Enabling NDR integration in the manager
Enabling NDR integration in the Manager consists of the following two tasks:
Configuring a Client Group created on the NDR appliance in the Manager.
Enabling association of the Client Group configured on the Manager at the domain level or device level.
Configuring a client group created on the NDR appliance
When any client group created on an NDR appliance has been configured on the Manager, you can enable its association per domain or per device to complete the task of NDR integration in the Manager.
Note
Make sure that you have configured the required Client Profile and Client Group on the NDR appliance. For more information how to configure a Client Profile and Client Group using the NDR CLI.
Perform the Following steps to add a client group in the manager.
Login to the Manager and navigate to Devices > Admin Domain Name > Global tab.
Select IPS Device Settings > NI Integration. The NDR integration page is displayed in the Manager.
Go to the Client Group Configuration tab and click the + icon to add client group.
In the Create New Client Group panel, specify the following:
Client Group: Client group name as configured on the NDR appliance.
NDR Appliance IP Address: The IPv4 address of the NDR appliance on which the Client Group has been configured.
Token: The authentication hash token of 32 bytes attached to the specific Client Group being configured.
Click Save. An message stating the successful addition of the client group appears.
Enabling association of the client group configured on the manager at the domain level or device level
The client group is added under the Client Group Configuration tab. You can now enable its association at the domain level from Global > IPS Device Settings > NDR configuration > Client Group association tab.
Select the Enable Association with NDR Appliance checkbox.
Select the required Client Group from the drop-down list, if the Client Group has been added in the Manager using the Devices > Admin Domain Name > Global > IPS Device Settings > NDR Integration > Client Group Configuration tab.
The IP address of the NDR appliance appears by default in the field once you specify the Client Group.
Click Save.
Enabling the association of a client group at the device level
You can enable association at the device level from Devices > Setup > NDR configuration > Client Group Association tab.
Select the Enable Association with NDR Appliance checkbox to start the process of enabling Client Group association for the selected Sensor.
Select the required Client Group from the drop-down list, if the Client Group has been added in the Manager using the Devices > Admin Domain Name > Global > IPS Device Settings > NDR Integration > Client Group Configuration tab.
The IP address of the NDR appliance appears by default in the field once you specify the Client Group.
Click Save. A successful completion message is displayed.