Tanium™ Appliance Deployment Guide
Total Page:16
File Type:pdf, Size:1020Kb
Tanium™ Appliance Deployment Guide Version 1.6.2 October 16, 2020 The information in this document is subject to change without notice. Further, the information provided in this document is provided “as is” and is believed to be accurate, but is presented without any warranty of any kind, express or implied, except as provided in Tanium’s customer sales terms and conditions. Unless so otherwise provided, Tanium assumes no liability whatsoever, and in no event shall Tanium or its suppliers be liable for any indirect, special, consequential, or incidental damages, including without limitation, lost profits or loss or damage to data arising out of the use or inability to use this document, even if Tanium Inc. has been advised of the possibility of such damages. Any IP addresses used in this document are not intended to be actual addresses. Any examples, command display output, network topology diagrams, and other figures included in this document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental. Please visit https://docs.tanium.com for the most current Tanium product documentation. This documentation may provide access to or information about content, products (including hardware and software), and services provided by third parties (“Third Party Items”). With respect to such Third Party Items, Tanium Inc. and its affiliates (i) are not responsible for such items, and expressly disclaim all warranties and liability of any kind related to such Third Party Items and (ii) will not be responsible for any loss, costs, or damages incurred due to your access to or use of such Third Party Items unless expressly set forth otherwise in an applicable agreement between you and Tanium. Further, this documentation does not require or contemplate the use of or combination with Tanium products with any particular Third Party Items and neither Tanium nor its affiliates shall have any responsibility for any infringement of intellectual property rights caused by any such combination. You, and not Tanium, are responsible for determining that any combination of Third Party Items with Tanium products is appropriate and will not cause infringement of any third party intellectual property rights. Tanium is committed to the highest accessibility standards to make interaction with Tanium software more intuitive and to accelerate the time to success. To ensure high accessibility standards, Tanium complies with the U.S. Federal regulations - specifically Section 508 of the Rehabilitation Act of 1998. We have conducted third-party accessibility assessments over the course of product development for many years, and most recently a comprehensive audit against the WCAG 2.1 / VPAT 2.3 standards for all major product modules was completed in September 2019. Tanium can make available any VPAT reports on a module-by-module basis as part of a larger solution planning process for any customer or prospect. © 2020 Tanium Inc. All Rights Reserved Page 2 As new products and features are continuously delivered, Tanium will conduct testing to identify potential gaps in compliance with accessibility guidelines. Tanium is committed to making best efforts to address any gaps quickly, as is feasible, given the severity of the issue and scope of the changes. These objectives are factored into the ongoing delivery schedule of features and releases with our existing resources. Tanium welcomes customer input on making solutions accessible based on your Tanium modules and assistive technology requirements. Accessibility requirements are important to the Tanium customer community and we are committed to prioritizing these compliance efforts as part of our overall product roadmap. Tanium maintains transparency on our progress and milestones and welcomes any further questions or discussion around this work. Contact your sales representative, email Tanium Support at [email protected], or email [email protected] to make further inquiries. Tanium is a trademark of Tanium, Inc. in the U.S. and other countries. Third-party trademarks mentioned are the property of their respective owners. © 2020 Tanium Inc. All rights reserved. © 2020 Tanium Inc. All Rights Reserved Page 3 Table of contents Tanium Appliance overview 22 Tanium Infrastructure types 22 Appliance roles 24 Topology 24 TanOS menus 25 Requirements 26 Tanium Appliance specifications 26 SSL certificates 26 Network connectivity and firewall 26 Internet access (direct or by proxy) 28 Proxies 28 Air gap 28 Getting started 29 Step 1: Install and configure the Tanium Appliance 29 Step 1: Set up the cloud environment 29 Step 2: Complete the initial setup 29 Step 3: Set up an Appliance Array 29 Step 4: Verify the installation 29 Completing the initial setup (hardware appliances) 30 Requirements 30 Configure temporary bootstrap network settings 30 View steps 30 Before you begin 31 © 2020 Tanium Inc. All Rights Reserved Page 4 Configure the temporary settings 31 Remote access to TanOS 31 Configure network and host settings 32 Configure user access 32 Before you begin 33 Change the default passwords 33 Add SSH keys 34 Add SSH keys for the tancopy user 34 Add SSH keys for TanOS users 37 Upload the license file (Tanium Core Platform 7.3 or earlier) 38 Steps for Tanium Core Platform 7.3 or earlier 38 Before you begin 39 Export the RAID controller security key 40 Export the grub key 43 Add TanOS system users 43 What to do next 44 Completing the initial setup (virtual appliances) 45 Requirements 45 Deploy the virtual image to the hypervisor 45 (Optional) Configure temporary bootstrap network settings 47 View steps 47 Before you begin 47 Configure the temporary settings 48 Remote access to TanOS 48 Configure network and host settings 48 © 2020 Tanium Inc. All Rights Reserved Page 5 Configure user access 49 Before you begin 50 Change the default passwords 50 Add SSH keys 50 Add SSH keys for the tancopy user 50 Add SSH keys for TanOS users 54 Upload the license file (Tanium Core Platform 7.3 or earlier) 55 Steps for Tanium Core Platform 7.3 or earlier 55 Before you begin 56 Export the grub key 57 Add TanOS system users 58 What to do next 58 Completing the initial setup (Tanium Cloud Appliance) 59 Requirements 59 Deploy the virtual image to the cloud provider 59 Remote access to TanOS 59 Configure network and host settings 60 Configure user access 60 Before you begin 61 Change the default passwords 61 Add SSH keys 61 Add SSH keys for the tancopy user 62 Add SSH keys for TanOS users 65 Upload the license file (Tanium Core Platform 7.3 or earlier) 66 Steps for Tanium Core Platform 7.3 or earlier 66 © 2020 Tanium Inc. All Rights Reserved Page 6 Before you begin 67 Export the grub key 68 Add TanOS system users 69 What to do next 69 Installing an Appliance Array 70 About Tanium clusters 70 Tanium cluster requirements and limitations 71 Before you begin 71 Import keys (optional) 72 Set up the Appliance Array 73 Create the array 73 Add members to the array 73 Assign roles 74 Install Tanium roles 74 Enable trust between Tanium Servers (Tanium Core Platform 7.4 and later) 75 Install the Zone Server Hubs 77 Configure AllowedHubs on the Tanium Zone Server appliances 77 Enable Zone Server trusts (Tanium Core Platform 7.4 and later) 78 Enable trust between the Tanium Servers and the Zone Server Hubs 78 Enable trust between the Zone Server and the Zone Server Hub 79 Set up TLS for the Tanium Server deployment (Tanium Core Platform 7.3 or earlier) 81 Tanium Core Platform version 7.3 or prior 81 Tanium Core Platform version 7.4 or later 81 What to do next 81 Installing a Tanium All-in-One role 82 © 2020 Tanium Inc. All Rights Reserved Page 7 Before you begin 82 Install the Tanium Server All-in-One role 83 What to do next 83 Installing an individual Tanium Server 84 Before you begin 84 Import keys (optional) 84 Install Tanium Server 85 Set up TLS for the Tanium Server deployment 86 Tanium Core Platform version 7.3 or prior 86 Tanium Core Platform version 7.4 or later 86 What to do next 86 Installing an individual Tanium Module Server 87 Before you begin 87 Install the Tanium Module Server 88 Configure the Tanium Server to use the remote Module Server 88 Enable the remote Module Server 88 What to do next 88 Installing an individual Tanium Zone Server 89 Overview 89 Before you begin 90 Install the Tanium Zone Server 90 Install the Zone Server 90 Import the Tanium Server public key file to the Zone Server 91 Import tanium.pub for Tanium Core Platform 7.3 and earlier 91 Import tanium-init.dat for Tanium Core Platform 7.4 and later 93 © 2020 Tanium Inc. All Rights Reserved Page 8 Install the Zone Server hub 94 Set up AllowedHubs on the Zone Server appliance 94 Configure trust mappings for 7.4 and later 95 Approve trust for the Zone Server Hub 95 Map the Zone Server to the Zone Server Hub 96 Set up TLS for the Tanium Zone Server 7.3 and earlier 99 Verifying the installation 100 Sign into the Tanium Console 100 Upload the Tanium license 101 Deploy the Tanium Client to your lab computers 101 Verify the basic deployment 101 Verify the Zone Server deployment 102 Verify a Tanium Cluster deployment 103 Deploying a standby Module Server 106 About the standby Module Server 106 Requirements and limitations 106 Before you begin 106 Set up the IPsec tunnel 107 Configure Sync 108 Perform a manual sync 108 Schedule sync jobs 108 View detailed status for Module Server sync 109 Add the Module server to the Appliance Array 109 Upgrading Tanium Appliance software 110 About Tanium Appliance software versions 110 © 2020 Tanium Inc.