NX HAG 6500 PDF
NX HAG 6500 PDF
D O C U M E N T A T I O N
NX SERIES
HARDWARE ADMINISTRATION GUIDE
NX 6500
FEI-017
NX SERIES / 2020
FireEye and the FireEye logo are registered trademarks of FireEye, Inc. in the United
States and other countries. All other trademarks are the property of their respective
owners.
FireEye assumes no responsibility for any inaccuracies in this document. FireEye
reserves the right to change, modify, transfer, or otherwise revise this publication
without notice.
Copyright © 2020 FireEye, Inc. All rights reserved.
NX Series Hardware Administration Guide
Revision 2
Contents
CHAPTER 2: Deployment 10
Inline Deployment 10
Prerequisites 10
Cabling 11
Inline Proxy Deployment 11
Prerequisites 12
Cabling 12
Test Access Point (TAP) Deployment 12
Prerequisites 13
Cabling 13
Port Mirroring (SPAN) Deployment 13
Prerequisites 14
Cabling 14
CHAPTER 3: Installation 16
Before You Begin 16
Installation Site Guidelines 16
© 2020 FireEye 2
Contents
Rack Precautions 17
Server Precautions 18
Rack-Mounting Precautions 18
Power Requirements 18
Ventilation Requirements 19
Cabling Requirements 19
Rack Installation 19
Installing the Inner Rails on the Appliance 20
Installing the Outer Rails on the Rack 22
Mounting the Appliance on the Rack 23
Attaching Cables to the Appliance 24
Turning On the Appliance 24
CHAPTER 4: Replacements 26
Return Process 26
Removing and Replacing a Disk Drive 26
Removing and Replacing a Power Supply Unit 27
Appendices 28
Appendix 1: System Specifications 28
Appendix 2: Product Compliance Information 30
Technical Support 32
Documentation 32
3 © 2020 FireEye
NX Series Hardware Administration Guide
The FireEye NX 6500 stops the new generation of cyber attacks that use zero-day Web
exploits and multiprotocol malware callbacks to compromise the majority of today's
networks. When used as a standard (or integrated) appliance, the NX Series appliance
performs both monitoring and analysis functions.
When used as a sensor within FireEye Network Security, the NX 6500 only monitors traffic,
extracting objects and URLs and sending them to an MVX cluster for analysis. This allows
a flexible approach to your security solution.
For information about using the NX Series appliance as a sensor, see the Network
Security Deployment Guide for your software release.
© 2020 FireEye 4
NX Series Hardware Administration Guide CHAPTER 1: The NX 6500
Buttons
l Power Button: Use the power button to turn the appliance on or off. Turning off the
power with this button removes the main power, but keeps the standby power
supplied to the appliance. Therefore, unplug the appliance before servicing.
l Reset Button: Use the reset button to reboot the system.
LEDs
The front panel has LEDs that provide critical information about parts of the appliance.
The following table describes each LED.
5 © 2020 FireEye
The Rear View
NIC LAN 2 Blue and Blue and steady No activity Blue and steady
flashing indicates normal
indicates data connectivity on
transfer via IPMI port
IPMI port
NIC LAN 1 Blue and Blue and steady No activity Blue and steady
flashing indicates normal
indicates data connectivity on ether1
transfer via port
ether1 port
© 2020 FireEye 6
NX Series Hardware Administration Guide CHAPTER 1: The NX 6500
NOTE: Hot swap of optics is not supported on NX 6500 capture ports. If the user
hot swaps the optics, reboot the appliance or run the following command fe-
fastpath NIC reset for the new change to take effect.
Power Port
l AC Power Port: Connect your power source to this port to provide power to the
appliance. The appliance comes with one redundant power supply unit for use if
the primary unit fails.
I/O Ports
l Serial Console: Connect to this port to manage the appliance from your terminal.
Communication settings for the serial port are 115200 baud, 8 data bits, no parity, 1
stop bit.
l Video: Connect a monitor to this port to view the appliance's command-line
interface.
l USB 3.0: These ports are USB 3.0 compliant.
7 © 2020 FireEye
The Rear View
Management Ports
l ether1 (RJ45): Connect your LAN to this port to enable remote access to the CLI and
Web UI. The RJ45 connector is a 10/100/1000BASE-T port.
l IPMI: Connect for access to out-of-band management functions, including power
control, console redirection, and appliance health status. The connector is a
100BASE-T port.
Monitoring Ports
Each interface pair is physically and logically segregated from other interface pairs,
preventing communication between the different network segments.
l pether (RJ45): Connect the switch port you want to monitor to this port. The RJ45
connectors are 10/100/1000BASE-T ports.
l pether (QSFP): with 2 qualified transceivers
Link partners connected to the same port pair must have the same data
transmission rate (1 Gbps or 10 Gbps). The port pairs are as follows:
l pether3 and pether4
l pether5 and pether6
l pether7 and pether8
l pether9 and pether10
© 2020 FireEye 8
NX Series Hardware Administration Guide CHAPTER 1: The NX 6500
9 © 2020 FireEye
NX Series Hardware Administration Guide Inline Deployment
CHAPTER 2: Deployment
There are two types of deployment: inline and out-of-band. An inline deployment provides
high security by blocking all malicious traffic from reaching your network. An out-of-band
deployment only monitors malicious content as it enters your network; it does not block
malicious content.
FireEye strongly recommends using an inline deployment mode.
Deployment modes include:
Inline Deployment
The diagram below illustrates the deployment of an NX 6500 appliance installed between
the LAN and the firewall in a typical network topology.
Prerequisites
Before connecting the NX 6500 appliance to your network:
© 2020 FireEye 10
NX Series Hardware Administration Guide CHAPTER 2: Deployment
l Make sure that the connecting routers or switches do not provide data output
greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
l Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 6500 appliance’s ports as follows:
l ether1: Connect one end of the cable to the NX 6500 appliance’s ether1 port, and
connect the other end to your LAN-facing switch. This will enable you to access the
appliance’s Web UI.
l pether3: Connect one end of the cable to the NX 6500 appliance’s pether3 port, and
connect the other end to your LAN-facing switch.
l pether4: Connect one end of the cable to the NX 6500 appliance’s pether4 port, and
connect the other end to the Internet-facing switch.
You can monitor another network segment by connecting a LAN-facing switch and
an Internet-facing switch to pether5–6.
l pether 4: Connect one end of the cable to the NX 6500 appliance’s pether4 port, and
connect the other end to the firewall or WAN facing switch/router.
Alternatively, pether5-12 can be used instead, with every 2 ports forming a pair (pether3-4,
pether5-6,pether7-8, pether9-10, pether11-12).
11 © 2020 FireEye
Test Access Point (TAP) Deployment
Connect your NX 6500 appliance between two routers or switches on your network, and to
your proxy.
Prerequisites
Before connecting the NX 6500 appliance to your network:
l Make sure that the connecting routers or switches do not provide data output
greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
l Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 6500 appliance’s ports as follows:
l ether1 cable: Connect one end of the cable to the NX 6500 appliance’s ether1 port,
and connect the other end to your LAN-facing switch. This will enable you to access
the appliance’s Web UI.
l pether3 cable: Connect one end of the cable to the NX 6500 appliance’s pether3 port,
and connect the other end to the LAN-facing switch.
l pether4 cable: Connect one end of the cable to the NX 6500 appliance’s pether4 port,
and connect the other end to the proxy server.
l pether5 cable: Connect one end of the cable to the NX 6500 appliance’s pether5 port,
and connect the other end to the LAN-facing switch.
You can monitor additional proxy servers by connecting additional proxies and LAN-
facing switches to pether6—14.
l You must purchase a separate TAP device to deliver packets to the NX Series
device.
l A TAP deployment does not block malware from accessing your network.
To deploy the FireEye NX Series appliance using a TAP device, you first connect the TAP
device inline to your network. You then connect the FireEye NX Series monitoring ports to
© 2020 FireEye 12
NX Series Hardware Administration Guide CHAPTER 2: Deployment
the ingress and egress ports on the TAP device. The following diagram illustrates the TAP
deployment in a typical network topology.
Prerequisites
Before connecting the NX 6500 appliance to your network:
l Make sure that the connecting routers or switches do not provide data output
greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
l Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 6500 appliance’s ports as follows:
l ether1: Connect one end of the cable to the NX 6500 appliance’s ether1 port, and
connect the other end to your LAN-facing switch. This will enable you to access the
appliance’s Web UI.
l pether3: Connect one end of the cable to the NX 6500 appliance’s pether3 port, and
connect the other end to your TAP device.
13 © 2020 FireEye
Port Mirroring (SPAN) Deployment
l Heavily used networks may result in dropped packets that are not passed to the NX
Series appliance.
l Port mirroring is active packet duplication. The router or switch uses its processing
power to mirror the network packets and pass these packets to the NX Series device.
In a heavily used network, the network quality and response times tend to degrade.
l The router or switch must be configured to provide port-mirrored data to the NX
Series appliance. Maintenance costs for this configuration can be higher than other
configurations.
l Detected malware cannot be prevented from accessing your network.
l SPAN port connectivity issues may cause delays in your deployment. You may
need to add a few days to troubleshoot the connectivity issues.
The following diagram illustrates the port mirroring deployment in a typical network
topology.
You must configure the SPAN port correctly and test it to make sure
that the mirroring ports are passing all of the traffic you want to
monitor. This usually requires an administrator with networking
expertise who can set up the SPAN port and run TCPDump or
WireShark to monitor the traffic and verify that there is bi-directional
TCP port 80 (HTTP) traffic passing through the port.
Prerequisites
Before connecting the NX 6500 appliance to your network:
l Make sure that the connecting routers or switches do not provide data output
greater than 1 Gbps for RJ45 ports and 10 Gbps for SFP+ ports.
l Determine which ports on your routers or switches provide ingress and egress data
Cabling
Connect the appropriate cables to the NX 6500 appliance’s ports as follows:
© 2020 FireEye 14
NX Series Hardware Administration Guide CHAPTER 2: Deployment
l ether1: Connect one end of the cable to the NX 6500 appliance’s ether1 port, and
connect the other end to your LAN-facing switch. This will enable you to access the
appliance’s Web UI.
l pether3: Connect one end of the cable to the NX 6500 appliance’s pether3 port, and
connect the other end to your SPAN device.
You can monitor more network segments by connecting additional SPAN devices to
pether4-12.
15 © 2020 FireEye
NX Series Hardware Administration Guide Before You Begin
CHAPTER 3: Installation
This chapter provides information about the site requirements of your installation location.
l Review the Packing Slip contained in the plastic slip attached to the top of the box.
Ensure the shipment contains the correct appliance.
l Ensure the serial number listed on the Packing Slip matches the one specified on the
sticker located on one side of the box.
l If there appears to be damage to the box, file a damage claim with the carrier who
delivered it.
© 2020 FireEye 16
NX Series Hardware Administration Guide CHAPTER 3: Installation
l Leave enough clearance in front of the rack for its door to open completely without
obstruction.
l Avoid environments that produce heat, electrical noise, and electromagnetic fields.
l Only install the appliance in a restricted access location such as a service closet or
dedicated equipment room.
l Make sure the location is properly ventilated.
l Make sure there is sufficient space for air flow.
Rack Precautions
FireEye recommends that you mount the appliance in a standard 19-inch rack. The vertical
hole spacing on the rack rails must meet standard ANSI/EIA-310-C requirements.
Consider the following before installing your appliance in the rack:
l Ensure the leveling jacks on the bottom of the rack are fully extended to the floor
with the full weight of the rack resting on them.
l In a single-rack installation, stabilizers should be attached to the rack.
l In a multiple-rack installation, the racks should be coupled together to increase their
stability.
l Always make sure the rack is stable before extending a component from the rack.
l Only extend one component from the rack at a time—extending two or more
simultaneously may cause the rack to become unstable.
l Ensure your rack meets the safety requirements of UL 60950-1.
17 © 2020 FireEye
Server Precautions
Server Precautions
FireEye recommends reviewing the electrical and general safety precautions that came with
each component you intend to install in the rack.
Review the following before installing the appliance in the rack:
l Ensure there is a minimum clearance of six inches behind the chassis to allow for
easy cable management.
l Install the heaviest component at the bottom of the rack first, then move up.
l Allow hot-swappable power supply units, disk drives, and transceivers to cool
before handling them.
l Use a regulating uninterruptible power supply to protect your components from
voltage spikes, power surges, and failure during a power outage.
l Keep all of the rack's doors and panels closed when you are not servicing the
components.
Rack-Mounting Precautions
Consider the following safety precautions when you install the appliance in the rack:
l Make sure the appliance is grounded at all times to prevent damage from
electrostatic discharge.
l Use an electrostatic wrist guard when handling the appliance.
l At least two technicians should be involved to install the appliance safely.
l FireEye recommends only individuals with rack-mounting experience should install
the appliance.
l Install the appliance in an environment compatible with the manufacturer's
maximum recommended ambient temperature (TMRA) for each component in your
rack.
Power Requirements
The NX Series 6500 appliance uses a 1000 W power supply unit with an input rating of
100-240 VAC (±10%), 10-5 A at 50-60 Hz.
© 2020 FireEye 18
NX Series Hardware Administration Guide CHAPTER 3: Installation
Ensure your power source has sufficient electrical overload protection. In North America,
connect the rack to a power source with over-current protection that complies with UL 489.
In Europe, the over-current protection must comply with IEC standards.
Ventilation Requirements
Ventilation and optimal location are essential to the proper operation of the NX Series
appliance. Give the unit at least six inches of space around ventilation openings so that
adequate ventilation is possible.
The NX Series appliance draws air through the front and expels it out the back. Note the
direction of the air intake and exhaust of the other components in the rack to ensure safe
ventilation of all components involved.
Cabling Requirements
The NX Series appliance ships with the following cables:
You must provide any additional cables required to connect your system to the network
and other devices. Do not exceed the maximum run length of the additional cables you
provide.
Rack Installation
This section explains how to install your appliance in a standard 19-inch wide rack with
the equipment provided. Because various rack units are available, the assembly procedure
may differ slightly from the following instructions. Refer to the installation instructions
that came with your rack.
19 © 2020 FireEye
Rack Installation
2. Press the rail-release lever (located between the middle and inner rails) downward and
slide the inner rail out until it is separated from the other two rail segments.
3. Align the notches of the inner rail with the tabs on the right side of the appliance.
4. While firmly pressing the inner rail against the appliance, slide it in the direction of the
tabs until you hear a click.
© 2020 FireEye 20
NX Series Hardware Administration Guide CHAPTER 3: Installation
6. (Optional) Further secure the inner rails to the appliance with the screws provided (one
for each rail).
21 © 2020 FireEye
Rack Installation
© 2020 FireEye 22
NX Series Hardware Administration Guide CHAPTER 3: Installation
6. Insert and tighten the screws at the rear of the rails to further secure the rails to the
rack.
3. Press the rail-release notches down on both rails and slide the appliance fully into
the rack. When the appliance has been pushed completely into the rack, you should
hear the locking tabs click.
23 © 2020 FireEye
Attaching Cables to the Appliance
© 2020 FireEye 24
NX Series Hardware Administration Guide CHAPTER 3: Installation
25 © 2020 FireEye
NX Series Hardware Administration Guide Return Process
CHAPTER 4: Replacements
Return Process
If you believe you have a defective part or system, you must first contact FireEye Technical
Support, who will validate the claim. If the part or system is defective, Technical Support
will initiate a Return Materials Authorization (RMA) and guide you through the process.
For more information, visit www.fireeye.com/legal.
2. Gently remove the bezel from the appliance to reveal the disk drives.
3. Locate the disk drive carrier that contains the failed disk drive.
4. Push the maroon button to release the latch handle.
7. Use the latch handle on the new drive carrier to slide the new drive into the empty
slot. When the drive is fully inserted into the slot, push the latch handle in until it
clicks.
© 2020 FireEye 26
NX Series Hardware Administration Guide CHAPTER 4: Replacements
For appliances running a release prior to NX Series 7.2, see the About > Hardware section
of the appliance’s Web UI to verify the RAID functionality of the replacement drive.
1. At the rear of the appliance, remove the power cable from the failed PSU.
2. While gripping the handle to the left of the power port and pressing the release lever
to the right of it, pull out the failed PSU.
3. Insert the replacement PSU in the open slot and slide it in until it clicks into place.
4. Attach the power cable to the new power supply.
27 © 2020 FireEye
NX Series Hardware Administration Guide Appendix 1: System Specifications
Appendices
USB 3.0
Memory 512 GB
© 2020 FireEye 28
NX Series Hardware Administration Guide Appendices
AC Power Supply Redundant (1+1) 1000 watt, 100 - 240 VAC 10.5 – 4.0A, 50-60
Hz IEC60320-C14 inlet, FRU
29 © 2020 FireEye
Appendix 2: Product Compliance Information
FCC Part 15 Class-A, CE (Class-A), CSA 22.2, IEC 60950, EN 60950*, RoHS
CNS 13438, UL 60950 REACH
CISPR 32, VCCI V-3, WEEE
EN 55024, EN 55032, EN 61000, Conflict
Minerals
ICES-003, KN 32, KN 35
© 2020 FireEye 30
NX Series Hardware Administration Guide Appendices
31 © 2020 FireEye
Technical Support
For technical support, contact FireEye through the Support portal:
https://csportal.fireeye.com
Documentation
Documentation for all FireEye products is available on the FireEye Documentation Portal
(login required):
https://docs.fireeye.com/
© 2020 FireEye 32
FireEye, Inc. | 601 McCarthy Blvd. | Milpitas, CA | 1.408.321.6300 | 1.877.FIREEYE | www.fireeye.com
© 2020 FireEye, Inc. All rights reserved. FireEye is a registered trademark of FireEye, Inc. All other brands,
products, or service names are or may be trademarks or service marks of their respective owners.