Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.



Similar documents
TECHNICAL NOTE SETTING UP A STRM UPDATE SERVER. Configuring your Update Server

By default, STRM provides an untrusted SSL certificate. You can replace the untrusted SSL certificate with a self-signed or trusted certificate.

Configuring Offboard Storage Guide

After you have created your text file, see Adding a Log Source.

This technical note provides information on how to customize your notifications. This section includes the following topics:

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Using the Content Management Tool

REPLACING THE SSL CERTIFICATE

Migrating Log Manager to JSA

Juniper Secure Analytics

IF-MAP FEDERATION WITH JUNIPER NETWORKS UNIFIED ACCESS CONTROL

Identity-Based Application and Network Profiling

Identity-Based Traffic Logging and Reporting

Installing JSA Using a Bootable USB Flash Drive

NSM Plug-In Users Guide

Adaptive Log Exporter Service Update

Junos Pulse. Windows In-Box Junos Pulse Client Quick Start Guide. Published: Copyright 2013, Juniper Networks, Inc.

Parallels Virtuozzo Containers 4.7 for Linux

MIGRATING IPS SECURITY POLICY TO JUNIPER NETWORKS SRX SERIES SERVICES GATEWAYS

TECHNICAL NOTE INSTALLING AND CONFIGURING ALE USING A CLI. Installing the Adaptive Log Exporter

Managing Vulnerability Assessment

Converting SSG 300M-series and SSG 500M-series Security Devices to J-series Services Routers with a USB Storage Device

STRM Log Manager Administration Guide

Junos Space. Virtual Appliance Deployment and Configuration Guide. Release 14.1R2. Modified: Revision 2

Juniper Networks Network and Security Manager

Setting up an icap Server for ISG- 1000/2000 AV Support

How to Backup XenServer VM with VirtualIQ

Custom Notifications

How to Set Up Your NSM4000 Appliance

WinCollect User Guide

Configuration Manager Error Messages

JUNOScope IP Service Manager

Limitation of Riverbed s Quality of Service (QoS)

Log Sources Users Guide

Adaptive Log Exporter Users Guide

Introduction to Junos Space Network Director

Meeting PCI Data Security Standards with Juniper Networks Security Threat Response Manager (STRM)

Meeting PCI Data Security Standards with

Juniper Networks Management Pack Documentation

Technology Overview. Lawful Intercept Using Flow-Tap. Published: Copyright 2014, Juniper Networks, Inc.

Juniper Secure Analytics

Using Symantec NetBackup with Symantec Security Information Manager 4.5

Junos Space. Junos Space Security Director Restful Web Services API Reference. Modified: Copyright 2016, Juniper Networks, Inc.

Ciphermail Gateway Separate Front-end and Back-end Configuration Guide

Backing up the Embedded Oracle database of a Red Hat Network Satellite

Network and Security. Product Description. Product Overview. Architecture and Key Components DATASHEET

Junos Pulse Mobile Security Dashboard. User Guide. Release 4.2. February 2013 Revision , Juniper Networks, Inc.

SRC Virtualization. Modified: Copyright 2015, Juniper Networks, Inc.

Network Configuration Example

Configuring Steel-Belted RADIUS Proxy to Send Group Attributes

Acronis Storage Gateway

Moving the TRITON Reporting Databases

PRODUCT CATEGORY BROCHURE. Juniper Networks SA Series

Implementing Failover Capabilities in Red Hat Network Satellite

Network Configuration Example

Junos Pulse Mobile Security Dashboard

Juniper Secure Analytics Release Notes

PRODUCT CATEGORY BROCHURE

VMWARE VIEW WITH JUNIPER NETWORKS SA SERIES SSL VPN APPLIANCES

Junos Pulse for Google Android

Monitoring Network Traffic Using sflow Technology on EX Series Ethernet Switches

Distributing the Web server

Network Configuration Example

Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection.

Junos Space Security Director

COORDINATED THREAT CONTROL

PERFORMANCE VALIDATION OF JUNIPER NETWORKS SRX5800 SERVICES GATEWAY

Client Error Messages

Juniper Secure Analytics

Junos Space. Junos Space Network Management Platform Getting Started Guide. Release Modified:

Juniper Secure Analytics

Configuring and Implementing A10

Upgrade Guide. CA Application Delivery Analysis 10.1

Juniper Secure Analytics

WEB2CS INSTALLATION GUIDE

Installing a Symantec Backup Exec Agent on a SnapScale Cluster X2 Node or SnapServer DX1 or DX2. Summary

STRM Log Manager Users Guide

StarWind iscsi SAN & NAS: Configuring HA Storage for Hyper-V October 2012

ACL Compliance Director FAQ

SAS 9.3 Foundation for Microsoft Windows

Juniper Networks Solution Portfolio for Public Sector Network Security

Juniper Networks Network and Security Manager

Preparing for the Installation

Using Network Attached Storage with Linux. by Andy Pepperdine

Secure, Mobile Access to Corporate , Applications, and Intranet Resources

Extreme Networks Security Upgrade Guide

Novell Identity Manager Resource Kit

Junos Space. Audit Logs. Release Published: Copyright 2014, Juniper Networks, Inc.

Junos Space. Service Now User Guide. Release Published: Copyright 2013, Juniper Networks, Inc.

Cloud.com CloudStack Community Edition 2.1 Beta Installation Guide

Managing Service Design for PTP Timing

Web Filtering For Branch SRX Series and J Series

Concepts & Examples ScreenOS Reference Guide

Juniper Secure Analytics

MONITORING NETWORK TRAFFIC USING sflow TECHNOLOGY ON EX SERIES ETHERNET SWITCHES

JUNIPER CARE PLUS ADVANCED SERVICES CREDITS

Offline Data Transfer to VMWare vcloud Hybrid Service

Operating System Installation Guide

UserGuide ReflectionPKIServicesManager

Transcription:

TECHNICAL USING NFS FOR STRM BACKUPS SEPTEMBER 2013 This technical note provides guidelines and procedures for using a Network File System (NFS) storage solution in your STRM deployment. Unless otherwise noted, all references to STRM refer to STRM, STRM Log Manager, and STRM Network Anomaly Detection. This document includes the following topics: NFS Considerations Implementing NFS for Backups NFS Considerations While STRM supports NFS for external storage, we recommend that you do not use NFS for storing active data, including: Postgres Dataase - The Postgres dataase is stored in the /store/postgres/ directory. When using NFS for the /store/ directory, dataase corruption can occur when writing Postgres data to the NFS. We recommend that you mount the /store/postgres partition on a local disk, not on NFS. Ariel Dataase - The Ariel dataase is stored on the /store/ariel/ directory. Performance issues can occur if the Ariel data is stored on NFS. A series of distinct files are created y STRM for each minute, which compromises STRM performance. For example, a locally mounted storage can perform up to five times faster than NFS mounted storage. For these reasons, we recommend that you only use NFS for STRM ackups, which are stored in the /store/ackup/ directory. To do this, mount your NFS storage as the /store/ackup/ partition. For more information aout acking up your information, see the STRM Administration Guide.

2 TECHNICAL Implementing NFS for Backups To implement NFS for ackups: Perform this procedure only on the primary HA host efore adding the secondary HA host. If HA is already configured, ensure that the primary HA host is active and remove the secondary HA host. Implement the NFS for ackups on the primary HA host, and then add the secondary host ack into HA. Step 1 Step 2 Step 3 Step 4 Step 5 Step 6 Using SSH, log in to STRM as the root user: Username: root Password: <password> Add your NFS server to the /etc/hosts file: a c Edit the following file: /etc/hosts Add your NFS server to the /etc/hosts file. <IP address> nfsserver <IP address> is the IP address of your NFS server. Save and close the file Edit the iptales firewall to allow the connection to your NFS server. a Open the following file: /opt/qradar/conf/iptales.pre Add the following line: -A INPUT -i <interface> -s <IP address> -j ACCEPT <IP address> is the IP address of your NFS server. <interface> is the STRM interface on your NFS network. This is typically ETH0, unless you have a dedicated NFS network and have connected ETH1 to that network instead of ETH0. To restart iptales, type the following command: /opt/qradar/in/iptales_update.pl The NFS services are disaled y default. To add the NFS to e part of the startup, type the following commands: cd /etc/rc3.d/ chkconfig --level 3 portmap on chkconfig --level 3 nfs on chkconfig --level 3 nfslock on To manually start NFS services, type the following commands:

Implementing NFS for Backups 3 service portmap start service nfslock start service nfs start If you are implementing NFS for ackups on a secondary HA host, your NFS ackup is now mounted and operational; no further configuration is required. We recommend that you verify that the ackup files are in the shared directory from the NFS server. Step 7 Configure the /store/ackup directory: a Edit the following file: /etc/fsta Add the following line: nfsserver:<shared_directory> /store/ackup nfs soft,intr,rw 0 0 <shared_directory> is the path to your shared directory on the NFS server. You may need to adjust the settings on the NFS mount point to accommodate your configuration. For example: /nfsshare/qradar/ackup /store/ackup nfs soft,intr,rw,noac 0 0. For more information aout common NFS mount options, type man nfs to view the Unix man page for NFS. Step 8 Migrate existing ackup files to the NFS volume: a To move your ackup files from the existing /store/ackup directory to a temporary location, type the following commands: c d cd /store/ mv ackup ackup.local To create a new ackup directory, type the following command: mkdir /store/ackup To mount the NFS volume, type the following command: mount /store/ackup To set the permissions for the NFS volume, type the following command: chown noody:noody /store/ackup e To move the ackup files from the temporary location into the NFS volume, type the following command: mv /store/ackup.local/* /store/ackup Your NFS ackup is now mounted and operational. We recommend that you verify that the ackup files are in the shared directory from the NFS server.

Juniper Networks, Inc.

Implementing NFS for Backups 5 1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408-745-2000 www.juniper.net Copyright 2012 Juniper Networks, Inc. All rights reserved. Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. All specifications are suject to change without notice. Juniper Networks assumes no responsiility for any inaccuracies in this document or for any oligation to update information in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this pulication without notice.