Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3

Unknown

PDF - Complete Book (17.74 MB)

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 - Cisco


File Info : application/pdf, 78 Pages, 17.74MB

PDF preview unavailable. Download the PDF instead.

b Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3
First Published: 2021-01-01 Last Modified: 2022-10-20
Americas Headquarters
Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000
800 553-NETS (6387) Fax: 408 527-0883

© 2019­2022 Cisco Systems, Inc. All rights reserved.

CONTENTS

CHAPTER 1 CHAPTER 2 CHAPTER 3 CHAPTER 4 CHAPTER 5 CHAPTER 6
CHAPTER 7

About this documentation 1 Document purpose 1 Warnings and notices 1
Overview 3
Requirements 7
Additional remarks 9
Known issues 11
Initial configuration 13 Configure the switch access 13 Check the software version 13 SD Card (IE3x00/IE9x00) 14 SSD Disk (Catalyst 9x00) 15 Check date and time 15 Enable IOx 16 Add the necessary configuration parameters (IE3x00) 17 Add the necessary configuration parameters (Catalyst 9x00/IE9x00) 19 Configure with ERSPAN 19 Configure with RSPAN (Catalyst 9x00 only) 21
Procedure with the Cisco Cyber Vision sensor management extension 23 Install the sensor management extension 23

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 iii

Contents

CHAPTER 8 CHAPTER 9 CHAPTER 10 CHAPTER 11

Management jobs 24 Create a sensor in the sensor management extension 25 Configure a sensor in the sensor management extension 27 Configure Active Discovery 31
Procedure with the Local Manager 35 Access the Local manager 35 Install the sensor virtual application 37 Configure the sensor virtual application (IE3x00/IE9x00) 38 Configure the sensor virtual application (Catalyst 9x00) 42 Generate the provisioning package 47 Import the provisioning package 50
Procedure with the CLI 53 Configure the sensor application 53 Install the sensor application 55 Generate the provisioning package 56 Copy the sensor application provisioning package 59 Final step 59
Upgrade procedures 61 Upgrade through the Cisco Cyber Vision sensor management extension 61 Update the sensor management extension 61 Update the sensors 62 Upgrade through the IOx Local Manager 64
Reconfigure/Redeploy a sensor 69

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 iv

1 C H A P T E R
About this documentation
· Document purpose, on page 1 · Warnings and notices, on page 1
Document purpose
This installation guide describes how to perform a clean installation of Cisco Cyber Vision on the following devices:
· Cisco Catalyst IE3300 10G Rugged Series Switch · Cisco Catalyst IE3400 Rugged Series Switch · Cisco Catalyst IE3400 Heavy Duty Series Switch · Cisco Catalyst IE9300 Rugged Series Switch · Cisco Catalyst 9300 Series Switch · Cisco Catalyst 9400 Series Switch Moreover, this document describes how to upgrade sensors through different methods. This documentation is applicable to system version 4.1.3.
Warnings and notices
This manual contains notices you have to observe to ensure your personal safety as well as to prevent damage to property. The notices referring to your personal safety and to your property damage are highlighted in the manual by a safety alert symbol described below. These notices are graded according to the degree of danger.
Warning Indicates risks that involve industrial network safety or production failure that could possibly result in personal injury or severe property damage if proper precautions are not taken.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 1

Warnings and notices

About this documentation

Important Indicates risks that could involve property or Cisco equipment damage and minor personal injury if proper precautions are not taken.
Note Indicates important information on the product described in the documentation to which attention should be paid.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 2

2 C H A P T E R
Overview
· Overview, on page 3
Overview
Proposed architecture: The architecture proposed and described in this document is for demonstration. The local network engineer should be consulted before applying the parameters used in this document. IP addresses, port numbers and VLAN IDs used should be verified beforehand as wrong configurations could stop normal exchanges and stop the process. The schema below explains the architecture virtually deployed in the switch to embed the sensor application. VLAN and physical ports configuration will allow OT traffic to be copied and communication with the Cisco Cyber Vision Center to be established. The communication between the Cisco Cyber Vision Center and the sensor is represented in blue on the schema. Mirrored OT traffic is represented in yellow. The architecture in this document is meant for a switch with an embedded sensor directly connected to the Cisco Cyber Vision Center. The schema presents two types of architecture:
· one with a direct connection to the Center (link="switchport access vlan 507"). · the other with a trunk to another switch or router which is connected to the Center (link="switch mode
trunk").
Several types of installation are explained. One of them is the installation with the Sensor Management extension. This method requires an access for the Cisco Cyber Vision Center to the switch's Local Manager. Several solutions exist: having the Center on the same subnet than the switch's Local Manager (<admin_VLAN> and <collection_VLAN> are the same). having a route path from the Center to an <admin_VLAN> that is different from <collection_VLAN>. Any port of the switch can be used for the communication with the Center or for OT traffic. Architecture diagram for:
· Cisco Catalyst IE3300 10G Rugged Series Switch · Cisco Catalyst IE3400 Rugged Series Switch
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 3

Overview

· Cisco Catalyst IE3400 Heavy Duty Series Switch

Overview

Architecture diagram for: · Cisco Catalyst 9300 Series Switch · Cisco Catalyst 9400 Series Switch · Cisco Catalyst IE9300 Rugged Series Switch

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 4

Overview

Overview

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 5

Overview

Overview

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 6

3 C H A P T E R
Requirements
· Requirements, on page 7
Requirements
The hardware must have an access set to the Local Manager and to the CLI (ssh or console port). Elements to collect
· The Cisco Cyber Vision Sensor application to collect from Cisco.com, i.e. · CiscoCyberVision-IOx-aarch64-<version>.tar (Cisco IE3300 10G, Cisco IE3400, Cisco IE9300) · CiscoCyberVision-IOx-x86-64-<version>.tar (Cisco Catalyst 9300) · CiscoCyberVision-IOx-Active-Discovery-aarch64-<version>.tar (Cisco IE3300 10G, Cisco IE3400, Cisco IE9300 with Active Discovery) · CiscoCyberVision-IOx-Active-Discovery-x86-64-<version>.tar (Cisco Catalyst 9300 with Active Discovery)
· A console cable, for the connection to the hardware's console port. OR
· An Ethernet cable, for the connection to one of the hardware's port.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 7

Requirements

Requirements

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 8

4 C H A P T E R
Additional remarks
· Additional remarks, on page 9
Additional remarks
About the IE3400 and IE3300 10G platforms: Cisco Cyber Vision Sensor application will receive ERSPAN traffic. Due to ERSPAN overhead it is recommended to not update the MTU of the platform (switch IE3x00) above 1940 bytes. Otherwise, large packets above 1940 will not be received by the sensor application. About the initial configuration: Configurations described in the initial configuration are given as examples to use a Cisco Cyber Vision sensor embedded in a switch. However, in case a more complex installation is required, a trained user will have to configure the switch with all the necessary VLAN and port settings.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 9

Additional remarks

Additional remarks

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 10

5 C H A P T E R
Known issues
· Known issues, on page 11
Known issues
· The deployment procedure with the Local Manager is not supported by firmware version 17.3.x. Perform the Procedure with the Cisco Cyber Vision sensor management extension, on page 23 instead.
· Cisco Catalyst 9300: deployments will be possible for sensors on firmware version 17.6.x as of Cisco Cyber Vision version 4.0.1.
· IOx redundancy is not supported: sensors will not persist after a failover. This applies in particular to stacks of Cisco Catalyst 9300, stacks of Cisco IE9300 and Cisco Catalyst 9400 with redundant processor boards.
· The sensor application supports RSPAN on Catalyst 9300 and Catalyst 9400 in addition to ERSPAN in Cisco Cyber Vision version 4.1.3. In case of RSPAN usage, multicast packets and packet VLAN information are not transferred to the sensor application.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 11

Known issues

Known issues

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 12

Initial configuration

6 C H A P T E R

in body: To install Cisco Cyber Vision on a Cisco switch, you must perform the Initial configuration which steps are described in this section.
· Configure the switch access, on page 13 · Check the software version, on page 13 · SD Card (IE3x00/IE9x00), on page 14 · SSD Disk (Catalyst 9x00), on page 15 · Check date and time, on page 15 · Enable IOx, on page 16 · Add the necessary configuration parameters (IE3x00), on page 17 · Add the necessary configuration parameters (Catalyst 9x00/IE9x00), on page 19
Configure the switch access
To configure each Cisco switch access refer to its corresponding installation guide available through the following links:
· Cisco Catalyst IE3x00: https://www.cisco.com/c/en/us/support/switches/catalyst-ie3300-rugged-series/series.html#~tab-documents https://www.cisco.com/c/en/us/support/switches/catalyst-ie3400-rugged-series/series.html#~tab-documents https://www.cisco.com/c/en/us/support/switches/catalyst-ie3400-heavy-duty-series/series.html
· Cisco Catalyst IE9x00: https://www.cisco.com/c/en/us/support/switches/catalyst-ie9300-rugged-series/series.html
· Cisco Catalyst 9x00: https://www.cisco.com/c/en/us/support/switches/catalyst-9300-series-switches/series.html#~tab-documents https://www.cisco.com/c/en/us/support/switches/catalyst-9400-series-switches/series.html#~tab-documents

Check the software version
· Check the software version using the following command in the switch's CLI:

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 13

SD Card (IE3x00/IE9x00)

Initial configuration

Show version
To be compatible with the Cisco Cyber Vision Sensor Application: · the displayed version for Cisco IE3x00 and Cisco Catalyst 9x00 must be 17.02.01 or higher. · the displayed version for Cisco IE9x00 must be 17.09.01 or higher.
For example: Cisco IE3400

If the version is lower, you must update the switch firmware. To do so, follow the links to the products page in Configure the switch access.
SD Card (IE3x00/IE9x00)
If not already done, insert a 4GB Cisco SD card into the switch SD Card slot. · You can format the SD card using the following command:
format sdflash: ext4

· You can partition the SD card using the following command:
partition sdflash: iox
Partition is intended for SD swap drive usage. For more information, refer to the corresponding switch user manual. · You can check the file system using the following command (check for ext4 and Read/Write):
show sdflash: filesys

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 14

Initial configuration
SSD Disk (Catalyst 9x00)
If not already done, insert a 120GB Cisco SSD disk in the SSD slot. · You can format the SSD disk using the following command:
format usbflash1: ext4

SSD Disk (Catalyst 9x00)

· You can check the file system using the following command (check for ext4 and Read/Write):
show usbflash1: filesys

Check date and time
The internal clock of the switch must be synchronized and configured properly.
Note Unlike hardware sensors (i.e. Cisco IC3000) that fetch their time from the Center, the Cyber Vision IOX application sensor gets the time from the host (switch platform). Therefore, it is critical that the host synchronizes its time with the Center or a valid NTP server if it's synchronized with the Center. If the time difference is large (hours or more), the user should adjust the Cisco IE3400 time using the Local Manager so it is close to the reference time. If not, the synchronization may take many update cycles.
1. Check the date and time using the following command:
Show clock
For examples: Cisco IE3400:
Cisco Catalyst 9300:
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 15

Enable IOx

Initial configuration

2. If needed, adjust to the UTC time using the following command:
clock set [hh:mm:ss] [month] [day] [year]
Or go to the Local Manager: For example: Cisco IE3400

Enable IOx
Before installing the Cisco Cyber Vision sensor on the hardware, you must enable IOx. 1. Enable IOx using the following command:
configure terminal iox
For examples: Cisco IE3400:
Cisco Catalyst 9300:
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 16

Initial configuration

Add the necessary configuration parameters (IE3x00)

2. Check the IOx service status using the following command:
exit show iox
For examples: Cisco IE3400:

Cisco Catalyst 9300:

Add the necessary configuration parameters (IE3x00)
The example of configuration given below is a simple one. This configuration is only valid if a direct link exists between the Center and the switch with the embedded sensor. In this case, the dedicated port is configured with the Collection VLAN (for example, 507). In many other cases, the port used for communication between the Center and the sensor will have to be configured as trunk. 1. Open the Cisco IE3300 10G/IE3400 CLI through ssh or via the console terminal.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 17

Add the necessary configuration parameters (IE3x00)
2. Configure a VLAN for traffic mirroring using the following commands:
configure terminal vtp mode off vlan 2508 remote-span exit

Initial configuration

The VTP off command is performed here since VTP is enabled by default and is not compatible with a high VLAN number. If needed, select another VLAN number and use the VTP configuration requested by the network. 3. Configure the AppgigabitEthernet port for communications to reach the IOx virtual application using the following commands:
interface AppGigabitEthernet 1/1 switchport mode trunk exit
4. Configure the SPAN session and add to the session the interfaces to monitor:
monitor session 1 source interface Gi1/10 both monitor session 1 destination remote vlan 2508 monitor session 1 destination format-erspan 169.254.1.2
5. Configure one of the switch's ports to enable the communication between the virtual sensor and the Center:
int gi1/3 switchport access vlan 507 no shutdown
6. Save the configuration using the following commands:
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 18

Initial configuration
exit write mem

Add the necessary configuration parameters (Catalyst 9x00/IE9x00)

The initial configuration is now complete. Proceed with the application installation and deployment following one of the procedures below:
· Procedure with the Cisco Cyber Vision sensor management extension, on page 23
· Procedure with the Local Manager, on page 35
· Procedure with the CLI, on page 53

Add the necessary configuration parameters (Catalyst 9x00/IE9x00)
The configuration examples given in this section are simple ones. They are only valid if a direct link exists between the Center and the switch with the embedded sensor. In this case, the dedicated port is configured with the Collection VLAN (for example, 507). In many other cases, the port used for communication between the Center and the sensor will have to be configured as trunk. Configuration with ERSPAN is recommended but requires routing to be enabled on the switch. If this is not possible, RSPAN is available on the Catalyst 9x00. However, note that Multicast and VLAN information will be missing with this configuration.
Configure with ERSPAN
Procedure

Step 1 Step 2
Step 3

Open the switch's CLI through ssh or via the console terminal. Configure a VLAN for traffic mirroring using the following commands:
configure terminal ip routing vlan 2508 exit int vlan 2508 ip address 169.254.1.1 255.255.255.252 no shutdown exit
Configure the AppGigabitEthernet port which will enable the communication to the IOx virtual application:
interface AppGigabitEthernet 1/0/1 switchport mode trunk exit

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 19

Configure with ERSPAN

Initial configuration

Step 4

Configure the SPAN session and add to the session the interfaces to monitor:
Note Disabling the ip routing command for IPv4 connections and ipv6 unicast-routing command for IPv6 connections stops ERSPAN traffic flow to the destination port. Link to Catalyst 9300 manual.
monitor session 1 type erspan-source source interface Gi1/0/2 - 24 both no shutdown destination erspan-id 2 mtu 9000 ip address 169.254.1.2 origin ip address 169.254.1.1 exit exit

Step 5

Configure one of the switch's ports to enable the communication between the virtual sensor and the Center:
interface GigabitEthernet1/0/1 switchport access vlan 507 no shutdown exit

Step 6

Save the configuration:
exit write mem

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 20

Initial configuration

Configure with RSPAN (Catalyst 9x00 only)

What to do next The initial configuration is now complete. Proceed with the application installation and deployment following one of the procedures below:
· Procedure with the Cisco Cyber Vision sensor management extension, on page 23 · Procedure with the Local Manager, on page 35 · Procedure with the CLI, on page 53

Configure with RSPAN (Catalyst 9x00 only)
Before you begin The VLAN configured for RSPAN (here 2508) must be filtered on all trunk ports except for the AppGigabitEthernet interface.
Procedure

Step 1 Step 2
Step 3

Open the switch's CLI through ssh or via the console terminal. Configure a VLAN for traffic mirroring using the following commands:
configure terminal vlan 2508 exit int vlan 2508 remote-span exit
Configure the AppGigabitEthernet port which will enable the communication to the IOx virtual application:
interface AppGigabitEthernet 1/0/1 switchport mode trunk exit

Step 4

Configure the SPAN session and add to the session the interfaces to monitor:
monitor session 1 source interface Gi1/0/2 - 24 both monitor session 1 destination remote vlan 2508

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 21

Configure with RSPAN (Catalyst 9x00 only)

Initial configuration

Step 5

Configure one of the switch's ports to enable the communication between the virtual sensor and the Center:
interface GigabitEthernet1/0/1 switchport access vlan 507 no shutdown exit

Step 6

Save the configuration:
exit write mem

What to do next The initial configuration is now complete. Proceed with the application installation and deployment following one of the procedures below:
· Procedure with the Cisco Cyber Vision sensor management extension, on page 23 · Procedure with the Local Manager, on page 35 · Procedure with the CLI, on page 53

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 22

7 C H A P T E R
Procedure with the Cisco Cyber Vision sensor management extension
After the Initial configuration, proceed to the steps described in this section. This section also describes the steps to configure Active Discovery.

Note To be able to use the Cisco Cyber Vision sensor management extension, an IP address reachable by the Center Collection interface must be set on the Collection VLAN.
· Install the sensor management extension, on page 23 · Create a sensor in the sensor management extension, on page 25 · Configure a sensor in the sensor management extension, on page 27 · Configure Active Discovery, on page 31
Install the sensor management extension
To install the sensor management extension, you must:
Procedure

Step 1 Step 2 Step 3

Retrieve the extension file (i.e. CiscoCyberVision-sensor-management-<version>.ext) from cisco.com. Access the Extension administration page in Cisco Cyber Vision. Import the extension file.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 23

Management jobs

Procedure with the Cisco Cyber Vision sensor management extension

Once the sensor management extension is installed, you will find a new management job under the sensor administration menu (Management jobs, on page 24), and the Install via extension button will be enabled in the Sensor Explorer page.
Management jobs
As some deployment tasks on sensors can take several minutes, this page shows the jobs execution status and advancement for each sensor deployed with the sensor management extension. This page is only visible when the sensor management extension is installed in Cisco Cyber Vision.

You will find the following jobs:
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 24

Procedure with the Cisco Cyber Vision sensor management extension

Create a sensor in the sensor management extension

· Single deployment This job is launched when clicking the Deploy Cisco device button in the sensor administration page, that is when a new IOx sensor is deployed.
· Single redeployment This job is launched when clicking the Reconfigure Redeploy button in the sensor administration page, that is when deploying on a sensor that has already been deployed. This option is used for example to change the sensor's parameters like enabling active discovery.
· Single removal This job is launched when clicking the Remove button from the sensor administration page.
· Update all devices This job is launched when clicking the Update Cisco devices button from the sensor administration page. A unique job is created for all managed sensors that are being updated.
If a job fails, you can click on the error icon to view detailed logs.

Create a sensor in the sensor management extension
Procedure

Step 1

In Cisco Cyber Vision, navigate to Admin > Sensors > Sensor Explorer and click Install sensor, then Install via extension.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 25

Create a sensor in the sensor management extension

Procedure with the Cisco Cyber Vision sensor management extension

Step 2

Fill the requested fields so Cisco Cyber Vision can reach the device: · IP address: admin address of the device. · Port: management port (443). · Login: user with the admin rights of the device. · Password: password of the admin user. · Capture Mode: Optionally, select a capture mode.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 26

Procedure with the Cisco Cyber Vision sensor management extension

Configure a sensor in the sensor management extension

Step 3

Click Connect.
The Center will join the device and the second parameter list will be displayed. For this step to succeed, the device needs to be reachable by the Center on its eth1 connection.

Configure a sensor in the sensor management extension
If the Center can join the switch, the following form appears: Form for the Cisco IE3x00 and the Cisco IE9x00:

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 27

Configure a sensor in the sensor management extension

Procedure with the Cisco Cyber Vision sensor management extension

Form for the Cisco Catalyst 9x00 with RSPAN configuration available:
While some parameters are filled automatically, you can still change them if necessary.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 28

Procedure with the Cisco Cyber Vision sensor management extension

Configure a sensor in the sensor management extension

Procedure

Step 1
Step 2 Step 3

Fill the following parameters for the Collection interface: · Capture IP address: IP address destination of the monitor session in the sensor · Capture prefix length: mask of the capture IP address · Capture VLAN number: VLAN of the monitor session in the sensor · Collection IP address: IP address of the sensor in the device · Collection prefix length: mask of the Collection IP address · Collection gateway: gateway of the Collection IP address · Collection VLAN number: VLAN of the sensor
Click Next. Active Discovery: If you want to enable Active Discovery on the sensor, select Passive and Active Discovery. You can:
· use the sensor Collection interface by selecting it:

· add new network interfaces filling the following parameters to set dedicated network interfaces and clicking Add: · IP address · Prefix length · VLAN number
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 29

Configure a sensor in the sensor management extension

Procedure with the Cisco Cyber Vision sensor management extension

Step 4

Click Deploy.
The Center starts deploying the sensor application on the target equipment. This can take a few minutes. You can go to the Management jobs page to check the deployment advancements.

Once the deployment is finished, a new sensor appears in the sensors list. The sensor's status will eventually turn to connected.
If the Active Discovery has been enabled and set -that is if the option Passive and Active Discovery was selected when configuring the sensor in the sensor management extension- the sensor is displayed as below with Active Discovery's status as Enabled.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 30

Procedure with the Cisco Cyber Vision sensor management extension

Configure Active Discovery

Configure Active Discovery
Once the sensor is connected, you can change the Active Discovery's network interface so it uses the Collection network interface instead, and add several network interfaces for the sensor to perform Active Discovery on several subnetworks at the same time.
Procedure
Step 1 Click the sensor to configure and click the Active Discovery button on its right side panel.

Step 2

The Active Discovery configuration appears with the interface currently set. Select Use collection interface for the Active Discovery to use the Collection network interface.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 31

Configure Active Discovery

Procedure with the Cisco Cyber Vision sensor management extension

To add a network interface to Active Discovery for the sensor to perform active monitoring on another subnetwork:

Step 3 Step 4

Add a new network interface by clicking the corresponding button. Fill the following parameters to set dedicated network interfaces:
· IP address

· Prefix length

· VLAN number

Step 5 Click Add.

Step 6

You can add as many network interfaces as needed. When you are done, click Configure.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 32

Procedure with the Cisco Cyber Vision sensor management extension

Configure Active Discovery

A message saying that the configuration has been applied successfully appears.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 33

Configure Active Discovery

Procedure with the Cisco Cyber Vision sensor management extension

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 34

8 C H A P T E R
Procedure with the Local Manager
After the Initial configuration, on page 13, proceed to the steps described in this section. · Access the Local manager, on page 35 · Install the sensor virtual application, on page 37 · Configure the sensor virtual application (IE3x00/IE9x00), on page 38 · Configure the sensor virtual application (Catalyst 9x00), on page 42 · Generate the provisioning package, on page 47 · Import the provisioning package, on page 50
Access the Local manager
1. Open a browser and navigate to the IP address you configured on the interface you are connected to. 2. Log in using the Local Manager user account and password.
For example: Cisco IE3300 10G/IE3400
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 35

Access the Local manager

Procedure with the Local Manager

3. Once logged into the Local Manager, navigate to Configuration > Services > IOx. For example: Cisco IE3300 10G/IE3400
4. Log in using the user account and password.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 36

Procedure with the Local Manager

Install the sensor virtual application

Install the sensor virtual application
Once logged in, the following menu appears:
1. Click Add New. 2. Add an Application id name (e.g. CCVSensor). 3. Select the application archive file
· "CiscoCyberVision-IOx-aarch64-xxx.tar" for the Cisco IE3300/IE3400/IE9300 · "CiscoCyberVision-IOx-Active-Discovery-aarch64.tar" for the Cisco IE3300/IE3400/IE9300 with
Active Discovery · "CiscoCyberVision-IOx-x86-64-xxx.tar" for the Cisco Catalyst 9300 · "CiscoCyberVision-IOx-Active-Discovery-x86-64.tar" for the Cisco Catalyst 9300
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 37

Configure the sensor virtual application (IE3x00/IE9x00)

Procedure with the Local Manager

The installation takes a few minutes.
When the application is installed, the following message is displayed:
Configure the sensor virtual application (IE3x00/IE9x00)
1. Click Activate to launch the configuration of the sensor application.

2. Change the disk size from the default size to 2048 MB. The disk size must not be larger than this.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 38

Procedure with the Local Manager

Configure the sensor virtual application (IE3x00/IE9x00)

3. Bind the interfaces in the container to an interface on the host in Network Configuration. Start with eth0 by clicking edit in the eth0 line.
4. Click Interface Setting.
5. Apply the following configurations: · Select Static · IP/Mask: IP and mask of the sensor · Default gateway: IP address of the Center
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 39

Configure the sensor virtual application (IE3x00/IE9x00)

Procedure with the Local Manager

· Vlan ID, which is defined below, is the VLAN in the Cisco IE3300 10G/IE3400 dedicated to the Collection network interface (link between the Center and the sensors), e.g. 507.

6. IPV6 must be set to Disable. 7. Click OK twice.

8. Click OK again on the popup.
9. Then, apply the following parameters to eth1: · Select Static. · IP/Mask: the IP and mask of the sensor for the mirrored traffic.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 40

Procedure with the Local Manager

Configure the sensor virtual application (IE3x00/IE9x00)

· Vlan ID, which is defined below, is the VLAN in the Cisco IE3300 10G/IE3400/IE9300 dedicated to traffic mirroring.

10. IPV6 must be set to Disable. 11. If configuring a sensor with Active Discovery, you must set an additional interface (eth2 without IP
address) dedicated to this feature.
12. Click the Activate App button.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 41

Configure the sensor virtual application (Catalyst 9x00)
The operation takes several minutes.

Procedure with the Local Manager

The application status changes to "RUNNING":

Configure the sensor virtual application (Catalyst 9x00)
1. Click Activate to launch the configuration of the sensor application.

2. Change the disk size from the default size to 80,000 MB. The disk size must not be smaller than this.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 42

Procedure with the Local Manager

Configure the sensor virtual application (Catalyst 9x00)

3. Bind the interfaces in the container to an interface on the host in Network Configuration. Start with eth0 by clicking edit in the eth0 line.
4. Select the mgmt.-bridge300 entry in the interface list.
5. Click Interface Setting.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 43

Configure the sensor virtual application (Catalyst 9x00)

Procedure with the Local Manager

6. Apply the following configurations: · Select Static · IP/Mask: the IP and mask of the sensor · Default gateway: the IP address of the Center · Vlan ID, which is defined below, is the VLAN in the Cisco Catalyst 9300 dedicated to the Collection network interface (link between the Center and the sensors), e.g. 507.

7. IPV6 must be set to Disable. 8. Click OK twice.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 44

Procedure with the Local Manager

Configure the sensor virtual application (Catalyst 9x00)

9. Click OK again on the following popup.
10. Apply the following configurations to eth1: · Disable IPv4. · Disable IPv6. · Set the VLAN id. · Set the mirror mode as enabled.
11. Click OK until you come back to the screen below. 12. Click the Activate App button.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 45

Configure the sensor virtual application (Catalyst 9x00)

Procedure with the Local Manager

The operation takes several seconds. 13. Click Applications to display the application status:

14. The application is activated and needs to be started. To do so, click the Start button.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 46

Procedure with the Local Manager

Generate the provisioning package

The operation takes several seconds.
The application status changes to "RUNNING".
Generate the provisioning package
1. In Cisco Cyber Vision, navigate to Admin > Sensors > Sensor Explorer and click Install sensor, then Manual install.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 47

Generate the provisioning package

Procedure with the Local Manager

The manual install wizard appears. 2. Select Cisco IOx Application and click Next.

3. Fill the fields to configure the sensor provisioning package: · The serial number of the hardware. · Center IP: leave blank. · Gateway: add if necessary. · Optionally, select a capture mode. · Optionally, select RSPAN (only with Catalyst 9x00 and if using ERSPAN is not possible).
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 48

Procedure with the Local Manager

Generate the provisioning package

4. Click Create sensor. 5. Click the link to download the provisioning package.
This will download the provisioning package which is a zip archive file with the following name structure: sbs-sensor-config-<serialnumber>.zip (e.g. "sbs-sensor-configFCW23500HDC.zip"). 6. Click Finish. 7. A new entry for the sensor appears in the Sensor Explorer list. The sensor status will switch from Disconnected to Connected.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 49

Import the provisioning package

Procedure with the Local Manager

Import the provisioning package
1. In the Local manager, in the IOx configuration menu, click Manage. Cisco IE3400:

Cisco Catalyst 9300:
2. Navigate to App_DataDir. For example Cisco IE3400:

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 50

Procedure with the Local Manager

Import the provisioning package

3. Click Upload.
4. Choose the provisioning package downloaded (i.e. "sbs-sensor-config-FOC2334V01X.zip") and add the exact file name in the path field (i.e. "sbs-sensor-config-FOC2334V01X.zip").
5. Click OK.
A popup indicating that Cisco Cyber Vision has been deployed successfully appears. 6. Click OK.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 51

Import the provisioning package

Procedure with the Local Manager

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 52

9 C H A P T E R
Procedure with the CLI
After the Initial configuration, on page 13, proceed to the steps described in this section. · Configure the sensor application, on page 53 · Install the sensor application, on page 55 · Generate the provisioning package, on page 56 · Copy the sensor application provisioning package, on page 59 · Final step, on page 59
Configure the sensor application
Note In this section, "CCVSensor" is used as the appid.
1. Connect to the device through SSH or a console. 2. Configure the application payload by typing the following commands:
Cisco IE3300 10G/IE3400:
enable configure terminal app-hosting appid CCVSensor app-vnic AppGigabitEthernet trunk vlan 507 guest-interface 0 guest-ipaddress 192.168.69.208 netmask 255.255.255.0 vlan 2508 guest-interface 1 guest-ipaddress 169.254.1.2 netmask 255.255.255.0 app-default-gateway 192.168.69.1 guest-interface 0 app-resource profile custom persist-disk 2048 cpu 1400 memory 2048 vcpu 2 end
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 53

Configure the sensor application

Procedure with the CLI

Cisco IE9300:
enable configure terminal app-hosting appid CCVSensor
app-vnic AppGigabitEthernet trunk vlan 507 guest-interface 0 guest-ipaddress 192.168.69.90 netmask 255.255.255.0 vlan 2508 guest-interface 1 guest-ipaddress 169.254.1.2 netmask 255.255.255.252
app-default-gateway 192.168.69.190 guest-interface 0 app-resource docker
run-opts 1 --rm app-resource profile custom
cpu 1000 memory 862 persist-disk 4000 end
Cisco Catalyst 9300:
enable configure terminal app-hosting appid CCVSensor app-vnic AppGigabitEthernet trunk vlan 507 guest-interface 0 guest-ipaddress 192.168.69.210 netmask 255.255.255.0 vlan 2508 guest-interface 1 guest-ipaddress 169.254.1.2 netmask 255.255.255.0 app-default-gateway 192.168.69.1 guest-interface 0 app-resource profile custom persist-disk 8192 cpu 7400 memory 2048
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 54

Procedure with the CLI
vcpu 2 end

Install the sensor application

For the app-resource profile's custom values, refer to the result of the show app-hosting resource command. In this example, all maximum values are used for:
· the CPU (CPU available units, here 1400 for the Cisco IE3300 10G/IE3400, 1000 for the Cisco IE9300, and 7400 for the Cisco Catalyst 9300)
· the VCPU (here 2), the memory (Memory available, here 2048) · the disk (only 2048 MB and 8192 MB respectively are used to let space for application updates)
Install the sensor application
The sensor package is to be retrieved on cisco.com. The file has the following name structure: · CiscoCyberVision-IOx-aarch64-<VERSION>.tar (Cisco IE3300 10G/IE3400/IE9300). · CiscoCyberVision-IOx-x86-64-<VERSION>.tar (Cisco Catalyst 9300).
1. Copy the package to a USB key or in the flash memory. 2. Type the following commands on the CLI:
enable app-hosting install appid CCVSensor package usbflash0:<FILENAME>.tar
Cisco IE3300 10G/IE3400/IE9300:
Cisco Catalyst 9300:
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 55

Generate the provisioning package

Procedure with the CLI

Note Adjust "usbflash0:" in accordance with the sensor package's localization (USB port or flash memory).
Note Replace "CiscoCyberVision-IOx-aarch64-<VERSION>.tar" with the right filename. 3. Check that the application is in "DEPLOYED" state:
show app-hosting list
For example: Cisco IE3400

4. Activate the application using the following command:
app-hosting activate appid CCVSensor
For example: Cisco IE3400
5. Start the application using the following command:
app-hosting start appid CCVSensor
For example: Cisco IE3400:

Generate the provisioning package
1. In Cisco Cyber Vision, navigate to Admin > Sensors > Sensor Explorer and click Install sensor, then Manual install.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 56

Procedure with the CLI

Generate the provisioning package

The manual install wizard appears. 2. Select Cisco IOx Application and click Next.

3. Fill the fields to configure the sensor provisioning package: · The serial number of the hardware. · Center IP: leave blank. · Gateway: add if necessary. · Optionally, select a capture mode. · Optionally, select RSPAN (only with Catalyst 9x00 and if using ERSPAN is not possible).
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 57

Generate the provisioning package

Procedure with the CLI

4. Click Create sensor. 5. Click the link to download the provisioning package.
This will download the provisioning package which is a zip archive file with the following name structure: sbs-sensor-config-<serialnumber>.zip (e.g. "sbs-sensor-configFCW23500HDC.zip"). 6. Click Finish. 7. A new entry for the sensor appears in the Sensor Explorer list. The sensor status will switch from Disconnected to Connected.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 58

Procedure with the CLI

Copy the sensor application provisioning package

Copy the sensor application provisioning package
· Copy the provisioning package from the USB key to the application using the following command:
app-hosting data appid CCVSensor copy usbflash0:sbs-sensor-config-<SERIAL-NUMBER>.zip sbs-sensor-config-<SERIAL-NUMBER>.zip
For example: Cisco IE3400

Final step
In the sensor's CLI save the product's configuration by typing the following command:
write mem

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 59

Final step

Procedure with the CLI

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 60

1 0 C H A P T E R

Upgrade procedures

· Upgrade through the Cisco Cyber Vision sensor management extension, on page 61 · Upgrade through the IOx Local Manager, on page 64
Upgrade through the Cisco Cyber Vision sensor management extension
Before updating IOx sensors, the Cisco Cyber Vision sensor management extension must be up-to-date. It is possible to select which sensors to update. The update status will be visible in the Management jobs, on page 24 page.
Update the sensor management extension
The Cisco Cyber Vision sensor management extension must be up-to-date to update IOx sensors.
Procedure

Step 1
Step 2 Step 3

Retrieve the sensor management extension file (i.e. CiscoCyberVision-sensor-management-<version>.ext) on cisco.com. In Cisco Cyber Vision, navigate to Admin > Extensions. Click Update to browse the new version of the extension file.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 61

Update the sensors

Upgrade procedures

Update the sensors
Procedure

Step 1 Step 2

In Cisco Cyber Vision, navigate to Admin > Sensors > Sensor Explorer. Sensors that are not up-to-date have their version displayed in red. Click Install sensor, then Update Cisco devices.

The update Cisco devices window pops up listing all sensors that have been deployed with the sensor management extension.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 62

Upgrade procedures

Update the sensors

Step 3 Select the sensors you want to update.

Step 4

Click Update.
The sensors' update status appear in the Management jobs page in batches per sensor type and of maximum ten sensors per batch.

Herebelow the management jobs indicate that the batch of sensors updated successfully.

If the batch update fails, click the red update error icon to see logs.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 63

Upgrade through the IOx Local Manager

Upgrade procedures

Upgrade through the IOx Local Manager
The following section explains how to upgrade the sensor through the IOx Local Manager. Note In the case of Cisco Cyber Vision upgrade for a Catalyst 9x00 from a release 4.1.2 or lower to a release
4.1.3, the update will fail due to the addition of the RSPAN option. The sensor application must be removed and deployed again. In the example below, the sensor is upgraded from Cisco Cyber Vision version 3.2.2 to version 3.2.3.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 64

Upgrade procedures

Upgrade through the IOx Local Manager

Figure 1: The sensor in version 3.2.2 in the Sensors administration page of Cisco Cyber Vision

1. Access the IOx Local Manager. 2. Stop the application.
The operation takes a few moments.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 65

Upgrade through the IOx Local Manager

Upgrade procedures

The application status switches to STOPPED. In Cisco Cyber Vision, the sensor status switches to Disconnected.
3. In the IOx Local Manager, click the Deactivate button. The application status moves to DEPLOYED.
4. Click Upgrade.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 66

Upgrade procedures
The pop up Upgrade application appears.

Upgrade through the IOx Local Manager

5. Select the Preserve Application Data option. 6. Select the new version of the application archive file.
e.g. CiscoCyberVision-IOx-aarch64-3.2.3.tar

The operation takes a few moments.

A message indicating that the sensor has been successfully upgraded is displayed.
7. Check the number of the new version. 8. Click Activate.
Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 67

Upgrade through the IOx Local Manager

Upgrade procedures

9. Check configurations. It can happen that network configurations are lost during the upgrade. If they are, refer to Configure the sensor virtual application in the Procedure with the Local Manager corresponding to the switch used and do as explained.
10. Click the Activate App button. The application status moves to ACTIVATED.
11. Click the Start button. The application status changes to RUNNING. In Cisco Cyber Vision, the sensor is upgraded from version 3.2.2 to 3.2.3 and its status moves to Connected.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 68

1 1 C H A P T E R

Reconfigure/Redeploy a sensor

· Reconfigure/Redeploy a sensor, on page 69
Reconfigure/Redeploy a sensor
The Redeploy button is used when you need to replace a sensor model with another one keeping the same network configurations (e.g. replacing a Cisco IE3400 with a Cat 9300), change configurations, or if you need to reconfigure the sensor (e.g. to enable Active Discovery). To do so:
Procedure

Step 1 Step 2

On the Sensor Explorer page, click the sensor to reconfigure/redeploy. The sensor right side panel appears. Click Redeploy.

Step 3 Step 4

A pop up asking to confirm the redeployment of the sensor appears.
Click OK to proceed. A summary of the sensor configuration is displayed. In this example, we're going to change the Collection VLAN number.
Click Start.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 69

Reconfigure/Redeploy a sensor

Reconfigure/Redeploy a sensor

Step 5

Enter the credentials to reach the sensor to redeploy and click Connect.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 70

Reconfigure/Redeploy a sensor

Reconfigure/Redeploy a sensor

Step 6

Click the blue link to fill the warning fields with the current sensor configuration. We change the Collection VLAN number value to 49.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 71

Reconfigure/Redeploy a sensor

Reconfigure/Redeploy a sensor

Step 7 Step 8 Step 9
Step 10

Click Next. You can enable Active Discovery selecting Passive and Active Discovery. Click Deploy. A message saying that the sensor is being redeployed appears. You can either go the jobs page or go back to the Sensor Explorer page.
Click Go to the jobs page.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 72

Reconfigure/Redeploy a sensor

Reconfigure/Redeploy a sensor

You are redirected to the Management jobs to see the redeployment advancement. This can take several minutes.

If you go back to the Sensor Explorer page, you will see that the sensor is in Redeploying status.

Once the redeployment is finished, the sensor will switch status to connected and the Active Discovery to Enabled.

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 73

Reconfigure/Redeploy a sensor

Reconfigure/Redeploy a sensor

Cisco Cyber Vision Sensor Application for Cisco Switches Installation Guide, Release 4.1.3 74



References

DITA Open Toolkit XEP 4.30.961; modified using iText 2.1.7 by 1T3XT