PX 2004ESS24 Hardware Administration Guide

Prev Next

FIREEYE TECHNICAL DOCUMENTATION

PX SERIES / 2019

Compliance Number: FEI-007

The PX 2004ESS24

Angled front-left view of a FireEye PX 2004ESS24 rack appliance showing the metal top and multiple front drive bays

The PX 2004ESS24 is a powerful forensics tool that continuously captures packets at a high rate of speed without loss. It enables packet search and retrieval in minutes using an intelligent real-time indexing method.

The Front View

Front view of the FireEye PX 2004ESS24 showing the full array of drive bays and left-side control panel with red numbered callouts labeled 1, 2, 3


1) Disk Drive Carrier

3) Reset Button

2) Power Button

 

  • Reset Button: Use the reset button to restart the appliance.

  • Power Button: Use the power button to turn the appliance on or off. Turning off the power with this button removes the main power but keeps the standby power supplied to the appliance. Therefore, unplug the appliance before servicing.

  • Disk Drive Carrier: Each carrier house a hot-swappable disk drive.

The Rear View

Rear view icon / notice Your appliance has one of the following configurations, depending on when you purchased it.

Rear panel photograph showing the full back of the appliance with numbered red callouts for ports and components (power supplies, drive carriers, management ports, USB, video, SAS ports, capture ports, etc.)

1) Power Port

7) Video Port

2) Serial Console Port

8) SAS 1 Port

3) IPMI/Serial over Ethernet Port

9) SAS 2 Port

4) USB Ports

10) 1PPS Connector

5) eth0 (RJ45) Management 1 Port

11) Capture Ports

6) eth1 (RJ45) Management 2 Port

12) Disk Drive Carrier

Alternate rear panel photograph with numbered callouts showing a different configuration of ports and drive carriers


1) Power Port

7) Serial Console Port

2) Video Port

8) 1PPS Connector

3) IPMI/Serial over Ethernet Port

9) Capture Ports

4) USB Ports

10) SAS 0 Port

5) eth0 (RJ45) Management 1 Port

11) SAS 1 Port

6) eth1 (RJ45) Management 2 Port

12) SAS 2 Port

13) Disk Drive Carrier

Power Port

  • Power: Connect your power source to this port to provide power to the appliance. The appliance comes with one redundant power supply unit for use if the primary fails.

I/O Ports

  • Video: Connect a monitor to this port to view the appliance's command-line interface.

  • USB: The port is USB 2.0 compliant.

  • Serial Console: To connect a Cyclades-type serial cable, use a DB-9 to RJ45 adapter (for example, ADB0036).

  • 1PPS: Connect a 1 PPS (pulse-per-second) timing signal to this port if your application requires an external timing signal for the PX capture ports.

  • SAS: Connect a PX SX appliance to this port for additional storage space. See Expanding Storage Space on page 17 for more information.

Management Ports

  • ether2 (RJ45): Connect your LAN to the Eth0 port to manage the appliance. The RJ45 connectors are 10/100/1000BASE-T ports.

  • IPMI: Connect for access to out-of-band management functions, including power control, console redirection, and appliance health status. The connector is a 100BASE-T port. IPMI can be configured using the configure system > network command through CaptureOS.

Blue exclamation mark inside a circle

Restrict IPMI access to trusted internal networks. Traffic from IPMI should be restricted to a management VLAN segment with strong network controls.

Capture Ports

  • Fixed RJ45 interface or pluggable SFP (Gigabit Ethernet ports) with RJ45 or LC fiber (multimode or singlemode) connectors

  • SFP (1G Gigabit Ethernet ports) and SFP+ (10 Gigabit Ethernet ports) modules with LC fiber connectors. SFP and SFP+ modules can be used in any combination.

Blue circular transceiver icon

Uncertified transceiver modules are not supported. For a list of supported transceiver modules, please contact your sales engineer.


Installation

This chapter provides information about the site requirements of your installation location, instructions for installing your appliance in the rack, and instructions for configuring your appliance for remote access.

Site Requirements

This section contains guidelines for the appropriate location of your rack unit and appliance and precautions.

Installation Site Guidelines

Follow these guidelines when you select an installation site:

  • Leave enough clearance in front of the rack for its door to open completely without obstruction.

  • Avoid environments that produce heat, electrical noise, and electromagnetic fields.

  • Only install the appliance in a Restricted Access Location such as a service closet or dedicated equipment room.

  • Make sure the location is properly ventilated.

  • Make sure there is sufficient space for air flow.

Rack Precautions

FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements, which call for a one-inch (2.54-cm) spacing.

Consider the following before installing your appliance in the rack:

  • Ensure the leveling jacks on the bottom of the rack are fully extended to the floor with the full weight of the rack resting on them.

  • In a single-rack installation, stabilizers should be attached to the rack.

  • In a multiple-rack installation, the racks should be coupled together to increase their stability.

  • Always make sure the rack is stable before extending a component from the rack.

  • Only extend one component from the rack at a time--extending two or more simultaneously may cause the rack to become unstable.

  • Ensure your rack meets the safety requirements of UL 60950-1.

Server Precautions

FireEye recommends reviewing the electrical and general safety precautions that came with each component you intend to install in the rack.

Review the following before installing the appliance in the rack:

  • Determine the placement of each component in the rack.

  • Ensure there is a minimum clearance of six inches behind the chassis to allow for easy cable management.

  • Install the heaviest component at the bottom of the rack first, then move up.

  • Allow hot-swappable power supply units and disk drives to cool before handling them.

  • Use a regulating uninterruptible power supply to protect your components from voltage spikes, power surges, and failure during a power outage.

  • Keep all of the rack's doors and panels closed when you are not servicing the components.

Rack-Mounting Precautions

Consider the following safety precautions when you install the appliance in the rack:

  • Make sure the appliance is grounded at all times to prevent damage from electrostatic discharge.

  • Use an electrostatic wrist guard when handling the appliance.

  • At least two technicians should be involved to install the appliance safely.

  • FireEye recommends only individuals with rack-mounting experience should install the appliance.

  • Install the appliance in an environment compatible with the manufacturer's maximum rated ambient temperature (Tmra) for each component in your rack.

Ventilation Requirements

Ventilation and optimal location are essential to the proper operation of the PX Series appliance. Give the unit at least six inches of space around ventilation openings so that adequate ventilation is possible.

All PX Series appliances draw air through the front and expel it out the back. Note the direction of the air intake and exhaust of the other components in the rack to ensure safe ventilation of all components involved.

Cabling Requirements

The Ethernet connectors are 10/10/1000BASE-T. The connecting cables must be Category 5 or greater unshielded twisted-pair Ethernet cables with standard RJ45-compatible plugs. The maximum cable length is 100 meters.

You must provide any additional cables required to connect your system to the network and other devices. Do not exceed the maximum run length of the additional cables you provide.

Power Requirements

The PX 2004ESS24 uses a 1280 W power supply unit with an input rating of 100-240 VAC (±10%), 8-6 A at 50/60 Hz.

Ensure your power source has sufficient electrical overload protection. In North America, connect the rack to a power source with over-current protection that complies with UL 489. In Europe, the over-current protection must comply with IEC standards. FireEye recommends that you use an uninterruptible power supply as your AC source. The power socket should be within 1.5 m (5 ft) of the rear of the appliance.

The power cable needs its own appropriately rated power socket: 110 VAC, 20 A or 240 VAC, 10 A.

US power cables are supplied. Appropriate power cables are available for locations outside the US.


Rack Installation

This chapter explains how to install your appliance in a standard 19-inch wide rack with the equipment provided. Because various rack units are available, the assembly procedure may differ slightly from the following instructions. Refer to the installation instructions that came with your particular rack unit.

The rack-installation process consists of three phases, as described in the following sections:

  • Installing the Inner Rails on the Appliance

  • Installing the Outer Rails on the Rack

  • Mounting the Appliance on the Rack

Installing the Inner Rails on the Appliance

  1. Pull the right inner rail from the outer rail until it is fully extended.

A metal server rail extended from its outer rail with a large red arrow overlaid pointing to the left, indicating the inner rail being pulled out.

  1. Press the rail-release lever (located between the middle and inner rails) downward and slide the inner rail out until it is separated from the other two rail segments.

Close-up circular inset showing a finger pressing the rail-release lever downward; red arrow indicates downward motion and a magnified red callout highlights the lever area.

Wider view of the inner rail and hand, with a red magnified callout showing the finger operating the release and the inner rail separated from the middle segment.

  1. Align the notches of the inner rail with the tabs on the right side of the appliance.

Front view of the appliance chassis showing the right-side tabs and the inner rail positioned for alignment with the notches.

  1. While firmly pressing the inner rail against the appliance, slide it in the direction of the tabs until you hear a click.


Close-up photo of a metal rack inner rail showing a mounting hole, a person's fingers on the rail, and a large red arrow pointing at the hole.

5. Repeat steps 1-4 for the left inner rail.

6. (Optional) Further secure the inner rails to the appliance with the screws provided (one for each rail).

Installing the Outer Rails on the Rack

  1. Press the black tabs of the right outer rail against the front rack column and insert the hooks at the desired height.


Close-up of a hand installing a server rail into a rack, showing rack unit markings 24, 23, 22 and the edge of the rack column

  1. Firmly press the rail down to lock it in place.

    Close-up of the rail being pressed down into the rack, showing the hand and rail engagement

  2. Extend the rail until it reaches the rear rack column.

  3. Insert the hooks and firmly press it onto the rack.

  4. Repeat steps 1-4 to install the left outer rail.

  5. Insert and tighten the screws at the rear of the rails to further secure the rails to the rack.


Mounting the Appliance on the Rack

  1. Align the appliance's inner rails with the rack's outer rails.

  2. Slide the appliance halfway into the rack.

Close-up of a rack rail and appliance inner rail with a large red arrow pointing at the rail-release notch area

  1. Press the rail-release notches down on both rails and slide the appliance fully into the rack. When the appliance has been pushed completely into the rack, you should hear the locking tabs click.

Appliance mounted in the rack with red arrows showing airflow/slide direction and an inset close-up of a finger pressing the rail-release notch


Attaching Cables to your Appliance

  1. Connect the PX 2004ESS24 to one or more network devices using the appropriate cables specific to the deployment of your choice.

  2. Connect the power cables to the power ports on the back of the appliance.

  3. Connect the appropriate cables for console or terminal access. See Accessing the Appliance on page 18 for more information.

Turning On the Appliance

Power on the appliance by pressing the power button next to the handle. The initial system startup will take a little longer than a typical startup because the IPMI controller must fully power up.

Expanding Storage Space

You can increase your storage space by connecting up to two PX SX appliances to your PX 2004ESS24 via the SAS ports located on the back of your appliance.

The PX 2004ESS24 appliance has two SAS ports.

To connect one PX SX appliance to a PX ESS appliance:

  1. Connect one end of an SAS cable to the PX ESS appliance’s SAS 1 port.

  2. Connect the other end of the SAS cable to the PX SX appliance’s SAS 1 port.

To connect two PX SX appliances to a 2U PX ESS appliance:

  1. Connect one end of an SAS cable to the PX ESS appliance’s SAS 1 port.

  2. Connect the other end of the SAS cable to the first PX SX storage appliance’s SAS 1 port.

  3. Connect one end of an SAS cable to the PX ESS appliance’s SAS 2 port.

  4. Connect the other end of the SAS cable to the second PX SX appliance’s SAS 2 port.

Diagram showing SAS1 and SAS2 port layout on a PX ESS appliance and a PX SX appliance with a cable connecting SAS1 ports.

Diagram showing a PX ESS appliance SAS1 connected to the first PX SX appliance SAS1, and PX ESS SAS2 connected to the second PX SX appliance SAS2.

Diagram illustrating SAS port numbering and typical cable routing between PX ESS and PX SX units (three stacked examples).

Baseline Configuration

This chapter contains information and instructions for performing the basic configuration of your appliance.

Accessing the Appliance

You can access the PX 2004ESS24 via a console or terminal.

To access the appliance using a console:

  1. Connect a keyboard, mouse, and VGA monitor to the back of the appliance. See The Rear View on page 7 for more information.

  2. Use the arrow keys on the keyboard to select PX 4.x.x for console access.

To access the appliance via a terminal server:

  1. Connect a serial terminal device to the back of the appliance. See The Rear View on page 7 for more information.

  2. Use the arrow keys on the keyboard to select ttyS0 (rear-panel serial port) to select terminal access.

Information icon — circular blue icon with the letter i

The communications settings for the serial port are 8-bits, no parity, 1 stop bit, with no flow control. For PX Series release 4.4, the baud rate is 115,200 bps. For releases prior to 4.4, the baud rate is 38,400 bps.

End User License Agreement

When you first start up the PX 2004ESS24, you are asked to review the End User License Agreement (EULA). At any time while the EULA is displayed, you can press Q to quit. Following the license information, you have the following options:

  • Enter accept to move forward.

  • Enter eula to review it again.

  • Enter no to halt the system.

Console screenshot showing a black terminal with the FireEye End User License Agreement prompt and commands such as Type accept to accept the agreement., Type eula to review the EULA again., and Type no if you do not accept the agreement.

After entering accept, you have the option to customize your system, including IP addresses, netmask, gateway, DNS settings, and IPMI IP settings.

Blue circular exclamation icon

Restrict IPMI access to trusted internal networks. Traffic from IPMI should be restricted to a management VLAN segment with strong network controls.

After you enter this information, the system asks you to review and accept your changes. When you accept, the system automatically reboots to apply the new settings.

Logging In

The default administrative credentials are:

Username: npadmin

Password: hammerhead

Sudo Password: hammerhead

FireEye strongly recommends that you change the default log‑in information.

[IMAGE PLACEHOLDER: Circular icon indicating remote login or SSH]

This device allows remote root log in via password. FireEye recommends that you configure the SSH log in to suit your organization’s needs and policies. For additional information on SSH and remote log in, see the PX System Administration Guide.

Configuring Management Ports

This section describes how to configure the management ports on your PX 2004ESS24.


Blue circular clipboard icon with a sheet of paper

Connect your LAN to the Eth0 port at the back of your appliance. See The Rear View on page 7 for more information.

To configure the management ports:

  1. Log into the console.

  2. Enter enable.

  3. Enter your password.

  4. Enter configure system.

  5. Enter setup.

  6. When prompted, enter the hostname, DNS, NTP, IPMI netmask, IPMI gateway, IPv4 address, IPv4 netmask, IPv4 gateway, IPv6 address, IPv6 netmask, and IPv6 gateway.

The current settings are shown in square brackets. To use the current value, press Enter without entering a new value.

  1. Enter y to save your changes.

  2. Enter shell.

  3. Enter service networking restart to restart the network services and have your changes take effect.

Required Ports and Protocols

The table below outlines the main connections for the PX 2004ESS24 appliance’s communications. Open the ports listed below on your firewall to permit these connections.

Additional ports are required for customers running PX with IA.


Source
Device

Destination
Device

Destination
Port

User
Configurable

Notes

PX

Any

UDP 514

Yes

Syslog exporting of PX log data

PX

Any

TCP/UDP 162

Yes

SNMP Traps

Any

PX

TCP 8140

Yes

Puppet management for PX

Any

PX

TCP 5666

Yes

Nagios NRPE

Any

PX

UDP 161

No

SNMP readable information

Any

PX

TCP 22

No

SSH management

Any

PX

TCP 443

No

HTTPS GUI and API access

PX

IA/PX

TCP 1194

No

Optional OpenVPN encryption of interdevice information

IA/PX

PX

TCP 1194

No

Optional OpenVPN encryption of interdevice information

IA

Any

IA

TCP 22

No

SSH Management access to custom "clish" shell

Any

IA

TCP 443

No

HTTPS GUI Access

IA/PX

PX

TCP 1194

No

OpenVPN encryption of interdevice information

IA

IA/PX

TCP 1194

No

OpenVPN encryption of interdevice information

PX/IA

IA/PX

TCP 873

No

Rsync metadata


Appendices

Appendix 1: System Specifications

The table below provides the technical specifications of the FireEye PX 2004ESS24.

Component

PX 2004ESS24 Specifications

Form Factor

2U Rack-Mount

Weight

52 lbs (23.6 kg)

Dimensions (W x D x H)

17.2 x 25.5 x 3.5 inches (43.7 x 64.8 x 8.9 cm)

Enclosure

2 RU, Fits 19-inch Rack

Management Interfaces

(2) 10/100/1000BASE-T Ports

Capture Port Configuration

(4) 1 Gbps, 10/100/1000BASE-T or SFP

Max Record Speed

4 Gbps

Drives Provided

(12) 3.5” 2 TB SAS hot-swappable drives

Drive Bays

14

Total Onboard Storage

24 TB Internal, expandable SAS attached storage

Power Supply

Redundant (1 + 1)
1280 W @ 100-240 VAC
8-6 A, 50/60 Hz
Auto-ranging

Regulatory (Power Supply)            

USA—UL listed

Canada—CUL listed

Germany—TUV Certified

EN 60950/IEC 60950–Compliant

CB Report

CCC Certification

Operating Temperature

10° to 35° C

Storage Temperature

-40° to 70° C

Operating Humidity

8% to 90% non-condensing

Storage Humidity

5% to 95% non-condensing

Compliance Model

FEI-007


For technical support: https://support.trellix.com