FEI-016
NX SERIES / 2019
CHAPTER 1: The NX 5500

The FireEye NX 5500 stops the new generation of cyber attacks that use zero-day Web exploits and multiprotocol malware callbacks to compromise the majority of today's networks.
When used as a standard (or integrated) appliance, the NX Series appliance performs both monitoring and analysis functions. When used as a sensor within the FireEye Network Security, the NX 5500 only monitors traffic, extracting objects and URLs and sending them to an MVX cluster for analysis. This allows a flexible approach to your security solution.
For information about using the NX Series appliance as a sensor, see the User Guide for your software release.
© 2019 FireEye
4
NX Series Hardware Administration GuideCHAPTER 1: The NX 5500
The Front View

1) USB 2.0 Ports | 6) Information LED |
2) Bezel Release | 7) ether1 LED |
3) Power Button | 8) IPMI LED |
4) HDD LED | 9) Reset Button |
5) Power LED |
Ports and Bezel
Bezel Release: Slide the release tab to the right to remove the bezel from the appliance to access the chassis.
USB 2.0: These ports are USB 2.0 compliant.
Buttons
Power Button: Use the power button to turn the appliance on or off. Turning off the power with this button removes the main power, but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.
Reset Button: Use the reset button to reboot the system.
LEDs
The front panel has LEDs that provide critical information about parts of the appliance. The following table describes each LED.
The Front View
LED | Flashing | Steady | Off | Normal State |
|---|---|---|---|---|
HDD | Flashing and blue indicates HDD activity. | N/A | HDD is idle. | Flashing and blue when in use and off when not in use. |
Power | N/A | Blue and steady indicates power is being supplied to the system | No power is being supplied to the system | Blue and steady |
Information | N/A | Red and steady indicates a platform event filter initiated by the motherboard | System is operating normally | Off |
ether1 | Blue and flashing indicates data transfer via ether1 port | Blue and steady indicates normal connectivity on ether1 port | No activity | Blue and steady |
IPMI | Blue and flashing indicates data transfer via IPMI port | Blue and steady indicates normal connectivity on IPMI port | No activity | Blue and steady |
Chassis

1) Disk Drive Carrier | 3) Handle Release |
2) Handle Lock | |
© 2019 FireEye
Handle Lock: Slide to the left to unlock the handle and slide to the right to lock it.
Handle Release: When the handle is unlocked, press this tab to release the handle. Use the handle to pull the disk drive carrier from the chassis.
The Rear View

1) Power Port | 11) pether6 (SFP+) Monitoring 6 Port |
2) Serial Console Port | 12) pether7 (SFP+) Monitoring 7 Port |
3) Video Port | 13) pether8 (SFP+) Monitoring 8 Port |
4) pether2 (RJ45) Optional Dedicated Out-of-Band Blocking 2 Port | 14) pether9 (SFP+) Monitoring 9 Port |
5) ether1 (RJ45) Management 1 Port | 15) pether10 (SFP+) Monitoring 10 Port |
6) USB 3.0 Ports | 16) Disabled Port |
7) IPMI Port | 17) pether11 (RJ45) Monitoring 11 Port |
8) pether3 (SFP+) Monitoring 3 Port | 18) pether12 (RJ45) Monitoring 12 Port |
9) pether4 (SFP+) Monitoring 4 Port | 19) pether13 (RJ45) Monitoring 13 Port |
10) pether5 (SFP+) Monitoring 5 Port | 20) pether14 (RJ45) Monitoring 14 Port |
© 2019 FireEye
7
The Rear View
Power Port
Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary unit fails.
I/O Ports
Serial Console: Connect to this port to manage the appliance from your terminal.
Video: Connect a monitor to this port to view the appliance's command-line interface.
USB 3.0: These ports are USB 3.0 compliant.
Management Ports
ether (RJ45): Connect your LAN to this port to enable remote access to the CLI and Web UI. The RJ45 connector is a 10/100/1000BASE-T port.
IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 100BASE-T port.
IMPORTANT: The IPMI interface port is only enabled in CM Release 8.2.0 or later and IPMI firmware version 2.07 or earlier.
Out-of-Band Blocking Port
pether2 (RJ45): If your appliance is deployed out of band, you can dedicate this port for use of the out-of-band blocking feature. See the NX Series System Administration Guide for your release for more information about operational modes.
Monitoring Ports
Each interface pair is physically and logically segregated from other interface pairs, preventing communication between the different network segments.
pether (RJ45): Connect the switch port you want to monitor to this port. The RJ45 connectors are 10/100/1000BASE-T ports.
NX Series Hardware Administration Guide
CHAPTER 1: The NX 5500
pether (SFP+): The SFP+ connectors accept the following modules:
1000BASE-SX/10GBASE-SR (LC MMF)
1000BASE-LX/10GBASE-LR (LC SMF)
1000BASE-T (RJ45)
10GBASE-CU (5m direct attach cable)
Pether3 through pether10 support data rates up to 10 Gbps. Connect the switch port you want to monitor to this port.

Link partners connected to the same port pair must have the same data transmission rate (1 Gbps or 10 Gbps). The port pairs are as follows:
pether3 and pether4
pether5 and pether6
pether7 and pether8
pether9 and pether10
pether11 and pether12
pether13 and pether14
Contact Customer Support to order the appropriate transceiver modules.
Disabled Ports
These ports are disabled by design.
NX Series Hardware Administration Guide
Inline Deployment
CHAPTER 2: Deployment
There are two types of deployment: inline and out-of-band. An inline deployment provides high security by blocking all malicious traffic from reaching your network. An out-of-band deployment only monitors malicious content as it enters your network; it does not block malicious content.
FireEye strongly recommends using an inline deployment mode.
Deployment modes include:
Inline Deployment below
Inline Proxy Deployment on the next page
Test Access Point (TAP) Deployment on page 12
Port Mirroring (SPAN) Deployment on page 13
Inline Deployment
The diagram below illustrates the deployment of an NX 5500 appliance installed between the LAN and the firewall in a typical network topology.

Prerequisites
Before connecting the NX 5500 appliance to your network:
© 2019 FireEye
NX Series Hardware Administration GuideCHAPTER 2: Deployment
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 5500 appliance’s ports as follows:
ether1: Connect one end of the cable to the NX 5500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 5500 appliance’s pether3 port, and connect the other end to your LAN-facing switch.
pether4: Connect one end of the cable to the NX 5500 appliance’s pether4 port, and connect the other end to the Internet-facing switch.
You can monitor another network segment by connecting a LAN-facing switch and an Internet-facing switch to pether5–6.
Alternatively, pether4—14 can be used instead.
Inline Proxy Deployment
The diagram below illustrates the deployment of an NX 5500 appliance installed between the LAN and the firewall in a typical network topology.

If your environment contains Web proxies or other NAT devices that obscure incoming IP addresses, deploy the NX device so that it sees Web traffic from the internal (or LAN) side of the proxy. If you place the NX device on the external side of the proxy, the NX appliance reports a malicious site as being the LAN IP of the proxy.

11© 2019 FireEye
Test Access Point (TAP) Deployment
Connect your NX 5500 appliance between two routers or switches on your network, and to your proxy.
Prerequisites
Before connecting the NX 5500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data.
Cabling
Connect the appropriate cables to the NX 5500 appliance’s ports as follows:
ether1 cable: Connect one end of the cable to the NX 5500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3 cable: Connect one end of the cable to the NX 5500 appliance’s pether3 port, and connect the other end to the LAN-facing switch.
pether4 cable: Connect one end of the cable to the NX 5500 appliance’s pether4 port, and connect the other end to the proxy server.
pether5 cable: Connect one end of the cable to the NX 5500 appliance’s pether5 port, and connect the other end to the LAN-facing switch.
You can monitor additional proxy servers by connecting additional proxies and LAN-facing switches to pether6—14.
Test Access Point (TAP) Deployment
Test Access Point (TAP) uses a TAP device to provide a real-time duplicate copy of the network traffic through the network.
Test Access Points have the following limitations:
You must purchase a separate TAP device to deliver packets to the NX Series device.
A TAP deployment does not block malware from accessing your network.
To deploy the FireEye NX Series appliance using a TAP device, you first connect the TAP device inline to your network. You then connect the FireEye NX Series monitoring ports to the ingress and egress ports on the TAP device. The following diagram illustrates the TAP deployment in a typical network topology.
[IMAGE PLACEHOLDER: Diagram of a TAP deployment showing a TAP device inline between network routers/switches with the FireEye NX 5500 appliance connected to the TAP device monitoring ingress and egress ports, and a LAN-facing switch and proxy server also shown.]
© 2019 FireEye12

Prerequisites
Before connecting the NX 5500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 5500 appliance’s ports as follows:
ether1: Connect one end of the cable to the NX 5500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 5500 appliance’s pether3 port, and connect the other end to your TAP device.
Port Mirroring (SPAN) Deployment
Port mirroring deployment, also known as Switch Port Analyzer (SPAN) packet capture, is usually the least expensive option in a low-traffic network environment. To set up port mirroring, you configure a router or switch with port mirroring capability to forward a copy of incoming and outgoing traffic passing between selected ports to SPAN ports on the switch. Then connect the SPAN ports to the appliance.
Port mirroring has the following limitations:
Heavily used networks may result in dropped packets that are not passed to the NX Series appliance.
© 2019 FireEye
Port Mirroring (SPAN) Deployment
Port mirroring is active packet duplication. The router or switch uses its processing power to mirror the network packets and pass these packets to the NX Series device. In a heavily used network, the network quality and response times tend to degrade.
The router or switch must be configured to provide port-mirrored data to the NX Series appliance. Maintenance costs for this configuration can be higher than other configurations.
Detected malware cannot be prevented from accessing your network.
SPAN port connectivity issues may cause delays in your deployment. You may need to add a few days to troubleshoot the connectivity issues.
The following diagram illustrates the port mirroring deployment in a typical network topology.


You must configure the SPAN port correctly and test it to make sure that the mirroring ports are passing all of the traffic you want to monitor. This usually requires an administrator with networking expertise who can set up the SPAN port and run TCPDump or WireShark to monitor the traffic and verify that there is bi-directional TCP port 80 (HTTP) traffic passing through the port.
Prerequisites
Before connecting the NX 5500 appliance to your network:
Make sure that the connecting routers or switches do not provide data output greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
Determine which ports on your routers or switches provide ingress and egress data.
Cabling
Connect the appropriate cables to the NX 5500 appliance’s ports as follows:
© 2019 FireEye
14
NX Series Hardware Administration GuideCHAPTER 2: Deployment
ether1: Connect one end of the cable to the NX 5500 appliance’s ether1 port, and connect the other end to your LAN-facing switch. This will enable you to access the appliance’s Web UI.
pether3: Connect one end of the cable to the NX 5500 appliance’s pether3 port, and connect the other end to your SPAN device.
You can monitor more network segments by connecting additional SPAN devices to pether5-8.
15© 2019 FireEye
NX Series Hardware Administration GuideBefore You Begin
CHAPTER 3: Installation
This chapter provides information about the site requirements of your installation location.
Before You Begin
Follow the steps in this section before you install the appliance.
Before Opening the Box
Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.
Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.
If there appears to be damage to the box, file a damage claim with the carrier who delivered it.
Unpacking the Appliance
Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.
Ensure your box contains:
The correct appliance model
An accessory kit
Online Documents Portal Referral
A rail kit
Installation Site Guidelines
Follow these guidelines when you select an installation site:
© 2019 FireEye
16
Leave enough clearance in front of the rack for its door to open completely without obstruction.
Avoid environments that produce heat, electrical noise, and electromagnetic fields.
Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.
Make sure the location is properly ventilated.
Make sure there is sufficient space for air flow.
Rack Precautions
FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.
Consider the following before installing your appliance in the rack:
Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.
In a single-rack installation, stabilizers should be attached to the rack.
In a multiple-rack installation, the racks should be coupled together to increase their stability.
Always make sure the rack is stable before extending a component from the rack.
Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.
Ensure your rack meets the safety requirements of UL 60950-1.

STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:
Before extending the rack to the installation position, read the installation instructions.
Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.
Do not leave the slide-rail mounted equipment with the rails extended in the installation position.
Server Precautions
FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.
Review the following before installing the appliance in the rack:
Determine the placement of each component in the rack.
Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.
Install the heaviest component at the bottom of the rack first, then move up.
Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.
Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.
Keep all of the rack's doors and panels closed when you are not servicing the components.
Rack-Mounting Precautions
Consider the following safety precautions when you install the appliance in the rack:
Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.
Use an electrostatic wrist guard when handling the appliance.
At least two technicians should be involved to install the appliance safely.
FireEye recommends only individuals with rack-mounting experience should install the appliance.
Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.
Power Requirements
The NX uses a 800 W power supply unit with an input rating of 100-240 VAC (±10%), 10-5 A at 50-60 Hz.
© 2019 FireEye
NX Series Hardware Administration GuideCHAPTER 3: Installation
Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the NX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.
The NX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.
Cabling Requirements
The NX Series appliance ships with the following cables:
(2) 6 ft AC power cord, SVT, 60°C, 3x18AWG (0.824mm²)
(1) 6 ft null modem DB9 female serial cable
You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.
The SFP+ connectors on the NX 5500 are 850nm multimode ports that support a 10Gbps transmission rate. The connecting cables must not exceed 100 meters.
Rack Installation
This section explains how to install your appliance in a standard 19-inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your rack.
Installing the Inner Rails on the Appliance
Starting with either rail (each works for both sides of the appliance), pull the inner rail from the outer rail until it is fully extended.
19
© 2019 FireEye
Attaching Cables to the Appliance
Push the arrow-shaped rail-release lever on the inner rail in the direction of the arrow and slide the inner rail out until it is detached from the outer rail.
Align the notches of the inner rail with the tabs on the side of the appliance.
While firmly pressing the inner rail against the appliance, slide it in the direction of the tabs until you hear a click.
Repeat steps 1—4 with the other inner rail on the other side of the appliance.
Installing the Outer Rails on the Rack
Insert the front end of an outer rail (“Front Bracket” is engraved on the front end) into the front rack column at the desired height. A metal tab will slide and lock onto the column automatically.
Extend the rail until it reaches the rear rack column.
Insert the back end into the rack column at the same height chosen in step 1.
Repeat steps 1—3 with the other outer rail on the other side of the rack.
Mounting the Appliance on the Rack
Align the rear of the inner rails installed on the appliance with the front channels of the outer rails installed on the rack.
Fully slide the appliance into the rack. The inner and outer rails will lock together automatically.
(Optional) Further secure the appliance to the rack by using the captive screws installed on the ears of the appliance.
Attaching Cables to the Appliance
Connect the NX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.
Connect the power cable or cables to the power port or ports on the back of the appliance.
Turning On the Appliance
Power on the appliance by pressing the power button on the ear to the right of the bezel.
© 2019 FireEye
20
NX Series Hardware Administration GuideCHAPTER 3: Installation
21© 2019 FireEye
NX Series Hardware Administration Guide
Return Process
CHAPTER 4: Replacements
Return Process
If you believe you have a defective part or system, you must first contact FireEye Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit www.fireeye.com/legal.
Removing and Replacing a Disk Drive
Perform the following steps to remove and replace a disk drive:
Remove the bezel at the front of the appliance by sliding the release tab to the right and pulling the bezel away from the chassis.
Locate the disk drive carrier that contains the failed disk drive. The carrier should have a blinking amber LED.
Unlock the disk drive handle by sliding the blue tab to the left.
Push the maroon button on the right to release the latch handle.
Pull the handle to slide the disk drive from its slot.
Insert the new disk drive carrier into the available slot and push in until it clicks.
Removing and Replacing a Power Supply Unit
Perform the following steps to remove and replace a power supply unit (PSU):
© 2019 FireEye
22
NX Series Hardware Administration GuideCHAPTER 4: Replacements
At the rear of the appliance, remove the power cable from the failed PSU.
While gripping the handle to the left of the power port and pressing the release lever to the right of it, pull out the failed PSU.
Insert the replacement PSU in the open slot and slide it in until it clicks into place.
Attach the power cable to the new power supply.
Removing and Replacing a Cooling Fan
Perform the following steps to remove and replace a failed fan:
Turn off the appliance.
Using a Phillips screwdriver, remove the four screws securing the middle section of the appliance’s top cover.
Remove the middle section of the top cover.
Remove the fan from the appliance by squeezing the plastic release tab and pulling.
Insert the new fan into the empty fan bracket, ensuring it is oriented the same way as the others. You will hear a click when it is secured.
Replace the top cover and secure it with screws.
NX Series Hardware Administration Guide
Appendix 1: System Specifications
Appendices
Appendix 1: System Specifications
The table below provides the technical specifications for the FireEye NX 5500.
Component | NX 5500 Specifications |
|---|---|
Form Factor | 2U Rack-Mount |
Weight of Appliance | 42.7 lbs (19.4 kg) |
Weight of Packaged Appliance | 63.8 lbs (29.0 kg) |
Dimensions (W x D x H) | 17.2 x 24.4 x 3.4 inches (437 x 620 x 88.4 mm) |
Enclosure | 2 RU, fits 19-inch Rack |
Management Interfaces | (2) 10/100/1000BASE-T Ports |
Monitoring Interfaces | (4) 10/100/1000BASE-T Ports |
Memory | 256 GB (16 x 16 GB) |
Drive Capacity | (2) 4 TB HDD, RAID 1, |
AC Power Supply | Redundant (1+1), FRU, |
© 2019 FireEye
24
NX Series Hardware Administration GuideAppendices
Component | NX 5500 Specifications |
Maximum Power Consumption | 658 W |
Operating Temperature | 0° to 35° C |
Maximum Thermal Dissipation | 2,245 BTU/hour |
Appendix 2: Product Compliance Information
The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the FireEye NX Series appliance.
EMC | LVD/Safety | Environmental |
FCC Part 15 Class-A, CE (Class-A), CNS 13438, CISPR 32, VCCI V-3, EN 55024, EN 55032, EN 61000, ICES-003, KN 32, KN 35 | CSA 22.2, IEC 60950, EN 60950*, UL 60950 | RoHS REACH WEEE Conflict Minerals |
*All current amendments
