620 likes | 921 Views
Tripwire Enterprise Server – Basic Tasks. Doreen Meyer and Vincent Fox UC Davis, Information and Education Technology July 12, 2006. Topics. Server install Q&A Understanding the UI Settings manager Your first node! Importing useful rules Agent install
E N D
Tripwire Enterprise Server – Basic Tasks Doreen Meyer and Vincent Fox UC Davis, Information and Education Technology July 12, 2006
Topics • Server install Q&A • Understanding the UI • Settings manager • Your first node! • Importing useful rules • Agent install • The managers: nodes, rules, actions, tasks, logs • Baselining, version Checks, promotion
Server Install • Single-server, just run the installer • Dual-server, you will need to add parameters to the install command • Windows cannot install over TS • STORE THOSE PASSWORDS! • *Note: in 5.5 problems using a Services Password > 8 chars
Server firewall/NAT • Firewall, see Installation Guide, Chapter 1. Network requirements • NAT, see Reference Guide, Chapter 4. System Properties
Tripwire UI • The TE GUI has many elements of a familiar desktop, but is not. This can lead to frustration and broken mice. • Zones of the console
Server Settings • User preference settings • System preferences • Email server
System Preferences • Shorten ‘session timeout’ to 10 minutes
Administration Settings • Configure login method • Creating roles • Creating a user group • Creating users
Creating User Groups • Functional groups usually by role • Obvious groupings: staff/admins, operations, management
Node Setup Tasks • Import TFS and/or UCD-basic rulesets • Install agent on a node • Create an action • Use tasks to associate rule, node, action, and schedule a time to run. • Create a baseline for the node • Wait. Example for a rule with 7,000 elements stored, took ~600 seconds.
Import Useful Rules • TFS rules very generic, usually result in many elements stored. • UCD rules leaner, meaner. • Rule names need to be unique or collision will occur.
Install the Agent Software • Install as Administrator • Enter port + services password • Punch holes in firewall! • There is a silent install option, see Users Guide, Ch. 2, Installation Procedures for TE Agent
Create First Task We just want a Check Rule Task for our example
Test That It Works • Modify a “watched” element • Run the task, or do a ‘node check’ • Note the change or check your email • Take action on the intrusion! Or, just promote the changes.
Node Manager • Adding a node group • Linking a node • Elements for file system nodes • Element versions • Node viewing filter
Action Manager • Viewing Actions • Creating an email action • Creating an SNMP action • Creating an execution action (locally or on TE server)
An Execution Action echoing the file name of a changed element to a file
Task Manager • Viewing tasks • Creating and deleting tasks
Log Manager • Viewing logs • Sorting and filtering Logs