Contents Contents 3 Overview Basic architecture Related documentation Skybox Appliance specifications Before you open the box What’s in the box Physical specifications Environmental specifications MTBF estimates for Skybox Appliance Front panel Back panel connectors File system partitions Setting up Skybox Appliance Hardware installation Starting Skybox Appliance Available Installation Processes...
Page 4
Skybox Appliance 7000 Quick Start Guide ISO burning SSH hardening Firmware updates for Skybox Appliance Checking your firmware revision via the console Checking your firmware revision via RMM Preparing to update Updating via the console Updating via RMM Adding your own certificate...
Chapter 1 Overview ® Skybox Appliance is a hardware solution that enables you to deploy Skybox without the burden of maintaining your own server. Skybox is an Automated Risk and Compliance Management (ARCM) platform that helps enterprise IT departments to discover and resolve potential security and compliance risks before they impact your organization.
Chapter 2 Skybox Appliance specifications This chapter contains product specifications and packaging information for your Skybox Appliance. In this chapter Before you open the box What’s in the box Physical specifications Environmental specifications MTBF estimates for Skybox Appliance Front panel Back panel connectors File system partitions Before you open the box...
Skybox Appliance 7000 Quick Start Guide FEATURE DESCRIPTION Form factor 1U rack mount chassis Rack dimensions 1.7” x 17.25” x 23.84” (43.2 mm x 438.15 mm x 605.56 mm) (H x W x D) Weight Packaged weight: 28.2 lb (12.8 kg) System weight: 19.6 lb (8.87 kg)
Model: Telcordia Issue 2 Method I-D Duty cycle 100% Quality Level II Note: The estimates listed here are for Appliance in 40°C ambient air. Front panel Skybox Appliance 7000 front panel includes 2 USB connectors, a power button, and LEDs. Skybox version 11.7.100...
Page 9
Skybox Appliance 7000 Quick Start Guide Power button and LEDs LETTER FEATURE System ID button with integrated LED NMI button (recessed; tool required for use) NIC1 and NIC2 activity LEDs System cold reset button System status LED Power button with integrated LED...
Power on: System powered off and in standby, no prior degraded/non- critical/critical state Back panel connectors Skybox Appliance 7000 back panel includes the connectors shown in the following figure. By default: eno1 is enabled and configured as DHCP eno2 is enabled and configured as static with the IP address: 192.168.1.1 /24 You can change these values.
Chapter 3 Setting up Skybox Appliance This chapter explains how to set up Skybox Appliance. In this chapter Hardware installation Starting Skybox Appliance Available Installation Processes System configuration What’s next Hardware installation Warning: These Appliance models include high wattage and high clock speed CPUs. Failure to maintain an ambient operating temperature of 27°...
Skybox Appliance 7000 Quick Start Guide Starting Skybox Appliance To start Skybox Appliance 1. Connect the AC power cords to the AC connectors on the Skybox Appliance back panel and connect the other ends to a power supply. Note: You can use Skybox with either a 110- or 220-volt power supply.
Chapter 3 Setting up Skybox Appliance To install Skybox Appliance as a specific type of server, see Selecting the Skybox Appliance Installation. System configuration Before running the Skybox Server, configure Skybox Appliance to be part of your network and perform initial system configuration. Configuring connection Before using Skybox Appliance Administration, configure connection of Skybox to your network locally using any of:...
Page 14
Skybox Appliance 7000 Quick Start Guide 4. Select BMC LAN configuration. 5. Select User Configuration to configure the RMM user. On the User Configuration page: a. Click User ID and set an unused user ID as the RMM user. b. Configure the user: Privilege: Select Administrator.
Page 15
Chapter 3 Setting up Skybox Appliance c. Select the IP mode (static or DHCP). If you select static mode, provide the IP address, netmask, and default gateway. 5. If you are using DHCP, run and note the IP address assigned to your Appliance. ifconfig You will need it later.
Skybox Appliance 7000 Quick Start Guide First-time configuration There are 2 system users defined at the operating system level: root and skyboxview. The default password for both is skyboxview In the preceding Configuring connection steps, depending on the method used, you changed the password of one user.
Page 17
Chapter 3 Setting up Skybox Appliance syslog server The syslog server on Skybox Appliance is preconfigured and is enabled by default. Updates to the configuration files of the syslog server are included in Skybox Appliance operating system updates. Skybox version 11.7.100...
Chapter 4 Configuring Skybox Appliance This chapter explains how to configure Skybox Appliance. In this chapter Configuration and management options Setting up network interface bonding Setting up SNMP configuration RADIUS authentication LDAP authentication Changing the TLS version Sending CentOS logs to a remote syslog server Configuration and management options Skybox Appliance configuration options are described in the following table.
Skybox Appliance 7000 Quick Start Guide PANE DESCRIPTION the time zone for the location of Skybox Appliance, so that reports and other data are timestamped correctly. Automatic configuration synchronizes Skybox with an NTP server. Provide the IP address or DNS of the NTP server to use. (You can use up to 3 NTP servers.)
Page 20
Chapter 4 Configuring Skybox Appliance 3. Select the interface to add to a network bond and click Add to Network Bond. 4. In the Network Bond Setup dialog box, add a bond interface. 5. Select the interfaces to bond to the new interface (as slaves). 6.
Skybox Appliance 7000 Quick Start Guide specification. Prerequisites: ethtool support in the base drivers for retrieving the speed and duplex of each slave. A switch that supports IEEE 802.3ad Dynamic link aggregation. Most switches require configuration to enable 802.3ad mode.
Chapter 4 Configuring Skybox Appliance On the Notification (Traps) tab: Destination: Name or IP address of the notification receiver traps server Traps User: SNMP community of the notification receiver traps server 4. Click Save SNMP Configuration to save the configuration and update the service with the new configuration.
Skybox Appliance 7000 Quick Start Guide Note: To use RADIUS authentication, the package must be installed on the pam_radius Skybox Server. To check whether the package is installed, run rpm -qa | grep pam_radius If you need help installing the package, contact Skybox Support.
Page 24
Chapter 4 Configuring Skybox Appliance Prerequisites To use LDAP authentication, the LDAP server must support either TLS/SSL or secure LDAP (LDAPS). To set up LDAP authentication 1. On the Security tab, click LDAP. 2. Define the authentication according to the fields shown in the following table. FIELD DESCRIPTION LDAP Servers...
Skybox Appliance 7000 Quick Start Guide FIELD DESCRIPTION User DN read permissions to read the user groups. Example: CN=LDAPUser,CN=Users,DC=YOURDOMAIN,DC=LOCAL LDAP Bind The password for the bind user. User Password Verify LDAP Verify the user password. Bind User Password Allowed Users A comma-separated list of permitted users. If empty, all users are permitted.
Page 26
Chapter 4 Configuring Skybox Appliance # Default Security configuration for SSL. Oldest compatible clients: Firefox 27, Chrome 30, IE 11 on Windows 7, Edge, Opera 17, Safari 9, Android 5.0, and Java 8. SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 SSLCipherSuite ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM- SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE- ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256- SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-...
Skybox Appliance 7000 Quick Start Guide systemctl restart httpd Sending CentOS logs to a remote syslog server To send the Skybox Appliance CentOS logs to a remote syslog server 1. On the System tab, click Syslog Server. 2. Select Send System Logs to Remote Syslog Server.
Chapter 5 Customizing the syslog server The syslog server in Skybox Appliance is preconfigured and is enabled by default. In this chapter Setting up TCP and UDP listeners Working with syslog files Setting up TCP and UDP listeners Skybox Appliance includes TCP and UDP listeners for the syslog server. To set up TCP and UDP listeners 1.
Page 29
Skybox Appliance 7000 Quick Start Guide What are the syslog folder names? Since an installation may have multiple firewalls from various vendors, the syslogs are stored in folders per vendor, as described in this table. Syslogs from vendors that do not have a specific folder are stored in /var/log/syslog-ng/new.
Chapter 6 Skybox Manager Installation Download Skybox Manager from Skybox Appliance over HTTP using the Skybox Appliance IP address ( ). For additional information, see https://<Appliance IP address>:444/manager Installing Skybox Manager. Skybox Manager runs on Windows. In this chapter Skybox Manager system requirements Installing Skybox Manager Upgrading Skybox Manager Skybox Manager system requirements...
Skybox Appliance 7000 Quick Start Guide Upgrading Skybox Manager If the Skybox Manager installation file on your Skybox Appliance is outdated, you can download the new Skybox Manager installation file (or you might receive it from the Skybox product support team) to replace the old installation file. This way, when Skybox users install Skybox Manager from the Appliance, they are installing the latest version.
Chapter 7 Updating the operating system on Skybox Appliance You might need to update the CentOS operating system on your Skybox Appliance (for example, after bug fixes or security patches are released for the operating system). Updates to the operating system do not affect Skybox. Note: These updates can only be applied to CentOS version 7 or higher.
Page 33
Skybox Appliance 7000 Quick Start Guide 8. We recommend that, when asked where to save the files, you select either a location on the file sharing system (and not on the Skybox Appliance server) or an external drive. The default location is /var/tmp/appliance_update_<patch>/backup/...
Chapter 8 ISO burning Skybox Appliance ISO is larger than 4 GB and does not fit on a standard DVD+R. We recommend that you use either a DVD+R DL (Dual Layer) or a flash drive if you need to burn the ISO. Note: For flash drives, we recommend using Rufus to burn the ISO (https://rufus.ie).
Chapter 9 SSH hardening The following lines in restrict access to remote login via SSH to the /etc/ssh/sshd_config root and skyboxview users only: AllowUsers root skyboxview AllowGroups root skyboxview This configuration is implemented as part of hardening the operating system of Skybox Appliance.
Chapter 10 Firmware updates for Skybox Appliance This chapter explains how to perform a firmware update for your Skybox Appliance. In this chapter Checking your firmware revision via the console Checking your firmware revision via RMM Preparing to update Updating via the console Updating via RMM Checking your firmware revision via the console To check the firmware revision on your Skybox Appliance...
Skybox Appliance 7000 Quick Start Guide If the firmware version detected on your Appliance is identical to the relevant version in this table, no update is required. If the version detected is lower than the version in this table, continue with Preparing to update.
Page 38
Chapter 10 Firmware updates for Skybox Appliance Important: You must know the model number for the update. 5. From the System Information tab, on the Summary page, check the firmware revision number in BMC FW Rev. Skybox version 11.7.100...
Skybox Appliance 7000 Quick Start Guide 6. Determine whether your Skybox Appliance requires a firmware update: Compare the Firmware/BMC version detected on your Appliance with the latest approved firmware versions listed in the following table. MODEL BMC FW REV 7000 1.16.11302...
Chapter 10 Firmware updates for Skybox Appliance What you need to update A USB flash drive formatted with a FAT or FAT32 file system. This requires a USB drive of 32 GB or less. The appropriate ZIP file for the Skybox Appliance model that you are using. For Skybox Appliance 8050 use the same file as Skybox Appliance 8000.
Skybox Appliance 7000 Quick Start Guide 8. Follow onscreen directions at the end of the BIOS update. Important: After a firmware update, the system takes longer to boot while the backup firmware region updates. This is normal behavior. Do not interrupt this process.
Page 42
Chapter 10 Firmware updates for Skybox Appliance Shut down the Skybox Collector: service sbvcollector stop 8. Reboot the machine using the BMC Web Console: a. From the BMC Web Console, click Server Power Control. b. Select Reset Server and select Force-enter Bios Setup. c.
Page 43
Skybox Appliance 7000 Quick Start Guide 10. From the Boot Manager, select Launch EFI Shell and press <Enter>. After about 5 seconds, the following screen appears. Skybox version 11.7.100...
Page 44
Chapter 10 Firmware updates for Skybox Appliance 11. Press <Enter>. When the procedure is almost finished, the screen displays the following. Skybox version 11.7.100...
Page 45
Skybox Appliance 7000 Quick Start Guide 12. Wait 2 minutes and log in again to the remote console. 13. Press 5 to exit the update. Skybox version 11.7.100...
Page 46
Chapter 10 Firmware updates for Skybox Appliance 14. Press any key to continue. Configuring Java for login This procedure enables you to log in to the RMM interface of the Skybox Appliance machine from your local machine. Skybox version 11.7.100...
Page 47
Skybox Appliance 7000 Quick Start Guide 1. From the Windows Start menu, select Configure Java. 2. In the Java Control Panel, click the Security tab. Skybox version 11.7.100...
Page 48
Chapter 10 Firmware updates for Skybox Appliance 3. Click Edit Site List. 4. Add the URL of the RMM interface of the Skybox Appliance machine. Skybox version 11.7.100...
Chapter 11 Adding your own certificate To connect to Skybox Appliance Administration via your own certificate, add the certificate to the Apache web server. Note: If you generated your own certificate using the Generating and installing a certificate using the Java keytool procedure in the Skybox Installation and Administration Guide , follow the directions in Exporting the Server certificate and private key from the Java keystore before...
Skybox Appliance 7000 Quick Start Guide a. Concatenate the intermediate CA certificate with the root CA certificate cat intermediate.pem root.pem > ca-chain.cert.pem b. Transfer the concatenated file to /etc/pki/tls/certs 5. Back up /etc/httpd/conf.d/skyboxwebadmin.conf 6. Create a symbolic link to your certificate: a.
Page 52
Chapter 11 Adding your own certificate server.keystore.p12 -deststoretype PKCS12 -srcalias <alias> - deststorepass skyboxview -destkeypass skyboxview If you do not remember your alias: a. Execute ../../thirdparty/jdk<version#>/bin/keytool -list -v -keystore server.keystore -storepass skyboxview b. Find your server certificate. Above it is Alias name; this is your alias. 4.
Chapter 12 Selecting the Skybox Appliance Installation This chapter explains the different options for installing Skybox Appliance. In this chapter Overview Modify the Skybox Server and Collector Parameters Install only the Skybox Collector Install Standalone Elasticsearch Node Overview Without user intervention, after several seconds Skybox Appliance boots from the local drive. Click the up or down arrow keys to select a different option before the boot.
Skybox Appliance 7000 Quick Start Guide Modify the Skybox Server and Collector Parameters To install the Skybox Server and Collector with modified parameters: 1. Mount the ISO and start the server. 2. From the boot menu of the Skybox Appliance ISO, select Skybox Server Installation.
Chapter 12 Selecting the Skybox Appliance Installation Install only the Skybox Collector You can install Skybox Appliance as a Skybox Collector without installing the Skybox Server. This option optimizes the partitioning scheme for Appliances to run as a Collector. A collector-only installation results in the following configuration: The operating system is installed from scratch;...
Skybox Appliance 7000 Quick Start Guide Install Standalone Elasticsearch Node You can install Skybox Appliance as a Skybox standalone Elasticsearch node. You can use standalone Elasticsearch nodes to enhance the scalability of the new, Elasticsearch-based Skybox Web Client. Selecting this option in the boot menu skips the interactive installation dialog and selects the...
Chapter 13 Monitoring SNMP Skybox Appliance supports standard Linux OIDs. OIDs that you can monitor include: CPU load statistics 1 minute load: .1.3.6.1.4.1.2021.10.1.3.1 5 minute load: .1.3.6.1.4.1.2021.10.1.3.2 15 minute load: .1.3.6.1.4.1.2021.10.1.3.3 CPU statistics Percentage of user CPU time: .1.3.6.1.4.1.2021.11.9.0 Raw user CPU time: .1.3.6.1.4.1.2021.11.50.0 Percentages of system CPU time: .1.3.6.1.4.1.2021.11.10.0...
Page 58
Skybox Appliance 7000 Quick Start Guide Java Memory Utilization Java Memory Utilization: .1.3.6.1.4.1.8072.1.3.2.3.1.2.19.49.46.51.46.54.46.49.46.52.46.49.46.49.5 7.55.54.56.46.52 Skybox Server and Skybox Collector In addition to the standard OIDs, the following OIDs are supported for Skybox components. Skybox Server status: .1.3.6.1.4.1.8072.1.3.2.3.1.4.19.49.46.51.46.54.46.49.46.52.46.49.46.49.5 7.55.54.56.46.49 Skybox Collector status: .1.3.6.1.4.1.8072.1.3.2.3.1.4.19.49.46.51.46.54.46.49.46.52.46.49.46.49.5...
Page 59
Chapter 13 Monitoring SNMP For Java Memory Utilization Output: NET-SNMP-EXTEND-MIB::nsExtendOutputFull."1.3.6.1.4.1.19768.4" = STRING: server is up (pid=1570) (jstat -gcutil output) S0 S1 E O M CCS YGC YGCT FGC FGCT GCT 97.02 0.00 79.80 86.18 93.60 - 216 11.808 13 18.205 30.014 collector is up (pid=2075) (jstat -gcutil output) S0 S1 E O M CCS YGC YGCT FGC FGCT GCT 75.00 0.00 65.97 18.63 95.59 93.18 28 0.567 3 0.320 0.888...
Chapter 14 Troubleshooting Getting version information when Skybox Appliance Administration is unavailable If you need to know the version of Skybox Appliance (the image version ) and other information about Skybox Appliance when Skybox Appliance Administration is unavailable, run the get_ script from the CLI.
Chapter 15 Restoring Skybox Appliance to factory defaults The Skybox USB flash drive that comes in the Skybox Appliance package is for restoring Skybox Appliance to factory defaults. This USB drive might not contain the most current ISO for your Skybox Appliance. The latest ISO can be downloaded from https://downloads.skyboxsecurity.com/files/iso/.
Chapter 16 Wiping the hard disk drive You might need to wipe the internal SDD storage, destroying the data on it (for example, if you are sending the Skybox Appliance back to Skybox for replacement). Warning: This procedure wipes the SDD completely; it will not be bootable or function at all. The following command overwrites all partitions, master boot records, and data: dd if=/dev/urandom of=/dev/sda bs=1M Skybox version 11.7.100...
Chapter 17 CIS benchmarks for CentOS 7 All new Skybox Appliances meet the following CIS benchmark recommendations for CentOS 7. Appliances updated to the new ISO also meet the recommendations. RECOMMENDATION SCORED DESCRIPTION ü 1.1.1.1 – 1.1.1.8 Ensure that mounting of the following file systems is disabled: cramfs freevxfs...
Page 64
Skybox Appliance 7000 Quick Start Guide RECOMMENDATION SCORED DESCRIPTION ü 1.4.2 Ensure that the bootloader password is set. Setting the boot loader password requires that anyone rebooting the system must enter a password before being able to set command line boot parameters...
Page 65
Chapter 17 CIS benchmarks for CentOS 7 RECOMMENDATION SCORED DESCRIPTION attempting to target specific exploits of a system. Authorized users can get this information by running uname -a after they log in. ü 3.1.2 Ensure that packet redirect sending is disabled. Rationale: An attacker could use a compromised host to send invalid ICMP redirects to other router devices in an attempt to corrupt routing and have users access a system...
Page 66
Skybox Appliance 7000 Quick Start Guide RECOMMENDATION SCORED DESCRIPTION /var/log/lastlog maintain records of the last time a user successfully logged in. The /var/run/failock directory maintains records of login failures via the pam_ faillock module. The file /var/run/utmp file tracks all currently logged in users.
Page 67
Chapter 17 CIS benchmarks for CentOS 7 RECOMMENDATION SCORED DESCRIPTION changes in scope. The file /etc/sudoers is written to when the file or its attributes have changed. The audit records are tagged with the identifier ‘scope’. Rationale: Changes in the /etc/sudoers file can indicate that an unauthorized change has been made to scope of system administrator activity.
Page 68
Skybox Appliance 7000 Quick Start Guide RECOMMENDATION SCORED DESCRIPTION password when authenticating with SSH. ü 5.2.7 Ensure that SSH HostbasedAuthentication is disabled. The HostbasedAuthentication parameter specifies whether authentication is permitted through trusted hosts via the user of .rhosts, or /etc/hosts.equiv, along with successful public key client host authentication.
Page 69
Chapter 17 CIS benchmarks for CentOS 7 RECOMMENDATION SCORED DESCRIPTION The following options are set in the /etc/security/pwquality.conf file: minlen=14: Password must be at least 14 characters dcredit=-1: Provide at least one digit ucredit=-1: Provide at least one uppercase character ocredit=-1: Provide at least one special character lcredit=-1: Provide at least one lowercase character Note: The values shown are sample values.
Page 70
Skybox Appliance 7000 Quick Start Guide RECOMMENDATION SCORED DESCRIPTION ü 6.1.10 Ensure that no world writable files exist. Unix-based systems support variable settings to control access to files. World writable files are the least secure. See the chmod (2) man page for more information.
Chapter 18 Regulatory and safety information This chapter includes regulatory and safety information for Skybox Appliance 7000 hardware. In this chapter Product regulatory compliance Regulatory compliance markings Electromagnetic compatibility notices for the server board Product regulatory compliance Intended application This product is to be evaluated and certified as Information Technology Equipment (ITE), which may be installed in offices, schools, computer rooms, and similar commercial type locations.
Skybox Appliance 7000 Quick Start Guide Environmental requirements Intel has a system in place to restrict the use of banned substances in accordance with worldwide regulatory requirements. A Material Declaration Data Sheet is available for Intel products. For more reference on material restrictions and compliance you can view Intel’s Environmental Product Content Specification at http://supplier.intel.com/ehs/environmental.htm.
Page 73
Chapter 18 Regulatory and safety information REGULATORY REGION MARKING COMPLIANCE VCCI Marking Japan (Class A) KC Mark (Korean Korea Communications Commission) Russia Ukraine Ukraine Certification BSMI Certification Taiwan (RPC) Number & Class A Warning FCC Marking This device complies with Part 15 of the FCC Rules. (Class A) Operation of this device is subject to the following two conditions: (1) This device may not cause harmful...
Page 74
Skybox Appliance 7000 Quick Start Guide REGULATORY REGION MARKING COMPLIANCE Recycling Package China Marks Will be added on Package label Other Recycling International Package Marks Will be added on Package label Battery Perchlorate USA (CA) Perchlorate Material – Special handling may apply. See Warning www.dtsc.ca.gov/hazardouswaste/perchlorate...
Chapter 18 Regulatory and safety information Electromagnetic compatibility notices for the server board FCC Verification Statement (USA) This device complies with Part 15 of the FCC Rules. Operation is subject to two conditions: (1) This device may not cause harmful interference, and (2) this device must accept any interference received, including interference that may cause undesired operation.
Page 76
Skybox Appliance 7000 Quick Start Guide VCCI (Japan) English translation of this notice: This is a Class B product based on the standard of the Voluntary Control Council for Interference (VCCI) from Information Technology Equipment. If this is used near a radio or television receiver in a domestic environment, it may cause radio interference.
Need help?
Do you have a question about the Appliance 7000 and is the answer not in the manual?
Questions and answers