NX 2500 Hardware Administration Guide

Prev Next

NX SERIES

FEI-013


CHAPTER 1: The NX 2500

The FireEye NX 2500 stops the new generation of cyber attacks that use zero-day Web exploits and multiprotocol malware callbacks to compromise the majority of today's networks.

When used as a standard (or integrated) appliance, the NX Series appliance performs both monitoring and analysis functions. When used as a sensor within the FireEye Network Security, the NX 2500 only monitors traffic, extracting objects and URLs and sending them to an MVX cluster for analysis. This allows a flexible approach to your security solution.

    Blue circular information icon     For information about using the NX Series appliance as a sensor, see the User Guide for your software release.


    © 2019 FireEye     5

NX Series Hardware Administration GuideCHAPTER 1: The NX 2500


The Front View

Front view of NX 2500 appliance showing front panel with numbered red callouts for Power LED, HDD LED, Console (RJ45) port, USB ports, disabled port, Ether 1 (RJ45) management port, and Pether 3–6 (RJ45) monitoring ports

1) Power LED

6) Ether 1 (RJ45) Management 1 Port

2) HDD LED

7) Pether 3 (RJ45) Monitoring 3 Port

3) Console (RJ45) Port

8) Pether 4 (RJ45) Monitoring 4 Port

4) USB Ports

9) Pether 5 (RJ45) Monitoring 5 Port

5) Disabled Port

10) Pether 6 (RJ45) Monitoring 6 Port

LEDs

The LEDs provide critical information about parts of the appliance. The following table describes each LED.

LED

Flashing

Steady

Off

Normal State

Power

N/A

Green and steady indicates the appliance is receiving power

No power is supplied to the system or host is not turned on

Green and steady

HDD

Amber and flashing indicates normal HDD activity

N/A

No HDD activity

Off

I/O Ports

  • USB: Connect a keyboard to this port to manage the appliance locally. The port is USB 3.0 compliant.

  • Console: Connect to this port using a RJ45 to DB9F cable to manage the appliance from your terminal.

The Front View


Disabled Port

This port is disabled by design.

Management Port

  • ether (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.

Monitoring Ports

Blue circular icon showing a clipboard/information symbol Each interface pair is physically and logically segregated from other interface pairs, preventing communication between the different network segments.

  • pether (RJ45): Connect the switch port you want to monitor to this port. The RJ45 connectors are 10/100/1000BASE-T ports.

LEDs on ports pether3 through pether6 provide information about the LAN connection. The Link Speed LED on the left is green, amber, or off to indicate the speed of the connection. The Activity LED on the right is green or amber to indicate connection and activity.

Link Speed LED (Left)

Color

Speed

Off

No Link

Off (Activity LED is Green)

10 Mbps

Amber

100 Mbps

Green

1 Gbps

Activity LED (Right)

State

Color

Definition

Connect

Green

Blinking indicates network activity.

Bypass

Amber

Bypass state

Disconnect

Blinking Amber

Disconnected state

The Rear View

Rear view of the appliance showing the rear panel with numbered callouts 1, 2, and 3 — metal chassis, ventilation, power inlet and fan

1) pether2 (RJ45) Optional Dedicated Submission Port or Dedicated Out-of-Band Blocking Port

3) Power Port

2) Power Switch

Power

  • Switch: Use this switch to turn the appliance on or off. Turning off the power with this switch removes the main power, but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.

  • Port: Connect your power source to this port to provide power to the appliance.

Submission/Out-of-Band Blocking Port

  • pether (RJ45): If the appliance is in sensor mode, use this port to communicate with the broker in your MVX Smart Grid. If the appliance is integrated, you can dedicate this port to out-of-band blocking. The RJ45 connectors are 10/100/1000BASE-T ports. See the NX Series System Administration Guide for your release for more information about operational modes.

LEDs on the pether2 port provide information about the LAN connection. The Activity LED on the left is off or green to indicate connection and activity. The Link Speed LED on the right is green, amber, or off to indicate the speed of the connection.

Activity LED (Left)

Color

Definition

Off

Link is down.

Solid Green

Link is up.

Blinking Green

Blinking indicates network activity.

The Rear View


Link Speed LED (Right)

Color

Speed

Off

No Link

Off (Activity LED is Green)

10 Mbps

Amber

100 Mbps

Green

1 Gbps


© 2019 FireEye

9

NX Series Hardware Administration Guide

CHAPTER 1: The NX 2500



10

© 2019 FireEye

NX Series Hardware Administration Guide

Inline Deployment


CHAPTER 2: Deployment

There are two types of deployment: inline and out-of-band. An inline deployment provides high security by blocking all malicious traffic from reaching your network. An out-of-band deployment only monitors malicious content as it enters your network; it does not block malicious content.

FireEye strongly recommends using an inline deployment mode.

Deployment modes include:

Inline Deployment

The diagram below illustrates the deployment of an NX 2500 appliance installed between the LAN and the firewall in a typical network topology.

Network topology diagram showing Internet cloud, edge router, firewall, NX Series appliance placed between the firewall and the core switch, core switch connecting to LAN/WAN with multiple workstations. The diagram is dashed to indicate network boundary and labels include Internet, Edge Router, NX Series, Core Switch, and LAN or WAN.

Prerequisites

Before connecting the NX 2500 appliance to your network:

© 2019 FireEye

    NX Series Hardware Administration Guide     CHAPTER 2: Deployment


  • Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.

  • Determine which ports on your routers or switches provide ingress and egress data

Cabling

Connect the appropriate cables to the NX 2500 appliance’s ports as follows:

  • ether1: Connect one end of the cable to the NX 2500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.

  • pether3: Connect one end of the cable to the NX 2500 appliance’s pether3 port, and connect the other end to your LAN-facing switch.

  • pether4: Connect one end of the cable to the NX 2500 appliance’s pether4 port, and connect the other end to the Internet-facing switch.

You can monitor another network segment by connecting a LAN-facing switch and an Internet-facing switch to pether5–6.

Inline Proxy Deployment

The diagram below illustrates the deployment of an NX 2500 appliance installed between the LAN and the firewall in a typical network topology.

If your environment contains Web proxies or other NAT devices that obscure incoming IP addresses, deploy the NX device so that it sees Web traffic from the internal (or LAN) side of the proxy. If you place the NX device on the external side of the proxy, the NX appliance reports a malicious site as being the LAN IP of the proxy.

Network diagram showing NX 2500 inline between the Internet (cloud), edge router, firewall, proxy, core switch, and LAN; illustrates inline proxy deployment topology.

Connect your NX 2500 appliance between two routers or switches on your network, and to your proxy.

12

© 2019 FireEye

Test Access Point (TAP) Deployment


Prerequisites

Before connecting the NX 2500 appliance to your network:

  • Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.

  • Determine which ports on your routers or switches provide ingress and egress data

Cabling

Connect the appropriate cables to the NX 2500 appliance’s ports as follows:

  • ether1 cable: Connect one end of the cable to the NX 2500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.

  • pether3 cable: Connect one end of the cable to the NX 2500 appliance’s pether3 port, and connect the other end to the LAN-facing switch.

  • pether4 cable: Connect one end of the cable to the NX 2500 appliance’s pether4 port, and connect the other end to the proxy server.

  • pether5 cable: Connect one end of the cable to the NX 2500 appliance’s pether5 port, and connect the other end to the LAN-facing switch.

You can monitor an additional proxy server by connecting additional proxies and LAN-facing switches to pether5—6.

Test Access Point (TAP) Deployment

Test Access Point (TAP) uses a TAP device to provide a real-time duplicate copy of the network traffic through the network.

Test Access Points have the following limitations:

  • You must purchase a separate TAP device to deliver packets to the NX Series device.

  • A TAP deployment does not block malware from accessing your network.

To deploy the FireEye NX Series appliance using a TAP device, you first connect the TAP device inline to your network. You then connect the FireEye NX Series monitoring ports to the ingress and egress ports on the TAP device. The following diagram illustrates the TAP deployment in a typical network topology.


© 2019 FireEye13

NX Series Hardware Administration Guide

CHAPTER 2: Deployment


Network diagram showing an Internet cloud connected to an edge router, firewall, network devices, a Network TAP Device connected to an NX Series appliance, a core switch, and a LAN with multiple workstation icons inside a dashed boundary.

Prerequisites

Before connecting the NX 2500 appliance to your network:

  • Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.

  • Determine which ports on your routers or switches provide ingress and egress data.

Cabling

Connect the appropriate cables to the NX 2500 appliance’s ports as follows:

  • ether1: Connect one end of the cable to the NX 2500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.

  • pether3: Connect one end of the cable to the NX 2500 appliance’s pether3 port, and connect the other end to your TAP device.

Port Mirroring (SPAN) Deployment

Port mirroring deployment, also known as Switch Port Analyzer (SPAN) packet capture, is usually the least expensive option in a low-traffic network environment. To set up port mirroring, you configure a router or switch with port mirroring capability to forward a copy of incoming and outgoing traffic passing between selected ports to SPAN ports on the switch. Then connect the SPAN ports to the appliance.

Port mirroring has the following limitations:

  • Heavily used networks may result in dropped packets that are not passed to the NX Series appliance.


14

© 2019 FireEye

Port Mirroring (SPAN) Deployment


  • Port mirroring is active packet duplication. The router or switch uses its processing power to mirror the network packets and pass these packets to the NX Series device. In a heavily used network, the network quality and response times tend to degrade.

  • The router or switch must be configured to provide port-mirrored data to the NX Series appliance. Maintenance costs for this configuration can be higher than other configurations.

  • Detected malware cannot be prevented from accessing your network.

  • SPAN port connectivity issues may cause delays in your deployment. You may need to add a few days to troubleshoot the connectivity issues.

The following diagram illustrates the port mirroring deployment in a typical network topology.

Network topology diagram showing Internet cloud to Edge Router, firewall, Port Mirroring Switch connected to NX Series appliance, Core Switch and LAN with multiple hosts inside a dashed boundary indicating mirrored traffic flow

Red warning icon

You must configure the SPAN port correctly and test it to make sure that the mirroring ports are passing all of the traffic you want to monitor. This usually requires an administrator with networking expertise who can set up the SPAN port and run TCPDump or WireShark to monitor the traffic and verify that there is bi-directional TCP port 80 (HTTP) traffic passing through the port.

Prerequisites

Before connecting the NX 2500 appliance to your network:

  • Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.

  • Determine which ports on your routers or switches provide ingress and egress data

Cabling

Connect the appropriate cables to the NX 2500 appliance’s ports as follows:


© 2019 FireEye

15

NX Series Hardware Administration Guide

CHAPTER 2: Deployment


  • ether1: Connect one end of the cable to the NX 2500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.

  • pether3: Connect one end of the cable to the NX 2500 appliance’s pether3 port, and connect the other end to your SPAN device.


16

© 2019 FireEye

NX Series Hardware Administration GuideBefore You Begin

CHAPTER 3: Installation

This chapter provides information about the site requirements of your installation location.

Before You Begin

Follow the steps in this section before you install the appliance.

Before Opening the Box

  • Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.

  • Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.

  • If there appears to be damage to the box, file a damage claim with the carrier who delivered it.

Unpacking the Appliance

Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.

Ensure your box contains:

  • The correct appliance model

  • An accessory kit

  • Online Documents Portal Referral

  • A rail kit

Installation Site Guidelines

Follow these guidelines when you select an installation site:


© 2019 FireEye

17

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.

  • Make sure there is sufficient space for air flow.

Rack Precautions

FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:

Yellow triangular warning sign with black exclamation mark

  • Before extending the rack to the installation position, read the installation instructions.

  • Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.

  • Do not leave the slide-rail mounted equipment with the rails extended in the installation position.

Server Precautions


Server Precautions

FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

  • Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • FireEye recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.

Power Requirements

The NX 2500 uses a 250 W power adapter unit with an input rating of 100-240 VAC (±10%), 3.5 A at 47-63 Hz.


© 2019 FireEye

19

NX Series Hardware Administration GuideCHAPTER 3: Installation


Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.

Cabling Requirements

The NX ships with the following cables:

  • RJ45-to-DB9F cable

  • Power cable

You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the NX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

The NX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Mounting the NX to the Rack

Refer to the instructions provided with the rail kit included with your appliance.

Attaching Cables to the Appliance

  1. Connect the NX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.

  2. Connect the power cable or cables to the power port or ports on the back of the appliance.

Turning On the Appliance


Turning On the Appliance

    Power on the appliance by pressing the power switch on the back of the appliance.


© 2019 FireEye

21

NX Series Hardware Administration Guide

CHAPTER 3: Installation



22

© 2019 FireEye

NX Series Hardware Administration Guide

Return Process


CHAPTER 4: Replacements

Return Process

    If you believe you have a defective part or system, you must first contact FireEye Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit www.fireeye.com/legal.


© 2019 FireEye

23

NX Series Hardware Administration Guide

CHAPTER 4: Replacements


24

© 2019 FireEye

Appendices

Appendix 1: System Specifications

The table below provides the technical specifications for the FireEye NX 2500.

Component

NX 2500 Specifications

Form Factor

1U Rack-Mount

Weight of Appliance

16.2 lbs (7.3 kg)

Weight of Packaged Appliance

28.2 lbs (12.8 kg)

Dimensions (W x D x H)

17.2 x 19.7 x 1.7 inches (437 x 500 x 44 mm)

Enclosure

1 RU, Fits 19-inch Rack

Management Interfaces

(2) 10/100/1000BASE-T Ports

Monitoring Interfaces

(4) 10/100/1000BASE-T Ports

Memory

32 GB (2 x 16 GB)

Drive Capacity

Single 3.5” 6TB SATA drive, internal fixed

AC Power Supply

Non-redundant, non-FRU, internal
250 W @ 100-240 VAC (±10%)
3.5 A, 47-63 Hz

Maximum Power Consumption

85 W

Operating Temperature

0° to 40° C

Maximum Thermal Dissipation

290 BTU/hour

© 2019 FireEye    25

NX Series Hardware Administration Guide

Appendices


Appendix 2: Product Compliance Information

The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the NX appliance.

EMC

LVD/Safety

Environmental

FCC Part 15 Class-A, CE (Class-A),

CNS 13438,

CISPR 32, VCCI V-3,

EN 55024, EN 55032, EN 61000,

ICES-003, KN 32, KN 35

CSA 22.2, IEC 60950, EN 60950*,

UL 60950

RoHS

REACH

WEEE

Conflict Minerals

*All current amendments

© 2019 Fire