Perform the following steps to create a client profile:
Log into the NDR CLI using a terminal window or SSH client:
Using the SSH protocol, log into the appliance with management interface's IP address or hostname.
$ ssh npadmin@<NDR IP address>Enter the password when prompted. The
hostname > promptis displayed after you have logged in.
Enter privileged mode on the NDR CLI.
npadmin@hostname> enable
Enter the
npadminpassword, when prompted. The password can be 5 to 24 characters long.[sudo] password for npadmin: <password>
Enter configuration mode.
npadmin@hostname# configure system
The prompt changes to
npadmin@hostname(config)#on the terminal indicating that configuration mode is enabled. You can now proceed with the client profile configuration task.Type
client-profileat the terminal and pressEnter.The Client Profile configuration options are displayed on the terminal.
Note
You can configure up to 20 client profiles on an appliance using its CLI.
To add a new client profile, type
Ain theEnter your choice fieldand pressEnter. The Add new profile page is displayed with the configuration options.Type
1and pressEnterto create a name for the client profile. Enter the name of the profile in theEnter profile name fieldand pressEnter. The name given will now reflect in theNamesection.Type
2and pressEnterto setup filters related to L7 metadata that you want to be exported to the NDR by the sensors when the IA integration is enabled. Configure L7 metadata page is displayed on the terminal with the configuration options.L7 metadata configuration is disabled by default. Type
1and PressEnterto enable it. TheEnabledfield turns toTruewhen it is enabled.To enable or disable specific protocols, type
2and pressEnter. Enable/Disable event types configuration is displayed in 3 pages. All the protocols are disabled by default and showsNto reflect the disabled status. TypeNand pressEnterto go to the next page andPto go back to the previous page. The configuration options in all the 3 pages appear.To enable a specific protocol, type the numeric value assigned to that protocol and press
Enter. The status of the protocol changes toYto reflect the enabled mode. For example, you need to type6and PressEnterto enable HTTP protocol. Repeat the same procedure for all the protocols you wish to enable as per your network requirement.Type
Eand pressEnterif you wish to enable all the protocols in a page. To save and return to the Configure l7 metadata page, typeXand PressEnter. Or, typeCand press Enter to abort the changes made and return to the Configure l7 metadata page. As per the configuration options enabled, the Configure L7 metadata page shows the Enabled status and Event types count.To save and return to the Add new profile page, type
Xand pressEnter.
On Add new profile page, type
3and pressEnterto enable alerts based on alert severity thresholds. Configure alerts page is displayed.Filters specific to alert severity threshold is disabled by default. Type
1and pressEnterto enable the alert severity threshold configuration option. As a result, theEnabledstatus under the Configure alerts page changes toTrue.You can now enable alerts as per the alert severity thresholds (Low, Medium, and High). When an alert severity threshold is set, it denotes that alerts of that level and above would be exported to NDR. The alert Severity Threshold is set to Low by default. If you want to change it, type
2and pressEnter. Configure alert severity threshold page is displayed. To enable an alert severity threshold level, type the corresponding numeric value assigned to the specific severity threshold, and press Enter. For example, if you want to view only high severity alerts on NDR after its integration, type3and pressEnter.Once the alert severity threshold level is configured, you are redirected back to the Configure alerts page which shows the
Enabledstatus and the Severity Threshold.Press
Xand pressEnterto save the changes and return to the Add new profile page in the Client Profile configuration task.Add new profile page is displayed, which shows the name of the Client Profile, L7 metadata configuration status and protocol count, and alert configuration status and severity threshold as configured,
Type
Xand pressEnterto save the changes and finish the Client Profile configuration task. If you do not want to proceed with the Client Profile configuration changes, typeCand pressEnter. This will cancel all the configurations made and redirect you back to the Profile(s) page.