Tšebeliso e sireletsehileng ea CISCO Network Analytics
Tlhahisoleseding ya Sehlahiswa
Litlhaloso:
- Lebitso la Sehlahisoa: Tšebeliso ea Cisco Secure Network Analytics
- Kopanyo: Khokahano ea Cisco ISE bakeng sa ANC
Cisco Secure Network Analytics Deployment le Cisco ISE Integration bakeng sa ANC
Ho kenngoa ha SMC
Kena ho console, thaepa taelo SystemConfig. Kenya tlhophiso ea marang-rang bakeng sa sesebelisoa.
Ho kenngoa ha Datastore Node
Kena ho console, thaepa taelo SystemConfig. Kenya tlhophiso ea marang-rang bakeng sa sesebelisoa.
Re hlophisitse sebopeho sa tsamaiso, se latelang ke sebopeho sa bobeli sa marang-rang bakeng sa puisano ea inter-Data Node (puisano le lisebelisoa tse ling tsa data).
Ho kenngoa ha Phallo Collector
Kena ho console, thaepa taelo SystemConfig. Etsa bonnete ba hore likhetho tsohle tsa telemetry li khethiloe.
Lokisa likou tsa telemetry.
- Netflow: 2055
- Network Ponahalo Mojule: 2030
- Li-Firewal Logs: 8514
Kenya tlhophiso ea marang-rang bakeng sa sesebelisoa.
Ho kenya Sensor ea Phallo
Kena ho console, thaepa comand SystemConfig. Kenya tlhophiso ea marang-rang bakeng sa sesebelisoa.
Ho kenya Cisco Telemetry Broker
Cisco Telemetry Brocker karolo ea mantlha ea
Cisco Secure Network Analytics (eo pele e neng e le Cisco Stealthwatch) le sesebelisoa se matla sa ho ntlafatsa telemetry, se sebelisoa haholo:
- Ho nolofatsa pokello le ho kopanya sephethephethe sa Netflow, SNMP le Syslog.
- E nolofatsa ho hlophisa le ho romella data ea Netflow ho sebelisa morekisi a le mong ho Lisebelisoa tsa hau tsa marang-rang ho fapana le barekisi ba fapaneng, haholo ha o na le bahlahlobisisi ba marang-rang ba fapaneng joalo ka Cisco Secure Network Analytics, SolarWinds kapa LiveAction, kapa haeba u na le babokelli ba phallo ba bangata ba Cisco Secure Network Analytics.
- Ntle le moo, e nolofatsa Melapo ea Telemetry ha u sebelisa libaka tse ngata le litharollo tsa taolo ea li-log.
Moralo oa Cisco Telemetry Broker o na le likarolo tse peli:
- Motsamaisi Node
- Node ea Broker.
Li-Broker Node kaofela li laoloa ke mookameli a le mong oa Cisco Telemetry Broker a sebelisa Sebopeho sa Tsamaiso. Motsamaisi Node e hloka sebopeho se le seng sa marang-rang bakeng sa sephethephethe sa tsamaiso. Broker Node e hloka li-interfaces tse peli tsa marang-rang. Khokahano e le 'ngoe ea taolo bakeng sa puisano le mookameli le segokanyimmediamentsi sa Telemetry ho romella Telemetry ho Flow Collector eo le eona e romellang libaka tse lokiselitsoeng tse kang SMC Management Console ho Cisco Secure Network Analytics tharollo. The Destination Flow Collector IP Address / Port ea telemetry traffic ho Cisco Secure Network Analytics tharollo e eketsoa ho Node ea Mookameli 'me e sutumelletsoa ho ea ho Broker Node ka sebopeho sa tsamaiso ho ba laela hore na sephethephethe sa NetFlow se hokae.
Ha u kenya Node ea Broker, u tlameha ho e kopanya le Node ea mookameli u sebelisa taelo ea sudo ctb-manage le ho fana ka Aterese ea IP le lintlha tsa tsamaiso tsa Node ea Mookameli. Hang ha Node ea Broker e eketsoa ho Node ea Mookameli, the Web GUI ea Node ea Motsamaisi e bonts'a Node ea Broker e kentsoeng ka Aterese ea eona ea IP ea tsamaiso. Ho qeta ho kopanya pakeng tsa Node ea Broker le Node ea Mookameli, o hloka ho eketsa Data kapa Telemetry Network Interface ea Node ea Broker ho Node ea Mookameli. Qetellong Lisebelisoa tsa Network tse kang li-firewall, Routers le Switches li sebelisa Broker Node Telemetry Interface IP Address e le Netflow Exporter.
Kenya Node ea Motsamaisi
Matha taelo ea sudo ctb-install -init.
Kenya lintlha tse latelang :
- Password bakeng sa mosebelisi oa admin
- Lebitso la moamoheli
- Aterese ea IPv4, subnet mask, le aterese ea kamehla ea heke bakeng sa sebopeho sa Marang-rang a Tsamaiso
- DNS nameserver IP aterese
Kenya Node ea Broker
Matha taelo ea sudo ctb-install -init.
Kenya lintlha tse latelang :
- Password bakeng sa mosebelisi oa admin
- Lebitso la moamoheli
- Aterese ea IPv4, subnet mask, le aterese ea kamehla ea heke bakeng sa sebopeho sa Marang-rang a Tsamaiso
- DNS nameserver IP aterese
Sebelisa taelo ea sudo ctb-manage.
Kenya lintlha tse latelang :
- Aterese ea IP ea node ea Motsamaisi
- Lebitso la mosebelisi la akhaonto ea admin ea node ea Motsamaisi
Kena ho Cisco Telemetry Broker. Ho a web sebatli, kenya aterese ea IP ea tsamaiso ea Motsamaisi oa node ea mookameli. Ho tsoa ho menu e kholo, khetha Broker Nodes.
Tafoleng ea Broker Nodes, tobetsa node ea broker. Karolong ea Telemetry Interface, Lokisa Sehokelo sa Telemetry le heke ea kamehla.
Hona joale lisebelisoa tsa SNA li hlophisitsoe ka aterese ea IP ea tsamaiso, re hloka ho tlatsa Sesebelisoa sa Setupo sa Lisebelisoa (AST) karolong ka 'ngoe ea SNA.
The Appliance Setup Tool (AST) e tla lokisa lisebelisoa hore li khone ho buisana le karolo e setseng ea SNA.
SMC
- Fumana SMC GUI.
- Fetola Li-password tsa Default bakeng sa admin, motso, le sysadmin.
Ha ho liphetoho bakeng sa Sehokelo sa Marang-rang sa Tsamaiso.
Lokisa Lebitso la Moamoheli le Libaka.
- Lokisa li-server tsa DNS.
- Lokisa Seva ea NTP.
- Qetellong ngodisa SMC.
- SMC e tla qala hape.
Datastore Node
Latela mokhoa o ts'oanang, phapang e le 'ngoe feela ke tlhophiso ea Litlhophiso tsa Bohareng ba Tsamaiso. Karolong ena Kenya aterese ea IP ea SMC 198.19.20.136 le lebitso la mosebelisi/password.
Mokelli oa Phallo
Latela mokhoa o ts'oanang, phapang e le 'ngoe feela ke tlhophiso ea Litlhophiso tsa Bohareng ba Tsamaiso. Karolong ena Kenya aterese ea IP ea SMC 198.19.20.136 le lebitso la mosebelisi/password.
Sensor ea ho phalla
- Latela mokhoa o ts'oanang, phapang e le 'ngoe feela ke tlhophiso ea Litlhophiso tsa Bohareng ba Tsamaiso. Karolong ena Kenya aterese ea IP ea SMC 198.19.20.136 le lebitso la mosebelisi/password.
- Ho phethela tlhophiso, Qala node ea DataStore.
- SSH ho node ea DataStore 'me u tsamaise taelo ea SystemConfig.
- Latela puisano e kopanetsoeng ho qala node ea DataStore.
- Fumana SMC GUI, ho Central Management re ka bona lisebelisoa tsohle tsa Cisco SNA li hokahane le SMC.
Cisco Telemetry Broker Configuration
Fumana GUI ea Cisco Telemetry Broker Manager node. Tobetsa Eketsa Sebaka ebe u khetha UDP Destination. Lokisa liparamente tse latelang.
- Lebitso la Sebaka: SNA-FC
- IP Address: 198.19.20.137
- Boema-kepe ba UDP: 2055
Tobetsa Add Rule.
- Kenya 2055 joalo ka Boema-kepe bo Fumanang UDP.
Tobetsa Eketsa Sebaka ebe u khetha UDP Destination.
Lokisa liparamente tse latelang.
- Lebitso la Sebaka: Motsamaisi
- IP Address: 198.19.20.136
- Boema-kepe ba UDP: 514
- Tobetsa Add Rule.
- Kenya 2055 joalo ka Boema-kepe bo Fumanang UDP.
Cisco ISE Identity Services Engine Integration
Eya ho Tsamaiso > pxGrid > Litifikeiti.
Tlatsa foromo ka tsela e latelang:
- Tobetsa ho Ke batla ho leba tšimong ebe u khetha Khoasolla Motso oa Setifikeiti sa Chain
- Tobetsa sebakeng sa Mabitso a Mabitso ebe u khetha admin
- Tobetsa tšimong ea Format ea Setifikeiti ebe u khetha khetho ea PEM
- Tobetsa Create
- Download the file joalo ka ISE-CA-ROOT-CHAIN.zip.
- Ho SMC GUI, tobetsa Central Management. Leqepheng la Bohareng ba Tsamaiso, fumana sesebelisoa sa Motsamaisi oa SMC, ebe u khetha Edita Configuration.
- Tobetsa Kakaretso.
- Tsamaisetsa tlase ho Trust Store ebe o tobetsa Kenya Ncha. Khetha CertificateServicesRootCA-admin_.cer file. Tobetsa Add Certificate.
- Hona joale SMC e tla tšepa litifikeiti tse fanoeng ke ISE CA.
- Tobetsa tab ya Appliance. Tsamaisetsa tlase ho karolo ea Li-Client Identity tsa SSL/TLS ebe o tobetsa Kenya Ncha.
- E tla botsa hore na o hloka ho hlahisa CSR, khetha E ebe o tobetsa E latelang.
Tlatsa CSR ka tsela e latelang:
- Bolelele ba Senotlolo sa RSA
- Mokhatlo
- Lekala la Mokhatlo
- Sebaka kapa Motse
- Naha kapa Porofense
- Khoutu ea Naha
- Aterese ea imeile
Tobetsa Hlahisa CSR, ebe U Khoasolla CSR.
Fumana Cisco ISE GUI. Eya ho Tsamaiso > pxGrid > Litifikeiti.
Sebelisa lintlha tse latelang:
- Sebakeng seo ke batlang ho se etsa, khetha Hlahisa setifikeiti se le seng (ka kopo ea ho saena setifikeiti)
- E fetile CSR lebaleng la Lintlha tsa Kopo ea ho Saena Setifikeiti
- Tlanya SMC tšimong ea Tlhaloso
- Khetha Aterese ea IP lebaleng la SAN ebe u kenya 198.19.20.136 joalo ka Aterese ea IP e amanang le eona.
- Khetha sebopeho sa PKCS12 joalo ka khetho ea Setifikeiti sa Khoasolla Format
- Kenya phasewete
- Tobetsa Create
- Boloka setifikeiti se entsoeng ka lebitso SMC-PXGRID.
Hlokomela :
Ts'ebetsong e 'ngoe e teng ea Cisco ISE, e kanna ea ba u na le litifikeiti tsa sistimi tse felloang ke nako tse sebelisoang bakeng sa lits'ebeletso tsa admin, eap le pxGrid joalo ka ha ho bonts'itsoe ka tlase.
Lebaka ke hobane litifikeiti tsa Cisco ISE tsa ka hare tsa CA tse saenang litifikeiti tsena tsa sistimi li felile.
Ho nchafatsa litifikeiti tsa sistimi. Eya ho Tsamaiso > Litifikeiti > Likopo tsa ho Saena Setifikeiti. Sebakeng sa Ts'ebeliso, khetha ISE Root CA, ebe o tobetsa ho Replace ISE Root CA Certificate Chain.
Cisco ISE e hlahisa setifikeiti se secha sa Internal CA. Se ke oa lebala ho lokisa sebaka sa Trusted For bakeng sa lits'ebeletso tse nepahetseng joalo ka pxGrid.
Hona joale litifikeiti tsa sistimi li sebetsa.
Fumana SMC GUI. Eya ho Central Management. Ho "SMC Appliance Configuration" tab, tsamaisetsa tlase ho Kenya SSL/TLS Client Identity form, ebe o tobetsa Khetha. File, khetha setifikeiti sa SMC-PXGRID.
Ho SMC GUI, ea ho Deploy > Cisco ISE Configuration.
Lokisa ISE Configuration ka liparamente tse latelang:
- Lebitso la Sehlopha: ISE-CLUSTER
- Setifikeiti: SMC-PXGRID
- PxGrid Node ea mantlha: 198.19.20.141
- Lebitso la Moreki: SMC-PXGRID
Tsamaea ho ea ho Hlahloba > Basebelisi.
Hlokomela hore re ka bona data ea mosebelisi ho SMC.
Melao ea ISE Adaptive Network Control (ANC).
Kgetha Dits'ebetso> Taolo e Ikamahanyang le Marang-rang> Lethathamo la Leano> Eketsa 'me u kenye SW_QUARANTINE bakeng sa Lebitso la Leano le Koranteng bakeng sa Ketso.
Fumana SMC GUI. Khetha aterese ea IP ho dashboard, re ka bona hore Leano la ISE ANC le na le batho ba bangata.
- Melao ea mokhelo ea tumello ea lefats'e e u thusa ho hlalosa melao e fetisang melao eohle ea tumello ho lihlopha tsohle tsa hau tsa pholisi. Hang ha u se u hlophisitse leano la mokhelo la tumello ea lefats'e, le eketsoa ho lihlopha tsohle tsa maano.
- Molao oa mokhelo oa tumello ea lehae o hlakola melaoana ea mokhelo lefatšeng ka bophara. Kahoo molao oa mokhelo oa lehae o sebetsoa pele, ebe molao oa mokhelo oa lefats'e, mme qetellong, molao o tloaelehileng oa leano la tumello.
- E 'ngoe ea linyeoe tsa tšebeliso e khahlisang ea Melao ena ea Exception ke ha u lokisa Cisco Secure Network Analytics (Stealth watch) le Cisco ISE bakeng sa Tsamaiso ea Likarabo u sebelisa Adaptive Network Policy (ANC) e le hore ha alamo e phahamisoa, Cisco Secure Network Analytics (Stealth watch) e tla kopa Cisco ISE ho arola moamoheli ka Leano la Adaptive Network Control ka Px Grid.
- Mokhoa o motle oa ho hlophisa Leano la tumello ho Cisco ISE ho behella moamoheli ka thoko ho Mokhethoa oa Lehae kapa Mokhelo oa Lefatše.
- Haeba u batla ho sebelisa Leano la ANC ho lisebelisoa tsohle tsa hau tsa pholisi, VPN, wired wireless aka VPN e nang le lithapo le basebelisi ba waelese. Sebelisa Mokhelo oa Lefatše.
- Haeba u batla ho sebelisa Leano la ANC feela ho basebelisi ba VPN kapa basebelisi ba Wired. Sebelisa Leano la Lehae ka hare ho Litlhophiso tsa Leano la VPN kapa Leano la Wired Policy ka ho latellana.
Ketso e Ikemetseng le Karabo le ANC
Boemo : Khamphani e sebelisa Cisco Umbrella e le seva sa DNS ho thibela litšokelo tsa inthanete. Re batla alamo e tloaelehileng e le hore ha basebelisi ba ka hare ba sebelisa li-server tse ling tsa DNS tsa ka ntle, ho hlahisoa alamo ho thibela ho hokahanya le li-server tsa DNS tse ka 'nang tsa lebisa sephethephethe libakeng tsa ka ntle bakeng sa merero e kotsi. Ha alamo e phahamisoa, Cisco Secure Network Analytics e tla kopa Cisco ISE ho behella moamoheli ea sebelisang li-server tsa DNS tse mabifi ka Leano la Taolo ea Adaptive Network ka PxGrid. Tsamaea ho ea ho Configure > Host Management. Sehlopheng se amohelang batsoali ka Inside Hosts, theha Sehlopha sa Host se bitsoang Corporate Networks bakeng sa marang-rang a hau a ka hare.
Sehlopheng sa batsoali ba amohelang Baeti ba Kantle, theha Sehlopha sa Host se bitsoang Umbrella DNS Servers bakeng sa liaterese tsa IP tsa Umbrella.
Basebelisi ba ka hare ba sebelisa Cisco Umbrella e le seva sa DNS ho thibela litšokelo tsa inthanete. Lokisa alamo e tloaelehileng e le hore ha basebelisi ba ka hare ba sebelisa li-server tse ling tsa DNS tsa ka ntle, ho hlahisoa alamo ho thibela ho hokahanya le seva sa DNS se ka 'nang sa lebisa sephethephethe libakeng tsa ka ntle bakeng sa merero e kotsi. Ha alamo e phahamisoa, Cisco Secure Network Analytics e tla kopa Cisco ISE ho behella moamoheli ea sebelisang li-server tsa DNS tse mabifi ka Leano la Taolo ea Adaptive Network ka PxGrid.
Tsamaisa ho Seta > Taolo ea Leano.
Theha Liketsahalo tse Tloaelehileng ka lintlha tse latelang:
- Lebitso : Sephethephethe sa DNS se sa lumelloeng
- Lihlopha tsa Baamoheli ba Sehlooho : Likhoebo tsa Marang-rang
- Lihlopha tsa Baamoheli ba Lithaka : Kantle ho Moamoheli Ntle le Li-server tsa Umbrella DNS
- Peer Port / Protocols : 53 / UDP 53 / TCP
Ha e le hantle ketsahalo ena e qala ha moamoheli leha e le ofe ea nang le Corporate Networks Host Group a buisana le moamoheli leha e le ofe ka hare ho Outside Hosts Host Group ntle le ba ka hare ho Umbrella DNS Servers Host Group, ka 53/UDP kapa 53/TCP, alamo e phahamisoa.
Tsamaea ho Seta > Taolo ea Likarabo. Tobetsa ho Liketso.
Khetha Ketso ea Leano la ISE ANC. Fana ka lebitso 'me u khethe sehlopha sa Cisco ISE se lokelang ho iteanya le bona ho sebelisa leano la ho arola batho ka thoko bakeng sa tlolo efe kapa efe kapa khokahano ho li-server tse sehloho.
Tlas'a karolo ea Melao. Etsa Molao o mocha. Molao ona o tla sebetsa Ketso ea pejana ha moamoheli leha e le ofe ka hare ho marang-rang a ka hare a leka ho romela sephethephethe sa DNS ho li-server tsa DNS tse kotsi. Karolong ena "Rule" e hlahisoa haeba, khetha Type, theolela tlase ebe u khetha ketsahalo e tloaelehileng e entsoeng pejana. Tlas'a Liketso Tse Amanang, khetha ketso ea ISE ANC e entsoeng pejana.
Ho tsoa ho moamoheli ea ka hare, bula khomphutha ea CMD. Phetha taelo ea nslookup, ebe taelo ea seva 8.8.8.8. Ngola liaterese tse 'maloa bakeng sa seva sa 8.8.8.8 DNS ho rarolla.
Eya ho Monitor > ISE ANC Policy Assignments. U lokela ho bona hore Cisco Secure Network Analytics e sebelisitse Leano la Taolo ea Adaptive Network ka PxGrid le ISE ho behella Moamoheli ka thoko.
LBH
P: Ke tlatsa Sesebelisoa sa Ho Seta Sesebelisoa (AST) joang karolong ka 'ngoe ea SNA?
A: Hang ha lisebelisoa tsa SNA li hlophisoa ka aterese ea IP ea tsamaiso, u ka tlatsa AST karolong e 'ngoe le e' ngoe ka ho latela litaelo tse tobileng tse fanoeng bakeng sa karolo eo ka har'a buka ea mosebedisi kapa tataiso ea ho seta.
Litokomane / Lisebelisoa
![]() |
Tšebeliso e sireletsehileng ea CISCO Network Analytics [pdf] Buka ea Taelo Tšireletso e Sireletsehileng ea Litlhaloso tsa Marang-rang, Tšebeliso ea Litlhaloso tsa Marang-rang, Tšebeliso ea Litlhaloso, Tšebeliso |