PX 1004S6 Hardware Administration Guide

Prev Next

PX SERIES / 2020

Compliance Number: FEI-013

The PX 1004S6

Front view of a FireEye PX 1004S6 1U rack appliance, silver chassis with FireEye logo

The FireEye PX 1004S6 is a powerful forensics tool that continuously captures packets at a high rate of speed without loss. It enables packet search and retrieval in minutes using an intelligent real-time indexing method.

The Front View

Front view of a FireEye appliance showing labeled ports and LEDs across the front panel

1) Power LED

6) Ether 1 (RJ45) Management Port

2) HDD LED

7) Pether 3 (RJ45) Capture Port

3) Serial Console (RJ45) Port

8) Pether 4 (RJ45) Capture Port

4) USB Ports

9) Pether 5 (RJ45) Capture Port

5) IPMI Port

10) Pether 6 (RJ45) Capture Port

Serial Console Port

RJ45: Connect to this port to manage the appliance from your terminal. Communication settings for the serial port are 115200 baud, 8 data bits, no parity, 1 stop bit.

IPMI Port

The connector is a 100BASE-T port.

Management Port

ether (RJ45): The RJ45 connector is a 1-Gigabit (1GbE) Ethernet port.

Capture Ports

pether3 through pether6 (RJ45): The RJ45 connectors are 1 GB Ethernet ports.

LEDs

LED

Flashing

Steady

Off

Normal State

Power

N/A

Green and steady indicates the appliance is receiving power.

No power is supplied to the system or the host is not turned on.

Green and steady.

HDD

Amber and flashing indicates normal HDD activity.

N/A

No HDD activity.

off

The Rear View

Rear panel of the appliance showing fans, AC power inlet, power switch, bays and numbered red callouts 1, 2, 3

1) Not used.

3) AC Power Port

2) Power Switch

Power

  • Power Switch: Use this switch to turn the appliance on or off. Turning off the power with this switch removes the main power, but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing. This is a momentary contact switch, so pressing it briefly turns on the power.

  • AC Power Port: Connect your AC power source to this port to provide power to the appliance.

Installation

This chapter provides information about the site requirements of your installation location.

Before You Begin

Follow the steps in this section before you install the appliance.

Before Opening the Box

  • Review the Packing Slip contained in the plastic slip attached to the top of the box. Ensure the shipment contains the correct appliance.

  • Ensure the serial number listed on the Packing Slip matches the one specified on the sticker located on one side of the box.

  • If there appears to be damage to the box, file a damage claim with the carrier who delivered it.

Unpacking the Appliance

Carefully remove the appliance from the box in an area away from heat, electrical noise, and electromagnetic fields.

Ensure your box contains:

  • The correct appliance model

  • An accessory kit

  • Online Documents Portal Referral

Installation Site Guidelines

Follow these guidelines when you select an installation site:

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a restricted access location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.

  • Make sure there is sufficient space for air flow.

Rack Precautions

FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time—extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

STABILITY HAZARD: The rack may tip over causing serious personal injury. To prevent injury:

  • Before extending the rack to the installation position, read the installation instructions.

  • Do not put any load on the slide-rail mounted equipment when the rails are extended in the installation position.

  • Do not leave the slide-rail mounted equipment with the rails extended in the installation position.

Yellow triangular warning icon with black exclamation mark

Server Precautions

FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

  • Allow hot-swappable power supply units, disk drives, and transceivers to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • FireEye recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum recommended ambient temperature (TMRA) for each component in your rack.

Power Requirements

The PX 1004S6 uses a 250 W power adapter unit with an input rating of 100-240 VAC (±10%), 3.5 A at 47-63 Hz.

Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards.

Cabling Requirements

The PX ships with the following cables:

  • RJ45-to-DB9F cable

  • Power cable

You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the PX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

The PX Series appliance draws air through the front and expels it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Mounting the PX to the Rack

Refer to the instructions provided with the rail kit included with your appliance.

Attaching Cables to the Appliance

  1. Connect the PX Series appliance to one or more network devices using the cables appropriate to the deployment of your choice.

  2. Connect the power cable or cables to the power port or ports on the back of the appliance.

Turning On the Appliance

Power on the appliance by pressing the power switch on the back of the appliance.

Replacements

Return Process

If you believe you have a defective part or system, you must first contact FireEye Technical Support, who will     validate the claim. If the part or system is defective, Technical Support will initiate a Return Materials     Authorization (RMA) and guide you through the process. For more information, visit https://support.trellix.com  

Appendices

Appendix 1: System Specifications

The table below provides the technical specifications for the FireEye PX 1004S.

Component

PX 1004S Specifications

Form Factor

1U rack-mount

Weight of Appliance

18.1 lbs (8.2 kg)

Weight of Packaged Appliance

30.3 lbs (13.7 kg)

Dimensions (W x D x H)

17.2 x 19.7 x 1.7 inches (43.7 x 50.0 x 4.4 cm)

Enclosure

1 RU, fits 19-inch rack

Management Interfaces

(1) 1 GbE port

IPMI

(1) 10/100/1000BASE-T port

Capture Ports

(4) 1 GE ports

Storage

6 TB (1 x 6 TB)

Drive Capacity

Single 3.5" 6TB SATA drive, internal fixed

AC Power Supply

Non-redundant, non-FRU, internal
250 W @ 100-240 VAC (±10%)
3.5 A, 47-63 Hz            

Maximum Power Consumption

110 W

Operating Temperature

0° to 40° C

Maximum Thermal Dissipation

375 BTU/hour

Appendix 2: Product Compliance Information

The following table lists the electromagnetic compatibility (EMC), low voltage directive (LVD), safety, and other regulatory standards met by the PX appliance.

EMC

LVD/Safety

Environmental

FCC Part 15 Class‑A, CE (Class‑A),           CNS 13438, CISPR 32, VCCI V‑3,               EN 55024, EN 55032, EN 61000,               ICES‑003, KN 32, KN 35            

CSA 22.2, IEC 60950, EN 60950*,               UL 60950            

                RoHS
                REACH
                WEEE
                Conflict Minerals            

Appendix 3: IPMI Guide

IPMI is enabled by default for PX 1004S6 appliances. The IPMI web interface provides a web based approach for accessing the Baseboard Management Controller (BMC) to manage and monitor the system's health status more easily.

IPMI Access

Perform the following steps to connect the console:

  1. Connect the console to the appliance serial console port. Communication settings for the serial port are 115200 baud, 8 data bits, no parity, 1 stop bit.

  2. Accept the EULA and follow the startup wizard to configure IPMI, including the IPMI IP address. You can now access the IPMI using either the static or DHCP IPMI address

Perform the following steps to access IPMI:

  1. Configure the IP address for the BMC as desired (by default, the BMC IP has been set as static address 0.0.0.0).

  2. Configure the IP of the remote computer and make sure the remote computer's IP address and the BMC IP address are located in the same subnet.

  3. On the remote computer, start a web browser (FireFox is used in our example) to access the BMC secure website.

  4. Enter the BMC URL in the address bar:

    https://<BMC IP>

  5. Press Enter and you shall end up with the IPMI login page:

The following web browsers have been verified with this interface:

  • Firefox version 50 or later

  • Chrome version 66 or later

FireEye login page screenshot showing a browser window with the FireEye logo at top-left and a centered white login box labeled Login containing Username and Password fields and a LOGIN button.

Use the default BMC LAN channel credentials (case sensitive) for login:

User name: ADMIN

Password: ADMIN

The main page appears if the login is successful:

FireEye main page screenshot showing a browser window with a blue navigation bar (Main Page, Health, Configuration, Remote Control) and a content area titled Main Page with Firmware Version and Network Information details on the left.


Web Pages Menu

The menu structure of IPMI is as follows:

  • Main Page

  • Health        

    • Sensor Status

    • Event Log

  • Configuration        

    • Alerts

    • Network

    • SMTP

    • SSL

  • Remote Control        

    • Server Power Control

    • iKVM

Main Page

The Main Page shows the BMC firmware version and BIOS version, as well as IPv4 network setting information.

A screenshot of the BMC web interface Main Page showing a browser window with a blue navigation bar containing tabs Main Page, Health, Configuration, and Remote Control, and a left column listing Firmware Version and Network Information.



red circular alert icon with white exclamation mark NOTE There is one Alert Status icon and one Refresh button located on the top-right corner of every page (except the Login Page).

Health Page

Sensor Status

The Sensor Status page provides the latest sensor readings of threshold-based sensors on the left. The color of sensor status light represents:

  • GREEN: sensor reading is normal

  • RED: sensor reading reaches upper or lower threshold setting

  • GREY: no sensor reading

On the right of this page, the last 300 minutes of historic readings of a single sensor are presented. Select a sensor name to show its historic sensor readings.

There is a combo box located on the left which can be used to filter preferred sensors:

  • All Sensors: list all 19 sensors

  • Temperature Sensors: list only 4 temperature sensors

  • Voltage Sensors: list only 12 voltage sensors

  • Fan Sensors: list only 3 fan sensors

red circular alert icon with white exclamation mark NOTE The sensor readings will not be auto-refreshed. You should click Health > Sensor Status again to get the latest readings..

FireEye Sensor Status web interface screenshot — shows FireEye logo and blue header bar at top; left pane contains a boxed sensor list with green status indicators and readings (examples: 12V, 5VCC, 5VSB, 3.3VCC) and a vertical scrollbar; right pane titled Sensor Detail displays Sensor Name, Sensor ID, Entity, Last Reading, a horizontal historic reading curve/graph with green data points, and a Thresholds bulleted list below.

On the left, select a sensor from the sensor list to see its sensor ID, entity, thresholds, historic reading curve, etc.

Additional view of the FireEye Sensor Status page showing the top portion of the interface with the blue navigation bar, status icons (Normal, Refresh, Logout), and the Sensor Status title and layout similar to the main screenshot above.


Event Log

The Event Log page shows the System Event Log (SEL) of the platform. For each SEL entry, you can retrieve the event ID, time stamp, sensor name and assertion and de-assertion events description.

Screenshot of the FireEye web interface showing the Event Log page — a browser window with a blue navigation bar and a large scrollable table titled Event log with columns such as Event ID, Time Stamp, Sensor Name and Description and many SEL entries listed.

Configuration Page

Alerts

This page provides alert setting modification, includes alert level (event severity), destination type and IP address.


NOTE The Send Test Alert will be available only for the first alert setting (no. 1)..

red circular warning icon with exclamation NOTE If you changes the Alert setting, an appropriate dialog box will open to inform you about the new configuration and the change. The dialog box will contain:

“Alert settings are changed successfully.”

For each alert, you can click the Modify button to change event severity, destination IP, email address, email subject, and message body.

FireEye web interface screenshot showing the Alerts page with a modal alert configuration dialog open (fields: Alert Number, Event Severity, Destination IP, Email Address, Subject, Message).

Network

You can view or modify BMC IPv4 network configuration settings in this page, such as IP source (DHCP or Static IP) selection, IP address, default gateway address, etc.

FireEye Network page screenshot showing LAN Channel, LAN Settings, MAC Address, and IPv4 Configuration section with IP Source set to DHCP and IPv4 Address field containing 172.17.9.141.


The Discard button discards all unsaved settings in the network configuration page (on this page, you need to click the Save IPv4 button if you wish to save IPv4 changes). When the Discard button is clicked, only the unsaved changes to network settings will be reset to the last-saved value.

Red circular warning icon with an exclamation mark

NOTE If you change a Network setting, an appropriate dialog box opens to inform you about the new configuration and the change. The dialog box will contain: “Network configuration is going to be changed. Network connectivity might be lost.”

SMTP

The SMTP page is used to modify SMTP related settings, such as server name, port number, user name, password, and sender’s address.

Screenshot of the FireEye web interface showing the SMTP configuration page with fields such as SMTP Server, SMTP Port Number, SMTP User Name, SMTP Password, and Sender’s Address

Red circular warning icon with an exclamation mark

NOTE If you change the SMTP setting, an appropriate dialog box will be opened to inform you about the new configuration and the change. The dialog box will contain: “SMTP configuration is going to be changed. SMTP service might be interrupted.”

SSL

The SSL page is used to upload an SSL private key and certificate file, or view SSL information.

Screenshot of FireEye web interface showing an SSL upload page inside a browser window, with navigation bar, status icons, and a boxed upload form labeled “UPLOAD SSL”.

IPMI will show a “Fail to replace the certificate, uploaded files are not valid” message if either a faulty private key or certificate is uploaded. A “Missing files” message appears if you upload only a private key or certificate file, and then click the Upload button.

Browser screenshot of FireEye web interface showing certificate details table and top navigation with FireEye logo

Remote Control Page

Server Power Control

You can issue power or reset control commands in the Server Power Control page. Available commands are:

  • Reset

  • Hard power off

  • Power cycle

  • Power on

Select an appropriate power command, and then click the Perform Action button to issue immediate command.

For any control command, IPMI disables all user input on that tab for that session for 30 seconds (counting run up from 1 to 30) once the Perform Action button is pressed and waits until the power action completes.

Screenshot of the FireEye web interface showing the top navigation bar, a left-side Host status: On control, and a Perform Action button on the right — IPMI Server Power Control console view.

Second screenshot showing a wider view of the FireEye Server Power Control page with the FireEye logo/header, blue navigation bar, grey Server Power Control panel, a loading spinner in the center, and a Perform Action button visible on the right.

iKVM

On this page, click the Open iKVM button to launch the Advantech iKVM client that supports keyboard, video, and mouse redirection for remote control. The iKVM screen will open in another new tab.

Screenshot of the FireEye web interface in a browser window showing the site header and a highlighted Open button on the right used to launch iKVM

Red circular warning icon NOTE The default iKVM inactivate timeout is 5 minutes.

Red circular warning icon NOTE The iKVM mouse pointer will be a normal arrow.

The iKVM console screen appears:

Browser-based iKVM window showing a blue header with the label KVM and a large black console area; visible console text reads Ubuntu 14.04.3 LTS fuw-6522c-std tty1 and fuw-6522c-std login:

Full iKVM screen showing the iKVM settings pane on the left with toggles and sliders (Display, Input, Auto Scale Mode, Key Press Mode, Jpeg Quality, Scale) and a large black console area on the right



A tool-tip for each setting is displayed when the mouse cursor hovers at the top of each setting:

Display: Enable or disable display redirection. A colourful image will be shown if Display is in disabled mode.

Input: Enable or disable input (mouse and keyboard) redirection. This will be set as disabled if display redirection is disabled.

Auto Scale Mode: Enable or disable auto scale mode. In this mode the frame will be automatically downscaled to fit browser screen size.

Key Press Mode: Enable or disable key-press mode. Enable this in slow network condition to enhance keyboard usability. This is a feature to help the user to type in bandwidth limited conditions due to network connections or low BMC performance, etc.

Jpeg Quality: Lower jpeg quality for better performance. Higher quality setting means more bandwidth and compute power are required lead to system have lower performance then.

Scale: Scale down for better performance. The scale rate is not editable in auto scale mode.

Sampling Mode: YUV-444 has more accurate color compression which requires more bandwidth. YUV-420 has less accurate color compression which requires less bandwidth.

Keyboard Layout: Make sure the keyboard layout setting here is the same as the host system (in which the browser is opened), and also the same as the remote system (which is shown in browser). Currently we support is US and DE keyboard.

Status Bar: Show or hide the status bar on the bottom.

Soft keys on Status Bar

There are seven modification soft keys on the Status bar:

  • LCtrl (left Ctrl key)

  • LShift (left Shift key)

  • LAlt (left Alt key)

  • LGUI (Windows key)

  • RCtrl (Right Ctrl Key)

  • RShift (right Shift key)

  • RAlt (right Alt key)

You can use either the soft keys on the screen or press the modification keys on keyboard.

When you press a soft key on the keyboard, the soft key switches on; when you release it, the soft key switches off. If you click a soft key on screen, it will not be released until you click it again on screen or press it on keyboard.

TIPS AND TROUBLESHOOTING

Web Page Timeout

The default web page timeout setting is 5 minutes. The timer is reset for the following conditions:

  • Switching between the pages

  • Clicking on any button on any page

Security Warning Message

When you invoke IPMI or iKVM, the web browser may show the warning message shown below due to a self-signed certificate integrated into IPMI by default. You can ignore the warning and trust the connection:

Browser security/privacy warning page titled Your connection is not private showing a red triangle icon and message, with the link text Proceed to 172.17.6.109 (unsafe) highlighted

Login Session Limitation

A session is identified by cookie and IP address. If you open multiple tabs in the same browser and log them all into IPMI using the same account, all these tabs are seen as the same session, so they all work.

However, if you open two different browsers or use two different IP addresses, only the session that you last logged into is valid. Any IPMI operation in the other browsers results in showing the login page. Only one session per user is allowed at one time. A new login will always kill the old session.

Log Out

Click the Logout button in the top-right corner to log out from IPMI:

Screenshot of the IPMI web interface (FireEye) showing the Sensor Status list on the left and Sensor Detail panel on the right; the browser window's top-right corner highlights a blue Logout button within a red outline.


Technical Support

For technical support, https://support.trellix.com