Documente Academic
Documente Profesional
Documente Cultură
x
Configuration Guide
50 Series
Revision 1
5.
6.
b) Standby: (i) Standby systems are licensed for use as coldstandby deployments only, except as specifically provided in
this sub-paragraph; (ii) In the event the production system
that the Standby system has been purchased with is
unavailable due to failure or maintenance, the Standby system
may be used in a production environment. In no event may
redundant system pairs operate concurrently beyond the use
required due to failure or maintenance. Use of the Standby
system in a production environment shall be subject to the
license restrictions of the production environment it is
replacing.
7.
8.
9.
2.
3.
Support Services.
a) Support Access. Qualified personnel will: (1) Aid in the
diagnosis of, and correct, Material Defects in the Software
and hardware (as defined below); and, (2) Provide advice
through selected examples on how to use the Software
and hardware by way of phone, e-mail, and web-based
technical assistance.
We will provide such reasonable
support for unaltered versions of the Products. The
number for telephone support is (781) 375-9000, or such
other number or numbers as we shall advise you of from
time to time. All support hours are U.S. Eastern Time and
shall be determined by your purchased Coverage level.
Standard and Extended Coverage hours shall be subject to
change by RSA upon written notice and exclude holidays
that RSA is not open for business. Partial coverage of a
Customers Software and/or hardware is not permitted.
i)
ii)
b)
c)
d)
b)
3.
Obligations of Customer.
a)
b)
c)
d)
4.
5.
c)
Limitation of Liability.
RSAS LIABILITY IN
CONTRACT, TORT, OR OTHERWISE ARISING OUT
OF OR IN CONNECTION WITH ANY SERVICES,
PRODUCTS, OR ANY OUTPUT OF ANY PRODUCTS
OR ANY SALES OR LICENSE AGREEMENT WITH
YOU SHALL NOT EXCEED THE AMOUNT PAID BY
YOU TO RSA IN MAINTENANCE SUPPORT FEES FOR
THE PRIOR TWELVE (12) MONTH PERIOD. IN NO
EVENT SHALL RSA BE LIABLE FOR ANY SPECIAL,
INCIDENTAL,
TORT,
OR
CONSEQUENTIAL
DAMAGES (INCLUDING ANY DAMAGES RESULTING
FROM LOSS OF USE, LOSS OF DATA, LOSS OF
PROFITS OR LOSS OF BUSINESS) ARISING OUT OF
OR IN CONNECTION WITH THE PERFORMANCE OF
THE PRODUCTS OR RSAS PERFORMANCE OF
SERVICES, EVEN IF RSA HAS BEEN ADVISED OF
THE POSSIBILITY OF SUCH DAMAGES.
6.
7.
8.
Entire Agreement.
This SHMA constitutes the entire
agreement between the parties regarding the subject hereof
and supersedes all prior or contemporaneous agreements,
understandings, and communications, whether written or
oral. This SHMA may only be amended by you with a written
document signed by both parties. The terms on any Order
Agreement or similar document will have no effect.
9.
Table of Contents
Table Of Contents
Chapter 1. Introduction
Site Deployment....................................................................................................... 1-2
vii
viii
Preface
Preface
This guide contains information on configuring your RSA enVision site and setting up the enVision
processing options.
Audience
The Configuration Guide is for new users who need to configure an enVision site.
Documentation Set
The enVision documentation set consists of the following:
Documentation
Description
Hardware Guide
Configuration Guide
Migration Guide
Online Help
ix
Preface
Conventions
This guide uses the following conventions:
Item
Formatting
Bold font.
Preface
Contact RSA
Contact RSA at:
200 Lowder Brook Drive
Suite 2000
Westwood, MA 02090
U.S.A.
Telephone: 781.375.9000
Fax: 781.375.9100
World Wide Web: http://www.rsa.com/node.aspx?id=3170
Sales
You can purchase enVision directly from our dedicated team of sales professionals or through our
North American and international resellers. Call us at 781.375.9000 or send us an email at
sales@network-intelligence.com.
Technical Support
Technical support is available during business hours via telephone at 800.995.5095 (Option #4 from
the menu).
You can also send email to the support team at support@network-intelligence.com.
Go to http://www.rsa.com/node.aspx?id=3170 and log into Customer Care to:
review the Support Knowledge Base for troubleshooting, tips, FAQs, and so forth.
Revision Tracker
Revision
Number
Date
Revision
3/17/08
Added step telling VAM users to download latest Content Update after
completing installation for both Single and Multiple Appliance Sites.
xi
Preface
xii
1. Introduction
1. Introduction
RSA enVision is a feature-rich compliance and security application. It allows you to automatically
capture and analyze log information from your network, security, application, operating and storage
environments. RSA Security Inc.'s LogSmart Internet Protocol Database (IPDB) provides the only
architecture proven to automatically collect and protect all the data, from any network device, without
filtering or agents. It gives you a true picture of how your network is being used, and by whom. It
independently monitors your network to verify security policies, to generate alerts for possible
compliance breaches, and to analyze and report on network performance.
enVision is tightly coupled with the underlying appliance operating system and hardware, and together
they comprise a highly scalable platform that provides guaranteed levels of performance, plus the
ability to grow over time.
enVision is made up of three components:
Application - supports interactive users and runs the suite of analysis tools.
1-1
1. Introduction
Site Deployment
enVision is deployed on a site basis. The enVision components are deployed based on the type of site
you have. There are two types of sites:
1-2
2-1
Configuration Tasks
Here are the configuration tasks for a single appliance site:
Task
Activity
Complete the enVision Configuration Wizard Planning Worksheet - Single Appliance Site in this
chapter.
Connect the power cords to the appliance and plug them in. The appliance is now on.
Note: There are two power cords for each appliance. Attach the cords to separate power sources, to
ensure a consistent power supply.
b.
Make sure that everything is correct on the Review Page. If the review page is:
As the part of the configuration process, the wizard displays the enVision Configuration Wizard Log
window. The log shows the steps the system is performing to configure the site. The system restarts
several times while completing the setup.
The setup process takes approximately 30 minutes to complete.
The appliance restarts automatically when the site configuration process is complete.
c.
If users use the VAM (Vulnerabilities Asset Management) feature, download the most
recent Content Update (https://knowledge.rsasecurity.com/tDownloadstAll
DownloadstRSA enVisiontContent Updates) and install it immediately.
After the site configuration is complete, you must set up the processing options in enVision. See
Chapter 5, Next Steps, for more information.
You cannot change any of the site configuration options after the wizard is finished.
Complete the enVision Configuration Wizard Planning Worksheet - Single Appliance
Site in this chapter prior to starting the wizard.
2-2
A valid site name is a unique 2 to 11 alphanumeric character string. The site name must not be the
same as:
the NetBIOS name for a Windows domain. (The NetBIOS name for a Windows domain is the
name preceding the dot). For example if your Windows domain name is
MyDomainName.com, then the NetBIOS name for this Windows domain would be
MyDomainName; it would then be wrong to install an enVision site with the name
MyDomainName.
Selecting the site name is extremely important. Once you name the site you cannot change the name.
The site name is used in the following names:
Node name for the appliance. For example, for an HA series appliance site, if your site name
is Seattle, the HA appliance node name is Seattle-HA.
NIC Windows domain name created for your site. The site name also becomes the name of
the Windows domain created for your site, sitename.nic. For example, if your site name is
Seattle, the Windows domain for the site is Seattle.nic.
2-3
IP Address
There are default addresses for the appliance:
Gateway address identifies the computer that routes the traffic to the outside network.
You can override the default values during configuration. If you choose to override the default values,
write the new values in the table.
Default
2-4
LAN IP Address
192.168.1.155
Subnet Mask
255.255.255.0
Gateway Address
192.168.1.1
Override Value
DNS Servers
Identify the primary and secondary DNS servers on your network and options for the servers. enVision
uses the DNS servers to resolve IP addresses found in events for reporting and alerting.
DNS Server
IP Address
Primary
Secondary
Description
Option
Forwarding Timeout
_____ seconds
2-5
Time
Network Time Protocol (NTP)
Identify a server to which enVision will synchronize its time.
Known NTP time servers, such as atomic clocks, are outside your network and may be a
security issue. RSA Security Inc. assumes no risk to your network if you choose to use a
known NTP server.
Note: The enVision Configuration Wizard allows you to use the Windows Date and Time Properties
window to update your date and time directly from the wizard.
Select
NTP Servers
tock.usno.navy.mil
ntp2.usno.navy.mil
tock.usno.navy.mil
tick.usno.navy.mil
navobs1.oar.net
ntp0.mcs.anl.gov
navobs1.wustl.edu
tick.usnogps.navy.mil
tock.usnogps.navy.mil
tick.ucla.edu
bigben.cac.washington.edu
ntp.alaska.edu
tick.mhpcc.hpc.mil
Custom:
Time Zone
(While running the configuration wizard, you must confirm the current date and time in your selected
time zone.)
2-6
External IP Address
Indicate whether this site uses an external address.
2-7
3-1
Appliance Types
Here are the appliance types used in a multiple appliance site:
Component
Appliance
Type
Description
Database server
D-SRV
Application server
A-SRV1
Up to 3
A-SRV2
A-SRV3
LC1
LC2
LC3
Up to 3
(Minimally each site has 1 LC.)
Note: If you have 3 LCs, you can
only have up to 2 A-SRVs.
Each site can optionally host up to 16 Remote Collector (RC) server appliances; each RC is
considered a site. RCs capture incoming events remotely. Remote collectors have store-and-forward
technology that allows user-selectable critical events to be processed in real-time, while non-critical
events are compressed, encrypted, and locally cached until they can be forwarded to the master
enVision site (by the NIC Forwarder Service) for historical analysis as available WAN bandwidth
allows. (The Administrator sets up the remote collector's Forwarder parameters on the Modify
Collector Service window in enVision.) See Chapter 5, Remote Collector Site, for information on
configuring RCs.
Note: The total events per second (EPS) for all Collectors per site (per D-SRV) cannot exceed 30,000
EPS.
Here is an example of a multiple appliance site with one D-SRV, one A-SRV and three LCs.
3-2
3-3
3-4
Directories.
Query tool - process options and storage directory for saved queries.
Reports module - storage directory and format for saved report results.
Executive Dashboard - item settings. (Note: Permissions for the items are set
globally.)
Scheduled reports (can only be scheduled to run on the site where they were configured).
Configuration Tasks
See the Hardware Guide for information on the appliances. After the hardware is set up, you must
configure the enVision site. Here are the configuration tasks for a multiple appliance site:
Task
Activity
Complete the enVision Configuration Wizard Planning Worksheet - Multiple Appliance Site in
this chapter.
Connect the power cords to the appliances and plug them in.
The appliances are now on.
Note: There are two power cords for each appliance. Attach the cords to separate power sources, to
ensure a consistent power supply.
b.
Make sure that everything is correct on the Review Page. If the Review Page is:
As the last part of the configuration process, the wizard displays the enVision Configuration Wizard
Log window. The log shows the steps the system is performing to configure the site. The system
restarts several times while completing the setup.
The setup process takes approximately 30 minutes to complete.
The appliances restart automatically when the site configuration process is complete.
3-5
a.
Make sure that you have completed the enVision 3.5.0 installation.
b.
c.
If users use the VAM (Vulnerabilities Asset Management) feature, download the most recent
Content Update (https://knowledge.rsasecurity.com/tDownloadstAll DownloadstRSA
enVisiontContent Updates) and install it immediately.
Next Steps: If there is a Remote Collector (RC) associated with this site, go to Chapter 4, Remote
Collector Site, for information on configuring the remote site.
If you have a multiple site domain, repeat the tasks in this chapter to configure the remaining sites.
After the site configuration is complete, you must set up the processing options in enVision. See
Chapter 5, Next Steps, for more information.
You cannot change any of the site configuration options after the wizard is finished.
Complete the enVision Configuration Wizard Planning Worksheet - Multiple
Appliance Site in this chapter prior to starting the wizard.
3-6
Site. Complete this section for each site in your NIC Domain. (Make a copy of the worksheet,
so that you can complete a worksheet for each site.) If you are configuring a remote collector
for a multiple site appliance, complete the Remote Collector worksheet for each remote
collector.
NIC Domain
Draw a topology diagram of your NIC Domain. Label the Master Site of the NIC Domain. Label each
site with a site name to identify it for additional planning purposes.
3-7
Site
Complete this section of the worksheet for each site in the NIC Domain.
A valid site name is a unique 2 to 11 alphanumeric character string. The site name must not be the
same as:
the NetBIOS name for a Windows domain. (The NetBIOS name for a Windows domain is the
name preceding the dot). For example if your Windows domain name is
MyDomainName.com, then the NetBIOS name for this Windows domain would be
MyDomainName; it would then be wrong to install an enVision site with the name
MyDomainName.
Selecting the site name is extremely important. Once you name the site you cannot change the name.
The site name is used in the following names:
3-8
Node name for each of the appliances in the site. For example, if your site name is Boston,
the Database server appliance node name is Boston-DS1.
NIC Windows domain name created for your site. The site name also becomes the name of
the Windows domain created for your site, sitename.nic. For example, if your site name is
Boston, the Windows domain for the site is Boston.nic.
Gateway address - identifies the computer that routes the traffic to the outside network.
Select each appliance type in your site. If you choose to override the default values, write the new
values in the table.
Select
Appliance
Type
IP Address
Subnet Mask
Gateway Address
D-SRV
192.168.1.160
255.255.255.0
192.168.1.1
A-SRV1
192.168.1.156
255.255.255.0
192.168.1.1
A-SRV2
192.168.1.161
255.255.255.0
192.168.1.1
A-SRV3
192.168.1.162
255.255.255.0
192.168.1.1
LC1
192.168.1.157
255.255.255.0
192.168.1.1
LC2
192.168.1.158
255.255.255.0
192.168.1.1
LC3
192.168.1.159
255.255.255.0
192.168.1.1
If you have remote collectors associate with this site, complete the enVision Configuration Wizard
Planning Worksheet Remote Collector Site.
3-9
DNS Servers
Identify the primary and secondary DNS servers on your network and options for the servers. enVision
uses the DNS servers to resolve IP addresses found in events for reporting and alerting.
DNS Server
IP Address
Primary
Secondary
3-10
Field
Description
Option
Forwarding Timeout
_____ seconds
Time
Network Time Protocol (NTP)
Identify a server to which enVision will synchronize its time.
Known NTP time servers, such as atomic clocks, are outside your network and may be a
security issue. RSA Security Inc. assumes no risk to your network if you choose to use a
known NTP server.
Note: The enVision Configuration Wizard allows you to use the Windows Date and Time Properties
window to update your date and time directly from the wizard.
Select
NTP Servers
tock.usno.navy.mil
ntp2.usno.navy.mil
tock.usno.navy.mil
tick.usno.navy.mil
navobs1.oar.net
ntp0.mcs.anl.gov
navobs1.wustl.edu
tick.usnogps.navy.mil
tock.usnogps.navy.mil
tick.ucla.edu
bigben.cac.washington.edu
ntp.alaska.edu
tick.mhpcc.hpc.mil
Custom:
Time Zone
(While running the configuration wizard, you must confirm the current date and time in your selected
time zone.)
3-11
This sites data server (D-SRV) uses an external IP address and port number.
3-12
The site with which the RC is associated must have been configured and must be up and
running before you configure the RC.
4-1
Configuration Tasks
After your multiple appliance site is configured, you can configure the remote sites associated with it.
See the Hardware Guide for information on setting up the hardware.
Here are the configuration tasks to configure an RC site (associated with a multiple appliance site):
Task
1
Activity
Install the Remote Collector hardware. (See the Hardware Guide for information on multiple
appliance sites, remote sites, and the hardware layout.)
a.
b.
Insert the Network Connection cable into the network interface labeled LAN.
Complete the enVision Configuration Wizard Planning Worksheet Remote Collector Site in
this chapter.
Connect the power cords to the appliance and plug them in.
The appliance is now on.
Note: There are two power cords for each appliance. Attach the cords to separate power sources, to
ensure a consistent power supply.
b.
Make sure that everything is correct on the Review Page. If the Review Page is:
As the last part of the configuration process, the wizard displays the enVision Configuration Wizard
Log window. The log shows the steps the system is performing to configure the site. The system
restarts several times while completing the setup.
The setup process takes approximately 30 minutes to complete.
The appliance restarts automatically when the site configuration process is complete.
4-2
Configure the FTP server on the host sites D-SRV. (See the Configure the FTP Server on the D-SRV
section later in this chapter for complete instructions.)
Verify the RC configuration on the host sites A-SRV. (See the Verify the RC Configuration section
later in this chapter for complete instructions.)
Task
Activity
Configure the data forwarding scheduled task on the host sites A-SRV. (See the Configure the Data
Forwarding Task section later in this chapter for complete instructions.)
Test the configuration. (See the Test the Configuration section later in this chapter for complete
instructions.)
4-3
Connect to the D-SRV of the site associated with the remote collector.
2.
Click the Windows Start menu. Select Programs>Administrative Tools>Services. The system
displays the Services dialog box.
3.
a.
b.
c.
4.
a.
b.
In the left menu frame, drill down until Default FTP Site is located, right-click on Default
FTP Site and from the menu, select Properties.
c.
Click Security Accounts tab and review the Anonymous Connections check boxes:
d.
Click Home Directory tab and make sure the Write check box is selected.
e.
Click OK.
f.
Click Apply.
g.
Click OK.
b.
5.
4-4
Click the Windows Start menu and select Programs>Administrative Tools>Services. The
system displays the Services dialog box.
a.
b.
c.
2.
ii. In the Overview menu, click System Configuration. The system displays
the System Configuration menu.
iii. Click Services. Click Set Up Site Communication. The system displays
the Set Up Site Communication window.
b. Verify that the RC is listed as a site, and that the information displayed is correct.
4-5
Log into enVision on the application server (A-SRV) of the host site as follows:
a. Start your web browser.
b. Type http://address:8080 in the Address field, where address is the machine
name or IP address of the A-SRV and 8080 is the port through which you access
enVision. For example, http://sunshine:8080 or http://10.10.30.140:8080.
c. Press Enter.
enVision displays the Log In window.
d. Type your password and click Log In.
2.
b.
c.
3.
4.
Click Set Recurrence to tell enVision when and how often to perform the data forwarding
task.
enVision displays the Set Recurrence window.
5.
6.
Click Schedule.
enVision displays the task on the Manage Scheduled Tasks window.
4-6
7.
Click Apply.
8.
If the NIC Scheduler Service is not running, start the NIC Scheduler Service.
After the Data Forwarding task runs on the A-SRV, run a report (for example, Bandwidth
Usage by Address) to analyze the devices collected (the devices being collected should be
able to be analyzed through the master site).
2.
4-7
A valid site name is a unique 2 to 11 alphanumeric character string. The site name must not be the
same as:
the NetBIOS name for a Windows domain. (The NetBIOS name for a Windows domain is the
name preceding the dot). For example if your Windows domain name is
MyDomainName.com, then the NetBIOS name for this Windows domain would be
MyDomainName; it would then be wrong to install an enVision site with the name
MyDomainName.
Selecting the site name is extremely important. Once you name the site you cannot change the name.
The site name is used in the following names:
4-8
Node name for the appliance. For example, if your site name is Hartford, the appliance node
name is Hartford-RC1.
NIC Windows domain name created for your site. The site name also becomes the name of
the Windows domain created for your site, sitename.nic. For example, if your site name is
Hartford, the Windows domain for the site is Hartford.nic.
Gateway address identifies the computer that routes the traffic to the outside network.
Select the appliance type (RC1, RC2, etc.) for your remote collector, based on the NIC Domain
topology diagram on the enVision Configuration Wizard Planning Worksheet Multiple Appliance
Site. If you will override the default values, write the new values in the table.
Select
Appliance
Type
IP Address
Subnet Mask
Gateway Address
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
RC1
192.168.1.155
255.255.255.0
192.168.1.1
4-9
DNS Servers
Identify the primary and secondary DNS servers on your network and options for the servers. enVision
uses the DNS servers to resolve IP addresses found in events for reporting and alerting.
DNS Server
IP Address
Primary
Secondary
4-10
Field
Description
Option
Forwarding Timeout
_____ seconds
Time
Network Time Protocol (NTP)
Identify a server to which enVision will synchronize its time.
Known NTP time servers, such as atomic clocks, are outside your network and may be a
security issue. RSA Security Inc. assumes no risk to your network if you choose to use a
known NTP server.
Note: The enVision Configuration Wizard allows you to use the Windows Date and Time Properties
window to update your date and time directly from the wizard.
Select
NTP Servers
tock.usno.navy.mil
ntp2.usno.navy.mil
tock.usno.navy.mil
tick.usno.navy.mil
navobs1.oar.net
ntp0.mcs.anl.gov
navobs1.wustl.edu
tick.usnogps.navy.mil
tock.usnogps.navy.mil
tick.ucla.edu
bigben.cac.washington.edu
ntp.alaska.edu
tick.mhpcc.hpc.mil
Custom:
Time Zone
(While running the configuration wizard, you must confirm the current date and time in your selected
time zone.)
4-11
This sites data server (D-SRV) uses an external IP address and port number.
4-12
5. Next Steps
5. Next Steps
After the site configuration is complete, you must set up the processing options in RSA enVision. See
the online Help in enVision for information on setting up and using the enVision analysis tools.
Prior to setting up your system you should plan how the system will be set up to accomplish your
security goals, policies and requirements.
Set Up enVision
Setting up enVision involves three sets of tasks:
I. Appliance and device configuration tasks.
These are tasks that you perform outside of the enVision software.
II. Basic setup tasks.
These are tasks to set up the enVision software. This allows you to collect, report and alert on
events from supported devices.
1.
2.
3.
Set up views.
4.
5.
Schedule reports.
2.
3.
4.
5.
5-1
5. Next Steps
Each task has a list of Required Reading topics in enVision's online Help that provide the information
you need to make setup decisions related to the task. Additional tasks may be required to perform the
specific processing that you want.
To access Help within enVision:
1.
2.
3.
5-2
5. Next Steps
Log In to enVision
You log in to enVision via a remote system connecting to the enVision appliance [for multiple
appliance sites, connect to the A-SRV (Application Server)]. Use one of two protocols to access the
system depending on how enVision has been configured:
To log in to enVision:
1.
2.
3.
Press Enter.
If you are connecting via HTTPS, your browser may display certificate validation messages
the first time you access enVision. (Depending on how server certificates have been
configured on the appliance, these messages may cite validation issues such as a host name
mismatch between the server and its certificate.)
enVision displays the Log In window.
4.
5-3
5. Next Steps
Windows
Macintosh
O/S
OS X 10.4.6
Browser
JRE v1.4.1
enVision also supports the Sun Java
Plug-in version 1.5.x.
Processor
P3:1Ghz or P4:1.8Ghz
Athlon 1800+
G5 or higher
RAM
512MB
1 GB RAM
Network
100baseTX
100baseTX
Display Resolution
* You can use the Mozilla Firefox 1.0.7 web browser with enVision with the exception of the
Enterprise Dashboard tool. You cannot use Firefox to view the Enterprise Dashboard tool.
Popup blockers, ad banner blockers and personal firewalls can all interfere with the proper launching
of enVision, especially at first log in. The blockers should be trained to allow enVision to operate
normally, or be disabled. Configure personal firewalls to allow connections between enVision client
and appliance.
You must enable animation for web pages in your browser. For Microsoft Internet Explorer:
5-4
1.
2.
3.
Scroll to Multimedia and select the Play animations in web pages box.
4.
Click OK.
5.
5. Next Steps
Log Out
To log out of the user interface:
Click Log Out (bottom left-hand side of window). enVision closes all open windows. All
enVision services and processes continue to run without interruption.
5-5