Initial configuration
Cisco IC3000 front view
Before starting, take a moment to note and identify the following parts that will be used during the procedure:
- DC-in connectors (1)
- Serial number (2)
- Reset pinhole (3)
- SYS LED (4)
- Console connectors (5): RJ-45 and mini-USB
- USB port 2 (6)
- MGMT Ethernet port (7): Local Manager and Collection network interfaces
- Industrial Network Interfaces (8): 2x RJ45 10/100/1000 BaseT connectors and 2x SFP fiber ports
Connect the Cisco IC3000
The Cisco IC3000 contains 4 independent ports that can be used to capture in SPAN mode or to perform active scanning on the network. Depending on the port usage, the corresponding switch port must have the correct configuration (SPAN or access). The Cisco IC3000's Industrial network interface for DPI must be connected to switches configured in port mirroring only.
Procedure
- Step 1: Connect the Collection network interface (IC3000 to Center) to the MGMT ENET port (1).
- Step 2: Connect the Industrial network interface (IC3000 to on-site switches) to ports 1, 2, 3, 4 (up to 4 switches configured in port mirroring or access depending on the port usage). Ports 1 and 2 are RJ45 10/100/1000 BaseT Connectors. Ports 3 and 4 are SFP fiber ports.
Connect to the Cisco IC3000 with the serial console
This section describes how to establish a connection to the Cisco IC3000 from Windows 10 using PuTTY. This is required to perform a sensor management extension installation and to enable Active Discovery (optional) when performing a manual installation.
Note: This procedure will also work for other versions of Windows.
Requirements:
- A RJ45 or mini USB console cable.
- A serial console emulator, like PuTTY.
Procedure
- Step 1: Download and install a serial console emulator like PuTTY on your computer. Refer to its documentation for usage instructions.
- Step 2: Connect your computer to the Cisco IC3000 through its serial port using the RJ45 or mini USB console cable. If you are using Windows, you need to identify to which COM port the console is connected.
- Step 3: To identify the COM port, right-click on the Windows Start icon and select "Device Manager".
- Step 4: Scroll down and click the "Ports (COM & LPT)" menu. The COM number will appear.
To start a connection to the Cisco IC3000:
- Step 5: Make sure there is no USB drive plugged into the Cisco IC3000.
- Step 6: Disconnect the Cisco IC3000 from the DC Current source.
- Step 7: Open PuTTY.
- Step 8: Select "Serial" for the Connection type.
- Step 9: Enter "COM
" into the serial line field. Set speed at 9600. - Step 10: Click "Open" to display the shell prompt for PuTTY.
- Step 11: Connect the Cisco IC3000 to the DC current source. Wait a few moments. When booting is complete, the shell prompt will ask you to press return to start. The connection has established with success.
Cisco IC3000 platform initial configuration
Perform the following procedure if it's the first time the Cisco IC3000 device is installed in Cisco Cyber Vision.
Set Cisco IC3000 for Local Manager
Procedure
- Step 1: Click "Manage Cisco devices", then "Generate Day-0 config for IC3000".
- Step 2: Fill the following fields to set the Local Manager's network parameters and login:
- The Host Management's IP address, netmask, and gateway. These must be set to access the Local Manager of the Cisco IC3000 device.
- The Local Manager admin user name. The login is "admin" by default. Use the default login in case a factory reset is performed to avoid starting the whole procedure again. The user name will be asked later to log in to IOx Local Manager and in case of troubleshooting and configuration. Therefore, make sure to keep this information stored.
Prepare and import the Local Manager configuration file
After generating and downloading the file device_config.cfg, you must prepare and import it into the Cisco IC3000.
Procedure
- Step 1: Copy the file into a folder named as the serial number of the Cisco IC3000 (e.g., FCH2309Y01Z). The folder must be placed at the root directory of a USB drive formatted as FAT32.
- Step 2: Disconnect the Cisco IC3000 from the DC Current source. The USB drive must be plugged in at Cisco IC3000 boot.
- Step 3: Plug the USB drive into port 2 of the Cisco IC3000.
- Step 4: Connect the sensor to the DC Current source.
- Step 5: Wait a few moments. The Cisco IC3000 status changes to "Enrolled" on the Cisco Cyber Vision GUI.
- Step 6: Unplug the USB drive from port 2.
Configure date and time
The Local Manager should become available on the IP address defined during this procedure.
Before proceeding to the installation, you must set the correct date and time on the IC3000 through the Local Manager for its proper functioning.
Procedure
- Step 1: Access the Local Manager.
- Step 2: Navigate to "Device Config".
- Step 3: Slide down to "Time Source" and configure the date and time according to your network settings. You can choose between "Manual" or "NTP" for the time source. Configure the Date, Time, and Timezone accordingly.
For more information, check the Cisco IC3000 user documentation available on cisco.com.