Manuals
/
Force10 Networks
/
Computer Equipment
/
Network Card
Force10 Networks
100-00055-01
manual
Getting Started
Models:
100-00055-01
1
16
132
132
Download
132 pages
61.04 Kb
13
14
15
16
17
18
19
20
Specs
Install
Compiler Errors
Information Symbols
Configuration
Pnic resetconf
Command Line Reference
Accessing iSupport Services
Pnic updatemacvalue
Pnic aggregate-mode-disable
Page 16
Image 16
16
Getting Started
Page 15
Page 17
Page 16
Image 16
Page 15
Page 17
Contents
Series Installation and Operation Guide
Copyright 2008 Force10 Networks
Contents
Contents
Graphical User Interface
Command Line Reference
Glossary
Objectives
Audience
Conventions
Convention Description Keyword
Information Symbols
Symbol Warning Description
Related Documents
Additional Resources
This LED is blue when the hard disk is accessed
This LED is green when the power is on
Label Description
This LED is not used
Physical Connections
System Specifications
PB-10GE-2P
Step Task
Booting
Configuration
Once the appliance is booted
Security Check
Gmake install
Cp -Rf /usr/local/pnic/ /home
Tar xvzf PTPS-PMAIN
Cd SW
Cd upgradedirectory/pnic-compiler
Install pre-compiled firmware if needed
Re-compile all rules firmware with the new compiler
Located in the directory pnic-compiler
Returning to the Default Configuration
Chapter Getting Started
Getting Started
Chapter Introduction
Hardware Architecture Overview
Types of Rules
Sample Rules and Firmware
Rx1 Tx1 Mirror
Introduction
Rule Management
Deploying the P-Series
Sample Rules Files
Rule Set Description
Inline Deployment
Fail-safe Deployment
Highly-available Deployment
Passive Deployment
Capturing Matched Traffic
Series supports capturing matched traffic for analysis
Capturing to a Host CPU
Capturing Matched Traffic via the libpcap Interface
Mirroring to Another Device
Creating an IDS Accelerator with the P-Series
Invoke the GUI by entering the command pnic gui
Graphical User Interface
GUI Commands
GUI Commands
Command Description
Managing Rules, Policies, and Firmware
Rule Management GUI
Editing Dynamic Rules with the GUI
Option Description
Policy Capture
Permit Deny
Managing Capture/Forward Policies with the GUI
To modify dynamic rules
Selecting Firmware with the GUI
Managing Capture/Forward Policies GUI
To select firmware
Runtime Statistics
Select Manage Firmware see Figure
Runtime Statistics for Channel 0 and 1-FPGA Loaded
Runtime Statistics Description
Reloading Firmware
Statistic Description
Graphical User Interface
Web-based Management
Launching the P-Series Node Manager
Lauching the P-Series Node Manager Web-based Management
Web-browser Security Certificates
Managing the P-Series using Node Manager
Series Node Manager has four major management capabilities
Monitoring System Performance
Series Node Manager Home Panel Web-based Management
Managing Firmware Images
Managing the Network Interface Card
Page
Managing Policies
Page
Network Security Monitoring
Installing the Sguil Sensor
Installing the Sguil System
Installing the Sguil Server
Installing the Sguil Client
To uninstall the server
Source the server configuration file. The default
Wish
Installation Files
Sguil Files and Directories
File Location Sensor
Server
Running the Sguil System
Running the Sguil Sensor
Running the Sguil Server
Task Script
Running the Sguil Client
To run the Sguil Client
Selecting the Sensor to Monitor
CLI Commands
Editing Dynamic Rules with the CLI
MAC Rewriting
Change directories to /usr/local/pnic/0
Command Line Interface
Rewriting Destination MAC Addresses to Load Balance
Removing Vlan Tags
Command Line Interface
Creating Rules Files
Rules Capacity
Compiling Rules
To complile rules
Compilation Option Description
Content matching
Positives
Enter command gmake from pnic-compilerdirectory
Pnic-Compiler Option
Summary of configuration
Starting and Stopping the pnic-Compiler
Configuration and Generated Files
Configuration and Generated Files
File Description Location
Compiler Errors
Firmware Filenames
Describes each of the elements in this format
Firmware Filename Description
Snort Rule Headers
Snort Rule Syntax
Snort Rule Syntax
Protocol
Ports
Series Rule Syntax
Series Supported Snort Keywords
Snort Rule Options
Keyword Static Dynamic
Yes Only /8/16/24/32 masks
Seq Yes
Yes Yes, no ranges
Writing Stateful Rules
Stateful Matching
Pre-match Condition the S Value
Stateful Rule Examples
Support for Snorts flow Keyword
Handling Segmentation Evasion
Support for Snorts within Keyword
Anomalous TCP Flags
Writing Rules
Chapter Firewall
Deploying the P-Series as a Firewall
Enabling the Firewall
Firewall
Allowing Traffic through the Firewall
Writing Rules for a Firewall Deployment
Sample Firewall Rules
Appendix a Command Line Reference
Pnic aggregate-mode-disable number
Pnic aggregate-mode-disable
Appendix a
Pnic aggregate-mode-enable
Pnic aggregate-mode-enable number
Different ports. This is the default behavior
Pnic apply-firmware
Pnic apply-firmware Command Example
Display the available firmware
Pnic capture-off
Pnic capture-on
Pnic capture-off
Syntax pnic capture-on
Display the configuration parameters of the system
Pnic cardstatus
Pnic cardstatus number
Display the driver version
Pnic default-drop-disable
Pnic default-drop-disable number
Pnic compilerules
Pnic compilerules number
Pnic default-drop-enable
Enable firewall functionality
Run diagnostic tests on the card
Pnic diag
Pnic diag Command Example
Example pnic diag Command Example
Pnic flow-teardown-disable
Pnic flow-teardown-enable
Pnic flow-teardown-disable
Pnic flow-teardown-enable
Pnic getmachashindex
Example pnic flow-teardown-enable Command Example
Pnic getmachashindex number
Launch the graphical user interface
Pnic gui
Syntax pnic gui
Pnic gui Command Example
Pnic help
Pnic help
Pnic linkdown
Pnic linkup
Pnic loadconf
Pnic loadconf number
Pnic loadconf Address Mapping
Address Corresponding Parameter
Pnic loadeproms
Pnic loadparams deprecated
Load the PCI-X and front-end EEPROMs
Pnic loadeproms number
Pnic loadparams Command Example
Loadparams Address Mapping
Pnic loadrules
Pnic loadrules channel
Disable MAC rewriting. This is the default behavior
Enable MAC rewriting using the command pnic macrewrite-on
Disable MAC rewriting using the command pnic macrewrite-off
Pnic macrewrite-off
Syntax pnic off
Pnic off deprecated
100 Appendix a
Example pnic off Command Example
Enable the capturing of packets via direct memory access
Pnic on deprecated
Pnic on
Pnic passive-mode-disable
Syntax pnic passive-mode-disable number
Pnic params
Pnic params number
Pnic passive-mode-enable
Configure the ports to only receive traffic
Example pnic passive-mode-disable Command Example
Configure the ports to only receive traffic
Pnic resetconf
Pnic resetconf number
Pnic restart
Stop capturing and matching
Series Installation and Operation Guide, version 105
Pnic sguil-sensor-start
Start the Sguil sensor
Pnic restart
Pnic sguil-sensor-start -f
Series Installation and Operation Guide, version 107
Pnic sguil-sensor-stop
Stop the Sguil sensor
Pnic sguil-sensor-stop -f
Display configuration parameters of the card
Pnic showconf
Pnic show-firmwares
List the available firmware images
Series Installation and Operation Guide, version 109
Pnic showtech
Apply a specific firmware to the card
Pnic showtech number filename.dat
Disable the network interface using the command pnic stop
Example pnic showtech Command Example
Pnic start
Pnic start number
Turn off capture and disable the network interface
Enable the network interface using the command pnic start
Disable the network interface
Pnic stop
Pnic temp-mem-disable
Pnic temp-mem-enable
Disable temporary memory
Enable temporary memory. This is the default behavior
Pnic updatemacvalue
Disable temporary memory
Pnic updatemacvalue number
Specifies an LSB value for a particular hash index
Pnic vlan-remove-disable
Pnic vlan-remove-enable
Disable the Vlan Tag Remove feature
Vlan Tag Remove feature is disabled by default
Disable the web server using the command pnic web-gui-stop
Pnic version
Pnic web-gui-start
Display the driver version
Pnic web-gui-stop
Stop the web server
Stop the web server
Pnic web-gui-stop -f
Series Installation and Operation Guide, version 117
Start the web server
118 Appendix a
Description of P-Series Snort Keywords
Keyword Description Rule Syntax
Ack Checks for a specific TCP acknowledgment number
Flags!*+ FSRPAU120
Flow establishedstateless
Icmp idnumber
Icmp seq number
Ipproto ! name number
Uricontent ! datastring
Ttl This keyword checks for the specified IP time-to-live
122 Appendix B
Meta Rules
Meta Rules for Channel 0 and Channel
Evasion Rules
124 Appendix C
Unix Commands
Logout
Passwd
Pwd
Vi Commands
? text
Set number no
Number
Dynamic Rules
Flow
Garbage
Collection
Snort
Span Port
State
Static Rules
Accessing iSupport Services
Series Installation and Operation Guide, version 129
Manual Pages
ISupport Website
Contacting the Technical Assistance Center
Locating P-Series Serial Numbers
Requesting a Hardware Replacement
To request replacement hardware, follow these steps
132 Technical Support
Top
Page
Image
Contents