AWN203 Sensor - Mirroring DeploymentUpdated Nov 13, 2023
You can deploy an AWN203 Sensor with port mirroring.
The AWN203 Sensor is an external network device that allows you to monitor network traffic. When the sensor is deployed with port mirroring, a switch sends a copy of all network packets that are seen on one port to another port.
This image provides a simplified network map of a sensor with mirroring deployment:
|A||AWN203 Sensor with mirroring deployment|
|B||Management port network connection|
Verify that these items are in the box from Arctic Wolf®:
An AWN203 Sensor
Note: Your sensor has a tamper-evident asset ID: AWN-12XXXXXX. Contact your Concierge Security® Team at email@example.com if the asset ID is missing or was tampered with.
Two CAT6 RJ45 Ethernet cables, 2m
Two AC30 US power cords, 2m
A set of rack rails
Add all necessary IP addresses, ports, and services to your allowlist for full AWN203 Sensor functionality.
Tip: To see the complete list of IP addresses that you must allowlist, go to the Arctic Wolf Unified Portal, and then click Help > Allowlist Requirements. The IP addresses that must be allowlisted are listed under Sensors.
If you rate-limit the AWN203 Sensor with Quality of Service (QoS), remove this for best performance.
If your firewall provides SSL/TLS inspection, do not perform this inspection on the AWN203 Sensor management IP address.
If you are using an application proxy or layer 7 filter on your firewall, allow outbound traffic over OpenVPN for the AWN203 Sensor management IP address.
- Set up a customer-configured appliance.
- Install the hardware.
- Connect the sensor for mirroring deployment.
Note: This step only applies if you selected customer-configured appliance on your onboarding form.
See Set up a customer-configured appliance for more information.
Install the sensor in the applicable rack location.
If needed, use the provided rails.
Using a CAT6 RJ45 Ethernet cable, connect the management port on the sensor to the outbound connection on your network switch.
Using the two AC30 US power cords, connect the power connectors on the sensor to a power source.
Turn on the sensor power.
The system health and ID indicator is blue when the sensor power is on.
Ping the management IP address that you provided to Arctic Wolf to check network connectivity.
Wait 15 minutes, and then make sure the status LED is green. This shows that the sensor is connected to the Arctic Wolf monitoring service.
If you cannot successfully complete these steps, contact your CST at firstname.lastname@example.org.
Configure up to five 1G ports as mirror ports on your switch.
See the configuration instructions provided by your network switch manufacturer for more information:
Create a 1G mirror connection. Using a CAT6 RJ45 Ethernet cable, connect LAN0 on the sensor to a mirror port on your network switch.
(Optional) Create additional 1G mirror port connections. Repeat the previous step with any of these ports:
If you are configuring optional layer 3 mirroring, contact your CST at email@example.com. Include this information:
LAN<ID>, IP address, and netmask of the optional LAN interface.
- TCP/IP port, if the default port (4789) is not used for a VXLAN environment.
- Confirmation that the management IP address and
LAN<ID>IP address are not on the same subnet.
Contact your CST at firstname.lastname@example.org to confirm that Arctic Wolf is seeing your network traffic.
You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).
Note: For physical sensors, the management port IP address and
lan<ID> IP address cannot be on the same subnet.
This optional configuration requires assigning a static IP address to
lan<ID> for a physical sensor or
lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your CST at email@example.com to configure this option.
Use these diagrams to identify the components of the AWN203 Sensor:
Tip: Orange callouts show mandatory connections.
Front of sensor
Back of sensor
|Callout||Sensor component||Port configuration||Cable used||Connected to|
|A||System health and ID indicator||-||-||-|
|C||LCD display and navigation buttons||-||-||-|
|F||iDRAC direct Micro USB port||-||-||-|
|H||Management port||-||CAT6 RJ45 Ethernet cable||Network switch|
|I||LAN4||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|J||LAN0||1G mirror||CAT6 RJ45 Ethernet cable||Network switch|
|K||LAN1||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|L||LAN2||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|M||LAN3||1G mirror||CAT6 RJ45 Ethernet cable*||(Optional) Network switch|
|N||Power connector||-||AC30 US power cord||Power source|
|O||Power connector||-||AC30 US power cord||Power source|
|P||DB-15 VGA port||-||-||-|
|Q||iDRAC9 dedicated network port||-||-||-|
|R||USB 3.0 port||-||-||-|
|S||USB 3.0 port||-||-||-|
|T||System identification connector||-||-||-|
|U||System identification button||-||-||-|
*This cable is not provided by Arctic Wolf.