NS9300XC Sensor Quik Strt Guide Revision A MAfee Network Seurity Pltform This Quik Strt Guide explins how to quikly set up nd tivte your MAfee Network Seurity Pltform NS9300XC Sensor to e lod lned y MAfee Network Seurity Pltform XC-640 Lod Blner Appline. Cling the Sensor s QSFP+ (Qud Smll Form-ftor Pluggle) Monitoring ports into the XC-640 enles you to lod lne the Sensor trffi. To upgrde n existing NS9300 Sensor to NS9300XC, ontt the MAfee Tehnil Support. For more informtion on the XC-640 Lod Blner Appline, see the MAfee Network Seurity Pltform XC-640 Lod Blner Appline Quik Strt Guide. All produt doumenttion referened in this Quik Strt Guide is found on the MAfee Servie Portl. Figure 1 Sensor front pnel 1
The NS9300XC Sensor onsists of Primry Sensor, NS9300XC-P, nd Seondry Sensor, NS9300XC-S. 1 Console ports on the NS9300XC-P nd NS9300XC-S Sensors (2) 2 QSFP+ 40 Gigit Ethernet Interonnet ports (4). G0/1 nd G0/2 on NS9300XC-P Sensor nd G4/1 nd G4/2 on NS9300XC-S Sensor. 3 Four slots for I/O modules (Any omintion of the interfe modules n e used) QSFP+ 40 Gigit Ethernet ports (4) QSFP+ 40 Gigit Ethernet ports (2) SFP/SFP+ 1/10 Gigit Ethernet Monitoring ports (8) RJ-45 10/100/1000 Mps Ethernet Monitoring ports (6) 4 RJ-45 10/100/1000 Mps Ethernet Monitoring ports (16) The supported trnseiver modules re QSFP+, SFP+ (MM nd SM), Fier SFP (MM nd SM) nd Copper SFP. Figure 2 Sensor rer pnel 1 USB ports (4) 2 Power supply A (Pwr A) 3 Power supply B (Pwr B) 4 RJ 45 100/1000/10000 Mngement port (Mgmt) (2). Mgmt on NS9300XC-S Sensor is used s n interonnet port. 2
5 RJ 45 100/1000/10000 Response port (R1) (2). R1 on NS9300XC-P Sensor is used s n interonnet port. 6 RJ 45 Auxiliry ports (Aux) (2) 1 Verify the ontents in the ox The following essories re shipped in the NS-series Sensor rte: Sensor Power supply Power ords. MAfee provides stndrd nd interntionl power les. Set of rk mounting rils Printed Quik Strt Guide 40G Diret Atth le 2 Verify the hrdwre nd softwre requirements The following hrdwre requirements re to e met. For more informtion, see the Instlltion Guide. The following re the system requirements for Mnger server. 3
Operting system Minimum required Any of the following: Windows Server 2008 R2 Stndrd or Enterprise Edition, English operting system, SP1 (64-it) (Full Instlltion) Windows Server 2008 R2 Stndrd or Enterprise Edition, Jpnese operting system, SP1 (64-it) (Full Instlltion) Windows Server 2012 Stndrd Edition (Server with GUI) English operting system Windows Server 2012 Stndrd Edition (Server with GUI) Jpnese operting system Windows Server 2012 R2 Stndrd Edition (Server with GUI) English operting system Windows Server 2012 R2 Stndrd Edition (Server with GUI) Jpnese operting system Windows Server 2012 R2 Dtenter Edition (Server with GUI) English operting system Windows Server 2012 R2 Dtenter Edition (Server with GUI) Jpnese operting system Only x64 rhiteture is supported. Reommended Sme s the minimum required. Memory 8 GB 8 GB or more CPU Server model proessor suh s Intel Xeon Sme Disk spe 100 GB 300 GB or more Network 100 Mps rd 1000 Mps rd Monitor 32-it olor, 1440 x 900 disply setting 1440 x 900 (or ove) The following re the system requirements for lient systems onneting to the Mnger pplition. Operting system Minimum Windows 7 English or Jpnese Windows 8 English or Jpnese Windows 8.1 English or Jpnese The disply lnguge of the Mnger lient must e sme s tht of the Mnger server operting system. Reommended RAM 2 GB 4 GB 4
Minimum Reommended CPU 1.5 GHz proessor 1.5 GHz or fster Browser Internet Explorer 9, 10 or 11 Mozill Firefox Google Chrome in not supported sine the NPAPI plug-in is disled y defult nd will not e supported y Google going forwrd. This mens tht Jv pplet support is lso disled y defult. Internet Explorer 11 Mozill Firefox 20.0 or ove The following softwre re to e instlled. Sensor imge Mnger imge Signture set 3 Instll the slide rils Follow this proedure to ssemle the slide rils nd position the Sensor on it. Rk instlltion - Remove inner memer from slides front rket d inner memer outer memer e sfety loking pin rer rket f relese utton Pull the relese utton to remove inner memer from slides. 5
Rk instlltion - Instll slides to rk Align rkets to desired vertil position on the rk nd insert the fsteners. Move the ll retiner to the front of slides. Do not hndle the NS-series ppline y the mounting rkets Chssis instlltion - Instll inner memer to hssis 6
Align inner memer key holes to stndoffs on hssis, move inner memer following the diretion the piture. d Chssis instlltion - Instll hssis to fixed slides Pull the relese utton in the inner memer to relese the lok nd llow the hssis to lose. e Chssis removl - Extend slides Fully extend the slides until it is in the loked position, pull the relese utton to relese lok nd disonnet inner memer from slides. 7
f Chssis removl - Remove inner memer from hssis Press sfety loking pin to relese inner memer from hssis. While instlling NS9300XC, this proedure is to e followed for oth the primry nd the seondry Sensors. 4 Instll the interfe modules You n purhse the following interfe modules nd insert them into the relevnt slots on your NS-series Sensor. 2-port QSFP+ 40 Gigit interfe module 4-port QSFP+ 40 Gigit interfe module 4-port SFP/SFP+ 10/1 Gigit 8.5 µm (SM) interfe module with internl fil-open 4-port SFP/SFP+ 10/1 Gigit 50 µm (MM) interfe module with internl fil-open 4-port SFP/SFP+ 10/1 Gigit 62.5 µm (MM) interfe module with internl fil-open 8
5 8-port SFP/SFP+ 1/10 Gigit interfe module 6-port RJ-45 10/100/1000 Mps Ethernet interfe module Remove the module from its protetive pkging. Grip the sides of the module with your thum nd fore-finger nd insert the module into the slot. Drive in the srews fixed on the sides of the module to tth it to the Sensor. Cle the Mngement nd Console ports Plug Ctegory 5e Ethernet le in the Mngement port (leled Mgmt)on the rer pnel of the NS9300XC-P Sensor. Plug the other end of the le into the network devie onneted to your Mnger server. Plug the DB9 Console le(s) into the Console port (leled Console)on the front pnel of the NS9300XC-P nd NS9300XC-S Sensors. d Connet the other end of the Console port le diretly to COM port of the PC or terminl server you will e using to onfigure the Sensor (for exmple, PC running orretly onfigured Windows Hyperterminl softwre). You must onnet diretly to the onsole for initil onfigurtion; you nnot onfigure the Sensor remotely. Terminl servers re provided for onsole ess. 9
The required settings for Hyperterminl re: Bud rte: 115200 Stop Bits: 1 Numer of Bits: 8 Control Flow: None Prity: None e Plug one end of the power le into the power inlet nd plug the other end into power soure. The Sensor ships with stndrd US power nd interntionl les. The NS-series Sensor does not hve power swith; you need to only plug the power le into power soure. 6 Cle the Monitoring ports This proedure desries how to le Sensor to onnet it to the XC-640 Lod Blner Appline. Plug the le pproprite for use with your QSFP module into port G1/1. MAfee supports only those QSFP modules purhsed through MAfee or from MAfee-pproved vendor. Do not use XC ports. These ports re reserved for interonnetion etween the primry (NS9300XC-P) nd seondry (NS9300XC-S) Sensors. Connet the other end of the le to Sensor port on the XC-640 Lod Blner Appline. For instrutions on using the XC-640 Lod Blner Appline, see the MAfee Network Seurity Pltform XC Cluster Administrtion Guide. 10
7 Cle the interonnet ports This proedure desries how to onnet the NS9300XC-P Sensor to the NS9300XC-S Sensor. Plug the supplied 40G Diret Atth le into port G0/1 of the NS9300XC-P Sensor nd onnet the other end of the le into port G4/1 of the NS9300XC-S Sensor. Plug the supplied 40G Diret Atth le into port G0/2 of the NS9300XC-P Sensor nd onnet the other end of the le into port G4/2 of the NS9300XC-S Sensor. Plug the supplied le into the Response port (R1) of NS9300XC-P Sensor nd onnet the other end of the le into the Mngement port (Mgmt) port of the NS9300XC-S Sensor. 11
8 Add the Sensor to the Mnger The Mnger displys the Login ID pge. Log on to the Mnger. The defult Login ID is dmin nd the defult Pssword is dmin123. Clik Configure. You do not require liense file to enle IPS on NS9300XC Sensors. To dd Sensor in the Mnger, selet Devies <Admin Domin> Glol Add nd Remove Devies, nd then lik New. The Add New Devie pge is displyed. Enter the Devie Nme. The Sensor nme must egin with letter. The mximum length of the nme is 25 hrters. Enter the Devie Type, Lod Blner-XC-640. Enter the Shred Seret. Re-enter to onfirm. The shred seret must e minimum of 8 hrters nd mximum of 25 hrters in length. The key nnot strt with n exlmtion mrk nor n hve ny spes. The prmeters tht you n use to define the key re: 26 lphets: upper nd lower se (,,,...z nd A, B, C,...Z) 10 digits: 0 1 2 3 4 5 6 7 8 9 32 symols: ~ `! @ # $ % ^ & * ( ) _ + - = [ ] { } \ ; : " ',. <? / The Sensor nme nd shred seret key tht you enter in the Mnger must e identil to the shred seret tht you will lter enter during physil instlltion/initiliztion of the Sensor (using CLI). If not, the Sensor will not e le to register itself with Mnger. d Selet the Updting Mode, either Online or Offline. Seleting Offline enles Offline Sensor updte.online is the defult mode. 12
e f g h i Enter Contt Informtion nd Lotion (optionl) Clik Sve. An informtion ox onfirms suessful ddition of Sensor. Clik Next. The new Sensor is listed in the Sensors pge. You n selet the Sensor nd lik Edit to edit the Sensor settings. 9 Configure Sensor informtion Configure the Sensor with the network informtion, nme, nd the shred seret key tht the Sensor uses to estlish seure ommunition with the Mnger. Use the nme nd key vlues you set in step 5d. The first time you onfigure Sensor, you must hve physil ess to the Sensor. You onfigure the NS9300XC Sensor using the CLI of the primry Sensor (NS9300XC-P). At ny time during onfigurtion, you n type question mrk (?) to get help on the Sensor CLI ommnds. For list of ll ommnds, type ommnds. Log on to the primry Sensor using the terminl onneted to the Console port. At the prompt, log on using the defult Sensor usernme (dmin) nd pssword (dmin123). [Optionl, ut reommended]. Chnge the Sensor pssword. At the prompt, type: psswd.the Sensor prompts you to enter the new pssword nd prompts you for the old pssword. A pssword must ontin etween 8 to 25 hrters, is se-sensitive, nd n onsist of ny lphnumeri hrter or symol. d Set the nme of the Sensor: You n enter the setup ommnd t the prompt nd this will utomtilly prompt you to provide the informtion shown in items 4 through 7 nd item 10. Or, you use the set ommnd insted. If you use the set ommnd, you must mnully enter the omplete ommnd syntx s shown in items 4 through 7 nd item 10. 13
At the prompt, type: set sensor nme <word>. Exmple: set sensor nme HR_sensor1 The Sensor nme is se-sensitive hrter string up to 25 hrters. The string n inlude hyphens, undersores, nd periods, nd must egin with letter. e f g If the Sensor is not on the sme network s the Mnger, set the ddress of the defult gtewy. At the prompt, type: set sensor gtewy <A.B.C.D> Exmple: set sensor gtewy 192.168.3.68 Set the IP ddress of the Mnger server. At the prompt, type: set mnger ip <A.B.C.D>. Exmple: set mnger ip 192.168.2.8 Set the IP ddress nd sunet msk of the Sensor. At the prompt, type: set sensor ip <A.B.C.D> <E.F.G.H>. Exmple: set sensor ip 192.168.2.12 255.255.255.0 Speify n IP ddress using four otets seprted y periods: X.X.X.X, where X is numer etween 0 nd 255, followed y sunet msk in the sme formt. h If prompted, reoot the Sensor. Type: reoot The Sensor n tke up to five minutes to omplete its reoot. i j Ping the Mnger from the Sensor to determine if your onfigurtion settings to this point hve suessfully estlished the Sensor on the network. At the prompt, type: ping <mnger IP ddress>. If the ping is suessful, ontinue with the following steps. If not, type show to verify your onfigurtion settings nd hek tht the informtion is orret. Set the shred seret key vlue for the Sensor. At the prompt, type: set sensor shredseretkey. The Sensor then prompts you to enter nd, susequently, onfirm the shred seret key vlue. This vlue is used to estlish trust reltionship etween the Sensor nd the Mnger. The seret key vlue n e etween 8 nd 25 hrters of ny ASCII text. The shred key vlue is se-sensitive. Mke sure the vlue mthes the shred seret key vlue you provided in the Mnger interfe. k l To verify the onfigurtion informtion, type show. Chek tht ll informtion is orret. To exit the session, type exit. 10 Verify suessful instlltion A hndshke proess egins etween the Sensor nd the Mnger. The devies will tke few seonds to estlish ommunition. 14
Perform the following steps to verify suessful ommunition etween the Sensor nd the Mnger. d In the Sensor CLI, type: sttus. The sttus report ppers. The Sensor prmeter System Initilized should e yes, nd for Mnger ommunition Trust Estlished should e yes. Return to the Mnger. In the Mnger Home pge, view the Mnger sttus in the System Helth setion. The Mnger sttus should e up nd the Sensor sttus should e tive. From the Mnger Home pge, lik Devies to open the Devies pge. Selet your dded Sensor from the Devies t. The ports for this Sensor pper under the Devies <Admin Domin Nme> Devies <Devie_Nme> Setup Physil Ports. <Devie_Nme> indites the nme of the Sensor you dded. e Clik the utton representing the ports on the Sensor tht you led. Ensure tht your port settings mth the ling. 11 You're up nd running! Your Sensor is tively monitoring onneted segments nd ommuniting with the Mnger for dministrtion nd mngement opertions. d Red MAfee Network Seurity Pltform Quik Tour for n overview of the system. For detiled usge instrutions, see MAfee Network Seurity Pltform Instlltion Guide nd MAfee Network Seurity Pltform IPS Administrtion Guide, or lik the Detiled Help uttons in the upper-right orner of eh window in the Mnger. Lunh the Thret Anlyzer from the Home pge to view lert sttistis s ttks re deteted. These will disply in the Unknowledged Alert Summry re of the Mnger Home pge. Hving prolems? Chek MAfee Network Seurity Pltform Trouleshooting Guide for trouleshooting informtion. Note tht most deployment prolems stem from onfigurtion mismthes etween the Sensor nd the network devies to whih it is onneted. Chek your duplex nd uto-negotition settings on oth devies to ensure they re synhronized. If you need to ontt Tehnil Support, go to https://mysupport.mfee.om. 15
Copyright 2015 MAfee, In. www.intelseurity.om Intel nd the Intel logo re trdemrks/registered trdemrks of Intel Corportion. MAfee nd the MAfee logo re trdemrks/ registered trdemrks of MAfee, In. Other nmes nd rnds my e limed s the property of others. 16 700-4519A00