NETFORT LANGUARDIAN INSTALLING LANGUARDIAN ON MICROSOFT HYPER V
Instructions apply to installs on Windows Server 2012 R2 Before you begin When deployed in a Hyper V environment, LANGuardian will capture and analyze traffic only the virtual network. During the installation, you will configure LANGuardian to join your network. You must use a fixed IP address. Please make sure you have obtained a valid IP address and subnet mask, and know the address of the default gateway, before starting the installation. Download the LANGuardian.iso file and copy to a share accessible to the Hyper V server 1.1 Create the virtual machine New Virtual Machine Wizard In Hyper V Manager create a New Virtual Machine Choose a name and storage location Page 1
New Virtual Machine Wizard Assign Memory A minimum of 2 gigabytes of memory is recommended New Virtual Machine Wizard Configure Networking We do not configure networking at this stage. Ensure Connection is Not Connected Page 2
New Virtual Machine Wizard Connect Virtual Hard Disk A minimum of 100Gb of disk space is recommended. Page 3
New Virtual Machine Wizard Installation Options Choose Install an operating system from a boot CD/DVD Rom Choose Image file (.iso): - Browse to /and select the LANGuardian install iso from the the share where you placed the.iso file. Page 4
New Virtual Machine Wizard Completing the new virtual machine wizard Click next and finish Virtual Machine Settings Now we must edit some of the virtual machine settings. Right click on the virtual machine and choose Settings Add Hardware Add a Legacy Network Adapter click OK Repeat this process so you should have 2 Legacy Network Adapters in the settings page. Page 5
Page 6
Network Configuration Attach the network adapters to the virtual switch (s) Select the first Legacy Network Adapter and attach it to a virtual switch. This adapter is to be used for the LANGuardian Management Interface. This virtual switch must be an External virtual switch. Select the second Legacy Network Adapter and attach it to a virtual switch. This adapter is to be used for the LANGuardian Monitoring Interface. This is the virtual switch to which the virtual machines you wish to monitor are attached. Page 7
Configure the network adapter for monitoring Select the second Legacy Network Adapter and go to Advanced Features Change the Mirroring Mode to be Destination Page 8
LANGuardian Installation Start up the Vm and complete the LANGuardian Installation. Details of the installation can be found at www.netfort.com Note: At the end of the installation LANGuardian will prompt for a reboot. You will need to disconnect the CD iso to prevent the system from booting from the cd. Follow the procedure in the Tidy Up section below Page 9
Tidy Up On the virtual machine settings page change the bios setting and move CD down the order so the machine will boot from the hard drive. (or alternatively remove the.iso file settings applied earlier) On the virtual machine settings page delete the device labelled: Network Adapter Not Connected Page 10
Configure Virtual Machines for Monitoring Select a virtual machine you wish to be monitored. Visit the settings page and go to Network Adapter Advanced settings. Change the Mirroring Mode to be Source Repeat for every Virtual Machine/Adapter you wish to be monitored. Page 11
External SPAN / Port Mirroring: SPAN can be connected to Hyper-V (2012/R2) instance by enabling Port Mirroring on Virtual Switch, and configuring it as a source for external SPAN traffic. Steps required: Open PowerShell with Administrator privileges on Hyper-V machine and type in below commands, replacing Your_Switch_Name with the name of your Virtual Switch connected to your SPAN / Mirroring port. $enablespan = Get-VMSystemSwitchExtensionPortFeature -FeatureName "Ethernet Switch Port Security Settings" $enablespan.settingdata.monitormode = 2 Add-VMSwitchExtensionPortFeature -ExternalPort -SwitchName Your_Switch_Name - VMSwitchExtensionFeature $enablespan By entering the above commands, all the traffic passing on the NIC of the Virtual Switch will be mirrored to the LANGuardian instance. Page 12