Configuring Multiple NICs on an Existing KeyControl Node

When you deploy a new KeyControl node, you configure the management interface during that process. We strongly recommend that you do not change this interface after you have deployed the node if the node is part of a cluster or if there are VMs registered with the node.

The following procedure describes how to add and configure additional NICs on an already-deployed node. For details about deploying a new KeyControl node, see Installing KeyControl from an OVA Template or Installing the First KeyControl Node from an ISO Image.

Warning: During the following procedure, the node will be unavailable at certain points. If the node is part of a cluster, the cluster will become degraded if the node is unreachable for too long. If the node is a standalone node, any VMs registered with the node will be unable to retrieve their keys while the node is offline.

In addition, if the node is part of a cluster and you want to change the management interface, you must remove the node from the cluster first.

  1. If the additional NICs you want to use have not yet been configured on the VM in which the KeyControl node is running, do the following:

    1. If the KeyControl node is powered on, shut it down using your hypervisor or the node's HyTrust KeyControl System Console. For details, see Using the KeyControl HyTrust KeyControl System Console.
    2. In your hypervisor, add the new NICs to the KeyControl VM and configure them using your corporate standards.

      Note: Make sure that the new NICs use the same adapter type as the existing NICs. For example, if the management interface NIC is of type VMXNET, the new NICs must be of type VMXNET as well.

    3. Make a note of the MAC address you are using for each NIC. When the NICs are displayed in KeyControl, they are identified by their MAC address. Therefore, when you go to configure the NIC in KeyControl later in this procedure, you will need to know its MAC address.
    4. Power on the KeyControl VM.
  2. Log in as htadmin on the KeyControl node whose NICs you want to configure.

    KeyControl displays the HyTrust KeyControl System Console TUI (Text-based User Interface).

  3. Select Manage Network Settings.
  4. Select Manage IP Address Settings.
  5. On the Interfaces screen, select the NIC you want to configure and press Enter.

    The NIC that is the current management interface has 'Current management interface' listed after the name. We strongly recommend that you do not change this interface after deployment if this node is part of a KeyControl cluster or any VMs are registered with this node. If you select the management interface, acknowledge the configuration request at the prompt.

  6. On the Secondary Network Configuration screen, specify the static IP address and netmask for the KeyControl node.

    Note:  

    • Changing the hostname on one NIC changes it for all NICs, including the management interface NIC. If this node is part of a cluster, you should not change the hostname for the node.
    • All NICs must use the same default gateway and DNS server list.

    • Make sure you specify a static IP address and netmask for the KeyControl node.
  7. When you have finished specifying the network information, select OK and press Enter.

    KeyControl restarts the network services using the new configuration. Contact with the node via the KeyControl webGUI or by any VMs registered with the node will be unavailable until the restart is finished.

    When the network finishes restarting, KeyControl displays the HyTrust KeyControl System Console.

  8. Repeat the proceeding steps for any other NICs you want to configure. KeyControl will restart the network services and the node will be unreachable for a short time after each configuration change.
  9. If you want to verify the configuration information, select Manage Network Settings. From there, select Show Current Network Configuration to view a list of the configured NICs with their IP addresses and netmasks. The management interface IP address is shown as the main interface. Any additional interfaces that are configured are shown below.