Extreme Networks Fabric Engine (VOSS) Switch
Details
Support: Levels 1- 4
Supported Versions: 9.0, 9.1, 9.2, 9.3
To onboard an Extreme Networks Fabric Engine (VOSS) switch device, complete the following steps.
Step 1: Configure the Device
- Create a RO (Read Only) account for the Security Manager data collector.
- Log in to the Extreme Networks dashboard.
- From the navigation, click Configure > Accounts > New User.
- Enter a Username and Password.
- For Access Permission, select RO.
Usage is supported only with a user account that has Read-Write privileges. To pull usage data from the device, the account must have Read-Write privileges; Read-Only privileges are not supported for usage.
- Click Submit.
Step 2: Onboard the Device in the Administration Module
Contact FireMon Support to receive a specific device pack (a .jar file) if it was not included in the FMOS GA release. Review the steps to upload a device pack.
- Click Create, and then click Extreme Networks > Fabric Engine (VOSS).
- General Properties section.
- In the Name box, type the name of the device as you want to see it in SIP.
- In the Description box, type an optional description of the device being added.
- In the Management IP Address box, type the IP address of the device.
- In the Data Collector Group box, select the IP address of the data collector group that will collect data from this device.
- In the Central Syslog Server box, select the syslog server from the list (optional).
Syslog fields are optional if the device uses the same IP for syslog and management.
A central syslog server is required only if syslog messages come from a different IP. A central syslog server must be created before it can be assigned to a device. To track usage via syslog, the device must support Level 3+.
- In the Syslog Match Names box, type the syslog match names (optional). You can enter multiple names separated by a comma.
- By default, the Automatically Retrieve Configuration checkbox is selected.
- In the External ID box, type a unique identifier to be used when the device identifier is different than what is displayed in SIP.
- For Collection Configuration, enable Update Rule Documentation on Member Devices to allow Rule Documentation fields on member devices to inherit a value from the management station. Any management stations Rule Documentation field updates will override updates on the member device. A rule marked to be removed will not be updated. Default is what is set on the installed device pack.
Credentials
- In the User Name box, enter the user name used for the RO account.
- In the Password box, enter the password used for the RO account.
Usage is supported only with a user account that has Read-Write privileges. To pull usage data from the device, the account must have Read-Write privileges; Read-Only privileges are not supported for usage.
- In the Re-enter Password box, retype the password entered above.
Retrieval
- By default, Protocol is SSH and the Port is 22.
-
Monitoring section.
Log Monitoring
By default, the Enable Log Monitoring checkbox is selected to use for Rule Usage Analysis.
- Track Usage Via is set to Hit Counters.
- Log Update Interval is set to 5 (minutes); this number determines how often usage data is sent to the application server.
Hit counts are collected at the policy level rather than per rule. As a result, each rule within a policy displays the same hit count value. This value reflects total policy usage and cannot be used to determine whether a specific rule was matched.
Rule hit counts reflect total policy hits. Individual rule matches are not tracked.Change Monitoring
By default, the Enable Check for Change checkbox is selected to enable checking for configuration changes after the specified interval, and perform a retrieval if changes are detected. Selecting the checkbox will display additional fields.
- Enter an optional Alternate Syslog Source IP.
- Select the Perform Change Verification checkbox to allow the data collector to verify that changes exist prior to posting a revision. This will enable more efficient use of disk space by not posting revisions that did not change from the last normalized revision.
-
Retrieval section.
Scheduled Retrieval
Select the Enable Scheduled Retrieval checkbox to perform a retrieval at a set time daily regardless of change. When selected, additional fields to set display.
- The default Check for Change Interval time is 1440 minutes (every 24 hours). You can change the check interval time to best fit your requirements. The minimum required interval is 60 minutes (1 hour).
- Set an optional time in the Check for Change Start Time box. To schedule the first retrieval for a specific time, select the Starting at checkbox and select a time. The first retrieval will run at the time you enter. All subsequent retrievals will occur at the interval you entered above, based on the time that the first retrieval occurred. If you do not select a Change Start Time, the first scheduled retrieval will occur immediately after you save the settings. Subsequent retrievals will occur at the interval you entered.
Check for Change Retrieval
Select the Enable Check for Change checkbox to enable checking for configuration changes after the specified interval, and perform a retrieval if changes are detected. When selected, the Check for Change Interval (minutes) displays and is set to 1440.
- Advanced section.
- File Retrieval Options: Select the Use Batch Config Retrieval checkbox only if you are manually sending configurations for this device using your data collector's batchconfig directory. While this option is enabled, online retrievals will be disabled.
- SSH Key Options: Select the Automatically Update SSH Keys checkbox if you want the data collector to automatically update the SSH key for a device when a conflict occurs.
-
Enforcement section.
Select an Enforcement Option from the list:
Allow All: All automation is allowed (enforcement, change, manual).
Manual Only: When selected all changes must be manually pushed for this device.
Prevent All: No automation is allowed.
Window Only: Automation can only take place in the assigned enforcement window.
If this device is assigned to an enforcement or change window, it will be listed. If no assignment, changes must be manually pushed for this device.
-
Supplemental Routes section.
Supplemental routes cannot be added until after a retrieval normalizes successfully. You can perform a manual retrieval before continuing.
- Select an Interface.
If you select an Interface, you will not need to select a virtual router and next virtual router. If no interface is selected, you will need to select a Virtual Router and Next Virtual Router.
- Type the Destination IP address.
- Type the Gateway IP address.
- Select a Virtual Router.
- Select a Next Virtual Router.
- Switch the Drop toggle to enable (disabled = Accept).
- Click Add.
-
Click Save.
Step 3: Verify Communication
Because automatically retrieving a configuration is enabled by default, there is nothing for you to do. Security Manager will automatically attempt to retrieve a device configuration.
To do a manual retrieval, select the device row, click the Menu icon
and then click Retrieve Configuration.
It may take up to 15 minutes to see the status result of the retrieval.