M-2750 Sensor Quik Strt Guide Revision B MAfee Network Seurity Pltform This Quik Strt Guide explins how to quikly set up nd tivte your MAfee Network Seurity Pltform M-2750 Sensor in in-line mode. Cling the Sensor's Smll Form-ftor Pluggle (SFP) Gigit Ethernet Monitoring ports for in-line mode enles you to onfigure the Sensor to drop ttks efore they reh their trget. If you re setting up your Sensor in SPAN or Tp mode, see the Sensor's Produt Guide for ling instrutions. All produt doumenttion referened in this Quik Strt Guide is found on the MAfee Servie Portl. The Sensor pnel The M-2750 Sensor is 2RU (2 rk unit) nd is equipped with the following omponents: 1 RJ-45 10/100/1000 Mngement port (1) 6 Externl Compt Flsh port (1) 2 RS-232C Console port (1) 7 Front pnel LEDs (4) 3 RS-232C Auxiliry port (1) 8 Power supply A (inluded) 4 RJ-11 Fil-Open Control ports (10) 9 Power supply B (optionl; sold seprtely) 5 SFP One Gigit Ethernet Monitoring ports (20) 10 Bk pnel LEDs (5) 1
Sensor setup overview This setion explins how to position nd le the vrious ports of your Sensor. This setion lso riefly explins how to instll the Mnger nd then dd the Sensor to the Mnger, nd verify tht you hve suessfully estlished ommunition etween the Sensor nd the Mnger. 1 Positioning the Sensor Relese the rils nd tth inner rils (of three-in-one set) to the hssis y fstening it with the srews provided. Atth L-shpe nd externl rils to the rk frme. Instll the Sensor into rk nd mount ers. You n lso mid-mount the Sensor (optionl). 2
d Instll the redundnt power supply (optionl). e Instll modules in the Sensor's Monitoring ports. 2 Cling the Mngement nd Console ports Ensure the Sensor is powered OFF efore tthing les. d Plug Ctegory 5e Ethernet le in the Mgmt port. Plug the other end of the le into the network devie onneted to your Mnger server. Plug the DB9 Console le supplied in the Sensor ox into the Console port (leled Console on the Sensor front pnel). Connet the other end of the Console port le diretly to COM port of the PC or terminl server you will e using to onfigure the Sensor (for exmple, PC running orretly onfigured Windows HyperTerminl softwre). You must onnet diretly to the onsole for initil onfigurtion; you nnot onfigure the Sensor remotely. 3
The required settings for HyperTerminl re: Bud rte: 38400 Stop Bits: 1 Numer of Bits: 8 Control Flow: None Prity: None e Plug the femle end of power le into the power inlet nd plug the other end into power soure. The Sensor ships with stndrd US power nd interntionl les. The M-2750 does not hve power swith; you need to only plug the power le into power soure. 3 Cle the Monitoring ports This proedure desries how to le Sensor to run in in-line mode. Plug the le pproprite for use with your SFP module into one of the Monitoring ports leled xa (for exmple, 1A). MAfee supports only those SFP modules purhsed through MAfee or from MAfee-pproved vendor. Plug nother le into the peer of the port used in the erlier step. This port will e leled xb (for exmple, 1B). Connet the other end of eh le to the network devies tht you wnt to monitor. (For exmple, if you pln to monitor trffi etween swith nd router, onnet the le onneted to 1A to the router nd the one onneted to 1B to the swith.) For instrutions on how to le the Sensor to run in other operting modes, see the MAfee Network Seurity Pltform Sensor Produt Guide for your Sensor model. 4 Instll the Mnger Softwre For detiled instrutions, refer to MAfee Network Seurity Pltform Instlltion Guide. You must hve dministrtor privileges on the trget Windows server to instll the Mnger softwre. A MySQL dtse is inluded with the Mnger nd is instlled (emedded) utomtilly on your trget Windows server during this proess. 4
Following steps riefly explin the Mnger instlltion: d e f Prepre the system ording to the requirements outlined in MAfee Network Seurity Pltform Instlltion Guide nd the Network Seurity Pltform Relese Notes. Close ll open pplitions. Go to MAfee Updte Server nd log on, using the grnt numer nd pssword. Go to Mnger Softwre Updtes folder nd selet the ltest Mnger softwre version ville. Downlod the zip file to the trget Windows server nd extrt the setup file. Doule-lik Mnger_<version>_setup.exe nd follow the on sreen prompts. 5 Strt the Mnger Clik Strt Progrms MAfee Network Seurity Mnger Network Seurity Mnger. You do not require liense file for using Mnger/Centrl Mnger version 5.1.17.2 or ove, nd 6.0.7.x or ove. 6 Adding the Sensor to the Mnger The Mnger displys the Login ID pge. Log on to the Mnger. The defult Login ID is dmin nd the defult Pssword is dmin123. Clik Configure. 5
An dd-on liense is required to enle NAC on M-series Sensors. To import nd ssign n dd-on liense, go to Devie List Add-On Lienses pge. For more informtion, see MAfee Network Seurity Pltform Instlltion Guide. You do not require liense file to enle IPS on M-series Sensors. d To dd Sensor in the Mnger, lik Devie List Devies, nd then lik New. The Add New Devie pge is displyed. e Enter informtion in the pproprite fields nd lik Sve. Rememer the Shred Seret vlue entered t this step. This vlue is used while you onfigure the Sensor. For more informtion on the fields in Add New Devie pge, see MAfee Network Seurity Pltform Instlltion Guide. 7 Configuring Sensor informtion Configuring the Sensor involves speifying network informtion, nme, nd the shred seret key tht the Sensor uses to estlish seure ommunition with the Mnger. Use the sme nme nd key vlues set erlier. The first time you onfigure the Sensor, you must hve physil ess to the Sensor. 6
At ny time during onfigurtion, you n type question mrk (?) to get help on the Sensor ommnd-line interfe (CLI) ommnds. For list of ll ommnds, type ommnds. Log on to the Sensor using the terminl onneted to the Console port. At the prompt, log on using the defult Sensor user nme (dmin) nd pssword (dmin123). Optionl, ut reommended Chnge the Sensor pssword. At the prompt, type: psswd. The Sensor prompts you to enter the new pssword nd prompts you for the old pssword. A pssword must ontin etween 8 nd 25 hrters, is se-sensitive, nd n onsist of ny lphnumeri hrter or symol. d Set the nme of the Sensor: You n enter the setup ommnd t the prompt nd this will utomtilly prompt you to provide the neessry informtion or you n use the set ommnd insted. If you use the set ommnd, you must mnully enter the omplete ommnd syntx. Exmple: At the prompt, type: set sensor nme <word>. Exmple: set sensor nme HR_sensor1 The Sensor nme is se-sensitive hrter string up to 25 hrters. The string n inlude hyphens, undersores, nd periods, nd must egin with letter. e f g If the Sensor is not on the sme network s the Mnger, set the ddress of the defult gtewy. At the prompt, type: set sensor gtewy <A.B.C.D>. Exmple: set sensor gtewy 192.168.3.68 Set the IP ddress of the Mnger server. At the prompt, type: set mnger ip <A.B.C.D>. Exmple: set mnger ip 192.168.2.8 Set the IP ddress nd sunet msk of the Sensor. At the prompt, type: set sensor ip <A.B.C.D> <E.F.G.H>. Exmple: set sensor ip 192.168.2.12 255.255.255.0 Speify n IP ddress using four otets seprted y periods: X.X.X.X, where X is numer etween 0 nd 255, followed y sunet msk in the sme formt. h If prompted, reoot the Sensor. Type: reoot. The Sensor n tke up to five minutes to omplete its reoot. 7
i j Ping the Mnger from the Sensor to determine if your onfigurtion settings to this point hve suessfully estlished the Sensor on the network. At the prompt, type: ping <mnger IP ddress>. If the ping is suessful, ontinue with the following steps. If not, type show to verify your onfigurtion settings nd hek tht the informtion is orret. Set the shred seret key vlue for the Sensor. At the prompt, type: set sensor shredseretkey. The Sensor then prompts you to enter the shred key vlue nd onfirm the sme. This vlue is used to estlish trust reltionship etween the Sensor nd the Mnger. The seret key vlue n e etween 8 nd 25 hrters of ny ASCII text. The shred key vlue is se-sensitive. Mke sure the vlue mthes the shred seret key vlue you provided in the Mnger interfe. k l To verify the onfigurtion informtion, type show. Chek tht ll informtion is orret. To exit the session, type exit. 8 Verify suessful instlltion A hndshke proess egins etween the Sensor nd the Mnger. The devies will tke few seonds to estlish ommunition. Perform the following steps to verify suessful ommunition etween the Sensor nd the Mnger. In the Sensor CLI, type: sttus. The sttus report ppers 8
d Return to the Mnger. In the Mnger Home pge, view the Mnger sttus in the System Helth setion. Mnger sttus should e up nd Sensor sttus should e tive. From the Mnger Home pge, lik Configure to open the Configurtion pge. Selet your dded Sensor: Devie List Sensor_Nme. The ports for this Sensor pper under the Sensor_Nme node. "Devie_Nme" indites the nme of the Sensor you dded. e A poliy nmed Defult Inline IPS is tive upon Sensor ddition. To view this poliy, selet IPS Settings Poliies IPS Poliy Editor. Now selet Defult Inline IPS from the list nd lik View / Edit. The Defult Inline IPS poliy ontins ttks lredy onfigured with "loking" Sensor response tion; if ny ttk in the poliy is triggered, the Sensor utomtilly loks the ttk. To tune this or ny other MAfee-provided poliies, you n lone the poliy nd then ustomize it s desried in the MAfee Network Seurity Pltform IPS Administrtion Guide. f Clik Devie List Devie_Nme Port Settings. For more informtion on port settings, see Configurtion Sensor monitoring nd response ports, MAfee Network Seurity Pltform IPS Administrtion Guide. g Clik the utton representing the ports on the Sensor tht you led. Ensure tht your port settings mth the ling (for exmple, In-line mode). 9
9 You're up nd running! Your Sensor is tively monitoring onneted segments nd ommuniting with the Mnger for dministrtion nd mngement opertions. d Red MAfee Network Seurity Pltform Quik Tour for n overview of the system. For detiled usge instrutions, see MAfee Network Seurity Pltform Instlltion Guide nd MAfee Network Seurity Pltform IPS Administrtion Guide, or lik the Detiled Help uttons in the upper-right orner of eh window in the Mnger. Lunh the Thret Anlyzer from the Home pge to view lert sttistis s ttks re deteted. These will disply in the Unknowledged Alert Summry re of the Mnger Home pge. Hving prolems? Chek MAfee Network Seurity Pltform Trouleshooting Guide for trouleshooting informtion. Note tht most deployment prolems stem from onfigurtion mismthes etween the Sensor nd the network devies to whih it is onneted. Chek your duplex nd uto-negotition settings on oth devies to ensure they re synhronized. If you need to ontt Tehnil Support, go to https://mysupport.mfee.om. 10
11
Copyright 2013 MAfee, In. Do not opy without permission. MAfee nd the MAfee logo re trdemrks or registered trdemrks of MAfee, In. or its susidiries in the United Sttes nd other ountries. Other nmes nd rnds my e limed s the property of others. 12 700-3594B00