Description
Reruns the Configuration Wizard to change the factory default settings or the settings you specified during the initial configuration of the appliance or the Central Management System appliance.
Syntax
configuration jump-start
Parameters
None
Example
The following example reruns the Configuration Wizard. Respond to the configuration prompts as they appear (see table below).
hostname (config) # configuration jump-start
To change an answer while running the Wizard, press CTRL+C, and then enter the step number.
After all the questions are answered, the Wizard summarizes the answers. To change an answer, enter the step number. To save changes and exit, press Enter.
Step | Response |
|---|---|
Hostname? | Enter the hostname for the appliance. |
Admin password? | (Optional)Enter a new administrator password. The new password must be from 8–32 characters. If you do not change the password, the administrator will be unable to log in to the appliance. |
Confirm admin password? | Re-enter the new administrator password. |
Enable remote access for ‘admin’ user? | Enter yes to enable the administrator to log in to the appliance remotely. Enter no to disable remote access. |
Use zeroconf on ether1 interface? | Enter yes to use zero-configuration (zeroconf) networking. Enter no to specify a static IP address and network mask. (If you specify yes, the next step is skipped.) NOTE: Do not use zeroconf on the primary interface. |
Primary IP address and masklen? | Enter the IP address for the management interface in A.B.C.D format and enter the network mask, for example: 1.1.1.2/12. |
Default gateway? | Enter the gateway IP address for the management interface. |
Primary DNS server? | Enter the IP address of the DNS server. |
Enable IPv6 on management interface (ether1)? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Enable DHCPv6 on ether1 interface? | Enter yes to enable configuration. Enter no to disable configuration. The default setting is no. |
Primary IPv6 address and masklen (connection may be lost upon change)? | Enter the IPv6 address in X:X:X:X:X:X:X:X format and the prefix length. Example: 2001:db8::1/64. |
Primary DNS server? | Enter the IPv6 address in X:X:X:X:X:X:X:X format. Example: 2001:db8::1. |
Include HOMENET private IP range [10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16] ? | Enter yes to configure the following homenet IP range for Snort rules. For further configuration, use the CLI homenet command or Web UI. 10.0.0.0 - 10.255.255.255 (10/8 prefix) 172.16.0.0 - 172.31.255.255 (172.16/12 prefix) 192.168.0.0 - 192.168.255.255 (192.168/16 prefix) HOMENET is a default variable in the Snort rules (snort.conf) supported by the standard libpcap library where you can specify IP addresses that are to be protected. The Network Security appliance allows the configuration of the HOME_NET variable the CLI and WebUI. |
Domain name? | Enter the domain for the management interface; for example: it.acme.com. |
Activation code (Virtual appliances only) | Enter the activation code you obtained from FireEye. |
Enable Incident Response or Compromise Assessment? (Network Security only) | Enter yes to configure an Incident Response or Compromise Assessment deployment. (If you enter yes, the next four steps are performed automatically, and the "Enable NTP?" and "Enable IPv6?" steps are skipped.) |
Enable fenet service? | Enter yes to enable access to the DTI network. (If you enter no, the next three steps are skipped.) |
Enable fenet license update service? | Enter yes to enable the licensing service to automatically download your licenses from the DTI network and install them. (If licenses are downloaded and installed successfully, the wizard skips the step that prompts for the product license key and the step that prompts for the security-content updates key.) |
Sync appliance time with fenet? | Enter yes to synchronize the appliance time with the DTI server time. If you enabled the licensing service, synchronization prevents a feature from being temporarily unlicensed due to a time gap. The wizard makes three attempts to perform this step before it gives up and moves to the next step. |
Update licenses from fenet? | Enter yes to download and install your licenses. The wizard makes three attempts to perform this step before giving up and moving on to the next step. |
Enable NTP? | Enter yes to enable automatic time synchronization with one or more Network Time Protocol (NTP) servers. Enter no to manually set the time and date on the appliance. (This step is skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable Incident Response or Compromise Assessment?" step.) NOTE: Endpoint Security (HX) Series appliances: If you enter no, specify the time and date in Greenwich Mean Time (GMT). |
Enable FaaS VPN? | Enter yes to enable the appliance to connect to FireEye as a Service over the Internet using a secure SSL VPN connection. (This step is skipped if no MD_ACCESS license is installed. On Network Security appliances, this step is performed automatically if you entered yes in the "Enable Incident Response or Compromise Assessment?" step.) |
Set time(<hh>:<mm>:<ss>)? | Enter the appliance time. (This step and the next step are skipped if you entered yes in the "Sync appliance time with fenet?" or "Enable NTP?" step.) |
Set date (<yyyy>/<mm>/<dd>)? | Enter the appliance date. |
Enable IPv6? | Enter yes to enable IPv6 protocol, which changes network IP routing from IPv4 to IPv6. (This step and the next two steps are skipped if you entered yes in the "Enable Incident Response or Compromise Assessment?" step. This step and the next two steps will be automatically performed if you entered yes in the “Enable FaaS VPN” step.) NOTE: Do not enable IPv6 for HX Series appliances. HX Series appliances do not support IPv6. |
Enable IPv6 autoconfig (SLAAC) on ether1 interface? | Enter yes to enable IPv6 autoconfig on the ether1 (management interface) port. (This step is skipped if you entered no in the "Enable IPv6?" step.) IMPORTANT! Do not use SLAAC on the management interface on an Email Security — Server appliance. |
Enable DHCPv6 on ether1 interface? | Enter yes to use DHCPv6 to configure IPv6 hosts with IP addresses. (This step is skipped if you entered no in the "Enable DHCP?" or "Enable IPV6?" step.) |
Submission: Interface? (By default on MVX sensor-only appliances and Intelligent Virtual Execution - Server appliances. On integrated appliances after MVX sensor mode or MVX hybrid mode is enabled.) | Press Enter to accept ether1 as the interface through which sensors and brokers communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next three steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface such as ether2, and not a monitoring interface. NOTE: Ether2 is currently not supported as the submission interface on File Protect appliances. |
Submission: Use DHCP on <name> interface? | DHCP is not currently supported on the submission interface. Enter no to manually configure the address settings. |
Submission: IP address and masklen? | Enter the IP address for the submission interface in A.B.C.D format and enter the network mask, for example: 10.1.1.1 /24. |
Submission: Default Ipv4 gateway? | Enter the gateway IP address for the submission interface. |
Cluster: Interface? (Intelligent Virtual Execution - Server only) | Press Enter to accept ether1 as the interface through which brokers and compute nodes communicate. Otherwise, enter the name of the other interface. (If you accept ether1, the next two steps are skipped.) NOTE: To keep management and data traffic separate, Trellix recommends that you use another management interface such as ether2, and not a monitoring interface. |
Cluster: Use DHCP on <name> interface? | Enter yes to use DHCP to configure the cluster interface IP address. (If you enter yes, the next step is skipped.) |
Cluster: IP address and masklen? | Enter the IP address for the cluster interface in A.B.C.D format and enter the network mask, for example: 10.1.1.1 /24. |
Mirror traffic to a PX appliance? (Network Security only) | Enter yes to use port mirroring to forward Network Security traffic to the PX Series appliance in an Incident Response deployment. If you enter no, you must manually configure your PX Series appliance to receive the proper traffic. (This step is skipped if you entered no in the "Enable Incident Response or Compromise Assessment?" step.) IMPORTANT! : Trellix recommends using port mirroring in an Incident Response deployment. |
Interface pair to mirror traffic to PX? | Enter the Network Security interface pair or pairs whose traffic will be forwarded to the PX Series appliance. If multiple mirror ports are already configured, this skip and the next step are skipped. If a single mirror port is already configured for one or more pairs, that pair or pairs are provided as the default for this step. IMPORTANT! Trellix recommends using the default pair (A) if you are configuring a new appliance. Otherwise, manual configuration steps may be required. |
Interface to mirror traffic to PX? | Enter the Network Security port that will forward the traffic to the PX Series capture port. Do not specify a port that belongs to an interface pair you entered in the previous step. If a single mirror port is already configured, it is provided as the default for this step. IMPORTANT! Trellix recommends using the default port (pether6) if you are configuring a new appliance. Otherwise, manual configuration steps may be required. |
Enable forensic analysis? (Network Security only) | Enter yes to perform full packet capture and analysis on the mirrored traffic. |
IP address of PX (Network Security only) | Enter the IP address of the PX Series appliance. (This step is skipped if you entered no in the "Enable forensic analysis?" step.) |
Product license key? | Enter the product license key you obtained from Trellix, or press Enter to install a 15-day evaluation license. (This step and the next step are skipped if you entered yes in the "Enable fenet license update service?" step and if licenses were successfully installed as a result.) |
Security-content updates key? | Enter the security-content license key you obtained from Trellix, or press Enter to skip this step and install the license later. NOTE: A support license is also required and should be installed after you complete the configuration wizard. |
Configure CMS HA? (Central Management System only) | Enter yes to configure the Central Management System appliance in a high availability (HA) environment. (For the remaining HA configuration steps, see the Central Management System High Availability Guide.) |