Installing a Direct Connect Zone Proxy

About Direct Connect Zone Proxies

For installations with Direct Connect, install a zone proxy to enable connections to endpoints through the Zone Server appliance. This configuration is required to use Direct Connect with endpoints that connect to the Module Server through a Zone Server.

Import and configure Direct Connect

In the Tanium Console, go to Administration > Configuration > Solutions and import Direct Connect. See Direct Connect User Guide: Installing Direct Connect for steps on how to import Direct Connect, verify the installation, and then set up Direct Connect. When you reach the steps to configure zone proxies, use the following steps to install the Direct Connect Zone Proxy to the Zone Server appliance.

Obtain the Direct Connect Zone Proxy Installer file

Obtain the Direct Connect Zone Proxy installer file for the Zone Server appliance from Contact Tanium Support. The upgrade package is provided as a token URL.

Install the Direct Connect Zone Proxy on each Zone Server Appliance

For the initial installation, you must repeat the following procedure each Zone Server Appliance in your array. You can either provide the token URL for the installer during the installation process or manually upload the RPM file to /incoming.

You can upgrade all Zone Proxy Appliances at the same time from the Tanium Server Appliance. For more information, see Upgrade the Direct Connect Zone Proxy on all Zone Server Appliances.

  1. Sign in to the TanOS console of the Zone Server Appliance as a user with the tanadmin role.
  2. Enter 1 to go to the Tanium Installation menu. ClosedView screen
  3. Enter D to go to the Tanium Direct Connect Zone Proxy menu. ClosedView screen
  4. If you have not uploaded a file to /incoming, enter T to enter the URL of a token download, and follow the prompts to download the installer.
  5. Enter a number from the list to install the Direct Connect Zone Proxy. ClosedView screen
  6. Copy the provision secret and certificate that appears at the end of the installation. Follow the steps that appear to return to the Direct Connect settings in the Tanium Console to complete the configuration. For steps to configure a zone proxy in Direct Connect, see Direct Connect User Guide: Configure Zone Proxies.
  7. Press Q and Enter to exit the installation.

Check installed versions of the Direct Connect Zone Proxy

You can check the version of the Direct Connect Zone Proxy that is installed on each Zone Proxy appliance from the Tanium Server Appliance.

  1. Sign in to the TanOS console of the Tanium Server Appliance as a user with the tanadmin role.
  2. Enter 1 to go to the Tanium Installation menu. ClosedView screen
  3. Enter D to go to the Tanium Direct Connect Zone Proxy menu. ClosedView screen
  4. Enter L to display the versions of the Direct Connect Zone Proxy that are installed on Zone Servers in the array. ClosedView screen

Upgrade the Direct Connect Zone Proxy on all Zone Server Appliances

You can upgrade the Direct Connect Zone Proxy on all Zone Proxy appliances t the same time from the Tanium Server Appliance. You can either provide the token URL for the installer during the installation process or manually upload the RPM file to /incoming.

  1. Sign in to the TanOS console of the Tanium Server Appliance as a user with the tanadmin role.
  2. Enter 1 to go to the Tanium Installation menu. ClosedView screen
  3. Enter D to go to the Tanium Direct Connect Zone Proxy menu. ClosedView screen
  4. If you have not uploaded a file to /incoming, enter T to enter the URL of a token download, and follow the prompts to download the installer.
  5. Enter a number from the list to upgrade the Direct Connect Zone Proxy. ClosedView screen
  6. Press Enter to exit the upgrade.

Remove the Direct Connect Zone Proxy

  1. Sign in to the TanOS console of the Zone Server Appliance as a user with the tanadmin role.
  2. Enter 1 to go to the Tanium Installation menu. ClosedView screen
  3. Enter D to go to the Tanium Direct Connect Zone Proxy menu. ClosedView screen
  4. Enter X and follow the prompts to remove the Direct Connect Zone Proxy.