Die Dokumentation ist derzeit nur auf Englisch verfügbar.

Rolling out the first Core

This chapter takes a freshly installed CanMe appliance to a fully working Core, with your own computer connected to the new network and ready to open Cansole. You'll need the requirements at hand: your license key, the Core's public IP, and access to your DNS provider.

1. Configure the appliance's network (device console)

NOTE: This step is only required when you install the CanMe stack from an ISO image in your local environment. If you used one of our cloud provider images (AWS, Azure, GCP), this step is not needed and the rollout page (see point 2 below) is already up and running.

Open the appliance's console. You'll see the CanMe device console login.

  • Username: admin
  • Password on first boot: network — you'll want to change it right away via Change Password.

From the main menu choose System Configuration → Network Configuration. You can pick:

  • DHCP — the appliance takes its address from your network automatically, or
  • Static IP — you're asked in turn for the IP address (in CIDR notation, e.g. 192.168.1.100/24), the Gateway, and the DNS server, then confirm.

The console tests the connection and reports either "Gateway reachable. Configuration applied." or a warning if the gateway couldn't be reached. Console sessions log out automatically after 10 minutes of inactivity.

2. Open the rollout page

In a browser, open:

https://<appliance-ip>:8443

Your browser will warn about a self-signed certificate — that's expected at this stage; proceed. No account is needed.

On the first screen choose Core, then Install new Core.

3. Fill in the installation form

The CanMe Core Installation form asks for four things:

Field What to enter
License Key Your CanMe license key
Core Address The full name your platform will live under — a valid FQDN, e.g. customer.example.com. This becomes the address of Cansole and all platform services
Customer Name Your organization's name (used for your network's internal naming; spaces are removed)
Public IP Address This Core's public IPv4. It is auto-detected — correct it if the appliance is behind NAT. Clients and the Core's DNS records will point here

Click Start Installation.

The Core Address does not need to resolve in DNS yet — you'll create the DNS records in the next step, while the installation is already running.

4. Create the DNS records while the installation runs

The Core Rollout in Progress page shows a live progress bar — keep it open. Partway through, it displays a box titled "Create these DNS records at your provider" with the exact records for your setup. They follow this pattern (for a Core Address of customer.example.com and public IP 203.0.113.10):

customer.example.com.        NS   core-1-customer.example.com.
core-1-customer.example.com.   A    203.0.113.10

Create both records in your DNS provider's zone for example.com:

  • The NS record hands the platform's name over to the Core itself — from now on, the Core answers DNS for it.
  • The A record tells the world where that name server (the Core) lives.
  • If a plain A record for the Core Address already exists, remove it — the Core serves this name itself now.

The page shows a live DNS status line and the installation waits until the records resolve (up to 10 minutes — newly created records can take a few minutes to become visible). Once DNS is confirmed, the installation continues on its own.

5. Retrieve your credentials

When the page shows "Rollout Completed Successfully!", one important step remains: enter your license key in the verification field and click Retrieve Credentials.

The credentials are shown only once and cannot be retrieved again. Copy them with Copy to Clipboard (or select and copy manually) and store them somewhere safe — they are the administrator login for your new platform.

After that, the rollout page disables itself. Your Core is live — one step remains before you can log in to it.

6. Connect with the Cannector

Cansole and all other platform services live inside your secure network — they are not reachable directly from the open internet. To open Cansole, your computer first has to join the network with the Cannector, the CanMe client:

  1. Download and install the Cannector. The join page has the download links and step-by-step install instructions for every platform. In short: on Windows and Linux you need local administrator rights for the install; on macOS and iOS you install from the App Store and approve the VPN extension on first launch.
  2. Join your network. Open the Cannector, enter your Core Address (e.g. customer.example.com) as the network address, and sign in with the administrator credentials you retrieved in the previous step.
  3. A few things to watch on your machine: the Cannector only needs outbound port 443, but disconnect any other VPN while using it, and make sure no firewall performs SSL/TLS inspection on the connection.

Once the Cannector shows you as connected, Cansole is reachable in your browser at your Core Address:

https://<core-address>

If something goes wrong

If the installation fails, the page offers a Download Logs button. Download the log bundle and send it to CanMe support together with a short description — support can pinpoint the issue from it. A failed installation can be retried after the underlying cause (usually network or DNS) is fixed.

Next: First steps in Cansole

Eingesetzt in den sichersten Umgebungen.

Bereit, ohne Firewalls voranzukommen?

Buchen Sie eine 30-minütige Demo. Sehen Sie, wie CanMe Ihre Netzwerksicherheit transformiert – ohne Rip-and-Replace.

Demo buchen →

Oder schreiben Sie uns an hello@canme.cloud