AWN1000 10G Sensor - Mirroring Deployment

Updated Nov 13, 2023

Deploy an AWN1000 10G Sensor with port mirroring

You can deploy an AWN1000 10G Sensor with port mirroring.

The AWN1000 10G Sensor is an external network device that allows you to monitor network traffic. When the sensor is deployed with port mirroring, a switch sends a copy of all network packets that are seen on one port to another port.

This image provides a simplified network map of a sensor with mirroring deployment:

Network with mirroring deployment

Callout Description
A AWN1000 10G Sensor with mirroring deployment
B Management port network connection
C Network switch
D Firewall
E Internet

Before you begin

Steps

  1. Set up a customer-configured appliance.
  2. Install the hardware.
  3. Connect the sensor for mirroring deployment.

Step 1: Set up a customer-configured appliance

Note: This step only applies if you selected customer-configured appliance on your onboarding form.

See Set up a customer-configured appliance for more information.

Step 2: Install the hardware

  1. Install the sensor in the applicable rack location.

    If needed, use the provided rack ears or rails.

  2. Using a CAT6 RJ45 Ethernet cable, connect the management port on the sensor to the outbound connection on your network switch.

  3. Using the two AC30 US power cords, connect the power connectors on the sensor to a power source.

  4. Turn on the sensor power.

    The power LED is green when the sensor power is on.

  5. Ping the management IP address that you provided to Arctic Wolf to check network connectivity.

  6. Make sure the sensor is connected to the Arctic Wolf monitoring service:

    1. Install the drivers for your sensor.

      See Console session drivers for all other appliances for more information.

    2. Connect to the serial console.

      See Connect to the serial console for more information.

    3. View the sensor connectivity status.

      See View the current configuration and connectivity status for more information.

  7. If you cannot successfully complete these steps, contact your CST at security@arcticwolf.com.

Step 3: Connect the sensor for mirroring deployment

  1. Configure up to four 10G and eight 1G ports as mirror ports on your switch.

    See the configuration instructions provided by your network switch manufacturer for more information:

    Note: You can configure four 10G mirror ports and eight 1G mirror ports, but the aggregate throughput of all ports cannot exceed 10G.

  2. Create a 10G mirror port connection. Using the appropriate cable and port for your sensor type, connect LAN0 on the sensor to a mirror port on your network switch:

    • 10G copper — Use a CAT6A Ethernet cable.
    • 10G Twinax — Use a passive 10G Twinax cables with an SFP+ transceiver installed on each end.
    • 10G fiber — Use an LC-LC short range multi-mode fiber cable.
  3. (Optional) Create an additional 10G mirror port connection. Repeat the previous step with port LAN1, LAN2, or LAN3.

  4. (Optional) Create 1G mirror port connections. Using a CAT6 RJ45 Ethernet cable, connect any of these ports on the sensor to a mirror port on your network switch:

    • LAN4
    • LAN5
    • LAN6
    • LAN7
    • LAN8
    • LAN9
    • LAN10
    • LAN11

    Note: When connecting multiple RJ45 mirroring interfaces from the same switch to a sensor, make sure that the mirroring interfaces do not connect to the same bridge pair.

    The bridge pairs for this sensor are LAN4 and LAN5, LAN6 and LAN7, LAN8 and LAN9, LAN10 and LAN11.

  5. If you are configuring optional layer 3 mirroring, contact your CST at security@arcticwolf.com. Include this information:

    • LAN<ID>, IP address, and netmask of the optional LAN interface.
    • TCP/IP port, if the default port (4789) is not used for a VXLAN environment.
    • Confirmation that the management IP address and LAN<ID> IP address are not on the same subnet.
  6. Contact your CST at security@arcticwolf.com to confirm that Arctic Wolf is seeing your network traffic.

Configure optional layer 3 mirroring

You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).

Note: For physical sensors, the management port IP address and lan<ID> IP address cannot be on the same subnet.

This optional configuration requires assigning a static IP address to lan<ID> for a physical sensor or lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your CST at security@arcticwolf.com to configure this option.

AWN1000 10G Sensor components

Use these diagrams to identify the components of the AWN1000 10G Sensor:

Tip: Orange callouts show mandatory connections.

Front of sensor - 10G Twinax

AWN1000 10G Sensor

Front of sensor - 10G copper

This sensor has four SFP+ RJ45 10GB Copper 30m transceivers preinstalled.

AWN1000 10G Sensor

Front of sensor - 10G fiber

This sensor has four multimode SR optical transceivers preinstalled.

AWN1000 10G Sensor

Back of sensor

AWN1000 10G Sensor

Callout Sensor component Port configuration Cable used Connected to
A Console port (RJ45) - - -
B Port 1: LAN0 10G mirror

  • If 10G copper, CAT6A Ethernet cable
  • If 10G Twinax, passive 10G Twinax cable with an SFP+ transceiver installed on each end
  • If 10G fiber, LC-LC short range multi-mode fiber cable

Network switch
C Port 3: LAN1 10G mirror

  • If 10G copper, CAT6A Ethernet cable
  • If 10G Twinax, passive 10G Twinax cable with an SFP+ transceiver installed on each end
  • If 10G fiber, LC-LC short range multi-mode fiber cable

(Optional) Network switch
D Management port - CAT6 RJ45 Ethernet cable Network switch
E LAN4 1G mirror CAT6 RJ45 Ethernet cable (Optional) Network switch
F LAN5 1G mirror CAT6 RJ45 Ethernet cable (Optional) Network switch
G LAN6 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
H LAN7 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
I Reset - - -
J Power LED - - -
K HDD activity LED - - -
L Status LED - - -
M USB 3.0 port (1 of 2) - - -
N Port 2: LAN2 10G mirror

  • If 10G copper, CAT6A Ethernet cable
  • If 10G Twinax, passive 10G Twinax cable with an SFP+ transceiver installed on each end
  • If 10G fiber, LC-LC short range multi-mode fiber cable

(Optional) Network switch
O Port 4: LAN3 10G mirror

  • If 10G copper, CAT6A Ethernet cable
  • If 10G Twinax, passive 10G Twinax cable with an SFP+ transceiver installed on each end
  • If 10G fiber, LC-LC short range multi-mode fiber cable

(Optional) Network switch
P Console port (mini USB) - - -
Q LAN8 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
R LAN9 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
S LAN10 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
T LAN11 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
U ESD jack - - -
V Grounding post - - -
W Alarm mute button - - -
X Power switch - - -
Y Power connector - AC30 US power cord Power source
Z Power connector - AC30 US power cord Power source

*This cable is not provided by Arctic Wolf.