Prerequisite: Make sure that you have set up the NI appliance and configured one or more required Client Profiles on it using the NI CLI. For more information, refer to the topic Create a Client Profile on the NI CLI.
Perform the following steps to create a Client Group on the NI CLI:
Log into the NI CLI using a terminal window or SSH client:
Using the SSH protocol, log into the appliance with management interface's IP address or hostname.
$ ssh npadmin@<NI appliance IP address>
Enter the password when prompted. The
hostname > promptis displayed after you have logged in.
Enter privileged mode on the NI CLI
npadmin@hostname> enableEnter the
npadminpassword, when prompted. The password can be 5 to 24 characters long.[sudo] password for npadmin: <password>Enter configuration mode
npadmin@hostname# configure systemThe prompt changes to
npadmin@hostname(config)#on the terminal indicating that configuration mode is enabled. You can now proceed with the Client Group configuration task.Type
client-groupat the terminal and press Enter.Client Group configuration options are displayed in the
Group(s)page on the terminal.Note
If you have already configured one or more Client Groups configured on the NI appliance, the prompt will display the names of all Client Groups under the
Group(s)section in ascending numerical order starting with value 0.Note
You can create up to 10 Client Groups on an NI appliance using its CLI.
Group(s) Page 1/1 ---------------------------------------- 0) IPSGroup_SantaClara 1) IPSGroup_SanJose ---------------------------------------- A) Add Group #) Edit/Delete Group Q) Exit ---------------------------------------- Enter your choice:
To add a new Client Group, type
Ain theEnter your choicefield and press Enter.Add new grouppage displayed with the following configuration options.Add new group. ---------------------------------------- 1. Name : 2. Profile : 3. Poll Interval(mins) : 30 4. Flow WhiteList(count) : 0 5. Metadata Engines : [] 6. Home_Network(count) : 0 7. PX Host(count) : 0 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
Type
1and pressEnterto create a name for the Client Group being configured. Enter the name of the group in theEnter group namefield and press Enter. The name given (i.e, IPS_Group in the example below) will now reflect in theNamesection.Add new group. ---------------------------------------- 1. Name : IPS_Group 2. Profile : 3. Poll Interval(mins) : 30 4. Flow WhiteList(count) : 0 5. Metadata Engines : [] 6. Home_Network(count) : 0 7. PX Host(count) : 0 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
Note
If you wish the edit the Client Group name, type
1again in theEnter your choicefield, and press Enter. Provide the new name and press Enter.Type
2and press Enter to assign a Client Profile to the Client Group being configured.The
Profile(s)page is displayed with the list of Client Profiles configured on the NI CLI.Profile(s): ---------------------------------------------- 1 ) IPS_Profile_SanJose 2 ) IPS_Profile_SantaClara 3 ) IPS_Profile C: Back to Prev Menu. Enter your choice:
To specify a Client Profile, type the numeric value assigned to the profile and press Enter. If you wish to assign
IPS_Profile(as shown the example above) to the group being configured, type3and press Enter. The Client Profile name will now reflect in theProfilefield under theAdd new grouppage.Add new group. ---------------------------------------- 1. Name : IPS_Group 2. Profile : IPS_Profile 3. Poll Interval(mins) : 30 4. Flow WhiteList(count) : 0 5. Metadata Engines : [] 6. Home_Network(count) : 0 7. PX Host(count) : 0 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
Or, Enter
Cand then press Enter to go back to the previousAdd new grouppage menuOn
Add new grouppage menu, type3and press Enter to set up the polling interval in minutes. This polling interval duration is used by both the Manager and Sensors to retrieve the configuration and filter parameters from the Client Profile assigned and apply the configuration or any changes made in the configuration to the alert data and flow data before exporting it to the NI appliance, when it is integrated with the Trellix IPS solution.Provide the Polling interval value in minutes. You can enter any number between 30 to 1440.
Enter poll interval between 30 to 1440:38
Note
The default polling interval is set to 30 minutes.
Once set, the value assigned will reflect in the
Add group namepage menu.Add new group. ---------------------------------------- 1. Name : IPS_Group 2. Profile : IPS_Profile 3. Poll Interval(mins) : 38 4. Flow WhiteList(count) : 0 5. Metadata Engines : [] 6. Home_Network(count) : 0 7. PX Host(count) : 0 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
(Optional) Type
5and press Enter to enable the metadata engine(s).Configure detection enginespage is displayed on the terminal with the following options:Configure detection engines. ---------------------------------------- 1. Beaconing N 2. Domain Generation Algorithm N 3. Data Exfiltration N ---------------------------------------- C. Cancel and Return X. Save and Return #. Toggle detection engine status ---------------------------------------- Enter your choice:
The metadata engines are disabled by default and shows
Nto reflect the disabled status. You may choose to enable any detection engine as per your investigation requirement.To enable a specific detection engine, type the numeric value assigned to that engine and press Enter. The status of the engine changes to
Yto reflect the enabled mode. For example, in the engine configuration options presented above, you need to type3and press Enter to enable Data Exfiltration Engine that allows you to monitor alerts generated by this engine on the NI Web UI and identify any data extraction patterns or possible malicious data exfiltration attack over your network. Repeat the same procedure for any other detection engine you wish to enable.
Note
Entering the numeric value assigned to metadata engine already configured disables it, and its status changes to
Nto reflect the disabled status.To save and return to the
Add new grouppage menu, typeXand press Enter. Or, typeCand press Enter to abort the changes made and return to theAdd new grouppage menu.The names of the metadata engine(s) enabled reflect in the
Add group namepage menu.Add new group. ---------------------------------------- 1. Name : IPS_Group 2. Profile : IPS_Profile 3. Poll Interval(mins) : 38 4. Flow WhiteList(count) : 0 5. Metadata Engines : ['dga', 'beaconing', 'data-exfill'] 6. Home_Network(count) : 0 7. PX Host(count) : 0 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
(Applicable only if you have any Packet Capture (PX) appliance deployed in your network and integrated with Trellix NI), type
7and press Enter to add the PX host(s).The
PX Host(s)page is displayed on the terminal.PX Host(s): ---------------------------------------- A. Add px #. Delete px C. Cancel and return. X. Save and return. Enter your choice:
To add a PX host to the Client Group, type
Aand press Enter.The
Px(s)page opens on the terminal showing the list of IP addresses of the PX hosts connected to NI.Px(s) Page 1/1 ---------------------------------------------- 1 ) 10.1.1.1 2 ) 10.1.1.2 3 ) 10.1.1.3 ---------------------------------------- C: Back to Prev Menu. Enter your choice:
To specify a PX host, type the numeric value assigned to the host's IP address and press Enter. You are directed to the
PX Host(s)page which now reflects PX host IP address chosen by you.PX Host(s): 1) 10.1.1.1 ---------------------------------------- A. Add px #. Delete px C. Cancel and return. X. Save and return. Enter your choice:
To save and return to the
Add New Grouppage menu, typeXand press Enter. Or, typeCand press Enter to abort the changes made and return to theAdd New Grouppage menu.The
Add new group pageopens on the terminal displaying the PX host count.Add new group. ---------------------------------------- 1. Name : IPS_Group 2. Profile : IPS_Profile 3. Poll Interval(mins) : 38 4. Flow WhiteList(count) : 0 5. Metadata Engines : ['dga', 'beaconing', 'data-exfill'] 6. Home_Network(count) : 0 7. PX Host(count) : 1 ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field Enter your choice:
Important
If you have already added a PX host to a Client Group, the same PX host cannot be added to any other Client Group. As a result, the IP address of that PX host will no longer be available in the
Px(s)page during the configuration of any other Client Group.
Type
Xand press Enter to save the changes and finish the Client Group configuration task. In case you do not wish to proceed with the Client Group configuration changes, typeCand press Enter which will cancel all the configurations made for the Group and redirects back to theGroup(s)page.You would see the following message at the terminal confirming the addition of the Client Group:
added group successfully Press enter to exit
Press Enter to go back exit the
Add new grouppage menu.The
Group(s)page is displayed with the configured Client Group in the list:Group(s) Page 1/1 ---------------------------------------- 0) IPSGroup_SantaClara 1) IPSGroup_SanJose 2) IPS_Group ---------------------------------------- A) Add Group #) Edit/Delete Group Q) Exit ---------------------------------------- Enter your choice:
Enter the numeric value assigned to the Client Group configured in the
Enter your choicefield and Press Enter. The group-specific details is displayed on the terminalGroup: Token : e4c567e18214df581214db8c62sb3n03 ---------------------------------------- 1. Name : IPS_Group 2. Profile : IPS_Profile 3. Poll Interval(mins) : 38 4. Flow WhiteList(count) : 0 5. Metadata Engines : ['dga', 'beaconing', 'data-exfill'] 6. Home Network(count) : 0 7. PX Host(count) : 1 ---------------------------------------- #. Edit group field D. Delete the group X. Save and Return C. Cancel and Return Enter your choice:
Note down the authentication hash token of 32 bytes and the Client Group name which would be required at the time of configuring the Client Group on the Manager UI for successful integration of NI.