Complete the following prerequisites before deploying PingIntelligence policy on Akana API gateway.
Verify that ASE is in sideband mode:Check that ASE is in sideband mode by running the following ASE command:
/opt/pingidentity/ase/bin/cli.sh status API Security Enforcer status : started mode : sideband http/ws : port 80 https/wss : port 443 firewall : enabled abs : enabled, ssl: enabled abs attack : disabled audit : enabled sideband authentication : disabled ase detected attack : disabled attack list memory : configured 128.00 MB, used 25.60 MB, free 102.40 MB
If ASE is not in sideband mode, then stop ASE and change the mode by editing the /opt/pingidentity/ase/config/ase.conf file. Set mode as sideband and start ASE.
# ./bin/cli.sh enable_sideband_authentication -u admin –p
Ensure SSL is configured in ASE for client side connection using CA-signed certificate.Please refer to Configure SSL for external APIs for more details.
# ./bin/cli.sh -u admin -p admin create_sideband_token
Enable connection keepalive between gateway and ASE- Navigate to /opt/pingidentity/ase/config/. Set the value of enable_sideband_keepalive to true in ase.conf file. If the ASE is running stop it, before making the change. Start ASE after setting the value. For more information on ASE configuration, see Sideband ASE configuration - ase.conf