FX 8400 Hardware Administration Guide

Prev Next

FX SERIES / 2016 / FEI-003 / Revision 2

Preface

This guide provides an overview of the FireEye FX 8400 and describes how to install it.

This guide is intended for system administrators responsible for deploying, operating, and maintaining FireEye products, and for security and information technology (IT) managers and personnel interested in learning more about FireEye technologies.  

This guide is intended for system administrators responsible for deploying, operating, and maintaining FireEye products, and for security and information technology (IT) managers and personnel interested in learning more about FireEye technologies.

The FX 8400

Front view photo of a FireEye FX 8400 rack-mounted appliance with a removable bezel, blue status display, and metallic chassis.

The FireEye FX 8400 analyzes network file shares to detect and quarantine malware that infiltrated the network via the Web, email, or manual means. It thwarts the lateral spread of advanced malware that traditional defenses miss.

The FX 8400 blocks malicious PDFs, MS Office, ZIP/RAR/TNEF, MP3, JPG, PNG, and other files from entering your network.

The Front View

The FX 8400 comes with a sleek removable bezel that can be removed to access the chassis.

Bezel

Front bezel of FireEye FX 8400 appliance showing a silver front panel with a blue display and five small red-numbered indicator callouts labeled 1 through 5 near the upper center

1) Power Button

4) NIC Activity LED

2) Power LED

5) HDD LED

3) System Health Indicator LED

Button

  • Power: Use the power button to turn the appliance on or off. Turning off the power with this button removes the main power but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.

LEDs

The LEDs provide critical information about parts of the appliance. The following table describes each LED.

LED

Flashing

Steady

Off

Normal State

Power

N/A

Green and steady indicates the appliance is receiving power

No power is supplied to the system

Green and steady

System Health Indicator

Amber and flashing at 1 Hz indicates a fan failure
Amber and flashing at 0.25 Hz indicates a power supply failure

Green and steady indicates proper functioning
Amber and steady along with a beeping buzzer indicates a power supply, fan, or overheat failure, which may be caused by cables obstructing the airflow in the appliance or the ambient room temperature being too high

No power is supplied to the system

Green and steady

NIC Activity

Flashing and green indicates activity via management 1 port and or management 2 port

N/A

No activity or no power is supplied to the system

Green and steady

HDD

Degraded SAS/SATA drive connection

Green and steady indicates normal operation

No power is supplied to the system

Green and steady

Chassis

Front view of the appliance chassis showing LCD panel, control buttons, and multiple drive bays numbered with red markers.

1) LCD Panel Navigation Buttons

2) Disk Drive Carrier

  • LCD Panel Navigation: Use the navigation buttons to perform basic configurations of the appliance. See Configuring the Appliance via the LCD Panel for more information.

  • Disk Drive Carrier: Each carrier can house a hot-swappable disk drive. See Removing and Replacing an FX 8400 Disk Drive for more information.

The Rear View

Rear view of the appliance showing power supplies, ports, and numbered connector locations highlighted with red markers.


1) Power Port

6) Serial Console Port

2) PS/2 Mouse Port

7) Video Port

3) PS/2 Keyboard Port

8) ether1 (RJ45) Management 1 Port

4) IPMI/Serial over Ethernet Port

9) ether2/pether2 (RJ45)

5) USB Ports

Power Port

I/O Ports

  • Mouse: Connect a mouse to this port to manage the appliance locally.

  • Keyboard: Connect a keyboard to this port to manage the appliance locally.

  • Video: Connect a monitor to this port to view the appliance's command-line interface.

  • USB: The port is USB 2.0 compliant.

  • Serial Console: Connect to this port to manage the appliance from your terminal.

Management Ports

  • ether (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.

  • IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 100BASE-T port.

Deployment

This chapter describes how to deploy the FX 8400 appliance in your network.

FX Series Deployment

The deployment of the FX 8400 requires a connection that provides remote access to the file share or shares in your network and that allows the appliance to mount a directory share in your file system. This connection can be practically anywhere in the network. The diagram below illustrates the deployment of an FX 8400 in a typical network topology.

Network topology diagram showing Internet cloud to Edge Router, firewall, Core Switch, LAN (with file server and multiple workstations), and an FX Series appliance connected to the LAN inside a dashed deployment boundary.

Prerequisites

Before connecting the FX 8400 to your network, ensure that your network device provides 10/100/1000BASE-T Ethernet output.

Cabling

To connect your FX 8400 to your network:

  1. Connect one end of an Ethernet cable to the ether1 or ether2 port.

  2. Connect the other end of the cable to the network device.

Installation

This section provides information about the site requirements of your installation location.

Before You Begin

Follow the steps in this section before you install the appliance.

Before Opening the Box

  • Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.

  • Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.

  • If there appears to be damage to the box, file a damage claim with the carrier who delivered it.

Unpacking the Appliance

Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.

Ensure your box contains:

  • The correct appliance model

  • One set of rails

  • An accessory kit

The accessory kit contains:

  • (8) 10-32 cage nuts

  • (8) 10-32 Phillips screws

  • 8 washers

  • Safety Guide

  • Online Documents Portal Referral

  • The cables listed in Cabling Requirements on the facing page.

Tools You'll Need

  • Phillips crosshead screwdriver

  • ESD wrist strap

Site Requirements

This section contains guidelines for the appropriate location of your rack unit and appliance and precautions.

Installation Site Guidelines

Follow these guidelines when you select an installation site:

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a Restricted Access Location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.

  • Make sure there is sufficient space for air flow.

Rack Precautions

FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements, which call for a one-inch (2.54-cm) spacing.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time--extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

Server Precautions

FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

  • Allow hot-swappable power supply units and disk drives to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • FireEye recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum rated ambient temperature (Tmra) for each component in your rack.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the FX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

The FX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Cabling Requirements

The FX 8400 ships with the following cables:

  • (2) 6 ft AC power cord, SVT, 60°C, 3x18AWG (0.824mm²)

  • (1) 6 ft null modem DB9 female serial cable

You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Power Requirements

The FX 8400 uses a 750 W power supply unit with an input rating of 100-240 VAC (±10%), 9-4.5 A at 50-60 Hz.

Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.

Rack Installation

This section explains how to install your appliance in a standard 19-inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your rack.

Installing the Inner Rails on the Appliance

  1. Fully extend the right rail until all three rail segments are visible.

Metal inner slide rail for a 19-inch rack with a large red arrow pointing to the rail-release arrow located between the second and third extended rail segments

  1. Push the rail-release arrow (located between the second and third extended rails) forward and continue sliding until it is separated from the other two rail segments.

A hand holding the inner rail with a large red arrow pointing to the right, indicating the rail notch alignment.

  1. Align the inner rail notches with the pegs on the right side of the appliance.

  2. Slide the rail toward the pegs.

Close-up of the appliance outer rail with a large red arrow pointing to a peg on the right side, showing where the rail engages the peg.

5. Insert the two screws to secure the inner rail to the appliance.

Close-up of a screwdriver inserting a screw into the inner rail of a metal appliance; a red curved arrow indicates the clockwise turning motion.

Installing the Outer Rails on the Rack

  1. Press the black tabs of the right outer rail against the front rack column and insert the hooks at the desired height.

Vertical close-up photograph of a rack column showing numbered rack units (25, 24, 23) and the outer rail hooks engaged with the column.


  1. Firmly press the rail into the rack to lock it in place.

    Close-up photo of a server rack rail showing numbered rack unit markings (23–25) and a metal rail locking clip.

  2. Extend the rail until it reaches the rear rack column and insert the rail using the same procedure described in the previous two steps.

  3. Repeat steps 1-3 for the left outer rail.

  4. Insert and tighten the screws at the rear of the rails to further secure them to the rack.

Mounting the Appliance on the Rack

  1. Align the inner rails installed on the appliance with the channels of the outer rails installed on the rack.

  2. Slide the appliance halfway into the rack.

Close-up of rack rail and appliance rail-release latch with a red arrow pointing to the latch

3. Press the rail-release notches down on both rails and slide the appliance fully into the rack.

Appliance on rack rails with a large red arrow indicating the sliding direction; circular inset zoom showing the rail-release notch

4. Tighten the thumbscrews located at the sides of the bezel to secure the appliance to the rack.

Close-up of a rack-mounted appliance front panel labeled NX 4400 showing a screw and a large red curved arrow indicating to turn the screw clockwise

Attaching Cables to your Appliance

  1. Connect the FX 8400 to one or more network devices using the appropriate cables specific to the deployment of your choice. See Deployment for more information.

  2. Connect the power cables to the power ports on the back of the appliance.

Turning On the Appliance

Power on the appliance by pressing the power button on the bezel.

Baseline Configuration

This chapter contains information and instructions for performing the basic configuration of your appliance.

Network Information Requirements

Before you configure the appliance, collect the information about your network outlined in the following table.

Network Item

Information Needed

FireEye Appliance

  • IP address

  • Subnet mask

  • Default Gateway address

Domain Name Service (DNS)

IP address of one or more DNS servers

Network Time Protocol (NTP) Service (Optional)

IP address of one or more NTP servers

Remote Management (Optional)

If you want to access the appliance's CLI remotely, the remote system must have an SSH client.

CMS (Central Management System) (Optional)

  • Static IP address

  • Subnet mask

Configuring the Appliance via the LCD Panel

You can perform basic configuration of the appliance using the LCD panel navigation buttons on the front panel. To access the LCD panel navigation buttons, you must remove the bezel from the appliance.

Small blue circular clipboard icon

FireEye recommends using the CLI to configure the appliance, if possible. For information about configuring the appliance via the CLI, see "Initial Configuration" in the System Administration Guide specific to your FireEye Series appliance and software release.

To remove the bezel from the appliance:

  1. Turn the screw located on the left side of the bezel clockwise to unlatch it from the appliance.

Front-left view of a FireEye appliance bezel with a screwdriver inserted, showing the screw being turned clockwise to unlatch the bezel


2. Gently pull the bezel away from the appliance.

Server front bezel being pulled away from the appliance showing a black front panel with a blue display and a red curved arrow indicating the removal direction

To reinstall the bezel, first align the tabs on right side with the ears of the appliance and then do the same with the left side. Some bezels will latch automatically when installed. For those that do not, turn the screw on the bezel counterclockwise.

LCD Panel Navigation Buttons

The table below describes the functions of each navigation button.

Navigation Button

Description

Square black button icon used to enter menus            

Press this button to enter a menu, setting prompt, or accept a change.            

Up arrow black triangular button icon            

Press this button to increment a numeric value, change an alphabetical or special character, or change between "yes" and "no."            

Down arrow black triangular button icon            

Press this button to decrement a numeric value, change an alphabetical or special character, or change between "yes" and "no."            


Navigation Button

Description

Black rectangular navigation button with left-pointing triangle

Press this button to move backward between menus, setting prompts, or characters in a sequence.

Black rectangular navigation button with right-pointing triangle

Press this button to move forward between menus, setting prompts, or characters in a sequence.

Black square navigation button with an X icon

Press this button to exit from a menu or setting prompt.

LCD Panel Menus

The LCD panel has four menus: Network, Config Options, LCD, and Restart Options. When the LCD panel is idle, press the center button to display the menu options. Use the arrows to cycle through the options and the center button to make a selection.

The following table provides information about the Network menu.

Blue circular information icon Additional prompts may be available depending on your software release.

Prompt

Description

Hostname

Hostname for the appliance.

DHCP enabled

Enter "yes" to use DHCP on the Ethernet 1 (management) port. Enter "no" to manually configure your IP address and network settings.

IPv6 enabled

Enter "yes" to enable IPv6 protocol and to change the management network IP routing from IPv4 to IPv6.

SLAAC enabled

The prompt is available if IPv6 is enabled. Enter "yes" to enable IPv6 autoconfig on the Ethernet 1 (management) port.

Static IP address

This prompt is available if DHCP is disabled. Enter the IP address for the Ethernet 1 (management) port.

Netmask

This prompt is available if DHCP is disabled. Enter the network mask.

Default gateway

This prompt is available if DHCP is disabled. Enter the gateway IP address for the management interface.

Hardware Administration GuideLCD Panel Menus

Prompt

Description

Primary DNS

This prompt is available if DHCP is disabled. Enter the Primary DNS server IP address.

Domain name

This prompt is available if DHCP is disabled. Enter the domain name for the management interface, for example, yourdomain.com.

Admin net login

Enter "yes" to enable the administrator to log in to the appliance remotely. Enter "no" to disable remote access.

MGD Defense VPN

Enter "yes" to enable Managed Defense VPN, allowing the Manage Defense service to properly integrate. Enabling this feature also automatically enables IP and IPv6 net filters. Disabling this feature afterward does not affect your IP and IPv6 net filter configurations.

The following table provides information about the Config Options menu.

Prompt

Description

Save settings

Saves changes made during this session so they will persist after a reboot.

Revert to factory defaults

Reverts the appliance to its factory default settings, which include username, password, and network configuration information.

Reset admin password

Resets the admin password for accessing the appliance itself. This does not set the password for accessing the LCD panel.

The following table provides information about the LCD menu.

Prompt

Description

Password

Sets a password for LCD-panel access. This does not set the password for accessing the appliance.

Brightness

Sets the LCD panel's level of brightness from 0 to 9, with 9 being the brightest.

Contrast

Sets the LCD panel's level of contrast between the background and text from 0 to 9, with 9 being the greatest contrast.

The following table provides information about the Restart Options menu.

Prompt

Description

Reboot System

Restarts the system.

Prompt

Description

Halt System

Puts the system in sleep mode.

Next boot loc

Specifies disk partition (1 or 2) to boot from during the next reboot.

Required Ports and Protocols

    The table below outlines the main connections for the FX 8400 appliance’s communications. Open the ports     listed below on your firewall to permit these connections.

Source

Destination

Destination Port

User Configurable

Notes

FX 8400: Ether1*

cloud.fireeye.com

TCP 443

Yes

Dynamic Threat Intelligence (DTI) Cloud Update Service

Administrator Workstation

FX 8400: Ether1

TCP 22

No

CLI Management

Administrator Workstation

FX 8400: Ether1

TCP 443

No

Web UI Management

FX 8400: Ether1

SMTP Relay

TCP 25

No

SMTP Alerts

FX 8400: Ether1

Internal DNS Servers

TCP/UDP 53

No

DNS Queries

FX 8400: Ether1

NTP Servers

UDP 123

No

NTP

FX 8400: Ether1

SIEM/Syslog Server

UDP 514

No

Syslog

FX 8400: Ether1

SNMP Server

UDP 162

No

SNMP

CM-Managed FX 8400: Ether1**

CM Ether1

TCP 22

No

CM Management Connection

Remote Console

FX 8400 IPMI

TCP 3520

No

Remote Console Redirection

Source

Destination

Destination Port

User
Configurable

Notes

* This is the default destination and port for stand-alone appliances and the CM Series platform. For a CM Series platform or standalone NX Series appliance running Release 7.5.0 or later, or a standalone EX Series appliance running Release 7.6.0 or later, the DTI source server can be either cloud.fireeye.com or staticcloud.fireeye.com. For a managed NX Series or EX Series appliance running these releases, the default DTI source server is the CM Series platform, but it can be either of the two servers mentioned above instead.

** For a managed appliance running Release 7.6.0 or later that uses the CM Series platform as its DTI source server, single-port communication is the default behavior. This means CM Ether1 port (TCP 22) is used for both DTI traffic and management traffic, unless otherwise configured.

For details, see the CM Series Administration Guide or the System Administration Guide for your appliance.

Blue circular icon with clipboard/document indicating informational note

For information about CM Series High Availability (HA) ports, see the CM Series High Availability (HA) Deployment Guide.

Replacements

This chapter contains instructions for replacing your appliance, with or without disk drives, and removing and replacing individual failed disk drives and power supplies. The disk drives and power supplies are hot-swappable, meaning they can be removed and replaced without unracking the appliance or powering it off.

Return Process

If you believe you have a defective part, you must first contact FireEye Technical Support, who will validate whether or not the part is defective. If the part is defective, Technical Support will initiate a Return Materials Authorization (RMA). No part can be returned without a FireEye-issued RMA number.

After receiving the replacement part from FireEye, please package and return the defective part within five (5) days, at FireEye's cost (provided that you utilize FireEye's designated courier service). If you fail to return the defective part within ten (10) business days after receiving the replacement, FireEye may invoice you as detailed in our Support Terms and Conditions, described here: http://www.fireeye.com/support/terms-and-conditions.html.

In the case of a defective disk drive or a defective system with disk drives, you may retain the disk drive(s) if you have purchased the Non-Returnable Disk Drive support option. Follow these instructions:

To return a defective part or system:

  1. Pack the defective part or the entire appliance in the packaging that the replacement part was received in, or in its original packaging material (or equivalent).

  2. Place a copy of the associated RMA Form (example shown below) inside the package. If you have more than one package, place a copy inside each package.

  3. Write the associated RMA number on the outside of each return package and in the reference field on each waybill. Returns cannot be processed without referencing the associated RMA number.

  4. Do not insure the shipment. FireEye is self-insured. Please declare "$0" in the "value for carrier" section.

  5. Send an email to RMA_Ops@fireeye.com listing the RMA number(s), the carrier name, and the carrier tracking number(s) for the return package.

  6. If you do not have a return shipping label, contact FireEye operations at RMA_Ops@fireeye.com and they will provide one for your return.

  7. All international shipments require three copies of a commercial invoice (CI). FireEye provides a partially completed CI. Please either use this CI, after completing the remaining required information, or create your own if you prefer. Please contact your distribution partner who can assist you. If you require additional assistance, please contact RMA_Ops@fireeye.com.

  8. Send the package directly to the location specified in the "SHIP TO" section on the RMA Form (example shown below) provided in the replacement part package.

For questions regarding an RMA return or status, please email: RMA_Ops@fireeye.com or call +1-408-321-7798.

Enclosed with your replacement part, you will receive a FireEye RMA Form similar to the following:

Sample FireEye RMA Form showing a table with COMPANY DETAILS and RMA NUMBER at top, SHIP TO and PRODUCT DETAILS sections, a REASON FOR RETURN checklist, and a large SAMPLE watermark across the form


Replacing an Appliance Including Disk Drives

Before replacing your FX 8400, take a backup of the current system, if possible. FireEye recommends that regular, full system backups are taken. For more information, see Backing Up and Restoring the Appliance Database on the next page. If you cannot back up the appliance, make sure your latest system backup is available. Contact FireEye Technical Support if you have questions on backing up your appliance.

To replace an appliance including the disk drives:

  1. Perform an orderly shutdown of the defective appliance.

  2. Unplug the appliance.

    Small blue circular clipboard icon

    Keep the power cord and cables for your replacement appliance.

  3. Unrack the defective appliance and rack-mount and re-cable the replacement appliance.

  4. Power on the replacement appliance.

  5. Configure the appliance as described in “Initial Configuration” of the System Administration Guide specific to your FireEye Series appliance and software release.

  6. Using a console connection, restore the appliance's configuration and database as described in Backing Up and Restoring the Appliance Database on the next page.

  7. Install replacement licenses as described in Applying License Keys.

  8. Set the DTI credentials as described in “Configuring DTI Credentials” in the System Administration Guide or Administration Guide specific to your FireEye Series appliance and software release.

Replacing an Appliance Excluding Disk Drives

Before replacing an appliance, take a backup of the current system, if possible. FireEye recommends that regular, full system backups are taken. If you cannot back up the appliance, make sure your latest system backup is available. For more information, see Backing Up and Restoring the Appliance Database on the next page Contact FireEye Technical Support if you have questions on backing up your appliance.

To replace an appliance without replacing the disk drives:

  1. Perform an orderly shutdown of the defective appliance.

  2. Remove the disk drives and insert them into the replacement appliance as described in Removing and Replacing an FX 8400 Disk Drive .

  3. Unplug the appliance.

small blue circular clipboard icon Be sure to keep the power cord and cables for your replacement appliance.

  1. Unrack the defective appliance.

  2. Rack-mount the replacement appliance as described in Rack Installation.

  3. Cable the appliance as described in Attaching Cables to your Appliance.

  4. Plug in a VGA monitor and USB keyboard.

  5. Power on the replacement appliance and watch the boot up process on the connected monitor.

  6. When a foreign configuration is detected, press F to import the saved configuration from the previous system.

  7. Configure the appliance via the LCD panel or console as described in Configuring the Appliance via the LCD Panel or "Initial Configuration" in the System Administration Guide specific to your FireEye Series appliance and software release.

  8. Install replacement licenses as described in Applying License Keys.

  9. Set the DTI Credentials as described in “Configuring DTI Credentials” in the System Administration Guide or Administration Guide specific to your FireEye Series appliance and software release.

Backing Up and Restoring the Appliance Database

Before replacing your FX 8400 appliance, take a backup of the current system so you can later restore it on the replacement.

Backing Up and Restoring the Database Using Release 7.4 and Earlier

Backing Up the Appliance Configuration

To back up an appliance configuration file:

  1. Enable the CLI configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Save the appliance configuration to a file:

    FX8400 (config) # configuration write to filename
  3. Upload the saved configuration file to a file server:

    FX8400 (config) # configuration upload filename-url
  4. Verify that the configuration file is on the file server.

    FX8400 (config) # show configuration files

The following example backs up the configuration file to a file named config_backup.

FX8400 (config) # configuration write to config_backup
FX8400 (config) # show configuration files
config_backup (active)
initial
initial.bak

Active configuration: config_backup
Unsaved changes: no
FX8400 (config) # configuration upload config_backup ?
<FTP/TFTP URL or scp://username[:password]@hostname/path/filename> ftp, tftp,
scp and sftp are supported. e.g. scp://username
[:password]@hostname/path/filename
FX8400 (config) # configuration upload config_backup
scp://username@backuphost/path/config_backup
Password (if required): ********

Backing Up the Appliance Database

Follow these steps to back up the appliance database using the CLI.

To back up the appliance’s database using the CLI:

Blue circular information icon

Be sure to back up in binary format, not ASCII, for FTP restores.

  1. Enable the CLI configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Save a backup of the appliance database to a file.

    FX 8400 (config) # fedb backup to-file filename
  3. Upload the database backup file to a file server.

    FX 8400 (config) # fedb backup upload filename-url
  4. Verify that the backup file is on the file server.

    FX 8400 (config) # show fedb backups

Blue circular information icon

Videos, binaries, and PCAPS are not backed up during this process. Contact FireEye Technical Support for more information.

The following example backs up the database file to a file named db_backup.

FX 8400 (config) # fedb backup to-file db_backup
Dumping database to backup file
Encrypting backup file
Created database backup file db_backup
FX 8400 (config) # show fedb backups
Created At Size Backup File
2014/04/15 03:00:00 50.0M db_backup
1 backup file available!
FX 8400 (config) # fedb backup upload db_backup
scp://username@backuphost/path/db_backup
Password (if required): ********

Restoring the Appliance Configuration

Be sure to make a copy of the current configuration before restoring an older configuration.

To restore a configuration file:

  1. Enable the CLI configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Fetch the saved configuration file from the file server.

    FX 8400 (config) # configuration fetch url filename
  3. Activate the saved configuration file.

    FX 8400 (config) # configuration switch-to filename

The following example restores the configuration file named config_backup.

FX 8400 (config) # configuration fetch ?
<download URL> http, https, ftp, tftp, scp and sftp are supported. e.g.
scp://username[:password]@hostname/path/filename
FX 8400 (config) # configuration fetch scp://username@backuphost/path/config_backup
Password (if required): ********
FX 8400 (config) # show configuration files
config_backup
initial (active)
initial.bak
Active configuration: initial
Unsaved changes: yes
FX 8400 (config) # configuration switch-to config_backup

Restoring the Appliance Database

Follow these steps to restore the appliance database using the CLI.

To restore the database using the CLI:

  1. Enable the CLI configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Fetch the database backup file from the file server.

    FX 8400(config) # fedb backup fetch filename
  3. Restore the database backup.

    FX 8400 (config) # fedb restore from-file filename
  4. Reload the appliance.

    FX 8400 (config) # reload

The following example restores the database file named db_backup.

FX 8400 (config) # fedb backup fetch ?
<HTTP/FTP/TFTP URL or scp://username:password@hostname/path/filename>
FX 8400 (config) # febd fetch scp://username@backuphost/path/db_backup
Password (if required): ******** FX 8400 (config) # show fedb backups
Created At Size Backup File
2014/04/01 03:00:00 50.0M db_backup
1 backup files available!
FX 8400 (config) # fedb restore from-file db_backup Decrypting backup file
Restore backup file into database
Backup
is from supported database version 9.1
Restored database backup file db_backup
Restarting Database clients ... done!
Appliance reload is recommended to ensure best results after a database restore.
FX 8400 (config) # reload
Configuration has been modified; save first? [yes]
Configuration changes saved.
Rebooting...

Backing Up and Restoring the Appliance Database Using Release 7.5 and Later

Backing Up the Database

Follow these steps to back up the appliance database using the CLI.

To back up the appliance database:

  1. Enable the CLI configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Specify the type of profile.

    • To set the profile for the configuration database, enter:

      FX 8400 (config) # backup profile config
    • To set the profile for the FireEye appliance database, enter:

      FX 8400 (config) # backup profile fedb
    • To set the profile for both the configuration database and the FireEye appliance database, enter:

      FX 8400 (config) # backup profile config+fedb
    • To set the profile for the configuration database, FireEye appliance database, and detected data (malware, alerts, reports, and so on), enter:

      FX 8400 (config) # backup profile full
  3. Specify the location for the backup file.

    • To save the backup file to a local destination on the appliance, enter:

      FX 8400 (config) # backup profile profile to local
    • To save the backup file on a remote server, enter:

      FX 8400 (config) # backup profile profile to url

      where url is the specified remote location using the following format:

      scp://username:password@hostname/remote path

    • To save the backup file to a USB drive on your local machine, enter:

      FX 8400 (config) # backup profile profile to usb
  4. Specify the prefix for the backup file name.

    FX 8400 (config) # backup profile profile to backup_location prefix prefix

    You can use the customized prefix to sort the list of the backup files.

  5. (Optional) Monitor the progress of the backup operation.

  • To disable progress tracking for the backup operation, enter:        

    FX 8400 (config) # backup profile profile to backup_location
    progress no-track
  • To enable progress tracking for the backup operation, enter:        

    FX 8400 (config) # backup profile profile to backup_location
    progress track

By default, progress tracking is enabled.

You can cancel progress tracking by using Ctrl+C. The backup operation still happens in the background. Use the show backup status command to find the status of the backup operation.

  1. (Optional) Disable public and private key encryption for the backup operation.        

    FX 8400 (config) # backup profile profile to backup_location no-encryption

Note: Each backup file is signed by default using the public and private key pairs. By default, encryption is always included in the backup.

Note: Encryption delays the backup operation. Backups are encrypted only using static keys.

To cancel a backup that is in progress, enter the backup cancel command. When you cancel the backup operation that is in progress, the system finishes the current step before canceling the entire operation.

The following example backs up the configuration database, detected data, and artifacts to a local destination on the appliance:

FX 8400 (config) # backup profile full to local
Step 1 of 4: Backing up config db
100.0% [#############################################]
Step 2 of 4: Backing up fedb
100.0% [#############################################]
Step 3 of 4: Backing up Artifacts
100.0% [#############################################]
Step 4 of 4: Generating Backup package
100.0% [#############################################]

Restoring the Appliance Database

Follow these steps to restore the appliance database from a backup file using the CLI.

To restore the appliance database from a backup file:

  1.         Enable the CLI configuration mode.        

    FX 8400 > enable
    FX 8400 # configure terminal
  2.         Locate the backup FEBKP file you want to restore.        

    • To display a list of the backup files on the USB drive, enter:                

      FX 8400 (config) # show backup available on-usb
    • To display a list of the backup files on the appliance, enter:                

      FX 8400 (config) # show backup available local

  1. Specify a backup profile.

    • To set the profile for the configuration database, enter:

      FX 8400 (config) # restore profile config
    • To set the profile for the FireEye appliance database, enter:

      FX 8400 (config) # restore profile fedb
    • To set the profile for both the configuration database and the FireEye appliance database, enter:

      FX 8400 (config) # restore profile config+fedb
    • To set the profile for the configuration database, FireEye appliance database, and detected data (malware, alerts, reports, and so on), enter:

      FX 8400 (config) # restore profile full
  2. Specify the location of the backup file.

    • To restore the backup from the local destination on the appliance, enter:

      FX 8400 (config) # restore profile profile from local
    • To restore the backup from a remote server, enter:

      FX 8400 (config) # restore profile profile from url

      where url is the specified remote location using the following format:

      https or scp://username:password@hostname/remote path

    • To restore the backup from a USB drive on your local machine, enter:

      FX 8400 (config) # restore profile profile from usb
  3. Enter the name of the backup file.

    FX 8400 (config) # restore profile profile from backup location backup name
  4. (Optional) Restore the network settings from the relevant backup.

    FX 8400 (config) # restore profile profile from backup location backup name include-network-config

    By default, the network settings are not included in the restore operation.

    Red circular warning icon

    Do not restore the current network settings while the appliance is performing a restore operation from a remote server.

  5. (Optional) Monitor the progress of the restore operation.

    • To disable progress tracking for the restore operation, enter:

      FX 8400 (config) # restore profile profile from backup location backup name progress no-track
    • To enable progress tracking for the restore operation, enter:

      FX 8400 (config) # restore profile profile from backup location backup name progress track

    By default, progress tracking is enabled.

    You can cancel progress tracking by using Ctrl+C. The restore operation still happens in the background. Use the show restore status command to find the status of the restore operation.

The following example shows how to restore a configuration database backup from your local appliance:

FX 8400 (config) # restore profile config from local backup wMPS-Config-7.5.0-sulabh-wmps-20141118-133123.febkp
Step 1 of 3: Performing Sanity checks
100.0% [##################################################]
Step 2 of 3: Extracting backup package
100.0% [##################################################]
Step 3 of 3: Restoring config db
100.0% [##################################################]

Applying License Keys

After you replace an appliance, you must apply replacement license keys.

To apply a license key from the CLI:

  1.         Enable the CLI configuration mode.        

    FX8400 > enable
    FX8400 # configure terminal
  2.         Enter the license key.        

    FX 8400 (config) # license install <license-key>
  3. Repeat step 2 for each additional license key you need to apply.

Identifying the Failed Disk Drive

Before removing and replacing the failed disk drive from your appliance, you must first identify the slot in which it resides.

Blue circular icon with a white clipboard/hard-drive symbol

To identify the slot of failed disk drive for appliances running a release prior to the FX Series 7.2 release, contact Customer Support.

To identify the slot number of a failed drive from the CLI:

  1.         Enable configuration mode.        

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Enter the show media disk command.

3. Note the slot number of the failed drive. View the sample output below for reference.

Disk - 0
Model: TOSHIBA AL13SEB600 0101X320A01NFTR8
Serial: 500003951800CEAD
Firmware Version: 0101
Size: 558.911 GB
Status: Failed
SMART Flag: No
Rebuild Status: Device(Encl-252 Slot-0) is not in rebuild process

Disk - 1
Model: TOSHIBA AL13SEB600 0101X320A022FTR8
Serial: 500003951800CEE9
Firmware Version: 0101
Size: 558.911 GB
Status: Online
SMART Flag: No
Rebuild Status: Device(Encl-252 Slot-1) is not in rebuild process

4. Proceed to the following section for instructions on removing and replacing the disk drive within the specified slot number.

Removing and Replacing an FX 8400 Disk Drive

Perform the following steps to remove and replace a disk drive:

  1. Turn the screw located on the left side of the bezel clockwise to unlatch it from the appliance.

Front of FX 8400 appliance bezel being unlatched by a screwdriver (close-up).

2. Gently remove the bezel from the appliance to reveal the disk drives.

Front-right view of a server appliance with the front bezel partially removed, exposing disk drive bays; a red curved arrow indicates the bezel being pulled away.

3. Locate the disk drive carrier that contains the failed disk drive.

Front view of the appliance showing multiple disk drive bays with two drives marked (16 and 17), highlighting how to identify the failed drive carrier.

4. Push the navy blue button to release the latch handle.

Close-up of the disk drive bay area showing the navy blue release button on the drive carrier circled in red.



  1. Carefully pull the latch handle forward.

  2. Pull the handle to slide the disk drive from its slot.

A rack-mounted FX 8400 with the front drive carrier partially removed; FireEye logo visible on the chassis and the drive latch handle pulled forward

  1. Use the latch handle on the new drive carrier to slide the new drive into the empty slot. When the drive is fully inserted into the slot, push the latch handle down until it clicks.

To verify the RAID functionality of the replacement drive:

  1. Enable configuration mode.

    FX 8400 > enable
    FX 8400 # configure terminal
  2. Enter the show system hardware status raid command.

  3. Verify that the disk status of the replaced drive is “Online.”

Removing and Replacing an FX 8400 Power Supply Unit

Perform the following steps to remove and replace a power supply unit (PSU):

  1. At the rear of the appliance, remove the power cable from the failed PSU.

  2. Press the green release toward the black handle in a pinching gesture to unlatch the unit and, while continuing to squeeze, pull out the PSU.

Rear of a rack appliance with the power supply unit partially removed; a large red arrow indicates the direction to pull the PSU, showing metal chassis, ventilation honeycomb, connectors, and a black handle with a green release piece.

  1. Insert the replacement PSU in the slot and slide it in until it clicks into place.

Appendices

Appendix 1: System Specifications

The table below provides the technical specifications of the FireEye FX 8400.

Component

FX 8400 Specifications

Form Factor

2U Rack-Mount

Weight of Appliance

42 lbs (19 kg)

Weight of Packaged Appliance

57 lbs (26 kg)

Dimensions
(W x D x H)

17.2 x 28.0 x 3.41 inches
(437 x 711 x 86.6 mm)

Enclosure

2 RU, Fits 19-inch Rack

Management Interfaces

(2) 10/100/1000BASE-T Ports

Drive Capacity

(2) 600 GB HDD, RAID 1, 2.5 inch, FRU

AC Power Supply

Redundant (1+1), FRU,
750 W @ 100-240 VAC (±10%) 9-4.5 A, 50/60 Hz
IEC60320-C14 inlet

Maximum Power Consumption

506 W

Operating Temperature

10° to 35° C

Maximum Thermal Dissipation

1726 BTU/hour


Appendix 2: Product Compliance Information

The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the FireEye FX Series appliances.

FX
Model

EMC (2004/108/EC)

LVD/Safety (2006/95/EC)

Other

5400

8400

EN 55022: 2010 + A1: 2011
Class A

EN 55024: 2010

EN 61000-3-2: 2006 + A1: 2009 + A2: 2009

EN 61000-3-3: 2008

EN 60950-1: 2006 + A11: 2009 + A1: 2010 + A12: 2011

RoHS

REACH

WEEE

IEC60320-C14 inlet