Series 4 and Series 5 Hardware Appliance Imaging Guide Contents Introduction 2 RESOURCES REQUIRED 2 Creating a Security Analytics USB Build Stick 3 UNIVERSAL NETBOOT INSTALLER (UNEBOOTIN) TOOL 3 CURRENT SECURITY ANALYTICS SOFTWARE ISO FILE VERSIONS 3 SECURITY ANALYTICS 10.X VERSION ISO FILES 3 Procedures 4 CREATE A SECURITY ANALYTICS USB BUILD STICK 4 COMPLETING THE BUILD STICK PROCESS 7 Imaging Process 8 Contacting Customer Care 12 Copyright 2010-2016 by RSA, The Security Division of EMC 1
Introduction These instructions tell you how to image an RSA Security Analytics host with the Security Analytics software image. This procedure covers the Series 4S and Series 5 Security Analytics appliance. Caution: Follow these instructions EXACTLY as stated. Failure to do so will result in a broken installation. Resources Required In order to complete these steps, you need the following tools: RSA Security Analytics host Universal Netboot Installer tool available here: http://sourceforge.net/projects/unetbootin/?source=directory. A utility to open ISO files and extract component files, such as WinZip or 7 Zip. Security Analytics USB and usbboot ISO files. Security Analytics ISO file. USB thumb drive with 4 GB capacity. Copyright 2010-2016 by RSA, The Security Division of EMC 2
Creating a Security Analytics USB Build Stick Note: You MUST use a flash drive that has a minimum of 4 GB with a USB drive that formatted as FAT32. Be sure to follow these instructions to create a USB build stick to load the operating system and Security Analytics software on your Security Analytics appliance. Universal Netboot Installer (UNebootin) Tool UNetbootin is an automated tool that helps create the build stick. It is available at http://unetbootin.sourceforge.net/. Current Security Analytics Software ISO File Versions When installing software on your Security Analytics appliance, make sure you are using the most recent release of the version you want installed unless you have been instructed to use an older release by Technical Support. Security Analytics 10.x Version ISO Files sa-upgrade-version-number-usb.iso sainstall-version-number-usbboot.iso Contact Security Analytics Technical Support at nwsupport@rsa.com for assistance. Copyright 2010-2016 by RSA, The Security Division of EMC 3
Procedures This section tells you how to: Create a Security Analytics USB build stick. Copy the ISO to the USB thumb drive. Create a Security Analytics USB Build Stick Warning: All existing data on the USB thumb drive will be destroyed. 1. Insert the USB thumb drive that you will use as the build stick. 2. Launch the UNetbootin tool. 3. Select the Diskimage radio button. 4. Select the USBDrive in the Type drop-down menu, and select the appropriate drive location from the Drive drop-down menu. 5. Select the appropriate version of the Security Analytics ISO by clicking on and navigating to the ISO file on the drive. Copyright 2010-2016 by RSA, The Security Division of EMC 4
6. Select the sa-upgrade-version-number-usbboot.iso file and click Open to select the ISO file. 7. Confirm the Type is set to USB Drive and the Drive is set to the appropriate USB drive. Click OK to start the build process. 8. Click OK to start the build process. The next two dialog boxes do not always appear when you create a build stick. However, when these dialog boxes are encountered, they may pop under other open windows, which bring the process to a halt until the messages are dismissed. Copyright 2010-2016 by RSA, The Security Division of EMC 5
If you receive a dialog box stating TRANS.TBL exists, overwrite?, select Yes to All and proceed. If you receive a dialog box stating The file E:\syslinux\menu.c32 already exists, select Yes to All. 9. Click Exit to complete the automated file extraction. Note: Do not click Reboot Now unless you want to reboot your Windows system. Copyright 2010-2016 by RSA, The Security Division of EMC 6
Completing the Build Stick Process Once you finish creating the build stick, the ISO file must be manually copied to the USB build stick. 1. Copy the sa-upgrade-version-number-usb.iso file into the root directory of the USB drive. Note: This file is over 2GB in size and takes several minutes to copy to the USB drive. Do not open the file. 2. Eject your USB build stick and remove it from the workstation. The build stick process is complete and the build stick is now ready to use. Copyright 2010-2016 by RSA, The Security Division of EMC 7
Imaging Process The following instructions explain how to image a Security Analytics appliance using the build stick created in the previous sections. 1. Plug the build stick into one of the USB ports on the Security Analytics appliance. 2. Power on or reboot the Security Analytics appliance. 3. During POST, press F11 to enter Boot Manager. The password is rsabios. 4. Select BIOS Boot Menu. 5. Select Hard drive C, and select the option that corresponds to the USB Drive. Press Enter. 6. The unit will load the Security Analytics Imaging Menu. An example 10.6 Security Analytics Imaging Menu is shown below. The menu items may change based on the Security Analytics version. 7. After you select the hardware type (in this example, RSA Qualified Hardware Installations), a submenu for all installations in your selected category is displayed, as shown in the following example. Copyright 2010-2016 by RSA, The Security Division of EMC 8
The following example displays the actual service that is installed. 8. Using the matrix shown in the following table, select the correct software version for the unit being imaged and press Enter. Copyright 2010-2016 by RSA, The Security Division of EMC 9
Product Name SKU Imaging Menu Series 4S Archiver Series 4S Analytics Server Series 4S Broker Series 4S Log Concentrator Series 4S Packet Concentrator Series 4S Log Decoder Series 4S Packet Decoder Series 4S Event Stream Analysis Series 5 Analytic Server Series 5 Hybrid for Logs Series 5 Hybrid for Packets Series 5 Archiver Series 5 Broker Series 5 Event Stream Analysis Series 5 Log Concentrator SA-S4H- ARCH-BR SA-S4H-AS- BH SA-S4H-BRO- BH SA-S4H-L- CON-BH SA-S4H-P- CON-BH SA-S4H-L- DEC- BH SA-S4H-P- DEC-BH SA-S4H-ESA- BR SA-S5H-AS- BH SA-S5- HYBRID-L-BH SA-S5- HYBRD-P-BH SA-S5H- ARCH-BH SA-S5H-BRO- BH SA-S5H-ESA- BH SA-S5H-L- CON-BH SA Archiver and ESA > Install Series IV/S: Archiver SA Server and SAW > Install Series IV/S: Security Analytics Server IV/S: Broker IV/S: Concentrator IV/S: Concentrator IV/S: Log IV/S: Packet SA Archiver and ESA > Series IV/S Newport: Event Stream Analysis SA Server and SAW > Install Series V/S: Security Analytics Server Install /Upgrade Series IV /S Newport - V : Logs Hybrid Install /Upgrade Series III - V : Packet Hybrid SA Archiver and ESA > Install Series V/S: Archiver V/S: Broker SA Archiver and ESA > Series V/S Newport: Event Stream Analysis Copyright 2010-2016 by RSA, The Security Division of EMC 10
V/S: Concentrator Series 5 Log Decoder SA-S5H-L-DEC-BH V/S: Log Series 5 Malware Series 5 Packet Concentrator Series 5 Packet Decoder SA-S5H- MAL-BH SA-S5H-P- CON-BH SA-S5H-P- DEC-BH SA Malware Protection > Install Series V/S Newport: Malware Protection V/S: Concentrator V/S: Packet 9. A Clear logical drive warning will appear. You must select yes by typing y, otherwise the software will default to no in 20 seconds. After selecting yes, the appliance will reboot and clear the logical drive configuration. 10. Repeat steps 3-7, then select no by typing n when the Clear logical drive warning is displayed. The unit will now load the software. 11. For Security Analytics versions 10.3 and 10.4, you need to reboot the unit. Press Enter to reboot the unit. 12. For Security Analytics versions 10.5 and 10.6, the system reboots automatically. Verify the unit boots to the Linux prompt. Unit displays the unit type on the first line of the output. The following example shows the output that is displayed on a Decoder. Note that this example may not be representative of actual output. The Security Analytics appliance is now loaded with the required Security Analytics software. The login is root and the password is netwitness. Copyright 2010-2016 by RSA, The Security Division of EMC 11
Contacting Customer Care RSA SecurCare: https://knowledge.rsasecurity.com Phone: 1-800-995-5095, Option 3 International Contacts: http://www.emc.com/support/rsa/contact/phone-- numbers.htm Email: nwsupport@rsa.com Community: http://www.emc.com/domains/netwitness/index.htm Basic Support: Technical Support for your technical issues is available during 8am to 5pm your local time, Monday through Friday. Enhanced Support: Technical Support is available by phone 24x7, 365 days of the year for Severity 1 and Severity 2 issues only. Copyright 2010-2016 by RSA, The Security Division of EMC 12
RSA Part Number R7167A1 Copyright 2010-2016 by RSA, The Security Division of EMC 13