Installation & Requirements
Overview
Cienaga Systems Virtual Appliance
The virtual appliance is an unobtrusive, passive data collector deployed to the network perimeter. It monitors communication patterns for signs of known malicious and unknown attacks. This simple to install application is typically deployed on a dedicated PC on the network perimeter and does not degrade or proxy the traffic in any way.
Installation
Learn how to install the Cienaga Systems Virtual Appliance in this brief video.
Network Configuration
Requirements:
- A network switch with SPAN (Switched Port Analyzer) configured as follows:
- Source port is the uplink port (internet)
- Destination port is the port hosting the listening station (i.e. a dedicated machine running the Cienaga Systems virtual appliance)
- Additional source ports can be mirrored as desired (for instance, to monitor lateral communications inside the network), following the same pattern
Typical Network Setup with Switch vLAN Mirroring to SPAN Port
System Requirements - Virtual Appliance (Listening Station)
CPU: 1 gigahertz (GHz) or faster processor or SoC
- Minimum: 2 Cores (4 vCPUs)
- Recommended: 4 Cores (8 vCPUs)
Memory:
- Minimum: 4 GB
- Recommended: 8 GB or more
Storage:
- Minimum: Solid state drive (SSD), 100 GB or more of free space in the C:\ partition
- Recommended: Solid state drive (SSD), 300 GB or more of free space in the C:\ partition
Operating Systems:
- Windows 10 or newer
Browsers:
- Any modern browser such as Microsoft Edge, Google Chrome, Safari or Firefox is required
Network Interface Cards (NICs):
- Two PCIe Gigabit Ethernet Network Interface Cards (NICs) compatible with WinPcap, Wireshark and similar
- First NIC (Monitoring Interface): Intel-based chipset such as the Intel Ethernet Server Adapter I210-T1
- Second NIC (Management Interface): Generic NIC card, such as the TP-Link TG-346
- Optional:
- Additional high performance NICs to monitor lateral traffic across VLANs