Prerequisites:
Make sure that you have set up an NI appliance and it is up and running. For more information on how to set up and perform initial configuration of the NI appliance, refer to Network Investigator System Administration Guide. If you wish to deploy a virtual instance of the NI appliance, refer to Network Investigator Deployment Guide.
Ensure that you have added an Inspection Options policy with Layer 7 Data Collection enabled at the required domain and have assigned it to the required interfaces and sub-interfaces. This enables the Sensor(s) to export L7 metadata to the NI as per the configuration of the Client Profile. Refer to the chapter Working with Inspection options policies for more detailed information.
Perform the following steps to create a Client Profile on the NI CLI:
Log into the NI CLI using a terminal window or SSH client:
Using the SSH protocol, log into the appliance with management interface's IP address or hostname.
$ ssh npadmin@<NI IP address>
Enter the password when prompted. The
hostname > promptis displayed after you have logged in.
Enter privileged mode on the NI CLI
npadmin@hostname> enableEnter the
npadminpassword, when prompted. The password can be 5 to 24 characters long.[sudo] password for npadmin: <password>Enter configuration mode
npadmin@hostname# configure systemThe prompt changes to
npadmin@hostname(config)#on the terminal indicating that configuration mode is enabled. You can now proceed with the Client Profile configuration task.Type
client-profileat the terminal and press Enter.Client Profile configuration options are displayed on the terminal.
Note
If you already have one or more Client Profiles configured on the NI appliance, the prompt will display the names of the Client Profiles under the
Profile(s)page in ascending numerical order starting with value 0.Note
You can configure up to 20 Client Profiles on an NI appliance using its CLI.
Profile(s) ---------------------------------------- 0) IPS_Profile_SanJose 1) IPS_Profile_SantaClara ---------------------------------------- A) Add Profile #) Edit/Delete Profile Q) Exit ---------------------------------------- Enter your choice:
To add a new Client Profile, type
Ain theEnter your choicefield and press Enter.Add new profilepage is displayed with the configuration options on the terminal.Add new profile. ---------------------------------------- 1. Name : 2. L7 Metadata : ['enabled':False,'event-types':0(count)] 3. Alerts : ['enabled':False,'severity-threshold':Low] ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field ---------------------------------------- Enter your choice:
Type
1and press Enter to create a name for the Client Profile being configured. Enter the name of the profile in theEnter profile namefield and press Enter. The name given will now reflect in theNamesection.Note
If you wish to edit the Client Profile name, type 1 again in the
Enter your choicefield, and press Enter. Provide the new name and press Enter.Type
2and press Enter to setup filters related to L7 metadata that you want to be exported to the NI by the Sensors when the NI integration is enabled in the Manager.Configure l7 metadatapage is displayed on the terminal with the following configuration options.Configure l7 metadata. ---------------------------------------- 1. Enabled : False 2. Event types : 0(count) ---------------------------------------- X. Save and Return C. Cancel and Return #. Select field to configure ---------------------------------------- Enter your choice:
L7 metadata configuration is disabled by default. Type
1and Press Enter to enable it. TheEnabledfield turns toTruewhen it is enabled.To enable or disable specific protocols, type
2and press Enter.Enable/Disable event typesconfiguration is displayed in 4 pages. All the protocols are disabled by default and showsNto reflect the disabled status. TypeNand press Enter to go to the next page andPto go back to the previous page. The configuration options in all the 4 pages appear as the following on the NI CLI terminal:Enable/Disable event types Page 1/4 ------------------------------------------- 0. DCERPC N 1. DHCP N 2. DNS N 3. DNP3 N 4. FILEINFO N 5. FLOW N 6. FTP Y 7. HTTP Y 8. HTTPS Y 9. IMAP N ------------------------------------------- N. Next Page E. Enable all on page C. Cancel and Return X. Save and Return # Toggle event type status ------------------------------------------- Enter your choice:
Enable/Disable event types Page 2/4 ------------------------------------------- 0. IRC N 1. KRB5 N 2. MODBUS N 3. MQTT N 4. MYSQL N 5. NFS N 6. POP3 N 7. RADIUS N 8. RDP N 9. RFB N ------------------------------------------- N. Next Page P. Previous Page E. Enable all on page C. Cancel and Return X. Save and Return # Toggle event type status ------------------------------------------- Enter your choice:
Enable/Disable event types Page 3/4 ------------------------------------------- 0. RTSP N 1. SIP N 2. SMB N 3. SMTP Y 4. SNMP N 5. SOCKS N 6. SSH N 7. TACPLUS N 8. TFTP N 9. TLS N ------------------------------------------- P. Previous Page E. Enable all on page C. Cancel and Return X. Save and Return # Toggle event type status ------------------------------------------- Enter your choice:
Enable/Disable event types Page 4/4 ------------------------------------------- 0. WEBSOCKET N ------------------------------------------- N. Next Page E. Enable all on page C. Cancel and Return X. Save and Return # Toggle event type status ------------------------------------------- Enter your choice:
To enable a specific protocol, type the numeric value assigned to that protocol and press Enter. The status of the protocol changes to
Yto reflect the enabled mode. For example, in the configuration options presented above, you need to type7and Press Enter to enable HTTP protocol on page 1. Repeat the same procedure for all the protocols you wish to enable as per your network requirement.Note
Entering the numeric value associated with any protocol already enabled disables it, and changes the status to
Nto reflect the disabled mode.Note
Currently, IPS Sensors export L7 metadata related to HTTP, HTTPS, HTTP2, SMTP, FTP, DNS, SMB, and DCERPC protocols to NI. For SMB and DCERPC protocols, Sensors running on version 11.1 Update 8 or later, and integrated with Trellix NI, send only SmartVision attack-related L7 metadata to NI. For more information on SmartVision attacks, see Harnessing SmartVision attacks for effective threat detection and response.
Type
Eand press Enter if you wish to enable all the protocols in a page. To save and return to theConfigure l7 metadatapage, typeXand Press Enter. Or, typeCand press Enter to abort the changes made and return to theConfigure l7 metadatapage. As per the configuration options enabled, theConfigure l7 metadatapage would show theEnabledstatus andEvent typescount.Configure l7 metadata. ---------------------------------------- 1. Enabled : True 2. Event types : 30(count) ---------------------------------------- X. Save and Return C. Cancel and Return #. Select field to configure ---------------------------------------- Enter your choice:
To save and return to the
Add new profilepage, typeXand press Enter.
On
Add new profilepage, type3and press Enter to enable alerts based on alert severity thresholds.Configure alertspage is displayed on the terminal.Configure alerts. ---------------------------------------- 1. Enabled : False 2. Severity Threshold : Low ---------------------------------------- X. Save and Return C. Cancel and Return #. Select field to configure ---------------------------------------- Enter your choice:
Filters specific to alert severity threshold is disabled by default. Type
1and press Enter to enable the alert severity threshold configuration option. As a result, theEnabledstatus under theConfigure alertspage changes toTrue.You can now enable alerts as per the alert severity thresholds (Low, Medium, and High). When an alert severity threshold is set, it denotes that alerts of that level and above would be exported by the IPS Manager to NI after the successful integration between Trellix IPS and NI. The table below describes the alert severity thresholds and what they indicate:
Alert Severity Thresholds
Description
Low
Includes Low, Medium, and High severity alerts
Medium
Includes both Medium and High severity alerts
High
Includes only High severity alerts
The alert
Severity Thresholdis set toLowby default. If you wish to change it, type2and press Enter.Configure alert severity threshholdpage is displayed on the terminal:Configure alert severity threshhold. ---------------------------------------- 1. Low 2. Medium 3. High ---------------------------------------- C: Back to Prev Menu. Enter your choice:
To enable an alert severity threshold level, type the corresponding numeric value assigned to the specific severity threshold, and press Enter. For example, if you wish to view only high severity alerts on the NI after its integration, type
3and press Enter.Once the alert severity threshold level is configured, you are redirected back to the
Configure alertspage which shows theEnabledstatus and theSeverity Thresholdas configured:Configure alerts. ---------------------------------------- 1. Enabled : True 2. Severity Threshold : High ---------------------------------------- X. Save and Return C. Cancel and Return #. Select field to configure ---------------------------------------- Enter your choice:
Press
Xand press Enter to save the changes and return to theAdd new profilepage in the Client Profile configuration task.
Add new profilepage is displayed, which shows the name of the Client Profile, L7 metadata configuration status and protocol count, and alert configuration status and severity threshold as configured, The example below shows the Client Profile Name as IPS_Profile, L7 metadata configuration status enabled for 30 protocols, and alerts enabled for High severity threshold.Add new profile. ---------------------------------------- 1. Name : IPS_Profile 2. L7 Metadata : ['enabled':True,'event-types':30(count)] 3. Alerts : ['enabled':True,'severity-threshold':High] ---------------------------------------- X. Save and Return C. Cancel and Return #. Select profile field ---------------------------------------- Enter your choice:
Type
Xand press Enter to save the changes and finish the Client Profile configuration task. If you do not wish to proceed with the Client Profile configuration changes, type C and press Enter which will cancel all the configurations made and redirect you back to theProfile(s)page.Profile(s) ---------------------------------------- 0) IPS_Profile_SanJose 1) IPS_Profile_SantaClara 2) IPS_Profile ---------------------------------------- A) Add Profile #) Edit/Delete Profile Q) Exit ---------------------------------------- Enter your choice: