IBM DataPower Virtual Edition

Amazon EC2 Installation guide

This guide will provide step by step instructions how to start using the installed products on your AWS EC2 instance.

1. Overview

This AMI contains a ready-to-run IBM DataPower Virtual Edition image at the selected version. In order to use this image, you need to launch it with your selected type. Once launched, the DataPower console will then be ready to access. 

2. Launching the instance

In order to launch IBM Datapower Virtual Edition (referred to as DataPower), a few settings need to be configured on the AWS console as follows.

The instructions for launching an instance differ depending on where you launch from. Initially you will launch the instance from the AWS Marketplace.

2.1 From the AWS Marketplace

  1. Select the IBM DataPower Product from the Midvision Products page in the AWS Marketplace;
  2. Click on the link to go to that versions page in AWS Marketplace;
  3. Check the 'Other Versions' link to see other versions available (you can select the actual version later).
  4. Under 'Pricing Details' panel select your Region and either Hourly or Yearly fees.
  5. Click on the 'Continue', button to go to the '1-Click Launch' tab on the configuration page;
  6. On the 'Software Pricing' panel choose your instance type and pricing type;
  7. On the 'Version' panel, select the fix pack version you require;
  8. On the 'Region' panel, select the Region you require;
  9. On the 'EC2 Instance Type' panel, choose the instance type. The m3.large type or larger is recommended when running IBM DataPower Virtual Edition. Larger instances may be required based on the throughput and number of Domains etc required and the expected resource use of each;
  10. On the 'VPC Settings' panel Configure the VPC settings to your requirements or leave the defaults;
  11. On the 'Security Group' panel, specify the security group. The security group needs to permit to following ports [note that the internal firewall will be configured later to permit only ports used by WebSphere]:
    1. Port 22 to connect via SSH (enabled by default) to the instance hosting the DataPower Virtual Edition, 
      
      Port 9990 to reach the IBM Datapower Virtual Edition Gateway Console, 
      Port 5550 to reach the IBM DataPower XML Management Interface (XMI)
      Port 9090 to reach RapidDeploy web console, 
      Port 20000 and 20100 to open for RapidDeploy Remote Agent (optional
    • If you don't already have a security group as above, go to your EC2 Control Panel and select 'Security Groups' under 'Network & Security'
    • Click 'Create Security Group' button
    • To open all ports, Click 'Add Rule'. 
    • In the 'Type' dropdown, Specify 'All TCP' or your preferred configuration.
    • In the 'Source' dropdown, Specify 'Anywhere' or your preferred configuration.
  12. On the 'Key Pair' panel, select a key pair to use. You will need this key later to connect to the instance.
  13. Scroll back to the top of the page and click 'Accept Software Terms and Launch with 1-Click'.
  14. The Instance will be Launched.

2.2 From the AWS EC2 Control Panel

  1. Select the IBM WAS AMI based on your requirements;
  2. Right click on the AMI, or from the drop down menu, choose the ‘Launch’ option;
  3. On the 'Choose Instance Type' tab, choose the instance type. The m3.large type or larger is recommended when running IBM DataPower Virtual Edition. t2.medium is the minimal requirement, which will be sufficient to run the instance but the response times may be quite poor. Larger instances may be required based on the throughput and number of Domains etc required and the expected resource use of each; Click 'Next: Configure Instance Details'.
  4. On the 'Configure Instance' tab Configure the instance to your requirements or leave the defaults. Click 'Next: Add Storage'.
  5. On the 'Add Storage' tab, add additional storage as required or leave as default. Click 'Next: Tag Instance'.
  6. On the 'Tag Instance' tab, Tag your instance with a suitable name. Click 'Next: Configure Security Group'.
  7. On the 'Configure Security Group' tab, specify the security group. The security group needs to permit to following ports:
    1. Port 22 to connect via SSH (enabled by default) to the instance hosting the DataPower Virtual Edition, 
      
      Port 9990 to reach the IBM Datapower Virtual Edition Gateway Console, 
      Port 5550 to reach the IBM DataPower XML Management Interface (XMI)
      Port 9090 to reach RapidDeploy web console, 
      Port 20000 and 20100 to open for RapidDeploy Remote Agent (optional
    • To open all ports, Click 'Add Rule'. 
    • In the 'Type' dropdown, Specify 'All TCP' or your preferred configuration.
    • In the 'Source' dropdown, Specify 'Anywhere' or your preferred configuration.
  8. Click 'Review and Launch'.
  9. Review settings, then click 'Launch'.
  10. Add your key pair, Check the 'Acknowledge key file access' checkbox and click 'Launch Instance'.

3. Initial login to Linux

On Launching the IBM DataPower Virtual Edition instance, the IBM DataPower Virtual Edition is also launched. Therefore it is not necessary to log into the instance, but if you want to do so, for example to change the initial password(s), the instructions are given here.

Once the instance has started up (you can see it by having " 2/2 checks passed " in EC2 console).

  1. Log onto the instance from the EC2 console or via SSH as the ‘midvision’ user, using the key you selected above.  For example:
    • From the EC2 console by clicking  the "Connect to your instance" button with username "midvision", using the previously (instance launch-time) selected .pem keyfile.
    • Via SSH from your desktop, for example
      1. ssh -i ./MidVisionUSMC.pem midvision@ec2-52-87-198-23.compute-1.amazonaws.com
  2. You should see the MidVision banner and then you are logged in as the midvision user.
    1. Welcome to                                                                                                                                             
      
       __  __ _     ___     ___     _                    ____ _                 _ 
      |  \/  (_) __| \ \   / (_)___(_) ___  _ __        / ___| | ___  _   _  __| |
      | |\/| | |/ _` |\ \ / /| / __| |/ _ \| '_ \ _____| |   | |/ _ \| | | |/ _` |
      | |  | | | (_| | \ V / | \__ \ | (_) | | | |_____| |___| | (_) | |_| | (_| |
      |_|  |_|_|\__,_|  \_/  |_|___/_|\___/|_| |_|      \____|_|\___/ \__,_|\__,_|
      
                                                                                  
                                                             A MidVision Service
      
              * WebSite: http://portal.midvision.com/page/cloud-applications
              * Support: http://support.midvision.com/redmine/projects/devtestcloud
              * Wiki:    http://support.midvision.com/redmine/projects/devtestcloud/wiki      
      
      
      Welcome, this is DevTestCloud DataPower Virtual Edition image first run configuration
      Note that you can rerun this configuration wizard again by executing /home/midvision/firstrunsetup.sh script
      Configuration steps
      1. Set DataPower Virtual Edition password
      1. Set RapidDeploy framework initial password
      2. Open ports on RHEL firewall
      Configuring password for DataPower 'admin' user
      Set password for DataPower user 'admin'. Submit blank for default value of the instance id: i-ec6ddf76
      Make sure your password is at least 6 characters long
  3. Type a password or leave blank for the default instance-id and hit [return]. Confirm the password. You should see the following output. 
    1. Setting DataPower password for user admin...
      spawn telnet 0 2200
      Trying 0.0.0.0...
      Connected to 0.
      Escape character is '^]'.
      ip-172-30-0-234.ec2.internal
      Unauthorized access prohibited.
      login: admin
      Password: **********
      
      Welcome to IBM DataPower Gateway console configuration. 
      Copyright IBM Corporation 1999-2016 
      
      Version: IDG.7.5.0.0 build 274960 on Mar 11, 2016 3:09:45 PM
      Serial number: 0000001
      idg# configure terminal
      Global configuration mode
      idg(config)# user-password
      Enter old password: **********
      Enter new password: ******
      Re-enter new password: ******
      Password for user 'admin' changed
      Cleared RBM cache
      idg(config)# exit
      idg# eConnection closed by foreign host.
      DataPower password successfully set
      
      
  4. Set initial password for RapidDeploy user "mvadmin". Hit [return] to accept the default of the instance id.
    1. Configuring password for RapidDeploy default user 'mvadmin'
      Set password for user 'mvadmin'. Submit blank for default value of the instance id: i-380002a3
  5. Open required firewall ports on Red Hat Linux firewall. Select 'y' and hit [return].
    1. Open firewall ports for RapidDeploy (port 9090) [y/n]?
  6. The wizard finishes with the following output:

  7. Configuration finished, you may now start using DataPower (port 9990) and RapidDeploy (9090) service.

4. Accessing the installation

4.1 Access the IBM DataPower Gateway Console

To confirm installation, access the DataPower Gateway Console at:    https://[publicip]:9990/

Enter the Username/Password:    admin/[instance-id]

The password defaults to the instance-id of the AWS instance, unless you changed it as part of section 3 above.

4.2 RapidDeploy

RapidDeploy server and agent will start up automatically when you start your instance. You can access the web console onhttp://[publicip]:9090/MidVision  Note: make sure you have port 9090 open in your Security group when trying to access RapidDeploy web console. The preconfigured admin username is  'mvadmin'. The password default value is '[instance-id]', unless you changed it as part of section 3 above.  

You can prevent auto starting RapidDeploy on instance startup by removing it from the system chkconfig list.

[midvision@ ] systemctl disable rapiddeploy.service

5. Maintaining the installation

5.1 Opening Red Hat Entreprise Linux firewall with the open-firewall.sh script

RHEL instances are shipped with a firewall by default to protect your machine. For security reasons, the instance is only accessible via SSH (port 22) at first, so further ports can be opened on the firewall as needed. You will need to open all the ports in this internal firewall, which you have open in your Security group. There is a script placed in the user home of midvision (/home/midvision), which is also the starting location when logged in. You will need to be the root user to run this script. Example usage:

[midvision@ ] sudo ./open-firewall.sh 9990
Open firewall port 9990 iptables: Saving firewall rules to /etc/sysconfig/iptables:[ OK ]

5.2 Starting and stopping RapidDeploy manually

To restart RapidDeploy manually from the filesystem, use the rapiddeploy linux service. The RapidDeploy version is 4.0.13. RapidDeploy home is located at /var/rd/midvision Example usage: 

[midvision@ ] sudo service rapiddeploy start 
[midvision@ ] sudo service rapiddeploy stop  

The RapidDeploy server uses an in-memory database, so your RapidDeploy framework needs to be shut down properly to save your work. This happens when the instance is stopping or when calling the stop service manually from the command line. Note that on instance restart, unsaved data will be lost.

5.3 Users

  • midvision: This is the default user, which you can log in as. It is permitted to use all SUDO rights. To switch to the root user, type "sudo su".
  • root:      This is the superuser in linux systems. You can log in as any other user without using passwords. E.g: "su ec2-user",  "su midvision"
  • ec2-user:  This user does not have SUDO rights. If you want to switch back to root user, type "exit", this will take you back to the previous user session.

5.4 Files used for MidVision-Cloud services

There are a few scripts and other files in midvision and root users home directory, which will need to remain unchanged in order to keep the provided scripts working. There are some hidden files used as well,  .firstrun  indicates that the setup wizard has already been run once.

6.0 Troubleshooting

6.1 Session loss during setup

If you lose your SSH connection to the target instance during the first run setup script execution (e.g. as a result of a network problem), we advise you to delete and recreate the EC2 instance and run the script again.

6.2 Cannot access the IBM DataPower Virtual Edition Gateway Console 

Check that the default server is running, and you have correctly opened all the required ports on the firewall, especially 9990, and that your instance was created using a security group definition that allows TCP access to the instance on the required ports.

6.3 Contacting MidVision support

Please visit our support website.