
Getting Started
Several steps should be taken before the BeyondTrust hardware is delivered and installed:
1. Allocate the necessary rack space for the B Series Appliance. Ensure the space has the necessary power and network access.
2. Reserve a static IP address for the B Series Appliance on the network. Refer to the following guides in order to reserve the correct
IP address(es):
lBeyondTrust Appliance B Series in the Network - www.beyondtrust.com/docs/privileged-remote-access/getting-
started/deployment/dmz
3. Configure a DNS A-record for the fully qualified domain name (FQDN) of your new site (e.g., access.example.com).
Note: A private DNS A-record resolving to the static IP address of the B Series Appliance will always be necessary. A
public A-record and public IP will also be required if clients on public, external networks will need access to the B
Series Appliance.
Although your B Series Appliance can function anywhere in your network
with internet access, you will need to decide where in your network you plan
to install the B Series Appliance prior to this step. If you are going to access
systems outside of your network, BeyondTrust recommends placing your B
Series Appliance in a DMZ or outside of your internal firewall. See the table
below for more details. For assistance with your firewall configuration,
please contact the manufacturer of your firewall software.
Note: If you must move the B Series Appliance to another
location to connect it to the internet, you will need to power down
before you unplug it from its power source. If you can log into the
/appliance administrative interface, go to the Status > Basics
page and click Shut Down This Appliance. Manual shut down is
possible if you press and release the power button one time. Wait
60 seconds for the B Series Appliance to power down before
unplugging the B Series Appliance from the power source. When
you reconnect the B Series Appliance at the new location, you will
need to power up again.
Network Location Advantages/Disadvantages
Outside your firewall
Does not require that ports 80 and 443 be open inbound for TCP traffic on your firewall. Simplifies the
setup process significantly because both the representative and customer clients are built to resolve
to a specific DNS; if your registered DNS resolves to a public IP address directly assigned to your B
Series Appliance, no additional setup is required by you to initiate a session.
DMZ May require additional setup depending on your router or routers.
Inside your firewall Requires port forwarding on your firewall and possibly additional setup of your NAT routing and
internal DNS.
Network Location Considerations for B Series Appliances
SALES: www.beyondtrust.com/contact SUPPORT: www.beyondtrust.com/support DOCUMENTATION: www.beyondtrust.com/docs 5
©2003-2021 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or
depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.
TC: 4/19/2021
PRIVILEGED REMOTE ACCESS
B SERIES APPLIANCE HARDWARE INSTALLATION