Manuals
/
Force10 Networks
/
Computer Equipment
/
Network Card
Force10 Networks
100-00055-01 manual Appendix C
Models:
100-00055-01
1
124
132
132
Download
132 pages
61.04 Kb
121
122
123
124
125
126
127
128
<
>
Specs
Install
Locating P-Series Serial Numbers Requesting a Hardware Replacement
Configuration
Wireshark
pnic resetconf on page pnic restart on page
Command Line Interface
Compiler Errors
Information Symbols
Accessing iSupport Services
Page 124
Image 124
124
Appendix C
Page 123
Page 125
Page 124
Image 124
Page 123
Page 125
Contents
Version
P-Series Installation and Operation Guide
May 27
Copyright 2008 Force10 Networks
Trademarks
Statement of Conditions
USA Federal Communications Commission FCC Statement
Contents
Contents
Installation
Preface
Command Line Interface
Graphical User Interface
Chapter
Web-based Management
Command Line Reference
Basic Unix Commands
Compiling Rules
Writing Rules
Appendix E
Glossary
Appendix F
Technical Support
Preface
About this Guide
Objectives
Audience
Information Symbols
Related Documents
Additional Resources
P-Series Release Notes
Installation
Chapter
Physical Connections
System Specifications
PB-10GE-2P
Step Task
Booting
Configuration
Security Check
Upgrading Software
mkdir ~/upgradedirectory
filename ~/upgradedirectory
cd upgradedirectory
scp username@serverabsolutepath
Command
cd upgradedirectory/pnic-compiler
cd upgradedirectory/firmware
gmake install
Returning to the Default Configuration
Getting Started
Chapter
To begin inspecting and filtering traffic you must
Getting Started
Hardware Architecture Overview
Introduction
Chapter
Types of Rules
Sample Rules and Firmware
Deploying the P-Series
Rule Management
Firewall Deployment” on page
Inline Deployment
Fail-safe Deployment
10-Gigabit
Optical Bypass 10-Gigabit
Highly-available Deployment
Passive Deployment
P1P0
10-Gigabit
Capturing Matched Traffic
Network Switch with SPAN port
Network Tap 10-Gigabit 10-Gigabit
P-Series P10
Capturing to a Host CPU
Mirroring to Another Device
PB-10GE-2P
M1 P1 P0 M0
Traffic to Monitor
Chapter 4 Graphical User Interface
GUI Commands
Command Description
Managing Rules, Policies, and Firmware
PNIC0 Not Active
Editing Dynamic Rules with the GUI
directory see “Editing Dynamic Rules with the GUI” on page
GUI” on page
To manage firmware, see “Selecting Firmware with the GUI” on page
To modify dynamic rules
Managing Capture/Forward Policies with the GUI
To change capture/forward policies
fn9000013
Selecting Firmware with the GUI
fn9000014
Runtime Statistics
Figure 19 Runtime Statistics for Channel 0 and 1-FPGA Loaded
Graphical User Interface
Reloading Firmware
Graphical User Interface
Launching the P-Series Node Manager
Chapter 5 Web-based Management
To launch the P-Series Node Manager
Figure 21 Lauching the P-Series Node Manager
Web-based Management
Managing the P-Series using Node Manager
Web-browser Security Certificates
Monitoring System Performance on page
Managing Firmware Images on page
Monitoring System Performance
Managing Firmware Images
Managing the Network Interface Card
Figure 25 P-Series Node Manager Card Management Panel
Web-based Management
Managing Policies
Figure 26 P-Series Node Manager Policy Managment Panel
Web-based Management
Chapter 6 Network Security Monitoring
P-Series Sensors
Sguil Server
Sguil Client
Installing the Sguil System
Installing the Sguil Sensor
Installing the Sguil Server
Hardware and Software Requirements
Uninstalling the Sguil Server
Installing the Sguil Client
Wireshark
Installation Files
# win32 example set TLSPATH c/progra~1/Tcl/lib/tls1.4.1/tls14.dll
Running the Sguil Sensor
Running the Sguil System
Writing New Rules
Running the Sguil Server
Running the Sguil Client
To run the Sguil Client
fn90028mp
fn90027mp
Chapter 7 Command Line Interface
CLI Commands
CLI commands are given in Command Line Reference on page
Editing Dynamic Rules with the CLI
In Figure
To enable MAC rewriting
Removing VLAN Tags
Command Line Interface
Compiling Rules
Creating Rules Files
Rules Capacity
Compiling Rules
Target Device
Match non-IP Traffic
page
3 Match Fragmented IPv4 Packets or IPv4 Packets w/ Options
Segmentation Evasion Rules
see Figure 36 on page
Maximum String
see Figure 37 on page
Enter command gmake from pnic-compiler directory
P-Series Installation and Operation Guide, version
Figure 36 pnic-Compiler Option
Summary of configuration
Starting and Stopping the pnic-Compiler
which the .bit files in /usr/local/pnic/0 are
Configuration and Generated Files
to which the .mapping files in /usr/local/pnic
Compiler Errors
Firmware Filenames
Writing Rules
Snort Rule Syntax
Snort Rule Headers
Action
Protocol
Source Addresses
Ports
Direction Operator
P-Series Rule Syntax
P-Series Supported Snort Keywords
Snort Rule Options
Destination Address and Port
Keyword
Static
Dynamic
protocol
Writing Stateful Rules
Stateful Matching
Equation
∧ si
= si ⎬
then cpi
Stateful Rule Examples
In Table
Handling Segmentation Evasion
Support for Snorts flow Keyword
The meta.rules File
Support for Snorts within Keyword
Anomalous TCP Flags
Writing Rules
Deploying the P-Series as a Firewall
Firewall
Chapter
Enabling the Firewall
Drop mode Disabled Drop mode Enabled
Verify Drop mode is Enabled
Figure 39 Enabling and Disabling Drop Mode
Allowing Traffic through the Firewall
Writing Rules for a Firewall Deployment
#permit let through and do not log to the host
Appendix A Command Line Reference
pnic aggregate-mode-disable on page
pnic aggregate-mode-enable on page pnic apply-firmware on page
pnic default-drop-disable on page pnic default-drop-enable on page
pnic aggregate-mode-disable
pnic temp-mem-disable on page pnic temp-mem-enable on page
pnic updatemacvalue on page pnic vlan-remove-disable on page
pnic vlan-remove-enable on page pnic web-gui-start on page
pnic aggregate-mode-enable
pnic apply-firmware
Parameters Command History Example
Commands
pnic show-firmwares
Display the available firmware
pnic capture-off
pnic capture-on
Enable the capturing of packets via direct memory access
Syntax Parameters Command History Example
pnic cardstatus
Commands
Syntax Parameters Command History Example
Commands
pnic default-drop-disable
pnic compilerules
pnic default-drop-enable
Temporary memory is disabled while the firewall is enabled
pnic diag
Parameters Command History Example
Usage Information
Parameters Command History Example
Version PMAIN2.3.0.014 root@localhost SW#
pnic flow-teardown-disable
pnic flow-teardown-enable
pnic flow-teardown-disable
pnic flow-teardown-enable
pnic getmachashindex
value for an IP address pairs
pnic gui
Enable MAC rewriting
Disable MAC rewriting
pnic updatemacvalue
P-Series Installation and Operation Guide, version
pnic gui Command Example
Example
pnic help
Syntax Command History Example
pnic help
output omitted
pnic linkdown
pnic linkup
Syntax Parameters Command History Example
Commands
pnic loadconf
Parameters Command History Example
Commands
Syntax Parameters Command History
Address
Corresponding Parameter
pnic loadeproms
pnic loadparams deprecated
pnic loadeproms number
pnic loadparams number
Address
Corresponding Parameter
Command History Example Usage Information
pnic loadrules
Syntax Parameters
pnic macrewrite-off
pnic macrewrite-on
pnic off deprecated
Syntax pnic off
pnic on deprecated
Usage Information Related Commands
Syntax Parameters Command History Example
pnic on deprecated
pnic passive-mode-disable
pnic params
pnic passive-mode-enable
pnic passive-mode-enable
Command
Commands
pnic resetconf
pnic restart
Syntax Parameters Command History Example
Stop capturing and matching
pnic sguil-sensor-start
Disable the network interface
Enable the network interface
Syntax Command History Example
Stop the Sguil sensor using the command pnic sguil-sensor-stop
Syntax Parameters Command History Example
Commands
pnic sguil-sensor-start -f
pnic sguil-sensor-stop
Syntax Parameters Command History Example
Commands
pnic sguil-sensor-start Start the Sguil sensor
pnic showconf
pnic show-firmwares
Syntax Parameters Command History Example
Commands
pnic showtech
Command History Example
Commands
Syntax Parameters Command History
pnic start
Load the capture/block configuration Load the runtime parameters
Enable the network interface
Disable the network interface using the command pnic stop
pnic stop
Enable the network interface
Commands
Syntax Parameters Command History Example
pnic temp-mem-disable
pnic temp-mem-enable
pnic updatemacvalue
Use this command with the MAC rewrite feature
pnic temp-mem-disable
Enable MAC rewriting
pnic vlan-remove-disable
pnic vlan-remove-enable
pnic vlan-remove-disable
pnic vlan-remove-enable
pnic version
pnic web-gui-start
Disable the web server using the command pnic web-gui-stop
Display the driver version
Enable the web server using the command pnic web-gui-start
pnic web-gui-stop
Commands
Command
Commands
pnic web-gui-start
Example
Related
Appendix A
Appendix B
Snort Keywords
ack number
dsize number number
Keyword
uricontent ! “datastring”
Keyword
Description
Rule Syntax
Appendix B
meta Rules
Appendix C Meta and Evasion Rules
Evasion Rules
Appendix C
Appendix D Basic Unix Commands
Unix Commands
Command
Description
vi Commands
Command
Description
? text
Appendix E
Glossary
Snort
SPAN Port
State
Static Rules
Accessing iSupport Services
Appendix F
Technical Support
Manual Pages
Locating P-Series Serial Numbers
Contacting the Technical Assistance Center
Serial Number see Locating P-Series Serial Numbers on page
Requesting a Hardware Replacement
To request replacement hardware, follow these steps
Technical Support