NX SERIES
FEI-014
CHAPTER 1: The NX 1500
The FireEye NX 1500 stops the new generation of cyber attacks that use zero-day Web exploits and multiprotocol malware callbacks to compromise the majority of today's networks. It functions as a sensor that extracts objects and URLs from the traffic it monitors, and sends submissions to an MVX cluster for analysis.
The Front View

1) Power LED | 2) HDD LED |
LEDs
The LEDs provide critical information about parts of the appliance. The following table describes each LED.
LED | Flashing | Steady | Off | Normal State |
|---|---|---|---|---|
Power | N/A | Green and steady indicates the appliance is receiving power. | No power is supplied to the system. | Green and steady |
HDD | Degraded SAS/SATA drive connection | Green and steady indicates normal operation. | No power is supplied to the system. | Green and steady |
The Rear View

1) Power Switch | 6) Pether 2 (RJ45) Optional Dedicated Submission Port |
2) Power Port | 7) Pether 3 (RJ45) Optional Dedicated Submission Port |
The Rear View
3) USB Ports | 8) Pether 4 (RJ45) Optional Dedicated Submission Port |
4) Console (RJ45) Port | 9) Pether 5 (RJ45) Optional Dedicated Submission Port |
5) Ether 1 (RJ45) Management 1Port | 10) Pether 6 (RJ45 ) Optional Dedicated Submission Port |
Power
Switch: Use this switch to turn the appliance on or off. Turning off the power with this switch removes the main power, but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.
Port: Connect your power source to this port to provide power to the appliance.
I/O Ports
USB: The port is USB 2.0compliant.
Console: Connect to this port using a RJ45-to-DB9F cable to manage the appliance from your terminal.
Management Ports
ether (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.
Submission/Cluster Ports
Pether (RJ45): Use this port to communicate with the broker in your MVX Smart Grid. The RJ45 connectors are 10/100/1000BASE-T ports. These ports do not support hardware bypass. See the NX Series System Administration Guide for your release for more information about operational modes.
© 2019 FireEye
7
NX Series Hardware Administration Guide
CHAPTER 1: The NX 1500
8
© 2019 FireEye
NX Series Hardware Administration Guide
Inline Deployment
CHAPTER 2: Deployment
There are two types of deployment: inline and out-of-band. An inline deployment provides high security by blocking all malicious traffic from reaching your network. An out-of-band deployment only monitors malicious content as it enters your network; it does not block malicious content.
FireEye strongly recommends using an inline deployment mode.
Deployment modes include:
Inline Deployment
The diagram below illustrates the deployment of an NX 1500 appliance installed between the LAN and the firewall in a typical network topology.

Prerequisites
Before connecting the NX 1500 appliance to your network:
© 2019 FireEye
9
NX Series Hardware Administration Guide CHAPTER 2: Deployment
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 1500 appliance’s ports as follows:
ether1: Connect one end of the cable to the NX 1500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 1500 appliance’s pether3 port, and connect the other end to your LAN-facing switch.
pether4: Connect one end of the cable to the NX 1500 appliance’s pether4 port, and connect the other end to the Internet-facing switch.
You can monitor another network segment by connecting a LAN-facing switch and an Internet-facing switch to pether5–6.
For information about changing the default submission interface, see the chapter “Performing the Initial Configuration” in the Threat Management Platform Deployment Guide for your software release.
Inline Proxy Deployment
The diagram below illustrates the deployment of an NX 1500 appliance installed between the LAN and the firewall in a typical network topology.

If your environment contains Web proxies or other NAT devices that obscure incoming IP addresses, deploy the NX device so that it sees Web traffic from the internal (or LAN) side of the proxy. If you place the NX device on the external side of the proxy, the NX appliance reports a malicious site as being the LAN IP of the proxy.

10 © 2019 FireEye
Test Access Point (TAP) Deployment
Connect your NX 1500 appliance between two routers or switches on your network, and to your proxy.
Prerequisites
Before connecting the NX 1500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 1500 appliance’s ports as follows:
ether1 cable: Connect one end of the cable to the NX 1500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3 cable: Connect one end of the cable to the NX 1500 appliance’s pether3 port, and connect the other end to the LAN-facing switch.
pether4 cable: Connect one end of the cable to the NX 1500 appliance’s pether4 port, and connect the other end to the proxy server.
pether5 cable: Connect one end of the cable to the NX 1500 appliance’s pether5 port, and connect the other end to the LAN-facing switch.
Test Access Point (TAP) Deployment
Test Access Point (TAP) uses a TAP device to provide a real-time duplicate copy of the network traffic through the network.
Test Access Points have the following limitations:
You must purchase a separate TAP device to deliver packets to the NX Series device.
A TAP deployment does not block malware from accessing your network.
To deploy the FireEye NX Series appliance using a TAP device, you first connect the TAP device inline to your network. You then connect the FireEye NX Series monitoring ports to the ingress and egress ports on the TAP device. The following diagram illustrates the TAP deployment in a typical network topology.
© 2019 FireEye
NX Series Hardware Administration Guide
CHAPTER 2: Deployment

Prerequisites
Before connecting the NX 1500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 1500 appliance’s ports as follows:
ether1: Connect one end of the cable to the NX 1500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 1500 appliance’s pether3 port, and connect the other end to your TAP device.
(For optional dedicated submission interface) pether3, pether4, pether5, and pether6: Connect one end of an Ethernet cable to the NX 1500 appliance’s pether3, pether4, pether5, or pether6 port, and connect the other end to your cluster-facing switch.
For information about changing the default submission interface, see the chapter “Performing the Initial Configuration” in the Threat Management Platform Deployment Guide for your software release.
Port Mirroring (SPAN) Deployment
Port mirroring deployment, also known as Switch Port Analyzer (SPAN) packet capture, is usually the least expensive option in a low-traffic network environment. To set up port mirroring, you configure a router or switch with port mirroring capability to forward a
12
© 2019 FireEye
Port Mirroring (SPAN) Deployment
copy of incoming and outgoing traffic passing between selected ports to SPAN ports on the switch. Then connect the SPAN ports to the appliance.
Port mirroring has the following limitations:
Heavily used networks may result in dropped packets that are not passed to the NX Series appliance.
Port mirroring is active packet duplication. The router or switch uses its processing power to mirror the network packets and pass these packets to the NX Series device. In a heavily used network, the network quality and response times tend to degrade.
The router or switch must be configured to provide port-mirrored data to the NX Series appliance. Maintenance costs for this configuration can be higher than other configurations.
Detected malware cannot be prevented from accessing your network.
SPAN port connectivity issues may cause delays in your deployment. You may need to add a few days to troubleshoot the connectivity issues.
The following diagram illustrates the port mirroring deployment in a typical network topology.


You must configure the SPAN port correctly and test it to make sure that the mirroring ports are passing all of the traffic you want to monitor. This usually requires an administrator with networking expertise who can set up the SPAN port and run TCPDump or WireShark to monitor the traffic and verify that there is bi-directional TCP port 80 (HTTP) traffic passing through the port.
Prerequisites
Before connecting the NX 1500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
© 2019 FireEye
13
Cabling
Connect the appropriate cables to the NX 1500 appliance’s ports as follows:
ether1: Connect one end of the cable to the NX 1500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 1500 appliance’s pether3 port, and connect the other end to your SPAN device.
(For optional dedicated submission interface) pether3, pether4, pether5, and pether6: Connect one end of an Ethernet cable to the NX 1500 appliance’s pether3, pether4, pether5, or pether6 port, and connect the other end to your cluster-facing switch.
For information about changing the default submission interface, see the chapter “Performing the Initial Configuration” in the Threat Management Platform Deployment Guide for your software release.
NX Series Hardware Administration GuideBefore You Begin
CHAPTER 3: Installation
This chapter provides information about the site requirements of your installation location.
Before You Begin
Follow the steps in this section before you install the appliance.
Before Opening the Box
Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.
Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.
If there appears to be damage to the box, file a damage claim with the carrier who delivered it.
Unpacking the Appliance
Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.
Ensure your box contains:
The correct appliance model
An accessory kit
Online Documents Portal Referral
Power Requirements
The NX 1500 uses a 60 W power adapter unit with an input rating of 100-240 VAC (±10%), 1.5 A at 50-60 Hz.
© 2019 FireEye
15
NX Series Hardware Administration Guide CHAPTER 3: Installation
Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.
Cabling Requirements
The NX 1500 ships with the following cables:
RJ45-to-DB9F cable
DC adapter
You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the NX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.
Attaching Cables to the Appliance
Connect the NX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.
Connect the power cable or cables to the power port or ports on the back of the appliance.
Turning On the Appliance
Power on the appliance by flipping the power switch on the back of the appliance.
16 © 2019 FireEye
NX Series Hardware Administration GuideReturn Process
CHAPTER 4: Replacements
Return Process
If you believe you have a defective part or system, you must first contact FireEye Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit www.fireeye.com/legal.
© 2019 FireEye 17
NX Series Hardware Administration Guide
CHAPTER 4: Replacements
18
© 2019 FireEye
Appendices
Appendix 1: System Specifications
The table below provides the technical specifications for the FireEye NX 1500.
Component | NX 1500 Specifications |
|---|---|
Weight of Appliance | 3.5 lbs (1.6 kg) |
Weight of Packaged Appliance | 4 lbs (1.8 kg) |
Dimensions (W x D x H) | 11.02 x 6.9 x 1.73 inches (280 x 175 x 44 mm) |
Management Interfaces | (2) 10/100/1000BASE-T Ports |
Submission Interfaces | (4) 10/100/1000BASE-T Ports |
Memory | 16 GB (2 x 8 GB) |
Drive Capacity | Single 500 GB HDD, internal, fixed |
AC Power Adapter | Non-redundant, non-FRU, internal 60 W @ 100-240 VAC 1.5 A, 50-60Hz |
Maximum Power Consumption | 24 W |
Operating Temperature | 10° to 35° C |
Maximum Thermal Dissipation | 82 BTU/hour |
© 2019 FireEye
Appendix 2: Product Compliance Information
The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the NX 1500 appliance.
EMC | LVD/Safety | Environmental |
|---|---|---|
FCC (Part 15 Class-A), CE (Class-A), CNS 13438, AS/NZS CISPR 22, VCCI, IEC 61000-3, EN 55022, EN 55024, EN 61000-3, EN 61000-6, ICES 003, KN 32, KN 35 | IEC / EN / CSA 60950* | RoHS REACH WEEE Conflict Minerals |
*All current amendments