Extrahop 8.1 Admin UI Guide © 2020 Extrahop Networks, Inc
Total Page:16
File Type:pdf, Size:1020Kb
ExtraHop 8.1 Admin UI Guide © 2020 ExtraHop Networks, Inc. All rights reserved. This manual in whole or in part, may not be reproduced, translated, or reduced to any machine-readable form without prior written approval from ExtraHop Networks, Inc. For more documentation, see https://docs.extrahop.com/. Published: 2020-08-01 ExtraHop Networks Seattle, WA 98101 877-333-9872 (US) +44 (0)203 7016850 (EMEA) +65-31585513 (APAC) www.extrahop.com Contents Introduction to the ExtraHop Admin UI 8 Supported browsers 8 Status and Diagnostics 9 Health 9 Audit Log 10 Send audit log data to a remote syslog server 11 Audit log events 11 Fingerprint 15 Exception Files 15 Support Scripts 15 Run the default support script 15 Run a custom support script 16 Network Settings 17 Connect to ExtraHop Cloud Services 17 Troubleshoot your connection to ExtraHop Cloud Services 17 Configure your firewall rules 18 Connect to ExtraHop Cloud Services through a proxy 18 Bypass certificate validation 18 Connectivity 19 Configure an interface 19 Interface throughput 20 Set a static route 21 Enable IPv6 for an interface 21 Global proxy server 22 ExtraHop Cloud proxy 22 Bond interfaces 22 Create a bond interface 23 Modify bond interface settings 23 Destroy a bond interface 24 Flow Networks 24 Configure the Discover appliance to collect traffic from NetFlow and sFlow devices 24 Configure the interface on your Discover appliance 24 Configure the flow type and the UDP port over which flow data is collected 24 Add the pending flow networks on the Discover appliance 25 View configured flow networks 25 Configure Cisco NetFlow devices 26 Set up shared SNMP credentials for your NetFlow or sFlow networks 27 Manually refresh SNMP information 27 Notifications 28 Configure email settings for notifications 28 Configure an email notification group 29 Configure settings to send notifications to an SNMP manager 29 Download the ExtraHop SNMP MIB 30 Send system notifications to a remote syslog server 30 SSL Certificate 30 Upload an SSL certificate 31 ExtraHop 8.1 Admin UI Guide 3 Generate a self-signed certificate 31 Create a certificate signing request from your ExtraHop system 31 Trusted Certificates 32 Add a trusted certificate to your ExtraHop system 32 Access Settings 34 Global Policies 34 Passwords 34 Change the default password for the setup user 34 Support Access 35 Generate SSH key 35 Enable the Support UI account 35 Regenerate or revoke the SSH key 35 Users 36 Users and user groups 36 Local users 36 Remote Authentication 36 Remote users 37 User groups 37 User privileges 38 Add a local user account 41 Add an account for a remote user 41 Sessions 42 Remote Authentication 42 Configure remote authentication through LDAP 42 Configure user privileges for remote authentication 44 Configure remote authentication through SAML 45 Configure SAML single sign-on with Okta 49 Enable SAML on the ExtraHop system 49 Configure SAML settings in Okta 49 Assign the ExtraHop system to Okta groups 52 Add identity provider information on the ExtraHop system 52 Log in to the ExtraHop system 54 Configure SAML single sign-on with Google 54 Enable SAML on the ExtraHop system 54 Add user custom attributes 54 Add identity provider information from Google to the ExtraHop system 55 Add ExtraHop service provider information to Google 56 Assign user privileges 58 Log in to the ExtraHop system 59 Configure remote authentication through RADIUS 59 Configure remote authentication through TACACS+ 60 Configure the TACACS+ server 61 API Access 62 Manage API key access 62 Configure cross-origin resource sharing (CORS) 62 Generate an API key 63 Privilege levels 63 System Configuration 66 Capture 66 Exclude protocol modules 66 Exclude MAC addresses 66 Exclude an IP address or range 67 Exclude a port 67 ExtraHop 8.1 Admin UI Guide 4 Filtering and deduplication 67 Pseudo devices 68 Protocol classification 69 Add a custom protocol classification 72 Configure Device Discovery 73 Discover local devices 73 Discover remote devices by IP address 73 Discover VPN clients 74 SSL decryption 74 Upload a PEM certificate and RSA private key 75 Upload a PKCS#12/PFX file 75 Add encrypted protocols 76 Add a global port to protocol mapping 76 Install the ExtraHop session key forwarder on a Windows server 76 Install the ExtraHop session key forwarder on a Linux server 86 Supported SSL cipher suites 96 Store SSL session keys on connected Trace appliances 98 View connected session key forwarders 98 Import external data to your Discover appliance 98 Enable the Open Data Context API 98 Write a Python script to import external data 99 Write a trigger to access imported data 100 Open Data Context API example 101 Install the software tap on a Linux server 102 Download and install on RPM-based systems 102 Download and install on other Linux systems 103 Download and install on Debian-based systems 103 Install the software tap on a Windows server 104 Monitoring multiple interfaces on a Linux server 106 Monitoring multiple interfaces on a Windows server 107 Enable network overlay decapsulation 109 Enable NVGRE decapsulation 109 Enable VXLAN decapsulation 109 Analyze a packet capture file 109 Set the offline capture mode 109 Datastore 110 Local and extended datastores 110 Calculate the size needed for your extended datastore 111 Configure an extended CIFS or NFS datastore 111 Add a CIFS mount 112 (Optional) Configure Kerberos for NFS 112 Add an NFS mount 112 Specify a mount as an active extended datastore 113 Archive an extended datastore for read-only access 114 Connect your ExtraHop system to the archived datastore 114 Import metrics from an extended datastore 114 Reset the local datastore and remove all device metrics from the ExtraHop system 115 Troubleshoot issues with the extended datastore 115 Ticket Tracking 117 Geomap Data Source 117 Change the GeoIP database 117 Override an IP location 118 Open Data Streams 118 Configure an HTTP target for an open data stream 119 Configure a Kafka target for an open data stream 120 ExtraHop 8.1 Admin UI Guide 5 Configure a MongoDB target for an open data stream 121 Configure a raw data target for an open data stream 122 Configure a syslog target for an open data stream 122 ODS Details 123 Trends 124 Back up and restore a Discover or Command appliance 124 Back up a Discover or Command appliance 124 Restore a Discover or Command appliance from a system backup 125 Restore a Discover or Command appliance from a backup file 126 Transfer settings to a new Command or Discover appliance 127 Reconnect Discover appliances to the Command appliance 128 Appliance Settings 129 Running Config 129 Save system settings to the running config file 129 Edit the running config 130 Download the running config as a text file 130 Disable ICMPv6 Destination Unreachable messages 130 Disable specific ICMPv6 Echo Reply messages 130 Services 131 Configure the SNMP service 131 Firmware 132 Upgrade the firmware on your ExtraHop system 132 Pre-upgrade checklist 132 Upgrade the firmware 133 System Time 133 Configure the system time 134 Shutdown or Restart 135 Appliance Migration 135 Migrate a Discover appliance 135 Prepare the source and target appliances 137 Start the migration 138 Configure the target appliance 138 License 139 Register your ExtraHop system 139 Register the appliance 139 Troubleshoot license server connectivity 140 Apply an updated license 140 Update a license 140 Disks 141 Replace a RAID 0 disk 141 Install a new packet capture disk 142 Command Nickname 144 Configure packet capture 145 Enable packet capture 145 Encrypt the packet capture disk 145 Format the packet capture disk 146 Remove the packet capture disk 146 Configure a global packet capture 146 Configure a precision packet capture 147 View and download packet captures 148 Recordstore 149 Send records from ExtraHop to Google BigQuery 149 ExtraHop 8.1 Admin UI Guide 6 Send records from ExtraHop to BigQuery 149 Transfer recordstore settings 150 Send records from ExtraHop to Splunk 150 Send records from ExtraHop to Splunk 150 Transfer recordstore settings 151 ExtraHop Command Settings 152 Generate Token 152 Connect to a Command appliance from a Discover appliance 152 Connect a Command appliance to Discover appliances 153 Generate a token on the Discover appliance 153 Connect the Command and Discover appliances 153 Manage Discover Appliances 154 ExtraHop Explore Settings 155 Connect the Discover and Command appliances to Explore appliances 155 Disconnect the Explore appliances 156 Manage Explore Appliances 157 Collect flow records 157 ExtraHop Explore Status 158 ExtraHop Trace Settings 159 Connect the Discover and Command appliances to the Trace appliance 159 Manage Trace Appliances 160 Appendix 161 Common acronyms 161 Configure Cisco NetFlow devices 162 Configure an exporter on Cisco Nexus switch 162 Configure Cisco switches through Cisco IOS CLI 163 ExtraHop 8.1 Admin UI Guide 7 Introduction to the ExtraHop Admin UI The Admin UI Guide provides detailed information about the administrator features and functionality of the ExtraHop Discover and Command appliances. This guide provides an overview of the global navigation and information about the controls, fields, and options available throughout the UI. After you have deployed your Discover or Command appliance, see the Discover and Command Post- deployment Checklist . We value your feedback. Please let us know how we can improve this document. Send your comments or suggestions to [email protected]. Supported browsers The following browsers are compatible with all ExtraHop systems. Apply the accessibility and compatibility features provided by your browser to access content through assistive technology tools. • Firefox • Google Chrome • Microsoft Edge • Safari Important: Internet Explorer 11 is no longer supported. We recommend that you install the latest version of any supported browser. ExtraHop 8.1 Admin UI Guide 8 Status and Diagnostics The Status and Diagnostics section provides metrics about the overall health of your ExtraHop system.