Passive Sensor Settings
Passive Sensors are the components of the eyeInspect Suite responsible for listening to the network traffic, as well as processing and analyzing the traffic for detection and firing Alerts.
To edit a passive sensor, navigate to the Sensors Overview page and click the name of a sensor from the table to open the Manage Sensor page.
The Manage Sensor page contains the following tiles:
Sensor attributes
Displays various sensor attributes such as the name, version, state and address.
Built-in modules
Displays a list of the available built-in modules. Modules are the building blocks of a Sensor. Each Module is configurable and provides specific functionality to a Sensor.
Click a module name to view its status and access settings.
Select the checkbox in the first column for one or more modules to enable the Pause/Start, Export Modules, and Share Module Settings options.
Network whitelists
Displays the list of Communication patterns (LAN CP) and Protocol fields (DPBI), and a link to the Configure, merge and fine-tune LAN CP rules playbook.
Click the + button above the tables to add a new LAN CP profile and a DPBI profile/protocol monitor respectively.
Network intelligence framework
The Network Intelligence Framework consists of detection engines that monitor and alert for specific scenarios related to networking, security, and operations of the monitored environment. The following detection engines are available - click each engine name to know more:
The following options are available in the secondary navigation bar on the Manage Passive Sensor page:
Back
Go back to the Sensor Overview page.
Edit
Edit the opened passive sensor. The following settings are available:
Basic settings:
In the basic settings tab, you can edit the Sensor name, associate monitored networks, and configure options such as IP address reuse and default LAN CP profiles. You can also view the sensor address and UUID. Fields marked with an asterisk (*) are required.
Advanced settings:
The following advanced settings are available:
- VLAN settings:
- TCP reassembly settings
- MPLS settings
- BPF filter
- UDP processing settings
- Alert settings
- IPV6 traffic settings
- L2 hosts settings
- Dynamic IP Support Settings
- ERSPAN traffic settings
- Bandwidth throttling settings
Date and time:
The summary on the top shows the current time zone, date and time of the Sensor. These settings can be changed in this panel. The time zone can be selected from a list and is a mandatory field. Next, NTP synchronization can be enabled or disabled. When enabled, the list of NTP servers can be modified.
To add a new NTP server:
- Click the + button
- Enter the domain name or IP address of the server
To remove one or more existing NTP servers:
- Select one or more servers that you want to remove
- Click on the trash bin icon, which is shown on the top right of the table, next to the "add" icon
When the NTP synchronization is disabled, the date and time of the Sensor can be set manually by clicking Set manually on the secondary navigation bar.
After making the changes, click Finish in the secondary nav bar to save. Click Back to go back, and Reload to refresh the settings.
Diagnostics
Sensor Diagnostics reports current and historic information about the CPU, memory and disk usage, network interfaces and the amount of network traffic (bandwidth and packets) received by the Sensor, the Sensor license information and logs in the form of charts and tables. The status of a diagnostics category can be Normal, Warning, or Critical. The status is also indicated with a colored icon. The most severe status among all categories dictates the color of the health status icon on the Sensors overview page.
All categories except for the license and the logs have customizable threshold settings to determine when the status changes from Normal, Warning, or Critical and back. Licenses statuses have their own corresponding health status. If the license is valid, the status will be "Normal" When the license is about to expire (within 30 days) the status level will become "Warning" and finally when the license has expired or is invalid, the status will be "Critical".
The diagnostics charts can be viewed using two time intervals: Last 24 hours and Last 30 days. Each of these trend charts reports the information in different time frames, with a decreasing data point precision as the time range grows bigger.Today's alerts
Takes you to the Alerts page, with the current day's passive sensor alerts open in a tab.
Configuration
The Configuration menu contains the following:
Import:
Import a module or profile from your local machine.
Share settings:
Share the passive sensor settings to other sensors.
Create template:
Create a template from the passive sensor configuration.
Apply template:
Choose an existing template and apply it to the selected sensors.
Templates overview:
View the list of available sensor configuration templates. The available predefined templates are:
- Default Factory Settings
- Recommended: Contains settings recommended by Forescout Professional Services, with medium detection verbosity
- Strict Detection: Designed for detection of all alerts
- OT/Edge: Designed for deployments at Control Room level with standard detection features
- Data Center: Designed for deployments at core level with high throughput (above 2 Gbps). Aims to cover the highest possible throughput, with the least possible detailed Alerts noise
- Medical: Optimized for sensors deployed at medical facilities, with prevalence of IT traffic and default medical SD scripts loaded in
For more information, go to the passive sensor templates page.
Select one or more templates to enable the Delete option in the secondary nav bar.
PCAP
The PCAP menu has the following options:
- Captures
- Replay
Captures:
Click Captures to open the traffic captures page, which displays the following two types of captures:
- Continuous capture:
Displays a list of the available continuous captures. Click a capture name to open the parameters dialog. Here, you can edit the various parameters such as maximum size, maximum size per file, maximum duration, and choose whether or not to capture from all network interfaces and whether or not to apply restrictions.
The action menu on the top-right corner above the continuous captures tables allows you to start/stop a capture, delete capture files, download captures and update the capture list.
-
On-demand capture:
Displays a list of the available on-demand captures. Click the + icon to add a new on-demand capture.
Click an on-demand capture name to open the parameters dialog. Here you can edit the various parameters.
Select one or more on-demand captures from the list to enable the action menu on the top right corner above the captures table. This menu allows you to start/stop a capture, download the capture, clone the capture and delete the capture.
Replay:
Click Replay to open the PCAP replay page, which displays the following:
- Replay options:
Allows you to replay PCAP sensor logs. In order to replay a PCAP, select first a PCAP Replay Sensor from the ”Replay options”. Any traffic replayed will be analyzed by this Sensor. Users can either replay a new PCAP by importing the PCAP file, or can replay a previously uploaded PCAP. The option to replay a PCAP from ”New file” is selected by default. To upload a new file for replay, first click ”Browse” and select either a PCAP, a PCAPNG or a ZIP file. After a file has been selected, click ”Replay”. The file will be uploaded and a replay will be started immediately.
To replay multiple files at once, package the PCAP files into a ZIP archive. All PCAP files in the ZIP’s root directory will be automatically replayed after upload. Other PCAP files are only stored and may be replayed at a later time. After a ZIP file has been uploaded, The Available PCAP files table will have a new directory with the same name as the ZIP file. Click the small ”plus” symbol (+) in front of the directory name to expand and show the files that were extracted.
Note: If a ZIP file is uploaded, only the PCAP files contained in the ZIP ”root” folder will be automatically replayed. The content of any (sub-)folder contained in the ZIP file will be preserved during the upload, and can be replayed by selecting ”Existing file” in the ”Replay Options” panel.To manage previously uploaded files, click ”Existing file”. A list with available PCAP files will be shown. In this list, one or more items can be selected. The available operations will be shown in the upper-right corner of the table when a selection is made.
A user can delete selected files, replay a single file, or replay a single directory. The option to replay a file or directory is shown only if a single item is selected.
eyeInspect will only allow an upload of new files if there at least 6 GB of free storage space on the server. An error will be shown when there is insufficient space available. If this happens, either delete existing PCAP files, or notify the eyeInspect administrator.
- Replay log:
Shows you the log of all replays performed.
Enable/Disable encryption
Choose this option to allow the sensor to encrypt/decrypt all profiles, modules and capture PCAPs stored on disk. A confirmation dialog is displayed before starting the encryption/decryption process.
Encryption allows to protect sensitive data, e.g. in case of theft of Sensor appliances. The following data is protected, if encryption is enabled:
- Alerts
- Modules
- Detection profiles
- Traffic captures
- Network files