AWN202 Sensor Mirroring Deployment
Deploy an AWN202 Sensor with port mirroring Direct link to this section
The AWN202 Sensor is an external network device that allows you to monitor network traffic. When the sensor is deployed with port mirroring, a switch sends a copy of all network packets that are seen on one port to another port.
This image provides a simplified network map of a sensor with mirroring deployment:
|A||AWN202 Sensor with mirroring deployment|
|B||Management port network connection|
Before you begin Direct link to this section
Verify that you received the following items from Arctic Wolf:
Note: Your sensor has a tamper-evident asset ID: AWN-12XXXXXX. Contact firstname.lastname@example.org if the asset ID is missing or was tampered with.
Three CAT6 RJ45 Ethernet cables, 2m
Crossover RJ45 Ethernet cable (red), 2m — Use only if needed
AC30 US power cord, 2m
Set of rack ears — Use only if needed
For best performance, do not rate-limit the sensor with Quality of Service (QoS).
If your firewall does SSL/TLS inspection, AllowList the sensor management IP address, and then check that your firewall allows outbound access from that IP address over port 443 to the necessary IP addresses.
To see the complete list of IP addresses that you must allowlist, go to the Arctic Wolf Portal, and then click Account > Arctic Wolf IP Addresses. The IP addresses that must be allowlisted are listed under If you are a Managed Detection and Response (MDR) customer.
Steps Direct link to this section
- Set up a customer-configured appliance.
- Install the hardware.
- Connect the sensor for mirroring deployment.
Step 1: Set up a customer-configured appliance Direct link to this section
Note: This step only applies if you selected customer-configured appliance on your onboarding form.
See Set up a customer-configured appliance for additional information.
Step 2: Install the hardware Direct link to this section
Install the sensor in the applicable rack location.
If necessary, use the provided rack ears.
Using a CAT6 RJ45 Ethernet cable, connect the management port (port 1) on the sensor to the outbound connection on your network switch.
Using the AC30 US power cord, connect the power connector on the sensor to a power source.
Turn on the sensor power.
The Power LED is green when the sensor power is on.
Ping the management IP address that you provided to Arctic Wolf to check network connectivity.
Wait 15 minutes, and then make sure the Status LED is green. This shows that the sensor is connected to the Arctic Wolf monitoring service.
If you cannot successfully complete these steps, email email@example.com.
Step 3: Connect the sensor for mirroring deployment Direct link to this section
Configure up to five 1G ports on your network switch as mirror ports.
See the setup instructions provided by your network switch manufacturer for more information:
Create a 1G mirror connection. Using a CAT6 RJ45 Ethernet cable, connect port 6 (LAN0) on the sensor to a mirror port on your network switch.
(Optional) Create additional 1G mirror port connections. Using a CAT6 RJ45 Ethernet cable, connect any of the following ports on the sensor to a mirror port on your network switch:
- Port 5 (LAN1)
- Port 4 (LAN2)
- Port 3 (LAN3)
- Port 2 (LAN4)
If you are configuring optional layer 3 mirroring, email firstname.lastname@example.org with the following information:
LAN<ID>, IP address, and netmask of the optional LAN interface.
- TCP/IP port, if the default port (4789) is not used for a VXLAN environment.
- Confirmation that the management IP address and
LAN<ID>IP address are not on the same subnet.
See Configure optional layer 3 mirroring for more information.
Email email@example.com to confirm that Arctic Wolf is seeing your network traffic.
Configure optional layer 3 mirroring Direct link to this section
You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).
Note: For physical sensors, the management port IP address and
lan<ID> IP address cannot be on the same subnet.
This optional configuration requires assigning a static IP address to
lan<ID> for a physical sensor or
lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your Concierge Security Team® (CST) or firstname.lastname@example.org to configure this option.
AWN202 Sensor components Direct link to this section
Use these diagrams to identify the components of the AWN202 Sensor:
Tip: Orange callouts show mandatory connections.
Front of sensor
Back of sensor
|Callout||Sensor component||Port configuration||Cable used||Connected to|
|C||USB port (1 of 2)||-||-||-|
|D||Port 1: management port||-||CAT6 RJ45 Ethernet cable||Network switch|
|E||Port 2: LAN4||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|F||Port 3: LAN3||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|G||Port 4: LAN2||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|H||Port 5: LAN1||1G mirror||CAT6 RJ45 Ethernet cable||(Optional) Network switch|
|I||Port 6: LAN0||1G mirror||CAT6 RJ45 Ethernet cable||Network switch|
|K||HDD activity LED||-||-||-|
|M||Display screen navigation buttons||-||-||-|
|P||Power connector||-||AC30 US power cord||Power source|
*This cable is not provided by Arctic Wolf.