First-Time Setup: A Simple Walkthrough
Your appliance is powered on and you are looking at the Appliance Console for the first time. This guide takes you from that screen to one working connection. Twelve steps, in order, no prior XONA experience needed.
Before you start
Have these ready. Sorting them out first is what makes the rest of this guide quick - the steps themselves take about an hour, but a firewall change can take days if nobody has asked for it yet.
- ☐ A spare power outlet (the plug type depends on your region)
- ☐ Two free Ethernet ports on your switch or firewall
- ☐ Two IP addresses, one for the Trusted interface and one for the Untrusted interface, on different subnets
- ☐ A computer you can use to reach the appliance once it has an IP address
You also need two firewall openings. Ask for these early - waiting on a firewall change is the most common reason a setup stalls.
| What to open | Why it is needed |
|---|---|
| TCP 443 to the Untrusted interface IP, from the networks your users are on | So your users can reach the appliance's login page in a browser |
| UDP 39251 outbound, from the CSG's Untrusted interface IP to the XCM | So the CSG and the XCM can talk to each other. Only needed if you have an XCM |
ℹ Using a virtual machine instead of a physical appliance?
Skip the power outlet and the Ethernet ports. Everything else on this page applies exactly the same way.
ℹ Do the steps in the order they are written
Several of them are difficult or impossible to undo later. If you have both an XCM and one or more CSGs, set up the XCM first, all the way through, then do each CSG.
Bring them up one at a time. Every appliance leaves the factory with the same default IP addresses, so two of them powered on to the same network at once will clash. Finish the first one's addresses before you power on the second.
First, the two places you log in
Every XONA appliance has two separate places to sign in. They have separate passwords that are not linked in any way. Mixing them up is the most common early confusion, so it is worth two minutes to learn the difference now.
How it fits together. The Appliance Console is a text menu used for network settings, while the web interface is used for licensing, users and connections.
Both use the username
admin, and both start with the passwordadmin. Changing one does not change the other.
Part 1 - In the Appliance Console
1. Appliance Console - Log in and set a new console password
Press ENTER, then log in with the password admin. Accept the license terms if you are shown them, then choose a new password when prompted.
The new password must be at least 15 characters and include a lowercase letter, an uppercase letter, a number, and a symbol. Save it in your password manager before you go any further.
Do not skip past the license terms. On a virtual appliance, accepting them is what creates the appliance's unique ID - and you cannot get a license file without that ID. You will need it in step 7.
⛔ There is no password reset for this
If the console password is lost on an XCM, the only fix is to rebuild or replace the appliance. Do not skip saving it.
2. Appliance Console - Write down the Recovery Key and the Installation ID
Go to Appliance Setup → About Appliance (shown as About CSG or About XCM). Copy the Recovery Key into your password manager or secret store.
This key unlocks the appliance's encrypted disk if it ever refuses to start on its own. XONA does not keep a copy of it.
On a virtual appliance there is no recovery key, and that is normal. Only physical appliances encrypt their own disk, using hardware built into them. If you are running a VM and see no key here, nothing is wrong - encrypt the VM's storage in your hypervisor instead.
⚠ Never force the power off
On a physical appliance, repeatedly cutting power can make it ask for this key at the next start. Always shut down properly rather than pulling the plug.
While you are on this screen, also note the Installation ID. That is what you send to XONA to get your license in step 7.
Installation ID blank? On a virtual appliance it does not exist until the license terms have been accepted. Go back and accept them, and reboot the appliance if it is still blank afterwards.
3. Appliance Console - Set the IP addresses
Go to Network Configuration and use Configure Trusted and Configure Untrusted. Set a static IP address on each interface you are using.
| Interface | What connects to it |
|---|---|
| Trusted (green dot) | The equipment your users will reach through the appliance |
| Untrusted (red dot) | Your users, and the XCM |
The two interfaces must be on different subnets that do not overlap, or traffic will not reach one of them.
Working over the network rather than a monitor and keyboard? Changing the address you are connected through will drop your session. That is normal. Reconnect using the new address.
Only using one of the two interfaces? On the one you are not using: clear its IP settings, turn off both IPv4 Configuration and IPv6 Configuration, and uncheck Automatically Connect.
4. Appliance Console - Give a gateway to one interface only
A gateway is the way out of the local network. Fill in the Gateway field on one interface only - the one that should carry traffic to the rest of your network. On the other interface, either leave the Gateway field empty or tick Never use this network for default route.
Then run Network Configuration → Restart Network to apply everything. Give it a few seconds.
NO - Two gateways
- Traffic leaves by the wrong path
- Symptoms look random and hard to trace
- The most common setup mistake there is
OK - One gateway
- One clear way out
- Predictable behavior
- Check it under Network Tools → Show Network
5. Appliance Console - Turn on time sync
Still in Network Configuration, open Set Time Servers and enter a time server the appliance can actually reach on your network. Then check Timesync Status and confirm it is enabled and working.
⚠ Do not leave this for later
A wrong clock is the single most common cause of trouble on these appliances. It breaks multi-factor codes, single sign-on, and the connection between a CSG and an XCM - all at once, and with confusing symptoms. Two minutes here saves hours later.
Part 2 - In the web interface
You can now leave the console. Open a browser and go to https:// followed by one of the IP addresses you just set. Either one reaches the same web interface - administrators normally work from the Trusted side, while your users will come in on the Untrusted side.
Your browser will warn you that the connection is not private. That is expected on a brand-new appliance, and step 8 explains why. Continue past the warning for now.
6. Web interface - Log in and set the web password
Sign in with admin / admin. You will be asked to choose a new password (at least 12 characters) and to accept the license agreement.
This is a different password from the console one. Save it separately.
Being asked about the license terms a second time is not a mistake. The console and the web interface each ask once. Accept it here too.
7. Web interface - Install your license
Go to Settings → General → License. Send the Installation ID you noted in step 2 (also called the System UUID) to XONA, and you will get a license file back. Then use Choose File and Upload License.
The license is tied to that one appliance's ID, so each CSG and XCM needs its own.
Check that the Expires date and connection limits look right afterwards.
ℹ Until it is licensed, the appliance is limited
It starts on an evaluation license that allows only a couple of connections, and shows a warning banner to administrators. That is normal at this stage.
8. Web interface - Install a certificate, or leave it for later
The appliance already protects traffic with a certificate it generated itself, called a self-signed certificate. It works, but browsers do not recognize who issued it, which is why you saw the warning.
✓ It is fine to stay on the self-signed certificate at first
Nothing in the rest of this guide needs a proper certificate, and it is completely normal to get everything working first and sort the certificate out afterwards. You will just keep clicking past the browser warning until you do. Plan to replace it before you hand the appliance to real users, so they are not taught to ignore security warnings.
When you are ready: go to Settings → Security Settings → Certificates and upload one. A certificate is issued to a name rather than an IP address, so this goes together with giving the appliance a DNS name on your network. That name is also required if you later want people to sign in with security keys.
Getting the certificate itself has its own guide - use the SSL Certificate Setup Guide that matches your tools, then come back here.
9. Web interface - Join the CSG to the XCM (skip if you have no XCM)
If you have an XCM, connect each CSG to it now, before you create users and connections. Two blocks of text are exchanged between the two appliances; see the Joining a CSG to the XCM guide for the exact steps.
This link runs over UDP port 39251, from the CSG out to the XCM, and nothing else. If the join does not complete, that port is the first thing to check.
⚠ Being able to ping the XCM does not prove this will work
Ping and web pages use different ports, and this link has no fallback to them. It needs UDP 39251 specifically. One more thing worth asking your firewall team for: some firewalls close idle UDP traffic after 30 seconds, which makes the link drop and reconnect. 60 seconds or more avoids it.
⚠ Two rules that catch people out
If you are installing software updates as part of setup, update the XCM before the CSGs - the XCM's version must never be older than a CSG's. And if you are setting up a high-availability pair, do that last, after the join, not before.
10. Web interface - Create a user
Go to Users and press Add a User. The only thing you must fill in is the Username. A first password is generated for you, and the user is made to change it when they first sign in.
Do not test with the admin account in the steps below. Use this real user.
Have an XCM? Create your users and groups on the XCM instead, so they work across every CSG joined to it. Those users sign in at a CSG as MGR\username.
11. Web interface - Create a connection
Go to Connections and press Add a connection. Pick the type (RDP, SSH, VNC, Telnet or Web), give it a name, and fill in the address of the equipment you want to reach.
Use the Connection Test button before moving on. It tells you whether the appliance itself can reach that equipment, which is a much smaller problem to solve than a failing login.
12. Web interface - Give the user permission, then test as them
Open the connection and grant your new user the Connect permission. Creating a connection does not give anyone access to it - permission is always a separate, deliberate step.
Now sign out, or use a private browsing window, and log in as that user. Open the connection and confirm it works. This is the only test that proves the setup is finished.
✓ Last step: take a backup
Once that connection works, download a fresh backup of the appliance and store it somewhere safe. You now have a known-good starting point to return to.
Words you will keep seeing
| Term | What it means |
|---|---|
| CSG | The gateway. Users connect to it, and it reaches your equipment. |
| XCM | The manager. It centrally manages several CSGs. Optional. |
| Trusted interface | The port facing the equipment you want to reach. Green dot. |
| Untrusted interface | The port facing your users, and the XCM. Red dot. |
| Fabric | The private link between a CSG and an XCM. |
| Appliance Console | The text-menu screen. Network settings live here. |
| Connection | One saved route to one piece of equipment. |
| Installation ID | The appliance's unique ID. Needed to get a license. |
Checklist
- ☐ TCP 443 open to the Untrusted IP from your user networks
- ☐ UDP 39251 open from the CSG to the XCM (if you have one)
- ☐ Console password changed and saved
- ☐ Recovery Key written down somewhere safe
- ☐ IP addresses set, on non-overlapping subnets
- ☐ Exactly one interface has a gateway
- ☐ Network restarted
- ☐ Time sync on and confirmed working
- ☐ Web password changed and saved separately
- ☐ License uploaded, expiry date checked
- ☐ Certificate installed, or a deliberate decision to stay self-signed for now
- ☐ CSG shows Connected on the XCM (if you have one)
- ☐ A real user connected successfully - not the admin account
- ☐ Backup downloaded and stored
If something is not working
Almost every problem at this stage is one of three things.
| What you are seeing | Where to look first |
|---|---|
| The web interface will not load at all | The IP address and gateway in steps 3 and 4, then whether TCP 443 is actually open. Network Tools → Show Network in the console shows what the appliance thinks its route out is |
| Sign-in fails, or codes from an authenticator app are rejected as wrong | Step 5. A clock that is off by even a couple of minutes makes correct codes look wrong |
| The CSG never moves past Pending on the XCM | Step 9. UDP 39251, outbound from the CSG. Nothing else carries this link |
ℹ Still stuck?
Contact XONA Customer Success, and tell them which step you reached. That one detail saves a round of questions.