PX SERIES / 2020
Compliance Number: FEI-013
The PX 1004S6

The FireEye PX 1004S6 is a powerful forensics tool that continuously captures packets at a high rate of speed without loss. It enables packet search and retrieval in minutes using an intelligent real-time indexing method.
The Front View

1) Power LED | 6) Ether 1 (RJ45) Management Port |
2) HDD LED | 7) Pether 3 (RJ45) Capture Port |
3) Serial Console (RJ45) Port | 8) Pether 4 (RJ45) Capture Port |
4) USB Ports | 9) Pether 5 (RJ45) Capture Port |
5) IPMI Port | 10) Pether 6 (RJ45) Capture Port |
Serial Console Port
RJ45: Connect to this port to manage the appliance from your terminal. Communication settings for the serial port are 115200 baud, 8 data bits, no parity, 1 stop bit.
IPMI Port
The connector is a 100BASE-T port.
Management Port
ether (RJ45): The RJ45 connector is a 1-Gigabit (1GbE) Ethernet port.
Capture Ports
pether3 through pether6 (RJ45): The RJ45 connectors are 1 GB Ethernet ports.
LEDs
LED | Flashing | Steady | Off | Normal State |
|---|---|---|---|---|
Power | N/A | Green and steady indicates the appliance is receiving power. | No power is supplied to the system or the host is not turned on. | Green and steady. |
HDD | Amber and flashing indicates normal HDD activity. | N/A | No HDD activity. | off |
The Rear View

1) Not used. | 3) AC Power Port |
2) Power Switch |
Power
Power Switch: Use this switch to turn the appliance on or off. Turning off the power with this switch removes the main power, but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing. This is a momentary contact switch, so pressing it briefly turns on the power.
AC Power Port: Connect your AC power source to this port to provide power to the appliance.
Installation
This chapter provides information about the site requirements of your installation location.
Before You Begin
Follow the steps in this section before you install the appliance.
Before Opening the Box
Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.
Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.
If there appears to be damage to the box, file a damage claim with the carrier who delivered it.
Unpacking the Appliance
Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.
Ensure your box contains:
The correct appliance model
An accessory kit
Online Documents Portal Referral
Installation Site Guidelines
Follow these guidelines when you select an installation site:
Leave enough clearance in front of the rack for its door to open completely without obstruction.
Avoid environments that produce heat, electrical noise, and electromagnetic fields.
Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.
Make sure the location is properly ventilated.
Make sure there is sufficient space for air flow.
Rack Precautions
FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.
Consider the following before installing your appliance in the rack:
Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.
In a single-rack installation, stabilizers should be attached to the rack.
In a multiple-rack installation, the racks should be coupled together to increase their stability.
Always make sure the rack is stable before extending a component from the rack.
Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.
Ensure your rack meets the safety requirements of UL 60950-1.
STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:
Before extending the rack to the installation position, read the installation instructions.
Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.
Do not leave the slide-rail mounted equipment with the rails extended in the installation position.

Server Precautions
FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.
Review the following before installing the appliance in the rack:
Determine the placement of each component in the rack.
Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.
Install the heaviest component at the bottom of the rack first, then move up.
Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.
Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.
Keep all of the rack's doors and panels closed when you are not servicing the components.
Rack-Mounting Precautions
Consider the following safety precautions when you install the appliance in the rack:
Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.
Use an electrostatic wrist guard when handling the appliance.
At least two technicians should be involved to install the appliance safely.
FireEye recommends only individuals with rack-mounting experience should install the appliance.
Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.
Power Requirements
The PX 1004S6 uses a 250 W power adapter unit with an input rating of 100-240 VAC (±10%), 3.5 A at 47-63 Hz.
Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.
Cabling Requirements
The PX ships with the following cables:
RJ45-to-DB9F cable
Power cable
You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the PX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.
The PX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.
Mounting the PX to the Rack
Refer to the instructions provided with the rail kit included with your appliance.
Attaching Cables to the Appliance
Connect the PX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.
Connect the power cable or cables to the power port or ports on the back of the appliance.
Turning On the Appliance
Power on the appliance by pressing the power switch on the back of the appliance.
Replacements
Return Process
If you believe you have a defective part or system, you must first contact FireEye Technical Support, who will validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials Authorization (RMA) and guide you through the process. For more information, visit https://support.trellix.com
Appendices
Appendix 1: System Specifications
The table below provides the technical specifications for the FireEye PX 1004S.
Component | PX 1004S Specifications |
|---|---|
Form Factor | 1U rack-mount |
Weight of Appliance | 18.1 lbs (8.2 kg) |
Weight of Packaged Appliance | 30.3 lbs (13.7 kg) |
Dimensions (W x D x H) | 17.2 x 19.7 x 1.7 inches (43.7 x 50.0 x 4.4 cm) |
Enclosure | 1 RU, fits 19-inch rack |
Management Interfaces | (1) 1 GbE port |
IPMI | (1) 10/100/1000BASE-T port |
Capture Ports | (4) 1 GE ports |
Storage | 6 TB (1 x 6 TB) |
Drive Capacity | Single 3.5" 6TB SATA drive, internal fixed |
AC Power Supply | Non-redundant, non-FRU, internal |
Maximum Power Consumption | 110 W |
Operating Temperature | 0° to 40° C |
Maximum Thermal Dissipation | 375 BTU/hour |
Appendix 2: Product Compliance Information
The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the PX appliance.
EMC | LVD/Safety | Environmental |
|---|---|---|
FCC Part 15 Class‑A, CE (Class‑A), CNS 13438, CISPR 32, VCCI V‑3, EN 55024, EN 55032, EN 61000, ICES‑003, KN 32, KN 35 | CSA 22.2, IEC 60950, EN 60950*, UL 60950 | RoHS |
Appendix 3: IPMI Guide
IPMI is enabled by default for PX 1004S6 appliances. The IPMI web interface provides a web based approach for accessing the Baseboard Management Controller (BMC) to manage and monitor the system's health status more easily.
IPMI Access
Perform the following steps to connect the console:
Connect the console to the appliance serial console port. Communication settings for the serial port are 115200 baud, 8 data bits, no parity, 1 stop bit.
Accept the EULA and follow the startup wizard to configure IPMI, including the IPMI IP address. You can now access the IPMI using either the static or DHCP IPMI address
Perform the following steps to access IPMI:
Configure the IP address for the BMC as desired (by default, the BMC IP has been set as static address 0.0.0.0).
Configure the IP of the remote computer and make sure the remote computer's IP address and the BMC IP address are located in the same subnet.
On the remote computer, start a web browser (FireFox is used in our example) to access the BMC secure website.
Enter the BMC URL in the address bar:
https://<BMC IP>Press Enter and you shall end up with the IPMI login page:
The following web browsers have been verified with this interface:
Firefox version 50 or later
Chrome version 66 or later

Use the default BMC LAN channel credentials (case sensitive) for login:
User name: ADMIN
Password: ADMIN
The main page appears if the login is successful:

Web Pages Menu
The menu structure of IPMI is as follows:
Main Page
Health
Sensor Status
Event Log
Configuration
Alerts
Network
SMTP
SSL
Remote Control
Server Power Control
iKVM
Main Page
The Main Page shows the BMC firmware version and BIOS version, as well as IPv4 network setting information.

NOTE There is one Alert Status icon and one Refresh button located on the top-right corner of every page (except the Login Page).
Health Page
Sensor Status
The Sensor Status page provides the latest sensor readings of threshold-based sensors on the left. The color of sensor status light represents:
GREEN: sensor reading is normal
RED: sensor reading reaches upper or lower threshold setting
GREY: no sensor reading
On the right of this page, the last 300 minutes of historic readings of a single sensor are presented. Select a sensor name to show its historic sensor readings.
There is a combo box located on the left which can be used to filter preferred sensors:
All Sensors: list all 19 sensors
Temperature Sensors: list only 4 temperature sensors
Voltage Sensors: list only 12 voltage sensors
Fan Sensors: list only 3 fan sensors
NOTE The sensor readings will not be auto-refreshed. You should click Health > Sensor Status again to get the latest readings..

On the left, select a sensor from the sensor list to see its sensor ID, entity, thresholds, historic reading curve, etc.

Event Log
The Event Log page shows the System Event Log (SEL) of the platform. For each SEL entry, you can retrieve the event ID, time stamp, sensor name and assertion and de-assertion events description.

Configuration Page
Alerts
This page provides alert setting modification, includes alert level (event severity), destination type and IP address.
NOTE The Send Test Alert will be available only for the first alert setting (no. 1)..
NOTE If you changes the Alert setting, an appropriate dialog box will open to inform you about the new configuration and the change. The dialog box will contain:
“Alert settings are changed successfully.”
For each alert, you can click the Modify button to change event severity, destination IP, email address, email subject, and message body.

Network
You can view or modify BMC IPv4 network configuration settings in this page, such as IP source (DHCP or Static IP) selection, IP address, default gateway address, etc.

The Discard button discards all unsaved settings in the network configuration page (on this page, you need to click the Save IPv4 button if you wish to save IPv4 changes). When the Discard button is clicked, only the unsaved changes to network settings will be reset to the last-saved value.

NOTE If you change a Network setting, an appropriate dialog box opens to inform you about the new configuration and the change. The dialog box will contain: “Network configuration is going to be changed. Network connectivity might be lost.”
SMTP
The SMTP page is used to modify SMTP related settings, such as server name, port number, user name, password, and sender’s address.


NOTE If you change the SMTP setting, an appropriate dialog box will be opened to inform you about the new configuration and the change. The dialog box will contain: “SMTP configuration is going to be changed. SMTP service might be interrupted.”
SSL
The SSL page is used to upload an SSL private key and certificate file, or view SSL information.

IPMI will show a “Fail to replace the certificate, uploaded files are not valid” message if either a faulty private key or certificate is uploaded. A “Missing files” message appears if you upload only a private key or certificate file, and then click the Upload button.

Remote Control Page
Server Power Control
You can issue power or reset control commands in the Server Power Control page. Available commands are:
Reset
Hard power off
Power cycle
Power on
Select an appropriate power command, and then click the Perform Action button to issue immediate command.
For any control command, IPMI disables all user input on that tab for that session for 30 seconds (counting run up from 1 to 30) once the Perform Action button is pressed and waits until the power action completes.


iKVM
On this page, click the Open iKVM button to launch the Advantech iKVM client that supports keyboard, video, and mouse redirection for remote control. The iKVM screen will open in another new tab.

NOTE The default iKVM inactivate timeout is 5 minutes.
NOTE The iKVM mouse pointer will be a normal arrow.
The iKVM console screen appears:


A tool-tip for each setting is displayed when the mouse cursor hovers at the top of each setting:
Display: Enable or disable display redirection. A colourful image will be shown if Display is in disabled mode.
Input: Enable or disable input (mouse and keyboard) redirection. This will be set as disabled if display redirection is disabled.
Auto Scale Mode: Enable or disable auto scale mode. In this mode the frame will be automatically downscaled to fit browser screen size.
Key Press Mode: Enable or disable key-press mode. Enable this in slow network condition to enhance keyboard usability. This is a feature to help the user to type in bandwidth limited conditions due to network connections or low BMC performance, etc.
Jpeg Quality: Lower jpeg quality for better performance. Higher quality setting means more bandwidth and compute power are required lead to system have lower performance then.
Scale: Scale down for better performance. The scale rate is not editable in auto scale mode.
Sampling Mode: YUV-444 has more accurate color compression which requires more bandwidth. YUV-420 has less accurate color compression which requires less bandwidth.
Keyboard Layout: Make sure the keyboard layout setting here is the same as the host system (in which the browser is opened), and also the same as the remote system (which is shown in browser). Currently we support is US and DE keyboard.
Status Bar: Show or hide the status bar on the bottom.
Soft keys on Status Bar
There are seven modification soft keys on the Status bar:
LCtrl (left Ctrl key)
LShift (left Shift key)
LAlt (left Alt key)
LGUI (Windows key)
RCtrl (Right Ctrl Key)
RShift (right Shift key)
RAlt (right Alt key)
You can use either the soft keys on the screen or press the modification keys on keyboard.
When you press a soft key on the keyboard, the soft key switches on; when you release it, the soft key switches off. If you click a soft key on screen, it will not be released until you click it again on screen or press it on keyboard.
TIPS AND TROUBLESHOOTING
Web Page Timeout
The default web page timeout setting is 5 minutes. The timer is reset for the following conditions:
Switching between the pages
Clicking on any button on any page
Security Warning Message
When you invoke IPMI or iKVM, the web browser may show the warning message shown below due to a self-signed certificate integrated into IPMI by default. You can ignore the warning and trust the connection:

Login Session Limitation
A session is identified by cookie and IP address. If you open multiple tabs in the same browser and log them all into IPMI using the same account, all these tabs are seen as the same session, so they all work.
However, if you open two different browsers or use two different IP addresses, only the session that you last logged into is valid. Any IPMI operation in the other browsers results in showing the login page. Only one session per user is allowed at one time. A new login will always kill the old session.
Log Out
Click the Logout button in the top-right corner to log out from IPMI:

Technical Support
For technical support, https://support.trellix.com