CISCO Secure Network Analytics Deployment
Fa'amatalaga o oloa
Fa'amatalaga:
- Igoa Oloa: Cisco Secure Network Analytics Deployment
- Fa'atasi: Cisco ISE Fa'atasi mo le ANC
Cisco Secure Network Analytics Deployment ma Cisco ISE Integration mo ANC
Fa'atulagaina o le SMC
Ulufale i totonu o le faʻamafanafanaga, faʻaoga le poloaiga SystemConfig. Ulufale i le fa'aoga feso'otaiga mo le masini.
Fa'apipi'i o le Node Fa'amaumauga
Ulufale i totonu o le faʻamafanafanaga, faʻaoga le poloaiga SystemConfig. Ulufale i le fa'aoga feso'otaiga mo le masini.
Ua matou faʻatulagaina le faʻaogaina o le pulega, o loʻo i lalo le fesoʻotaʻiga lona lua o fesoʻotaʻiga mo le fesoʻotaʻiga i totonu o Faʻamatalaga Node (fesoʻotaʻiga ma isi nodes faʻamatalaga).
Fa'atuina o le Flow Collector
Ulufale i totonu o le faʻamafanafanaga, faʻaoga le poloaiga SystemConfig. Ia mautinoa ua filifilia uma filifiliga telemetry.
Fa'atulaga ports mo le telemetry.
- Netflow: 2055
- Vaega Va'ai Feso'otaiga: 2030
- Ogalaau Faila: 8514
Ulufale i le fa'aoga feso'otaiga mo le masini.
Fa'atuina o le Flow Sensor
Ulufale i totonu o le faʻamafanafanaga, faʻaoga le poloaiga SystemConfig. Ulufale i le fa'aoga feso'otaiga mo le masini.
Fa'atuina ole Cisco Telemetry Broker
Cisco Telemetry Brocker le vaega autu o
Cisco Secure Network Analytics (muamua Cisco Stealthwatch) ma se masini mamana e faʻamalieina ai le telemetry, e masani ona faʻaaogaina:
- Ina ia faafaigofie le aoina ma le tuufaatasia o le Netflow, SNMP ma le Syslog traffic.
- E faafaigofieina le fetuutuunai ma le auina atu o faamatalaga Netflow e faaaoga ai se tagata e auina atu i fafo i lau Network Devices nai lo isi tagata e auina atu i fafo, aemaise lava pe a i ai au suʻesuʻega faʻasalalau eseese e pei o Cisco Secure Network Analytics, SolarWinds poʻo le LiveAction, pe afai e tele au faʻaputuga tafe ma Cisco Secure Network Analytics.
- E le gata i lea e faafaigofieina ai le Telemetry Streams pe a faʻaaogaina le tele o nofoaga ma eseese fofo o le puleaina o ogalaau.
O le fausaga o Cisco Telemetry Broker e aofia ai vaega e lua:
- Pule Node
- Broker Node.
Broker Nodes e pulea uma e le tasi Cisco Telemetry Broker pule e faʻaaoga ai le Pulega Faʻafesoʻotaʻi. E manaʻomia e le Pule Node se tasi fesoʻotaʻiga fesoʻotaʻiga mo fefaʻatauaiga. Broker Node e manaʻomia ni fesoʻotaʻiga se lua. Tasi le pulega faʻafesoʻotaʻi mo fesoʻotaʻiga ma le pule ma le Telemetry interface e lafo Telemetry i Flow Collector lea e auina atu i nofoaga faʻatulagaina e pei o le SMC Management Console i le Cisco Secure Network Analytics solution. Le Destination Flow Collector IP Address/Port of the telemetry traffic in Cisco Secure Network Analytics solution ua faʻaopoopoina i luga o le Pule Node ma tulei i lalo i le Broker Node e ala i le pulega faʻatautaia e aʻoaʻo ai i latou i le mea e agai i ai NetFlow traffic.
A faʻapipiʻi le Node Broker, e tatau ona e tuʻufaʻatasia i le pule Node e faʻaaoga ai le sudo ctb-manage command ma tuʻuina atu le IP Address ma faʻamatalaga faʻamaonia o le Pule Node. O le taimi lava e faaopoopo ai le Node Broker i le Pule Node, o le Web GUI o le Pule Node o loʻo faʻaalia ai le Broker Node faʻaopoopo ma lona tuatusi IP pulega. Ina ia maeʻa le tuʻufaʻatasia i le va o le Broker Node ma le Pule Node, e tatau ona e faʻaopoopoina le Faʻamatalaga poʻo le Telemetry Network Interface o le Broker Node i le Pule Node. Mulimuli ane, o le Network Devices e pei o firewalls, Routers and Switches e faʻaaogaina le Broker Node Telemetry Interface IP Address e avea ma Netflow Exporter.
Fa'atino le Pule Node
Faʻatonu le sudo ctb-install -init command.
Ulufale i faʻamatalaga nei:
- Password mo le tagata fa'aoga admin
- Igoa talimalo
- tuatusi IPv4, subnet mask, ma le tuatusi faitoto'a fa'aletonu mo le feso'otaiga o le Pulega
- DNS nameserver tuatusi IP
Fa'asoa le Node Broker
Faʻatonu le sudo ctb-install -init command.
Ulufale i faʻamatalaga nei:
- Password mo le tagata fa'aoga admin
- Igoa talimalo
- tuatusi IPv4, subnet mask, ma le tuatusi faitoto'a fa'aletonu mo le feso'otaiga o le Pulega
- DNS nameserver tuatusi IP
Faʻatonu le sudo ctb-manage command.
Ulufale i faʻamatalaga nei:
- tuatusi IP o le node Pule
- Username o le admin account o le Pule node
Ulufale i Cisco Telemetry Broker. I le a web su'esu'e, ulufale i le Pule's management interface IP address o le pule node. Mai le lisi autu, filifili Nodes Broker.
I le Broker Nodes table, kiliki le node broker. I le vaega Telemetry Interface, Fa'atulaga le Telemetry Interface ma le faitotoa faaletonu.
O le taimi nei ua faʻapipiʻiina meafaigaluega a le SNA ma se tuatusi IP pulega, matou te manaʻomia le faʻamaeʻaina o le Tool Setup Tool (AST) i vaega taʻitasi SNA.
O le Mea Fa'atonu Setup (AST) o le a fa'apipi'i masini ina ia mafai ona feso'ota'i ma isi vaega o le SNA fa'apipi'iina.
SMC
- Avanoa ile SMC GUI.
- Suia le Fa'amatalaga Fa'atonu mo le admin, root, ma le sysadmin.
Leai se suiga mo le Pulega Feso'ota'iga Interface.
Fa'atulaga le Igoa Host ma Domains.
- Fa'atulaga le DNS Servers.
- Fa'atulaga le NTP Server.
- Mulimuli ane resitala le SMC.
- Ole SMC ole a toe fa'afouina.
Node faleteuoloa
Mulimuli i le faiga lava e tasi, na o le pau lava le eseesega o le faʻatulagaina o Faʻatonuga Tutotonu. I totonu o lenei vaega Ulufale le tuatusi IP o le SMC 198.19.20.136 ma le username/password.
Aoina mai o le tafe
Mulimuli i le faiga lava e tasi, na o le pau lava le eseesega o le faʻatulagaina o Faʻatonuga Tutotonu. I totonu o lenei vaega Ulufale le tuatusi IP o le SMC 198.19.20.136 ma le username/password.
Tafe Sensor
- Mulimuli i le faiga lava e tasi, na o le pau lava le eseesega o le faʻatulagaina o Faʻatonuga Tutotonu. I totonu o lenei vaega Ulufale le tuatusi IP o le SMC 198.19.20.136 ma le username/password.
- Ina ia faʻamaeʻa le faʻatulagaina, Faʻamata le node o le DataStore.
- SSH i le node DataStore ma faʻatautaia le SystemConfig poloaiga.
- Mulimuli i le talanoaga fegalegaleai e amata ai le node DataStore.
- Avanoa i le SMC GUI, i le Pulega Tutotonu e mafai ona tatou vaʻaia uma Cisco SNA mea faigaluega e fesoʻotaʻi ma SMC.
Cisco Telemetry Broker Configuration
Avanoa ile Cisco Telemetry Broker Manager node GUI. Kiliki Add Destination ma filifili UDP Destination. Fa'atulaga fa'amaufa'ailoga nei.
- Su'ega Igoa: SNA-FC
- Ituaiga IP tuatusi: 198.19.20.137
- Taulaga UDP taunu'uga: 2055
Kiliki Fa'aopoopo Tulafono.
- Ulufale i le 2055 o le Taulaga UDP Mauaina.
Kiliki Add Destination ma filifili UDP Destination.
Fa'atulaga fa'amaufa'ailoga nei.
- Su'ega Igoa: Pule
- Ituaiga IP tuatusi: 198.19.20.136
- Taulaga UDP taunu'uga: 514
- Kiliki Fa'aopoopo Tulafono.
- Ulufale i le 2055 o le Taulaga UDP Mauaina.
Cisco ISE Identity Services Engine Integration
Su'e ile Pulega> pxGrid> Tusi Faamaonia.
Faatumu le fomu e pei ona taua i lalo:
- Kiliki i le ou te manaʻo i le fanua ma filifili le Download Root Certificate Chain
- Kiliki ile Host Names fanua ma filifili admin
- Kiliki i le Tusi Fa'ailoga Download Format fanua ma filifili le filifiliga PEM
- Kiliki Fausia
- La'u mai le file pei o ISE-CA-ROOT-CHAIN.zip.
- I luga ole SMC GUI, kiliki Central Management. I luga o le Central Management itulau, su'e le SMC Manager appliance, ona filifili lea o Edit Appliance Configuration.
- Kiliki General.
- Fa'asolo i lalo ile Faleoloa Mavaega ma kiliki Fa'aopoopo Fou. Filifili le CertificateServicesRootCA-admin_.cer file. Kiliki Add Certificate.
- O le a fa'atuatuaina nei e le SMC tusi pasi na tu'uina atu e le ISE CA.
- Kiliki le mea fa'apipi'i. Fa'asolo i lalo ile vaega Fa'asinomaga Fa'atagata Fa'aopoopo SSL/TLS ma kiliki Fa'aopoopo Fou.
- O le a fesili pe e te manaʻomia le fausiaina o se CSR, filifili Ioe ma kiliki le Next.
Faatumu le CSR e pei ona taua i lalo:
- RSA Ki Umi
- Faalapotopotoga
- Vaega Fa'alapotopotoga
- Nofoaga po'o le A'ai
- Setete poo Itumalo
- Tulafono a le Atunu'u
- Imeli tuatusi
Kiliki Fausia CSR, ona la'u mai lea o le CSR.
Avanoa i le Cisco ISE GUI. Su'e ile Pulega> pxGrid> Tusi Faamaonia.
Fa'aaogā fa'amatalaga nei:
- I le fanua Ou te manaʻo e fai, filifili Fausia se tusi faamaonia se tasi (faatasi ai ma le talosaga saini tusi pasi)
- Ua pasia le CSR i totonu o le Tusi Faamaonia Talosaga Talosaga Fa'amatalaga fanua
- Fa'ailoga SMC i le Fa'amatalaga fanua
- Filifili le tuatusi IP ile fanua SAN ma ulufale i le 198.19.20.136 e avea ma tuatusi IP e fesoʻotaʻi.
- Filifili le faatulagaga PKCS12 e fai ma filifiliga e sii mai ai Tusi Faamaonia
- Ulufale se upu faataga
- Kiliki Fausia
- Faasaoina le tusi faamaonia na faia ma se igoa SMC-PXGRID.
Fa'aaliga:
I nisi o lo'o i ai nei Cisco ISE deployment, atonu ua mae'a lau tusi pasi fa'aogaina mo le pulega, eap ma le pxGrid auaunaga e pei ona fa'aalia i lalo.
E mafua ona o le Cisco ISE i totonu CA tusi faamaonia o loʻo sainia nei tusi pasi faiga ua maeʻa.
Ina ia faafou tusi faamaonia faiga. Su'e i le Pulega > Tusi Fa'amaonia > Talosaga Saini Fa'ailoga. I le Fa'aoga fanua, filifili ISE Root CA, ona kiliki lea i luga Sui ISE Root CA Certificate Chain.
O le Cisco ISE e fa'atupuina se tusipasi fou i totonu CA. Aua nei galo e fetuutuunai le Trusted For field mo auaunaga talafeagai e pei ole pxGrid.
O lea la ua aoga tusipasi faiga.
Avanoa ile SMC GUI. Alu i le Pulega Tutotonu. I le SMC Appliance Configuration tab, tusi i lalo i le Add SSL/TLS Client Identity form, ona kiliki lea Filifili. File, filifili le tusi faamaonia SMC-PXGRID.
I le SMC GUI, fa'afeiloa'i ile Deploy> Cisco ISE Configuration.
Fa'atulaga le ISE Configuration fa'atasi ma ta'iala nei:
- Igoa Vaega: ISE-CLUSTER
- Tusi Faamaonia: SMC-PXGRID
- Primary PxGrid Node: 198.19.20.141
- Igoa Fa'atau: SMC-PXGRID
Su'e ile Mataitu > Tagata fa'aoga.
Faʻaaliga e mafai ona matou vaʻaia faʻamatalaga a le Tagata i luga ole SMC.
Faiga Fa'atonu a le ISE Adaptive Network Control (ANC).
Filifili Fa'agaioiga > Fa'atonu Feso'ota'iga Pulea > Lisi Fa'avae > Fa'aopoopo ma fa'aofi i totonu SW_QUARANTINE mo le Igoa o Faiga Fa'avae ma Karantina mo le Fa'atinoga.
Avanoa ile SMC GUI. Filifili se tuatusi IP i le dashboard, e mafai ona tatou vaʻaia o loʻo faʻatumauina le ISE ANC Policy.
- O faiga fa'avae fa'ataga fa'alelalolagi e mafai ai e oe ona fa'amatala tulafono e fa'amalo uma tulafono fa'atagaina i au seti uma. O le taimi lava e te fa'atulagaina ai se faiga fa'avae fa'atagaina i le lalolagi atoa, e fa'aopoopo i seti uma o faiga fa'avae.
- O le tulafono fa'atagaina fa'alotoifale e suia ai tulafono fa'apitoa a le lalolagi. O lea la e fa'agasolo muamua le tulafono fa'alotoifale, fa'asolo atu i le tulafono fa'ava-o-malo, ma mulimuli ane, o le tulafono masani o le faiga fa'atagaina.
- O se tasi o faʻaoga mataʻina o nei Tulafono Faʻapitoa o le taimi e te faʻapipiʻi ai Cisco Secure Network Analytics (Stealth watch) ma Cisco ISE mo le Faʻatonuina o Tali e faʻaaoga ai le Adaptive Network Policy (ANC) ina ia pe a faʻatupuina se faʻailo, Cisco Secure Network Analytics (Stealth watch) o le a talosagaina Cisco ISE e taofia le talimalo ile Adaptive Network Control Policy e ala ile Px Grid.
- Le faiga sili e fa'atulaga ai le Faiga Fa'atagaga i Cisco ISE e taofia ai le tagata talimalo pe i totonu o le Local Exception po'o le Global Exception.
- Afai e te manaʻo e faʻaoga le ANC Policy i au seti uma, VPN, uaea uaea aka uma uaea VPN ma uaealesi tagata faaaoga. Fa'aaogā le Va'aiga Fa'avaomalo.
- Afai e te manaʻo e faʻaoga le ANC Policy naʻo tagata VPN poʻo tagata faʻaoga uaea. Fa'aoga le Faiga Fa'alotoifale i totonu ole VPN Policy Sets po'o Wired Policy Set.
Otometi Gaioiga ma Tali ma le ANC
Tala: O loʻo faʻaogaina e se kamupani Cisco Umbrella e avea ma DNS server e puipuia ai faʻamataʻu i luga ole initaneti. Matou te mananaʻo i se faʻailoga faʻaleaganuʻu ina ia faʻaogaina e tagata faʻaoga i totonu isi sapalai DNS fafo, e faʻaosoina se faʻailo e taofia ai le fesoʻotaʻiga i sau DNS leaga e ono toe faʻafeiloaʻi ai fefaʻatauaiga i nofoaga i fafo mo faamoemoega leaga. A fa'atupuina se fa'ailo, Cisco Secure Network Analytics o le a talosagaina Cisco ISE e taofia le talimalo o lo'o fa'aogaina Rogue DNS Servers ma Adaptive Network Control Policy e ala i le PxGrid. Fa'asaga i le Fa'atonu> Pulea Talimalo. I totonu o le kulupu talimalo matua Inside Hosts, fa'atupu se Host Group e ta'ua o Auaunaga Lautele mo au feso'otaiga i totonu.
I totonu o le matua talimalo vaega Outside Hosts, fatuina se Host Group e igoa Umbrella DNS Servers mo tuatusi IP faamalu.
O loʻo faʻaogaina e tagata faʻaoga i totonu Cisco Umbrella e avea ma DNS server e puipuia ai faʻamataʻu i luga ole initaneti. Fa'atulaga se fa'ailoga fa'aleaganu'u ina ia fa'aogaina e tagata fa'aoga i totonu isi sapalai DNS i fafo, e fa'aoso se fa'ailo e taofia ai le so'otaga i le server DNS leaga e ono toe fa'afeiloa'i feoaiga i nofoaga i fafo mo fa'amoemoe leaga. A fa'atupuina se fa'ailo, Cisco Secure Network Analytics o le a talosagaina Cisco ISE e taofia le talimalo o lo'o fa'aogaina Rogue DNS Servers ma Adaptive Network Control Policy e ala i le PxGrid.
Fa'asaga i le Fa'atonu> Pulea Faiga Fa'avae.
Fausia se Faiga Fa'apitoa ma fa'amatalaga nei:
- Igoa : Ta'avale DNS e le'i fa'atagaina
- Vaega Talimalo Mataupu : Fesootaiga Autasi
- Vaega Talia a tupulaga : Talimalo i fafo Se'i vagana ai Umbrella DNS Servers
- Peer Port/Protocols : 53/UDP 53/TCP
O le mea moni o lenei mea e tupu pe a fesoʻotaʻi soʻo se talimalo o loʻo i totonu o le Corporate Networks Host Group ma soʻo se tagata talimalo i totonu o le Outside Hosts Host Group sei vagana ai i latou i totonu ole Umbrella DNS Servers Host Group, e ala i le 53/UDP poʻo le 53/TCP, e faʻatupuina se faʻailoga.
Fa'asaga i le Fa'atonu> Pulea Tali. Kiliki i luga Actions.
Filifili le ISE ANC Policy Action. Tu'u mai se igoa ma filifili le Cisco ISE fuifui e tatau ona fa'afeso'ota'i e fa'aoga se faiga fa'afalepuipui mo so'o se soliga po'o se feso'ota'iga i 'au'aunaga leaga.
I lalo o le vaega o Tulafono. Fausia se Tulafono fou. O lenei tulafono o le a faʻaaogaina le gaioiga muamua pe a taumafai soʻo se tagata talimalo i totonu o le upega tafaʻilagi e auina atu le DNS traffic i Rogue DNS Servers. I le vaega Tulafono e faʻaosoina pe afai, filifili Ituaiga, tusi i lalo ma filifili le mea masani na faia muamua. I lalo ole Faiga Fa'atasi, filifili le gaioiga ISE ANC na faia muamua.
Mai totonu ole talimalo, tatala le CMD console. Fa'atino le fa'atonuga nslookup, fa'atonu le server 8.8.8.8. Tusi i totonu ni nai tuatusi mo le 8.8.8.8 DNS server e foia.
Su'e ile Mata'itu > ISE ANC Policy Assignments. E tatau ona e vaʻai o le Cisco Secure Network Analytics na faʻaogaina le Adaptive Network Control Policy e ala i le PxGrid ma le ISE e taofia ai le Host.
FAQ
F: E fa'afefea ona ou fa'amae'aina le Mea Fa'atulaga Mea (AST) i vaega ta'itasi SNA?
A: O le taimi lava e fa'atulaga ai masini SNA ma se tuatusi IP pulega, e mafai ona e fa'atumu le AST i vaega ta'itasi e ala i le mulimuli i fa'atonuga patino o lo'o tu'uina atu mo lena vaega i totonu o le tusi fa'aoga po'o le ta'iala fa'atulagaina.
Pepa / Punaoa
![]() |
CISCO Secure Network Analytics Deployment [pdf] Tusi Taiala Saogalemu Network Analytics Deployment, Network Analytics Deployment, Analytics Deployment, Deployment |