-manager attach --auto


    yum install ntp
    ntpdate <ntp server hostname>
    systemctl enable ntpd.service
    systemctl start ntpd.service


Verify that the /etc/hosts file includes an entry with your server name mapped to your external server IP.

To find your server name, you may execute the command:

hostname

Required RPMs

Verify the existence of the following RPMs from the official RedHat/CentOS yum repositories:

  • httpd version 2.4.6-67 and above (together with the following dependencies: mailcap, apr, httpd_tools)
  • mod_ssl
  • curl
  • wget
  • unzip
  • iptables
  • iptables-services
  • bc
  • fontconfig

The installation is usually performed by executing:

yum install httpd mod_ssl curl wget unzip iptables iptables-services bc fontconfig

If this command can not find the package on account of it not being included in the repository, you will need to add the containing repository or manually download the RPMs files and install them.
For RedHat only - consider executing the following command:
subscription-manager repos --enable=rhel-7-server-rh-common-rpms


Ensure the httpd service is enabled and started by executing the command:

systemctl enable httpd.service && systemctl start httpd.service


Install mod_proxy_html:
  • This RPM is not always accessible from existing repositories. Try first to install it by executing the command: yum install mod_proxy_html
    If you get the error "No package mod_proxy_html available. Error: Nothing to do", you will need to download the RPM yourself, using one of the following methods:
    • Method 1 - download the RPM
      • Find your httpd version by executing the command: rpm -qa | grep httpd
      • The system will print something resembling httpd-2.4.6-67.el7_2.4.x86_64. This is the mod_proxy version you need to download.
      • For RedHat only - Download the mod_proxy with the correct version from the following url:
        https://access.redhat.com/downloads/content/mod_proxy_html/2.4.6-45.el7/x86_64/f21541eb/package (change the version part of the URL to match the httpd version you found above). Use wget or any other mechanism to download, and ensure to place the RPM inside the /tmp directory of the pre-installed OS server.
      • Install the RPM by executing the command:  rpm -Uvh mod_proxy_html-2.4.6-67.el7_2.4.x86_64.rpm (Note: your version may vary, as described above)
    • Method 2 - add a repository and install it from the repository using the commands (For RedHat only)
      subscription-manager repos --enable=rhel-7-server-optional-rpms
      yum install mod_proxy_html

Optional: Install Kibana OSS (please read Kibana access limitations):


In case you are using yum, it is recommended to clean its cache to make sure there is enough space in /var (yum cache can take a lot of the space there). To clean yum cache, execute the command:

yum clean all

Firewall access to DPOD server

To configure your firewall to allow access to DPOD server at port 443, execute the following commands:

Note

These commands may not be applicable if your system has no builtin firewall.

firewall-cmd --zone=public --add-port=443/tcp --permanent
firewall-cmd --reload
iptables-save | grep 443


If, for any reason, you need to remove this access (close the port) - execute the following commands:
firewall-cmd --zone=public --remove-port=443/tcp --permanent
firewall-cmd --reload
iptables-save | grep 443


Note

You should open port access for the DNS Server, your DataPower Gateways, your SMTP server and others as described in Firewall Requirements.

Please assist your network admin and Linux admin to enable access on these ports.


...