FX SERIES / 2016 / FEI-003 / Revision 2
Preface
This guide provides an overview of the FireEye FX 8400 and describes how to install it.
This guide is intended for system administrators responsible for deploying, operating, and maintaining FireEye products, and for security and information technology (IT) managers and personnel interested in learning more about FireEye technologies.
This guide is intended for system administrators responsible for deploying, operating, and maintaining FireEye products, and for security and information technology (IT) managers and personnel interested in learning more about FireEye technologies.
The FX 8400

The FireEye FX 8400 analyzes network file shares to detect and quarantine malware that infiltrated the network via the Web, email, or manual means. It thwarts the lateral spread of advanced malware that traditional defenses miss.
The FX 8400 blocks malicious PDFs, MS Office, ZIP/RAR/TNEF, MP3, JPG, PNG, and other files from entering your network.
The Front View
The FX 8400 comes with a sleek removable bezel that can be removed to access the chassis.
Bezel

1) Power Button | 4) NIC Activity LED |
2) Power LED | 5) HDD LED |
3) System Health Indicator LED |
Button
Power: Use the power button to turn the appliance on or off. Turning off the power with this button removes the main power but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.
LEDs
The LEDs provide critical information about parts of the appliance. The following table describes each LED.
LED | Flashing | Steady | Off | Normal State |
|---|---|---|---|---|
Power | N/A | Green and steady indicates the appliance is receiving power | No power is supplied to the system | Green and steady |
System Health Indicator | Amber and flashing at 1 Hz indicates a fan failure | Green and steady indicates proper functioning | No power is supplied to the system | Green and steady |
NIC Activity | Flashing and green indicates activity via management 1 port and or management 2 port | N/A | No activity or no power is supplied to the system | Green and steady |
HDD | Degraded SAS/SATA drive connection | Green and steady indicates normal operation | No power is supplied to the system | Green and steady |
Chassis

1) LCD Panel Navigation Buttons | 2) Disk Drive Carrier |
LCD Panel Navigation: Use the navigation buttons to perform basic configurations of the appliance. See Configuring the Appliance via the LCD Panel for more information.
Disk Drive Carrier: Each carrier can house a hot-swappable disk drive. See Removing and Replacing an FX 8400 Disk Drive for more information.
The Rear View

1) Power Port | 6) Serial Console Port |
2) PS/2 Mouse Port | 7) Video Port |
3) PS/2 Keyboard Port | 8) ether1 (RJ45) Management 1 Port |
4) IPMI/Serial over Ethernet Port | 9) ether2/pether2 (RJ45) |
5) USB Ports |
Power Port
Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary unit fails. See Removing and Replacing an FX 8400 Power Supply Unit for more information.
I/O Ports
Mouse: Connect a mouse to this port to manage the appliance locally.
Keyboard: Connect a keyboard to this port to manage the appliance locally.
Video: Connect a monitor to this port to view the appliance's command-line interface.
USB: The port is USB 2.0 compliant.
Serial Console: Connect to this port to manage the appliance from your terminal.
Management Ports
ether (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.
IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 100BASE-T port.
Deployment
This chapter describes how to deploy the FX 8400 appliance in your network.
FX Series Deployment
The deployment of the FX 8400 requires a connection that provides remote access to the file share or shares in your network and that allows the appliance to mount a directory share in your file system. This connection can be practically anywhere in the network. The diagram below illustrates the deployment of an FX 8400 in a typical network topology.

Prerequisites
Before connecting the FX 8400 to your network, ensure that your network device provides 10/100/1000BASE-T Ethernet output.
Cabling
To connect your FX 8400 to your network:
Connect one end of an Ethernet cable to the ether1 or ether2 port.
Connect the other end of the cable to the network device.
Installation
This section provides information about the site requirements of your installation location.
Before You Begin
Follow the steps in this section before you install the appliance.
Before Opening the Box
Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.
Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.
If there appears to be damage to the box, file a damage claim with the carrier who delivered it.
Unpacking the Appliance
Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.
Ensure your box contains:
The correct appliance model
One set of rails
An accessory kit
The accessory kit contains:
(8) 10-32 cage nuts
(8) 10-32 Phillips screws
8 washers
Safety Guide
Online Documents Portal Referral
The cables listed in Cabling Requirements on the facing page.
Tools You'll Need
Phillips crosshead screwdriver
ESD wrist strap
Site Requirements
This section contains guidelines for the appropriate location of your rack unit and appliance and precautions.
Installation Site Guidelines
Follow these guidelines when you select an installation site:
Leave enough clearance in front of the rack for its door to open completely without obstruction.
Avoid environments that produce heat, electrical noise, and electromagnetic fields.
Only install the appliance in a Restricted Access Location such as a service closet or dedicated equipment room.
Make sure the location is properly ventilated.
Make sure there is sufficient space for air flow.
Rack Precautions
FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements, which call for a one-inch (2.54-cm) spacing.
Consider the following before installing your appliance in the rack:
Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.
In a single-rack installation, stabilizers should be attached to the rack.
In a multiple-rack installation, the racks should be coupled together to increase their stability.
Always make sure the rack is stable before extending a component from the rack.
Only extend one component from the rack at a time--extending two or more simultaneously may cause the rack to become unstable.
Ensure your rack meets the safety requirements of UL 60950-1.
Server Precautions
FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.
Review the following before installing the appliance in the rack:
Determine the placement of each component in the rack.
Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.
Install the heaviest component at the bottom of the rack first, then move up.
Allow hot-swappable power supply units and disk drives to cool before handling them.
Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.
Keep all of the rack's doors and panels closed when you are not servicing the components.
Rack-Mounting Precautions
Consider the following safety precautions when you install the appliance in the rack:
Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.
Use an electrostatic wrist guard when handling the appliance.
At least two technicians should be involved to install the appliance safely.
FireEye recommends only individuals with rack-mounting experience should install the appliance.
Install the appliance in an environment compatible with the manufacturer's maximum rated ambient temperature (Tmra) for each component in your rack.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the FX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.
The FX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.
Cabling Requirements
The FX 8400 ships with the following cables:
(2) 6 ft AC power cord, SVT, 60°C, 3x18AWG (0.824mm²)
(1) 6 ft null modem DB9 female serial cable
You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.
Power Requirements
The FX 8400 uses a 750 W power supply unit with an input rating of 100-240 VAC (±10%), 9-4.5 A at 50-60 Hz.
Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.
Rack Installation
This section explains how to install your appliance in a standard 19-inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your rack.
Installing the Inner Rails on the Appliance
Fully extend the right rail until all three rail segments are visible.

Push the rail-release arrow (located between the second and third extended rails) forward and continue sliding until it is separated from the other two rail segments.

Align the inner rail notches with the pegs on the right side of the appliance.
Slide the rail toward the pegs.

5. Insert the two screws to secure the inner rail to the appliance.

Installing the Outer Rails on the Rack
Press the black tabs of the right outer rail against the front rack column and insert the hooks at the desired height.

Firmly press the rail into the rack to lock it in place.

Extend the rail until it reaches the rear rack column and insert the rail using the same procedure described in the previous two steps.
Repeat steps 1-3 for the left outer rail.
Insert and tighten the screws at the rear of the rails to further secure them to the rack.
Mounting the Appliance on the Rack
Align the inner rails installed on the appliance with the channels of the outer rails installed on the rack.
Slide the appliance halfway into the rack.

3. Press the rail-release notches down on both rails and slide the appliance fully into the rack.

4. Tighten the thumbscrews located at the sides of the bezel to secure the appliance to the rack.

Attaching Cables to your Appliance
Connect the FX 8400 to one or more network devices using the appropriate cables specific to the deployment of your choice. See Deployment for more information.
Connect the power cables to the power ports on the back of the appliance.
Turning On the Appliance
Power on the appliance by pressing the power button on the bezel.
Baseline Configuration
This chapter contains information and instructions for performing the basic configuration of your appliance.
Network Information Requirements
Before you configure the appliance, collect the information about your network outlined in the following table.
Network Item | Information Needed |
|---|---|
FireEye Appliance |
|
Domain Name Service (DNS) | IP address of one or more DNS servers |
Network Time Protocol (NTP) Service (Optional) | IP address of one or more NTP servers |
Remote Management (Optional) | If you want to access the appliance's CLI remotely, the remote system must have an SSH client. |
CMS (Central Management System) (Optional) |
|
Configuring the Appliance via the LCD Panel
You can perform basic configuration of the appliance using the LCD panel navigation buttons on the front panel. To access the LCD panel navigation buttons, you must remove the bezel from the appliance.

FireEye recommends using the CLI to configure the appliance, if possible. For information about configuring the appliance via the CLI, see "Initial Configuration" in the System Administration Guide specific to your FireEye Series appliance and software release.
To remove the bezel from the appliance:
Turn the screw located on the left side of the bezel clockwise to unlatch it from the appliance.

2. Gently pull the bezel away from the appliance.

To reinstall the bezel, first align the tabs on right side with the ears of the appliance and then do the same with the left side. Some bezels will latch automatically when installed. For those that do not, turn the screw on the bezel counterclockwise.
LCD Panel Navigation Buttons
The table below describes the functions of each navigation button.
Navigation Button | Description |
|---|---|
| Press this button to enter a menu, setting prompt, or accept a change. |
| Press this button to increment a numeric value, change an alphabetical or special character, or change between "yes" and "no." |
| Press this button to decrement a numeric value, change an alphabetical or special character, or change between "yes" and "no." |
Navigation Button | Description |
|---|---|
| Press this button to move backward between menus, setting prompts, or characters in a sequence. |
| Press this button to move forward between menus, setting prompts, or characters in a sequence. |
| Press this button to exit from a menu or setting prompt. |
LCD Panel Menus
The LCD panel has four menus: Network, Config Options, LCD, and Restart Options. When the LCD panel is idle, press the center button to display the menu options. Use the arrows to cycle through the options and the center button to make a selection.
The following table provides information about the Network menu.
Additional prompts may be available depending on your software release.
Prompt | Description |
|---|---|
Hostname | Hostname for the appliance. |
DHCP enabled | Enter "yes" to use DHCP on the Ethernet 1 (management) port. Enter "no" to manually configure your IP address and network settings. |
IPv6 enabled | Enter "yes" to enable IPv6 protocol and to change the management network IP routing from IPv4 to IPv6. |
SLAAC enabled | The prompt is available if IPv6 is enabled. Enter "yes" to enable IPv6 autoconfig on the Ethernet 1 (management) port. |
Static IP address | This prompt is available if DHCP is disabled. Enter the IP address for the Ethernet 1 (management) port. |
Netmask | This prompt is available if DHCP is disabled. Enter the network mask. |
Default gateway | This prompt is available if DHCP is disabled. Enter the gateway IP address for the management interface. |
Hardware Administration GuideLCD Panel Menus
Prompt | Description |
|---|---|
Primary DNS | This prompt is available if DHCP is disabled. Enter the Primary DNS server IP address. |
Domain name | This prompt is available if DHCP is disabled. Enter the domain name for the management interface, for example, yourdomain.com. |
Admin net login | Enter "yes" to enable the administrator to log in to the appliance remotely. Enter "no" to disable remote access. |
MGD Defense VPN | Enter "yes" to enable Managed Defense VPN, allowing the Manage Defense service to properly integrate. Enabling this feature also automatically enables IP and IPv6 net filters. Disabling this feature afterward does not affect your IP and IPv6 net filter configurations. |
The following table provides information about the Config Options menu.
Prompt | Description |
|---|---|
Save settings | Saves changes made during this session so they will persist after a reboot. |
Revert to factory defaults | Reverts the appliance to its factory default settings, which include username, password, and network configuration information. |
Reset admin password | Resets the admin password for accessing the appliance itself. This does not set the password for accessing the LCD panel. |
The following table provides information about the LCD menu.
Prompt | Description |
|---|---|
Password | Sets a password for LCD-panel access. This does not set the password for accessing the appliance. |
Brightness | Sets the LCD panel's level of brightness from 0 to 9, with 9 being the brightest. |
Contrast | Sets the LCD panel's level of contrast between the background and text from 0 to 9, with 9 being the greatest contrast. |
The following table provides information about the Restart Options menu.
Prompt | Description |
|---|---|
Reboot System | Restarts the system. |
Prompt | Description |
|---|---|
Halt System | Puts the system in sleep mode. |
Next boot loc | Specifies disk partition (1 or 2) to boot from during the next reboot. |
Required Ports and Protocols
The table below outlines the main connections for the FX 8400 appliance’s communications. Open the ports listed below on your firewall to permit these connections.
Source | Destination | Destination Port | User Configurable | Notes |
|---|---|---|---|---|
FX 8400: Ether1* | cloud.fireeye.com | TCP 443 | Yes | Dynamic Threat Intelligence (DTI) Cloud Update Service |
Administrator Workstation | FX 8400: Ether1 | TCP 22 | No | CLI Management |
Administrator Workstation | FX 8400: Ether1 | TCP 443 | No | Web UI Management |
FX 8400: Ether1 | SMTP Relay | TCP 25 | No | SMTP Alerts |
FX 8400: Ether1 | Internal DNS Servers | TCP/UDP 53 | No | DNS Queries |
FX 8400: Ether1 | NTP Servers | UDP 123 | No | NTP |
FX 8400: Ether1 | SIEM/Syslog Server | UDP 514 | No | Syslog |
FX 8400: Ether1 | SNMP Server | UDP 162 | No | SNMP |
CM-Managed FX 8400: Ether1** | CM Ether1 | TCP 22 | No | CM Management Connection |
Remote Console | FX 8400 IPMI | TCP 3520 | No | Remote Console Redirection |
Source | Destination | Destination Port | User | Notes |
|---|---|---|---|---|
* This is the default destination and port for stand-alone appliances and the CM Series platform. For a CM Series platform or standalone NX Series appliance running Release 7.5.0 or later, or a standalone EX Series appliance running Release 7.6.0 or later, the DTI source server can be either cloud.fireeye.com or staticcloud.fireeye.com. For a managed NX Series or EX Series appliance running these releases, the default DTI source server is the CM Series platform, but it can be either of the two servers mentioned above instead. ** For a managed appliance running Release 7.6.0 or later that uses the CM Series platform as its DTI source server, single-port communication is the default behavior. This means CM Ether1 port (TCP 22) is used for both DTI traffic and management traffic, unless otherwise configured. For details, see the CM Series Administration Guide or the System Administration Guide for your appliance. | ||||
For information about CM Series High Availability (HA) ports, see the CM Series High Availability (HA) Deployment Guide.
Replacements
This chapter contains instructions for replacing your appliance, with or without disk drives, and removing and replacing individual failed disk drives and power supplies. The disk drives and power supplies are hot-swappable, meaning they can be removed and replaced without unracking the appliance or powering it off.
Return Process
If you believe you have a defective part, you must first contact FireEye Technical Support, who will validate whether or not the part is defective. If the part is defective, Technical Support will initiate a Return Materials Authorization (RMA). No part can be returned without a FireEye-issued RMA number.
After receiving the replacement part from FireEye, please package and return the defective part within five (5) days, at FireEye's cost (provided that you utilize FireEye's designated courier service). If you fail to return the defective part within ten (10) business days after receiving the replacement, FireEye may invoice you as detailed in our Support Terms and Conditions, described here: http://www.fireeye.com/support/terms-and-conditions.html.
In the case of a defective disk drive or a defective system with disk drives, you may retain the disk drive(s) if you have purchased the Non-Returnable Disk Drive support option. Follow these instructions:
To return a defective part or system:
Pack the defective part or the entire appliance in the packaging that the replacement part was received in, or in its original packaging material (or equivalent).
Place a copy of the associated RMA Form (example shown below) inside the package. If you have more than one package, place a copy inside each package.
Write the associated RMA number on the outside of each return package and in the reference field on each waybill. Returns cannot be processed without referencing the associated RMA number.
Do not insure the shipment. FireEye is self-insured. Please declare "$0" in the "value for carrier" section.
Send an email to RMA_Ops@fireeye.com listing the RMA number(s), the carrier name, and the carrier tracking number(s) for the return package.
If you do not have a return shipping label, contact FireEye operations at RMA_Ops@fireeye.com and they will provide one for your return.
All international shipments require three copies of a commercial invoice (CI). FireEye provides a partially completed CI. Please either use this CI, after completing the remaining required information, or create your own if you prefer. Please contact your distribution partner who can assist you. If you require additional assistance, please contact RMA_Ops@fireeye.com.
Send the package directly to the location specified in the "SHIP TO" section on the RMA Form (example shown below) provided in the replacement part package.
For questions regarding an RMA return or status, please email: RMA_Ops@fireeye.com or call +1-408-321-7798.
Enclosed with your replacement part, you will receive a FireEye RMA Form similar to the following:

Replacing an Appliance Including Disk Drives
Before replacing your FX 8400, take a backup of the current system, if possible. FireEye recommends that regular, full system backups are taken. For more information, see Backing Up and Restoring the Appliance Database on the next page. If you cannot back up the appliance, make sure your latest system backup is available. Contact FireEye Technical Support if you have questions on backing up your appliance.
To replace an appliance including the disk drives:
Perform an orderly shutdown of the defective appliance.
Unplug the appliance.

Keep the power cord and cables for your replacement appliance.
Unrack the defective appliance and rack-mount and re-cable the replacement appliance.
Power on the replacement appliance.
Configure the appliance as described in “Initial Configuration” of the System Administration Guide specific to your FireEye Series appliance and software release.
Using a console connection, restore the appliance's configuration and database as described in Backing Up and Restoring the Appliance Database on the next page.
Install replacement licenses as described in Applying License Keys.
Set the DTI credentials as described in “Configuring DTI Credentials” in the System Administration Guide or Administration Guide specific to your FireEye Series appliance and software release.
Replacing an Appliance Excluding Disk Drives
Before replacing an appliance, take a backup of the current system, if possible. FireEye recommends that regular, full system backups are taken. If you cannot back up the appliance, make sure your latest system backup is available. For more information, see Backing Up and Restoring the Appliance Database on the next page Contact FireEye Technical Support if you have questions on backing up your appliance.
To replace an appliance without replacing the disk drives:
Perform an orderly shutdown of the defective appliance.
Remove the disk drives and insert them into the replacement appliance as described in Removing and Replacing an FX 8400 Disk Drive .
Unplug the appliance.
Be sure to keep the power cord and cables for your replacement appliance.
Unrack the defective appliance.
Rack-mount the replacement appliance as described in Rack Installation.
Cable the appliance as described in Attaching Cables to your Appliance.
Plug in a VGA monitor and USB keyboard.
Power on the replacement appliance and watch the boot up process on the connected monitor.
When a foreign configuration is detected, press F to import the saved configuration from the previous system.
Configure the appliance via the LCD panel or console as described in Configuring the Appliance via the LCD Panel or "Initial Configuration" in the System Administration Guide specific to your FireEye Series appliance and software release.
Install replacement licenses as described in Applying License Keys.
Set the DTI Credentials as described in “Configuring DTI Credentials” in the System Administration Guide or Administration Guide specific to your FireEye Series appliance and software release.
Backing Up and Restoring the Appliance Database
Before replacing your FX 8400 appliance, take a backup of the current system so you can later restore it on the replacement.
Backing Up and Restoring the Database Using Release 7.4 and Earlier
Backing Up the Appliance Configuration
To back up an appliance configuration file:
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalSave the appliance configuration to a file:
FX8400 (config) # configuration write to filenameUpload the saved configuration file to a file server:
FX8400 (config) # configuration upload filename-urlVerify that the configuration file is on the file server.
FX8400 (config) # show configuration files
The following example backs up the configuration file to a file named config_backup.
FX8400 (config) # configuration write to config_backup
FX8400 (config) # show configuration files
config_backup (active)
initial
initial.bak
Active configuration: config_backup
Unsaved changes: no
FX8400 (config) # configuration upload config_backup ?
<FTP/TFTP URL or scp://username[:password]@hostname/path/filename> ftp, tftp,
scp and sftp are supported. e.g. scp://username
[:password]@hostname/path/filename
FX8400 (config) # configuration upload config_backup
scp://username@backuphost/path/config_backup
Password (if required): ********Backing Up the Appliance Database
Follow these steps to back up the appliance database using the CLI.
To back up the appliance’s database using the CLI:

Be sure to back up in binary format, not ASCII, for FTP restores.
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalSave a backup of the appliance database to a file.
FX 8400 (config) # fedb backup to-file filenameUpload the database backup file to a file server.
FX 8400 (config) # fedb backup upload filename-urlVerify that the backup file is on the file server.
FX 8400 (config) # show fedb backups

Videos, binaries, and PCAPS are not backed up during this process. Contact FireEye Technical Support for more information.
The following example backs up the database file to a file named db_backup.
FX 8400 (config) # fedb backup to-file db_backup
Dumping database to backup file
Encrypting backup file
Created database backup file db_backup
FX 8400 (config) # show fedb backups
Created At Size Backup File
2014/04/15 03:00:00 50.0M db_backup
1 backup file available!
FX 8400 (config) # fedb backup upload db_backup
scp://username@backuphost/path/db_backup
Password (if required): ********Restoring the Appliance Configuration
Be sure to make a copy of the current configuration before restoring an older configuration.
To restore a configuration file:
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalFetch the saved configuration file from the file server.
FX 8400 (config) # configuration fetch url filenameActivate the saved configuration file.
FX 8400 (config) # configuration switch-to filename
The following example restores the configuration file named config_backup.
FX 8400 (config) # configuration fetch ?
<download URL> http, https, ftp, tftp, scp and sftp are supported. e.g.
scp://username[:password]@hostname/path/filename
FX 8400 (config) # configuration fetch scp://username@backuphost/path/config_backup
Password (if required): ********
FX 8400 (config) # show configuration files
config_backup
initial (active)
initial.bak
Active configuration: initial
Unsaved changes: yes
FX 8400 (config) # configuration switch-to config_backupRestoring the Appliance Database
Follow these steps to restore the appliance database using the CLI.
To restore the database using the CLI:
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalFetch the database backup file from the file server.
FX 8400(config) # fedb backup fetch filenameRestore the database backup.
FX 8400 (config) # fedb restore from-file filenameReload the appliance.
FX 8400 (config) # reload
The following example restores the database file named db_backup.
FX 8400 (config) # fedb backup fetch ?
<HTTP/FTP/TFTP URL or scp://username:password@hostname/path/filename>
FX 8400 (config) # febd fetch scp://username@backuphost/path/db_backup
Password (if required): ******** FX 8400 (config) # show fedb backups
Created At Size Backup File
2014/04/01 03:00:00 50.0M db_backup
1 backup files available!
FX 8400 (config) # fedb restore from-file db_backup Decrypting backup file
Restore backup file into database
Backupis from supported database version 9.1
Restored database backup file db_backup
Restarting Database clients ... done!
Appliance reload is recommended to ensure best results after a database restore.
FX 8400 (config) # reload
Configuration has been modified; save first? [yes]
Configuration changes saved.
Rebooting...Backing Up and Restoring the Appliance Database Using Release 7.5 and Later
Backing Up the Database
Follow these steps to back up the appliance database using the CLI.
To back up the appliance database:
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalSpecify the type of profile.
To set the profile for the configuration database, enter:
FX 8400 (config) # backup profile configTo set the profile for the FireEye appliance database, enter:
FX 8400 (config) # backup profile fedbTo set the profile for both the configuration database and the FireEye appliance database, enter:
FX 8400 (config) # backup profile config+fedbTo set the profile for the configuration database, FireEye appliance database, and detected data (malware, alerts, reports, and so on), enter:
FX 8400 (config) # backup profile full
Specify the location for the backup file.
To save the backup file to a local destination on the appliance, enter:
FX 8400 (config) # backup profile profile to localTo save the backup file on a remote server, enter:
FX 8400 (config) # backup profile profile to urlwhere url is the specified remote location using the following format:
scp://username:password@hostname/remote path
To save the backup file to a USB drive on your local machine, enter:
FX 8400 (config) # backup profile profile to usb
Specify the prefix for the backup file name.
FX 8400 (config) # backup profile profile to backup_location prefix prefixYou can use the customized prefix to sort the list of the backup files.
(Optional) Monitor the progress of the backup operation.
To disable progress tracking for the backup operation, enter:
FX 8400 (config) # backup profile profile to backup_location progress no-trackTo enable progress tracking for the backup operation, enter:
FX 8400 (config) # backup profile profile to backup_location progress track
By default, progress tracking is enabled.
You can cancel progress tracking by using Ctrl+C. The backup operation still happens in the background. Use the show backup status command to find the status of the backup operation.
(Optional) Disable public and private key encryption for the backup operation.
FX 8400 (config) # backup profile profile to backup_location no-encryption
Note: Each backup file is signed by default using the public and private key pairs. By default, encryption is always included in the backup.
Note: Encryption delays the backup operation. Backups are encrypted only using static keys.
To cancel a backup that is in progress, enter the backup cancel command. When you cancel the backup operation that is in progress, the system finishes the current step before canceling the entire operation.
The following example backs up the configuration database, detected data, and artifacts to a local destination on the appliance:
FX 8400 (config) # backup profile full to local
Step 1 of 4: Backing up config db
100.0% [#############################################]
Step 2 of 4: Backing up fedb
100.0% [#############################################]
Step 3 of 4: Backing up Artifacts
100.0% [#############################################]
Step 4 of 4: Generating Backup package
100.0% [#############################################]Restoring the Appliance Database
Follow these steps to restore the appliance database from a backup file using the CLI.
To restore the appliance database from a backup file:
Enable the CLI configuration mode.
FX 8400 > enable FX 8400 # configure terminalLocate the backup FEBKP file you want to restore.
To display a list of the backup files on the USB drive, enter:
FX 8400 (config) # show backup available on-usbTo display a list of the backup files on the appliance, enter:
FX 8400 (config) # show backup available local
Specify a backup profile.
To set the profile for the configuration database, enter:
FX 8400 (config) # restore profile configTo set the profile for the FireEye appliance database, enter:
FX 8400 (config) # restore profile fedbTo set the profile for both the configuration database and the FireEye appliance database, enter:
FX 8400 (config) # restore profile config+fedbTo set the profile for the configuration database, FireEye appliance database, and detected data (malware, alerts, reports, and so on), enter:
FX 8400 (config) # restore profile full
Specify the location of the backup file.
To restore the backup from the local destination on the appliance, enter:
FX 8400 (config) # restore profile profile from localTo restore the backup from a remote server, enter:
FX 8400 (config) # restore profile profile from urlwhere url is the specified remote location using the following format:
https or scp://username:password@hostname/remote path
To restore the backup from a USB drive on your local machine, enter:
FX 8400 (config) # restore profile profile from usb
Enter the name of the backup file.
FX 8400 (config) # restore profile profile from backup location backup name(Optional) Restore the network settings from the relevant backup.
FX 8400 (config) # restore profile profile from backup location backup name include-network-configBy default, the network settings are not included in the restore operation.

Do not restore the current network settings while the appliance is performing a restore operation from a remote server.
(Optional) Monitor the progress of the restore operation.
To disable progress tracking for the restore operation, enter:
FX 8400 (config) # restore profile profile from backup location backup name progress no-trackTo enable progress tracking for the restore operation, enter:
FX 8400 (config) # restore profile profile from backup location backup name progress track
By default, progress tracking is enabled.
You can cancel progress tracking by using Ctrl+C. The restore operation still happens in the background. Use the show restore status command to find the status of the restore operation.
The following example shows how to restore a configuration database backup from your local appliance:
FX 8400 (config) # restore profile config from local backup wMPS-Config-7.5.0-sulabh-wmps-20141118-133123.febkp
Step 1 of 3: Performing Sanity checks
100.0% [##################################################]
Step 2 of 3: Extracting backup package
100.0% [##################################################]
Step 3 of 3: Restoring config db
100.0% [##################################################]Applying License Keys
After you replace an appliance, you must apply replacement license keys.
To apply a license key from the CLI:
Enable the CLI configuration mode.
FX8400 > enable FX8400 # configure terminalEnter the license key.
FX 8400 (config) # license install <license-key>Repeat step 2 for each additional license key you need to apply.
Identifying the Failed Disk Drive
Before removing and replacing the failed disk drive from your appliance, you must first identify the slot in which it resides.
To identify the slot of failed disk drive for appliances running a release prior to the FX Series 7.2 release, contact Customer Support.
To identify the slot number of a failed drive from the CLI:
Enable configuration mode.
FX 8400 > enable FX 8400 # configure terminalEnter the show media disk command.
3. Note the slot number of the failed drive. View the sample output below for reference.
Disk - 0
Model: TOSHIBA AL13SEB600 0101X320A01NFTR8
Serial: 500003951800CEAD
Firmware Version: 0101
Size: 558.911 GB
Status: Failed
SMART Flag: No
Rebuild Status: Device(Encl-252 Slot-0) is not in rebuild process
Disk - 1
Model: TOSHIBA AL13SEB600 0101X320A022FTR8
Serial: 500003951800CEE9
Firmware Version: 0101
Size: 558.911 GB
Status: Online
SMART Flag: No
Rebuild Status: Device(Encl-252 Slot-1) is not in rebuild process4. Proceed to the following section for instructions on removing and replacing the disk drive within the specified slot number.
Removing and Replacing an FX 8400 Disk Drive
Perform the following steps to remove and replace a disk drive:
Turn the screw located on the left side of the bezel clockwise to unlatch it from the appliance.

2. Gently remove the bezel from the appliance to reveal the disk drives.

3. Locate the disk drive carrier that contains the failed disk drive.

4. Push the navy blue button to release the latch handle.

Carefully pull the latch handle forward.
Pull the handle to slide the disk drive from its slot.

Use the latch handle on the new drive carrier to slide the new drive into the empty slot. When the drive is fully inserted into the slot, push the latch handle down until it clicks.
To verify the RAID functionality of the replacement drive:
Enable configuration mode.
FX 8400 > enable FX 8400 # configure terminalEnter the show system hardware status raid command.
Verify that the disk status of the replaced drive is “Online.”
Removing and Replacing an FX 8400 Power Supply Unit
Perform the following steps to remove and replace a power supply unit (PSU):
At the rear of the appliance, remove the power cable from the failed PSU.
Press the green release toward the black handle in a pinching gesture to unlatch the unit and, while continuing to squeeze, pull out the PSU.

Insert the replacement PSU in the slot and slide it in until it clicks into place.
Appendices
Appendix 1: System Specifications
The table below provides the technical specifications of the FireEye FX 8400.
Component | FX 8400 Specifications |
|---|---|
Form Factor | 2U Rack-Mount |
Weight of Appliance | 42 lbs (19 kg) |
Weight of Packaged Appliance | 57 lbs (26 kg) |
Dimensions | 17.2 x 28.0 x 3.41 inches |
Enclosure | 2 RU, Fits 19-inch Rack |
Management Interfaces | (2) 10/100/1000BASE-T Ports |
Drive Capacity | (2) 600 GB HDD, RAID 1, 2.5 inch, FRU |
AC Power Supply | Redundant (1+1), FRU, |
Maximum Power Consumption | 506 W |
Operating Temperature | 10° to 35° C |
Maximum Thermal Dissipation | 1726 BTU/hour |
Appendix 2: Product Compliance Information
The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the FireEye FX Series appliances.
FX | EMC (2004/108/EC) | LVD/Safety (2006/95/EC) | Other |
|---|---|---|---|
5400 8400 | EN 55022: 2010 + A1: 2011 EN 55024: 2010 EN 61000-3-2: 2006 + A1: 2009 + A2: 2009 EN 61000-3-3: 2008 | EN 60950-1: 2006 + A11: 2009 + A1: 2010 + A12: 2011 | RoHS REACH WEEE IEC60320-C14 inlet |




