FIREEYE TECHNICAL DOCUMENTATION
PX SERIES / 2019
Compliance Number: FEI-007
The PX 2004ESS24

The PX 2004ESS24 is a powerful forensics tool that continuously captures packets at a high rate of speed without loss. It enables packet search and retrieval in minutes using an intelligent real-time indexing method.
The Front View

1) Disk Drive Carrier | 3) Reset Button |
2) Power Button |
|
Reset Button: Use the reset button to restart the appliance.
Power Button: Use the power button to turn the appliance on or off. Turning off the power with this button removes the main power but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.
Disk Drive Carrier: Each carrier house a hot-swappable disk drive.
The Rear View
Your appliance has one of the following configurations, depending on when you purchased it.

1) Power Port | 7) Video Port |
2) Serial Console Port | 8) SAS 1 Port |
3) IPMI/Serial over Ethernet Port | 9) SAS 2 Port |
4) USB Ports | 10) 1PPS Connector |
5) eth0 (RJ45) Management 1 Port | 11) Capture Ports |
6) eth1 (RJ45) Management 2 Port | 12) Disk Drive Carrier |

1) Power Port | 7) Serial Console Port |
2) Video Port | 8) 1PPS Connector |
3) IPMI/Serial over Ethernet Port | 9) Capture Ports |
4) USB Ports | 10) SAS 0 Port |
5) eth0 (RJ45) Management 1 Port | 11) SAS 1 Port |
6) eth1 (RJ45) Management 2 Port | 12) SAS 2 Port |
13) Disk Drive Carrier |
Power Port
Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary fails.
I/O Ports
Video: Connect a monitor to this port to view the appliance's command-line interface.
USB: The port is USB 2.0 compliant.
Serial Console: To connect a Cyclades-type serial cable, use a DB-9 to RJ45 adapter (for example, ADB0036).
1PPS: Connect a 1 PPS (pulse-per-second) timing signal to this port if your application requires an external timing signal for the PX capture ports.
SAS: Connect a PX SX appliance to this port for additional storage space. See Expanding Storage Space on page 17 for more information.
Management Ports
ether2 (RJ45): Connect your LAN to the Eth0 port to manage the appliance. The RJ45 connectors are 10/100/1000BASE-T ports.
IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 100BASE-T port. IPMI can be configured using the configure system > network command through CaptureOS.
Restrict IPMI access to trusted internal networks. Traffic from IPMI should be restricted to a management VLAN segment with strong network controls.
Capture Ports
Fixed RJ45 interface or pluggable SFP (Gigabit Ethernet ports) with RJ45 or LC fiber (multimode or singlemode) connectors
SFP (1G Gigabit Ethernet ports) and SFP+ (10 Gigabit Ethernet ports) modules with LC fiber connectors. SFP and SFP+ modules can be used in any combination.
Uncertified transceiver modules are not supported. For a list of supported transceiver modules, please contact your sales engineer.
Installation
This chapter provides information about the site requirements of your installation location, instructions for installing your appliance in the rack, and instructions for configuring your appliance for remote access.
Site Requirements
This section contains guidelines for the appropriate location of your rack unit and appliance and precautions.
Installation Site Guidelines
Follow these guidelines when you select an installation site:
Leave enough clearance in front of the rack for its door to open completely without obstruction.
Avoid environments that produce heat, electrical noise, and electromagnetic fields.
Only install the appliance in a Restricted Access Location such as a service closet or dedicated equipment room.
Make sure the location is properly ventilated.
Make sure there is sufficient space for air flow.
Rack Precautions
FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements, which call for a one-inch (2.54-cm) spacing.
Consider the following before installing your appliance in the rack:
Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.
In a single-rack installation, stabilizers should be attached to the rack.
In a multiple-rack installation, the racks should be coupled together to increase their stability.
Always make sure the rack is stable before extending a component from the rack.
Only extend one component from the rack at a time--extending two or more simultaneously may cause the rack to become unstable.
Ensure your rack meets the safety requirements of UL 60950-1.
Server Precautions
FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.
Review the following before installing the appliance in the rack:
Determine the placement of each component in the rack.
Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.
Install the heaviest component at the bottom of the rack first, then move up.
Allow hot-swappable power supply units and disk drives to cool before handling them.
Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.
Keep all of the rack's doors and panels closed when you are not servicing the components.
Rack-Mounting Precautions
Consider the following safety precautions when you install the appliance in the rack:
Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.
Use an electrostatic wrist guard when handling the appliance.
At least two technicians should be involved to install the appliance safely.
FireEye recommends only individuals with rack-mounting experience should install the appliance.
Install the appliance in an environment compatible with the manufacturer's maximum rated ambient temperature (Tmra) for each component in your rack.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the PX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.
All PX Series appliances draw air through the front and expel it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.
Cabling Requirements
The Ethernet connectors are 10/10/1000BASE-T. The connecting cables must be Category 5 or greater unshielded twisted-pair Ethernet cables with standard RJ45-compatible plugs. The maximum cable length is 100 meters.
You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.
Power Requirements
The PX 2004ESS24 uses a 1280 W power supply unit with an input rating of 100-240 VAC (±10%), 8-6 A at 50/60 Hz.
Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards. FireEye recommends that you use an uninterruptible power supply as your AC source. The power socket should be within 1.5 m (5 ft) of the rear of the appliance.
The power cable needs its own appropriately rated power socket: 110 VAC, 20 A or 240 VAC, 10 A.
US power cables are supplied. Appropriate power cables are available for locations outside the US.
Rack Installation
This chapter explains how to install your appliance in a standard 19-inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your particular rack unit.
The rack-installation process consists of three phases, as described in the following sections:
Installing the Inner Rails on the Appliance
Installing the Outer Rails on the Rack
Mounting the Appliance on the Rack
Installing the Inner Rails on the Appliance
Pull the right inner rail from the outer rail until it is fully extended.

Press the rail-release lever (located between the middle and inner rails) downward and slide the inner rail out until it is separated from the other two rail segments.


Align the notches of the inner rail with the tabs on the right side of the appliance.

While firmly pressing the inner rail against the appliance, slide it in the direction of the tabs until you hear a click.

5. Repeat steps 1-4 for the left inner rail.
6. (Optional) Further secure the inner rails to the appliance with the screws provided (one for each rail).
Installing the Outer Rails on the Rack
Press the black tabs of the right outer rail against the front rack column and insert the hooks at the desired height.

Firmly press the rail down to lock it in place.

Extend the rail until it reaches the rear rack column.
Insert the hooks and firmly press it onto the rack.
Repeat steps 1-4 to install the left outer rail.
Insert and tighten the screws at the rear of the rails to further secure the rails to the rack.
Mounting the Appliance on the Rack
Align the appliance's inner rails with the rack's outer rails.
Slide the appliance halfway into the rack.

Press the rail-release notches down on both rails and slide the appliance fully into the rack. When the appliance has been pushed completely into the rack, you should hear the locking tabs click.

Attaching Cables to your Appliance
Connect the PX 2004ESS24 to one or more network devices using the appropriate cables specific to the deployment of your choice.
Connect the power cables to the power ports on the back of the appliance.
Connect the appropriate cables for console or terminal access. See Accessing the Appliance on page 18 for more information.
Turning On the Appliance
Power on the appliance by pressing the power button next to the handle. The initial system startup will take a little longer than a typical startup because the IPMI controller must fully power up.
Expanding Storage Space
You can increase your storage space by connecting up to two PX SX appliances to your PX 2004ESS24 via the SAS ports located on the back of your appliance.
The PX 2004ESS24 appliance has two SAS ports.
To connect one PX SX appliance to a PX ESS appliance:
Connect one end of an SAS cable to the PX ESS appliance’s SAS 1 port.
Connect the other end of the SAS cable to the PX SX appliance’s SAS 1 port.
To connect two PX SX appliances to a 2U PX ESS appliance:
Connect one end of an SAS cable to the PX ESS appliance’s SAS 1 port.
Connect the other end of the SAS cable to the first PX SX storage appliance’s SAS 1 port.
Connect one end of an SAS cable to the PX ESS appliance’s SAS 2 port.
Connect the other end of the SAS cable to the second PX SX appliance’s SAS 2 port.



Baseline Configuration
This chapter contains information and instructions for performing the basic configuration of your appliance.
Accessing the Appliance
You can access the PX 2004ESS24 via a console or terminal.
To access the appliance using a console:
Connect a keyboard, mouse, and VGA monitor to the back of the appliance. See The Rear View on page 7 for more information.
Use the arrow keys on the keyboard to select PX 4.x.x for console access.
To access the appliance via a terminal server:
Connect a serial terminal device to the back of the appliance. See The Rear View on page 7 for more information.
Use the arrow keys on the keyboard to select ttyS0 (rear-panel serial port) to select terminal access.
The communications settings for the serial port are 8-bits, no parity, 1 stop bit, with no flow control. For PX Series release 4.4, the baud rate is 115,200 bps. For releases prior to 4.4, the baud rate is 38,400 bps.
End User License Agreement
When you first start up the PX 2004ESS24, you are asked to review the End User License Agreement (EULA). At any time while the EULA is displayed, you can press Q to quit. Following the license information, you have the following options:
Enter accept to move forward.
Enter eula to review it again.
Enter no to halt the system.

After entering accept, you have the option to customize your system, including IP addresses, netmask, gateway, DNS settings, and IPMI IP settings.
Restrict IPMI access to trusted internal networks. Traffic from IPMI should be restricted to a management VLAN segment with strong network controls.
After you enter this information, the system asks you to review and accept your changes. When you accept, the system automatically reboots to apply the new settings.
Logging In
The default administrative credentials are:
Username: npadmin
Password: hammerhead
Sudo Password: hammerhead
FireEye strongly recommends that you change the default log‑in information.
[IMAGE PLACEHOLDER: Circular icon indicating remote login or SSH]
This device allows remote root log in via password. FireEye recommends that you configure the SSH log in to suit your organization’s needs and policies. For additional information on SSH and remote log in, see the PX System Administration Guide.
Configuring Management Ports
This section describes how to configure the management ports on your PX 2004ESS24.

Connect your LAN to the Eth0 port at the back of your appliance. See The Rear View on page 7 for more information.
To configure the management ports:
Log into the console.
Enter enable.
Enter your password.
Enter configure system.
Enter setup.
When prompted, enter the hostname, DNS, NTP, IPMI netmask, IPMI gateway, IPv4 address, IPv4 netmask, IPv4 gateway, IPv6 address, IPv6 netmask, and IPv6 gateway.
The current settings are shown in square brackets. To use the current value, press Enter without entering a new value.
Enter y to save your changes.
Enter shell.
Enter service networking restart to restart the network services and have your changes take effect.
Required Ports and Protocols
The table below outlines the main connections for the PX 2004ESS24 appliance’s communications. Open the ports listed below on your firewall to permit these connections.
Additional ports are required for customers running PX with IA.
Source | Destination | Destination | User | Notes |
|---|---|---|---|---|
PX | Any | UDP 514 | Yes | Syslog exporting of PX log data |
PX | Any | TCP/UDP 162 | Yes | SNMP Traps |
Any | PX | TCP 8140 | Yes | Puppet management for PX |
Any | PX | TCP 5666 | Yes | Nagios NRPE |
Any | PX | UDP 161 | No | SNMP readable information |
Any | PX | TCP 22 | No | SSH management |
Any | PX | TCP 443 | No | HTTPS GUI and API access |
PX | IA/PX | TCP 1194 | No | Optional OpenVPN encryption of interdevice information |
IA/PX | PX | TCP 1194 | No | Optional OpenVPN encryption of interdevice information |
IA | ||||
Any | IA | TCP 22 | No | SSH Management access to custom "clish" shell |
Any | IA | TCP 443 | No | HTTPS GUI Access |
IA/PX | PX | TCP 1194 | No | OpenVPN encryption of interdevice information |
IA | IA/PX | TCP 1194 | No | OpenVPN encryption of interdevice information |
PX/IA | IA/PX | TCP 873 | No | Rsync metadata |
Appendices
Appendix 1: System Specifications
The table below provides the technical specifications of the FireEye PX 2004ESS24.
Component | PX 2004ESS24 Specifications |
|---|---|
Form Factor | 2U Rack-Mount |
Weight | 52 lbs (23.6 kg) |
Dimensions (W x D x H) | 17.2 x 25.5 x 3.5 inches (43.7 x 64.8 x 8.9 cm) |
Enclosure | 2 RU, Fits 19-inch Rack |
Management Interfaces | (2) 10/100/1000BASE-T Ports |
Capture Port Configuration | (4) 1 Gbps, 10/100/1000BASE-T or SFP |
Max Record Speed | 4 Gbps |
Drives Provided | (12) 3.5” 2 TB SAS hot-swappable drives |
Drive Bays | 14 |
Total Onboard Storage | 24 TB Internal, expandable SAS attached storage |
Power Supply | Redundant (1 + 1) |
Regulatory (Power Supply) | USA—UL listed Canada—CUL listed Germany—TUV Certified EN 60950/IEC 60950–Compliant CB Report CCC Certification |
Operating Temperature | 10° to 35° C |
Storage Temperature | -40° to 70° C |
Operating Humidity | 8% to 90% non-condensing |
Storage Humidity | 5% to 95% non-condensing |
Compliance Model | FEI-007 |
For technical support: https://support.trellix.com



