
3
Table of Contents
TABLE OF CONTENTS
INTRODUCTION
CHAPTER 1
Using StoneGate Documentation . . . . . . . . . . . 7
How to Use This Guide . . . . . . . . . . . . . . . . . . 8
Documentation Available . . . . . . . . . . . . . . . . . 9
Product Documentation. . . . . . . . . . . . . . . . . 9
Support Documentation . . . . . . . . . . . . . . . . 9
System Requirements. . . . . . . . . . . . . . . . . . 10
Supported Features . . . . . . . . . . . . . . . . . . . 10
Contact Information . . . . . . . . . . . . . . . . . . . . 10
Licensing Issues . . . . . . . . . . . . . . . . . . . . . 10
Technical Support. . . . . . . . . . . . . . . . . . . . . 10
Your Comments . . . . . . . . . . . . . . . . . . . . . . 10
Other Queries. . . . . . . . . . . . . . . . . . . . . . . . 10
PREPARING FOR INSTALLATION
CHAPTER 2
Planning the IPS Installation . . . . . . . . . . . . . . 13
Introduction to StoneGate IPS . . . . . . . . . . . . . 14
Example Network Scenario . . . . . . . . . . . . . . . 14
Overview to the Installation Procedure . . . . . . . 15
Important to Know Before Installation . . . . . . . 15
Supported Platforms. . . . . . . . . . . . . . . . . . . 15
Date and Time Settings . . . . . . . . . . . . . . . . 15
Capture Interfaces . . . . . . . . . . . . . . . . . . . . 16
Switch SPAN Ports . . . . . . . . . . . . . . . . . . . 16
Network TAPs. . . . . . . . . . . . . . . . . . . . . . . 16
Cabling Guidelines . . . . . . . . . . . . . . . . . . . . 16
Speed And Duplex . . . . . . . . . . . . . . . . . . . . 17
Installing IPS Licenses. . . . . . . . . . . . . . . . . . . 19
CHAPTER 3
Getting Started with IPS Licenses . . . . . . . . . . 20
Configuration Overview . . . . . . . . . . . . . . . . . 20
Generating New Licenses . . . . . . . . . . . . . . . . 20
Installing Licenses . . . . . . . . . . . . . . . . . . . . . 21
CHAPTER 4
Configuring NAT Addresses . . . . . . . . . . . . . . . 23
Getting Started with NAT Addresses . . . . . . . . . 24
Configuration Overview . . . . . . . . . . . . . . . . . 25
Defining Locations . . . . . . . . . . . . . . . . . . . . . 25
Adding SMC Server Contact Addresses . . . . . . 26
CONFIGURING SENSORS AND ANALYZERS
CHAPTER 5
Defining Sensors and Analyzers . . . . . . . . . . . . 31
Getting Started with Defining Sensors and
Analyzers. . . . . . . . . . . . . . . . . . . . . . . . . . . . 32
Creating Engine Elements. . . . . . . . . . . . . . . . 32
Defining System Communication Interfaces for IPS
Engines. . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Defining Physical Interfaces . . . . . . . . . . . . . 34
Defining VLAN Interfaces . . . . . . . . . . . . . . . 35
Defining IP Addresses . . . . . . . . . . . . . . . . . 36
Setting Interface Options for IPS Engines. . . . . 37
Defining Traffic Inspection Interfaces for Sensors 38
Defining Logical Interfaces . . . . . . . . . . . . . . 39
Defining Reset Interfaces . . . . . . . . . . . . . . . 40
Defining Capture Interfaces . . . . . . . . . . . . . 41
Defining Inline Interfaces . . . . . . . . . . . . . . . 42
Bypassing Traffic on Overload . . . . . . . . . . . . . 43
Finishing the Engine Configuration. . . . . . . . . . 44
CHAPTER 6
Saving the Initial Configuration . . . . . . . . . . . . 45
Configuration Overview . . . . . . . . . . . . . . . . . . 46
Saving the Initial Configuration for Sensors and
Analyzers. . . . . . . . . . . . . . . . . . . . . . . . . . . . 46
Transferring the Initial Configuration to Sensors
and Analyzers . . . . . . . . . . . . . . . . . . . . . . . . 49
CHAPTER 7
Configuring Routing and Installing Policies . . . 51
Configuring Routing . . . . . . . . . . . . . . . . . . . . 52
Adding Next-hop Routers . . . . . . . . . . . . . . . 53
Adding the Default Route . . . . . . . . . . . . . . . 54
Adding Other Routes . . . . . . . . . . . . . . . . . . 54
Installing the Initial Policy . . . . . . . . . . . . . . . . 55
Commanding IPS Engines. . . . . . . . . . . . . . . 57
INSTALLING SENSORS AND ANALYZERS
CHAPTER 8
Installing the Engine on Intel-Compatible
Platforms . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61
Installing the Sensor or Analyzer Engine. . . . . . 62
Configuration Overview . . . . . . . . . . . . . . . . . 62
Obtaining Installation Files . . . . . . . . . . . . . . . 62