The following steps describe how to add stacked Suricata Sensors to the Manager:
Start the Manager software.
Log in to the Manager (the default username is
adminand the default password isadmin123).To add stacked Sensors in the Manager, go to Devices → <Admin Domain> → Global → Device Manager, then select Stacks tab.
The Stacks tab is displayed. See Stacks for more information.
Click
to add a new stack.The Stack Details window opens.
Enter the following mandatory information in the appropriate fields.
Stack Name — The stack name must begin with a letter. The maximum length of the name is 25 characters, including numbers, hyphens, underscore, periods, and letters.
Device Type — Select Suricata Stack from the drop-down.
Model Type — Select IPS-NS9600 Sensor model for stacking.
Shared Secret — The shared secret must be a minimum of 8 characters and maximum of 25 characters in length. The key cannot start with an exclamation mark nor can have any spaces. The parameters that you can use to define the key are listed below:
26 alphabets: Uppercase and lowercase (A, B, C,...Z and a,b,c,...z)
10 digits: 0 1 2 3 4 5 6 7 8 9
31 symbols: ~ ` ! @ # $ % ^ & * ( ) _ + ‑ = [ ] { } \ | ; : " ' , . < /
Note
The Sensor stack name and node ID and shared secret key that you enter in the Manager must be identical to the shared secret that you will enter later during physical installation or initialization of the Sensor (using CLI). If not, the Sensor will not be able to register itself with the Manager.
Confirm Shared Secret — Confirm the shared secret key.
Capacity — Select 120 Gbps from the drop-down.
Sync Mode — By default, Direct mode is selected.
Note
Selecting Indirect enables Offline Sensor update.
Comment — (Optional) Enter any comments about the stack being added.
Click Save.
An informational message window appears showing the names of the member Sensors in the stack. Click OK to confirm the changes.
A warning pop-up appears on screen, if there is no valid license assigned to the stack being configured. Click OK to proceed with the license assignment task.
Capacity license for: <stack name> window appears, showing a list of the licenses in use by the stack (if any) ,with details such as Grant ID, Capacity, Key, and Expiration.
A 120 Gbps throughput license is required for a NS9600 Suricata stack of 2 nodes to run. To do so, click Change License.
Assign or Change license for <stack name> window appears. Select the required capacity license(s) from the list of licenses already added to the Manager and click Assign.
If you need to add the required license to the Manager, click
and follow the steps outlined in Add a license to the Manager. Once added to the Manager, assign the selected license to the stack.An informational message appears showing that the required license(s) have been assigned to the stack. Click OK.
Note
Alternatively, you can assign licenses to the stacked NS9600 Sensors by clicking
icon under the License field of the required stack on the Stacks tab of the Device Manager page.The new stack in displayed on the Stacks tab.
You must manually push the configuration after the license is assigned to the stack. For more information on licenses, see Management of NS9600 Sensor licenses.
Close the Stacks tab.
In the Device Manager page, the member Sensor instances are displayed as <Stackname-node id> (for example, <Stackname-1> and <Stackname-2>).
Capacity
Sensor name
120 Gbps
<Stackname-1>
<Stackname-2>
Using the Sensor CLI, configure the Sensors with the same name and node ID as the names displayed in the Device Manager page.