Deploy an AWN1000 Sensor with mirroring
You can deploy your AWN1000 Sensor with mirroring.
For more information about the network configuration of mirroring deployment, see Arctic Wolf Sensor mirroring deployment.
- Some detections may not be available if sensors cannot see the relevant network traffic, including traffic flowing through different switches or unmonitored firewalls. Make sure that sensors are properly placed across all network egress points.
- During connectivity tests, appliances may communicate with external IP addresses behind a cloud service that Arctic Wolf hosts.
These actions are required:
- Verify that these items are in the box from Arctic Wolf®:
- AWN1000 Sensor
Note:
Your sensor has a tamper-evident asset ID: AWN-12XXXXXX. Contact your Concierge Security® Team (CST) at security@arcticwolf.com if the asset ID is missing or was tampered with.
- Three CAT6 RJ45 Ethernet cables, 2m
- A crossover RJ45 Ethernet cable (red), 2m — Use only if needed
- Two AC30 US power cords
Note:
- If you are in these countries, you are shipped country-specific power cords:
- Australia
- Brazil
- China
- European Union
- India
- Israel
- Italy
- Switzerland
- United Kingdom
- If you are outside of these countries, you are shipped AC30 US power cords.
- If you are in these countries, you are shipped country-specific power cords:
- A set of rack ears — Use only if needed
- A set of rack rails
- AWN1000 Sensor
- Add all necessary IP addresses, ports, and services to your allowlist for full appliance functionality.
Tip: To see the IP addresses that you must allowlist, sign in to the Arctic Wolf Unified Portal, click , and then view the IP addresses in the section for your product.
- If you rate-limit the appliance with Quality of Service (QoS), remove this for best performance.
- If your firewall provides SSL/TLS inspection, do not do this inspection on the appliance management IP address.
- If you use an application proxy or layer 7 filter on your firewall, allow outbound traffic for the appliance management IP address.
- Configure log forwarding. For more information, see Syslog forwarding.
Install the hardware
Connect the sensor for mirroring deployment
Configure optional layer 3 mirroring
You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).
For physical sensors, the management port IP address and lanID IP address cannot be on the same subnet.
This optional configuration requires assigning a static IP address to lanID for a physical sensor or lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your CST at security@arcticwolf.com to configure this option.
AWN1000 Sensor components
Use these diagrams to identify your sensor components:
Orange callouts show mandatory connections.
Front of sensor
Back of sensor
|
Callout |
Sensor component |
Port configuration |
Cable used |
Connected to |
|---|---|---|---|---|
|
A |
Console port (RJ45) |
- |
- |
- |
|
B |
Port 1: LAN0 |
10G mirror |
- |
- |
|
C |
Port 3: LAN1 |
10G mirror |
- |
- |
|
D |
Management port |
- |
CAT6 RJ45 Ethernet cable |
Network switch |
|
E |
LAN4 |
1G mirror |
CAT6 RJ45 Ethernet cable |
Network switch |
|
F |
LAN5 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
G |
LAN6 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
H |
LAN7 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
I |
Reset |
- |
- |
- |
|
J |
Power LED |
- |
- |
- |
|
K |
HDD activity LED |
- |
- |
- |
|
L |
Status LED |
- |
- |
- |
|
M |
USB 3.0 port (1 of 2) |
- |
- |
- |
|
N |
Port 2: LAN2 |
10G mirror |
- |
- |
|
O |
Port 4: LAN3 |
10G mirror |
- |
- |
|
P |
Console port (mini USB) |
- |
- |
- |
|
Q |
LAN8 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
R |
LAN9 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
S |
LAN10 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
T |
LAN11 |
1G mirror |
CAT6 RJ45 Ethernet cable* |
(Optional) Network switch |
|
U |
ESD jack |
- |
- |
- |
|
V |
Grounding post |
- |
- |
- |
|
W |
Alarm mute button |
- |
- |
- |
|
X |
Power switch |
- |
- |
- |
|
Y |
Power connector |
- |
AC30 US power cord |
Power source |
|
Z |
Power connector |
- |
AC30 US power cord |
Power source |
*This cable is not provided by Arctic Wolf.