Lancope StealthWatch System Handbuch

StealthWatch® System Hardware
Installation Guide
(for StealthWatch System v6.7.0)

Back
Installation Guide: StealthWatch System v6.7.0 Hardware
© 2015 Lancope, Inc. All rights reserved.
Document Date: March 19, 2015
Trademarks
Lancope, StealthWatch, and other trademarks are registered or unregistered trademarks of Lancope, Inc. All
other trademarks are properties of their respective owners.

Contents iii
CONTENTS
1-INTRODUCTION . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Audience . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
How to Use This Guide . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Documentation Icons . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Common Abbreviations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7
Other Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Related Documents . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
NetFlow Ninjas Blog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
StealthWatch Video Library . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Contacting Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
Document Feedback. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8
2-PRE-CONFIGURATION CONSIDERATIONS . . . . . . . . . . . . . . . . . . . . . 9
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
StealthWatch Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
StealthWatch Management Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
FlowCollector . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
FlowSensors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
UDP Director (also known as FlowReplicator) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Identity Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Placement Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Placing the SMC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 12
Placing the StealthWatch FlowCollector . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Placing the StealthWatch FlowSensor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Placing Other StealthWatch Products . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Configuring Your Firewall for Communications . . . . . . . . . . . . . . . . . . . . 14
Communication Ports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Integrating the FlowSensor into Your Network . . . . . . . . . . . . . . . . . . . . 17
TAPs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Using Electrical TAPs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Using Optical TAPs. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18
Using TAPs Outside Your Firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19
Placing the FlowSensor Inside Your Firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . 20
SPAN Ports . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
3-INSTALLATION . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23

iv Contents
Mounting the Appliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Hardware Included with the Appliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
Additional Required Hardware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 24
FlowCollector 5000 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26
Changing the Default User Passwords . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Connecting to the Appliance . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Connecting with a Keyboard and a Monitor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27
Connecting with a Laptop . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
Changing the Default IP Addresses . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29
Change the sysadmin User Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Change the root User Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34
Connecting the Appliance to the Network . . . . . . . . . . . . . . . . . . . . . . . . 38
Types of Servers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
SMCs 1000 & 2000 and FlowCollectors 1000 & 2000 . . . . . . . . . . . . . . . . . . . . . 38
UDP Director 2000, FlowSensors 2000 and 3000 . . . . . . . . . . . . . . . . . . . . . . . . 39
FlowSensor 4000 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 39
FlowCollector 4000 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
FlowCollector 5000 Engine . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40
FlowCollector 5000 Database. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
FlowSensor 250 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 41
FlowSensor 1000 and UDP Director (also known as FlowReplicator) 1000. . . . . 41
SMC 1010, FlowCollectors 1010 & 4010, FlowSensors 2010, 3010, 4010 and
UDP Director 2010 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
FlowSensor 1010 and UDP Director 1010 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
SMC 2010 and FlowCollector 2010 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 42
Connecting to the Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43

Introduction 5
INTRODUCTION
OVERVIEW
This guide explains how to install StealthWatch System products. It describes the
StealthWatch System components and how they are placed in the system, including
the integration of the FlowSensors. Also, this guide describes the mounting and
installation of the StealthWatch System hardware.
This chapter includes the following topics:
Audience
How to Use This Guide
Documentation Icons
Common Abbreviations
Other Resources
Audience
This guide is designed for the person responsible for installing StealthWatch system
hardware. We assume that you already have some general understanding of installing
network equipment (FlowSensor, FlowCollector, UDP Director (also known as
FlowReplicator), and the StealthWatch Management Console).
For information on configuring StealthWatch System products, please refer to the
StealthWatch System Hardware Configuration Guide.

6Introduction
How to Use This Guide
In addition to this introduction, we have divided this guide into the following chapters,
as well as an index:
Documentation Icons
This guide uses the following documentation icons:
Chapter Description
2 - Pre-Configuration
Considerations
Describes the StealthWatch system components and
their placement and the configuration of the firewall
for communications
3 - Installation Describes the mounting and installation of
StealthWatch hardware
Icon Meaning Description
Note Additional information you may find useful
Tip Helpful information, such as shortcuts or easier ways of
performing certain tasks
Important Information you must observe to prevent significant
consequences, such as the malfunction of software
Caution Information you must observe to prevent loss of data or
damage to hardware
Warning Information you must observe to prevent risk of personal
injury

Introduction 7
Common Abbreviations
The following abbreviations appear in this guide:
Abbreviation Description
AC Alternation Current
DMZ Demilitarized Zone (a perimeter network)
DNS Domain Name Server/Service
FC FlowCollector
FS FlowSensor
FTP File Transfer Protocol
HTTPS Hypertext Transfer Protocol (Secure)
Hz Hertz
IP Internet Protocol
ISE Identity Services Engine
Mbps Megabits per second
ms Milliseconds
NAT Network Address Translation
NIC Network Interface Card
NTP Network Time Protocol
PCIe Peripheral Component Interconnect Express
SCP Secure Copy
SMC StealthWatch Management Console
SNMP Simple Network Management Protocol
SPAN Switch Port Analyzer
SSH Secure Shell
TAP Test Access Port
UPS Uninterruptible Power Supply
URL Universal Resource Locator
USB Universal Serial Bus
VLAN Virtual Local Area Network

8Introduction
Other Resources
In addition to this guide, you may find these documents and online resources useful.
Related Documents
Please refer to your StealthWatch System Documentation CD for information about
StealthWatch appliances and their installation and configuration. Except for the online
Help,
Additional information is available in the StealthWatch User Community section of
the Lancope Web site (https://community.lancope.com/). If you do not have login
access to the User Community, send an Email requesting access to
NetFlow Ninjas Blog
Lancope’s NetFlow Ninjas blog (http://www.lancope.com/blog) provides a wealth of
information about NetFlow, the NetFlow industry, and new StealthWatch features, as
well as tips and tricks on using StealthWatch.
StealthWatch Video Library
The StealthWatch online video library (http://www.lancope.com/resource-center/
videos) showcases the benefits of StealthWatch for network performance and security
management.
Contacting Support
If you need technical support, please do one of the following:
Contact your local Lancope partner.
Call +1 800-838-6574.
Send an Email to [email protected].
Submit a case using the Support form on the Lancope Customer Community
web site (https://community.lancope.com).
Document Feedback
If you have comments about this document, please contact Lancope at
[email protected]m. We appreciate your feedback.

Pre-Configuration Considerations 9
PRE-CONFIGURATION
CONSIDERATIONS
OVERVIEW
This chapter examines the considerations you should make before installing and
configuring your StealthWatch appliances. It explains where to place StealthWatch
system products and how to integrate them into your network.
This chapter includes the following topics.
StealthWatch Components
Placement Considerations
Configuring Your Firewall for Communications
Integrating the FlowSensor into Your Network
2

10 Pre-Configuration Considerations
STEALTHWATCH COMPONENTS
The StealthWatch system is made up of several hardware components that gather,
analyze, and present information about your network to improve network performance
and security. This section describes the major StealthWatch components.
StealthWatch Management Console
The StealthWatch Management Console (SMC) is the control center for
StealthWatch. It manages, coordinates, configures, and organizes all of the different
components of the system. The SMC client software allows you to access the SMC’s
user-friendly graphical user interface (GUI) from any local computer with access to a
Web browser. Through the client GUI, you can easily access real-time security and
network information about critical segments throughout your enterprise.
Featuring Java-based platform independence, the SMC enables:
Centralized management, configuration, and reporting for up to 25
StealthWatch FlowCollectors
Graphical charts for visualizing traffic
Drill-down analysis for troubleshooting
Consolidated and customizable reports
Trend analysis
Performance monitoring
Immediate notification of security breaches
FlowCollector
The StealthWatch FlowCollector for NetFlow gathers NetFlow, cFlow, J-Flow,
Packeteer 2, NetStream, and IPFIX data to provide cost-effective, behavior-based
network protection.
The FlowCollector aggregates high-speed network behavior data from multiple
networks or network segments to deliver end-to-end protection and improve
performance across geographically dispersed networks.
As the FlowCollector receives data, it identifies known or unknown attacks, internal
misuse, or misconfigured network devices, regardless of packet encryption or
fragmentation. Once StealthWatch identifies the behavior, the system can take any
action you have configured it to take, if any, for that kind of behavior.
Inhaltsverzeichnis
Beliebte Firewall Handbücher anderer Marken

Lanner electronics
Lanner electronics FW-7650 Series Bedienungsanleitung

Swisscom
Swisscom Internet Backup Bedienungsanleitung

SonicWALL
SonicWALL NSa 5700 Bedienungsanleitung

DPtech
DPtech FW1000 SERIES Bedienungsanleitung

FEITIAN
FEITIAN MultiPass FIDO Bedienungsanleitung

EBLOCKER
EBLOCKER PRO Bedienungsanleitung











