Arctic Wolf Appliances


AWN301 Sensor - Mirroring Deployment

Updated Feb 12, 2024

Deploy an AWN301 Sensor with mirroring

You can deploy an AWN301 Sensor with mirroring.

For more information about the network configuration of mirroring deployment, see Arctic Wolf Sensor mirroring deployment.

Before you begin

Steps

  1. Set up a customer-configured appliance.
  2. Install the hardware.
  3. Connect the sensor for internal tap deployment.

Step 1: Set up a customer-configured appliance

Note: This step only applies if you selected customer-configured appliance on your onboarding form.

See Set up a customer-configured appliance for more information.

Step 2: Install the hardware

  1. Install the sensor in the applicable rack location.

    If needed, use the provided rails.

  2. Using a CAT6 RJ45 Ethernet cable, connect the management port on the sensor to the outbound connection on your network switch.

  3. Using the two AC30 US power cords, connect the power connectors on the sensor to a power source.

    Note: Arctic Wolf recommends that you use an uninterruptible power supply (UPS) to prevent interruptions from power surges.

  4. Turn on the sensor power.

    The system health and ID indicator is blue when the sensor power is on.

  5. Ping the management IP address that you provided to Arctic Wolf to verify network connectivity.

  6. Wait 15 minutes, and then make sure the status LED is green. This shows that the sensor is connected to the Arctic Wolf monitoring service.

  7. If you cannot successfully complete these steps, contact your CST at security@arcticwolf.com.

Step 3: Connect the sensor for internal tap deployment

  1. Configure up to five 1G ports as mirror ports on your switch.

    For more information, see the configuration instructions provided by your network switch manufacturer:

  2. Create a 1G mirror connection. Using a CAT6 RJ45 Ethernet cable, connect LAN0 on the sensor to a mirror port on your network switch.

  3. (Optional) Create additional 1G mirror port connections. Repeat the previous step with any of these ports:

    • LAN1
    • LAN2
    • LAN3
    • LAN4
  4. If you are configuring optional layer 3 mirroring, contact your CST at security@arcticwolf.com. Include this information:

    • LAN<ID>, IP address, and netmask of the optional LAN interface.
    • TCP/IP port, if the default port (4789) is not used for a VXLAN environment.
    • Confirmation that the management IP address and LAN<ID> IP address are not on the same subnet.
  5. Contact your CST at security@arcticwolf.com to make sure that Arctic Wolf can see your network traffic.

Configure optional layer 3 mirroring

You can configure optional layer 3 mirroring on the sensor to receive network traffic from a remote IP address to the AWN Sensor through LAN 1. This configuration allows a sensor to be deployed anywhere that supports Encapsulated Remote Switched Port Analyzer (ERSPAN).

Note: For physical sensors, the management port IP address and lan<ID> IP address cannot be on the same subnet.

This optional configuration requires assigning a static IP address to lan<ID> for a physical sensor or lan0 for a virtual sensor. The sensor does not support DHCP or DHCP reservation for the LAN IP address. Contact your CST at security@arcticwolf.com to configure this option.

AWN301 Sensor components

Use these diagrams to identify the components of the AWN301 Sensor:

Tip: Orange callouts show mandatory connections.

Front of sensor

Front of sensor

Back of sensor

Back of sensor

Callout Sensor component Port configuration Cable used Connected to
A System health and ID indicator - - -
B Lock - - -
C LCD display and navigation buttons - - -
D Power button - - -
E USB port - - -
F iDRAC direct Micro USB port - - -
G Console port - - -
H Management port - CAT6 RJ45 Ethernet cable Network switch
I LAN4 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
J LAN0 1G mirror CAT6 RJ45 Ethernet cable Network switch
K LAN1 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
L LAN2 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
M LAN3 1G mirror CAT6 RJ45 Ethernet cable* (Optional) Network switch
N Power connector - AC30 US power cord Power source
O Power connector - AC30 US power cord Power source
P DB-15 VGA port - - -
Q iDRAC9 dedicated network port - - -
R USB 3.0 port - - -
S USB 3.0 port - - -
T System identification connector - - -
U System identification button - - -

*This cable is not provided by Arctic Wolf.