Tanium Appliance Installation Guide

Size: px
Start display at page:

Download "Tanium Appliance Installation Guide"

Transcription

1 Tanium Appliance Installation Guide Version September 25, 2017

2 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is believed to be accurate, but is presented without any warranty of any kind, express or implied, except as provided in Tanium s customer sales terms and conditions. Unless so otherwise provided, Tanium assumes no liability whatsoever, and in no event shall Tanium or its suppliers be liable for any indirect, special, consequential, or incidental damages, including without limitation, lost profits or loss or damage to data arising out of the use or inability to use this document, even if Tanium Inc. has been advised of the possibility of such damages. Any IP addresses used in this document are not intended to be actual addresses. Any examples, command display output, network topology diagrams, and other figures included in this document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental. Please visit for the most current Tanium product documentation. Tanium is a trademark of Tanium, Inc. in the U.S. and other countries. Third-party trademarks mentioned are the property of their respective owners Tanium Inc. All rights reserved Tanium Inc. All Rights Reserved Page 2

3 Table of contents Overview 9 Topology 10 Prerequisites 11 License 11 SSL certificates 11 Network connectivity and firewall 11 Internet access (direct or by proxy) 12 Getting started 15 Configuring network, host, and user settings 16 Configure temporary bootstrap network settings 16 Before you begin 16 Configure the temporary settings 16 Configure network and host settings 17 Before you begin 17 Configure the network and host settings 18 Configure user access 19 Before you begin 20 Change the default passwords 20 Add SSH keys for the tancopy account 20 Installing a Tanium All-in-One role 28 Before you begin 28 Install the Tanium Server All-in-One role 29 Next steps Tanium Inc. All Rights Reserved Page 3

4 Installing Tanium Server 32 Before you begin 32 Install Tanium Server 33 Next steps 35 Installing Tanium Module Server 36 Before you begin 36 Add required SSH keys 36 Install the Tanium Module Server 41 Configure the Tanium Server to use the remote Module Server 42 Enable the remote Module Server 44 Next steps 44 Installing Tanium Zone Server 45 Overview 45 Before you begin 46 Install the Tanium Zone Server 46 Install the Zone Server 47 Import the Tanium Server public key file to the Zone Server 48 Install the Zone Server hub 52 Edit the Zone Server List 54 Next steps 55 Installing the license file 56 Before you begin 56 Upload the license file 56 Install the license 59 Next steps Tanium Inc. All Rights Reserved Page 4

5 Verifying the deployment 62 Log into the Tanium Console 62 Deploy the Tanium Client to your lab computers 63 Before you begin 63 Install the Tanium Client Deployment Tool 64 Deploy the Tanium Client 66 Verify the basic deployment 67 Verify the Zone Server deployment 68 Installing Tanium Server in an active-active cluster 71 Overview 71 HA cluster requirements and limitations 72 Before you begin 73 Add required SSH keys 73 Set up the IPsec tunnel 77 Deploy the HA cluster 81 Verify the installation 83 Upgrading Tanium server software 86 Before you begin 86 Upgrade Tanium server software 86 Troubleshooting the installation 89 Run the Health Check 89 Restart services or networking 90 Restart services 91 Restart networking 91 Review logs Tanium Inc. All Rights Reserved Page 5

6 Review the configuration 93 Run Tanium Support Gatherer 94 Examine OS processes and files 95 Perform a software reset 100 Managing user access 102 Change TanOS user passwords 102 Change the tanadmin password 103 Reset the tanuser password 104 Reset the tanfactory password 105 Manage SSH keys 105 Before you begin 106 Generate keys 106 Add authorized keys 107 Display public keys 108 Configure the local authentication service 109 Add a local user 109 Set a user password 111 Delete a user 111 Disable the local authentication service 112 Configuring syslog 113 Configuring SNMP 117 Reference: Certificate and key files 120 Before you begin 120 Install a CA certificate file 120 Upload the CA certificate file Tanium Inc. All Rights Reserved Page 6

7 Install the SOAP certificate file 123 Manage content signing keys 126 Download the content signing key utility 126 Download the Tanium Server public key file 127 Import the Tanium public/private key pair 128 Upload the public and private key files 128 Replace the public and private keys 131 Reference: Tanium Service Control menu 132 Reference: Server configuration files 135 TaniumServer.ini reference 138 TaniumModuleServer.ini reference 140 TaniumZoneServer.ini reference 141 Reference: Appliance Maintenance menu 143 Back up and restore 143 Back up 143 Restore 145 Perform a software reset 145 Upgrade the TanOS shell 147 Clean SFTP and cores directories 148 Reboot or shut down 149 Reboot 149 Shut down 149 Reference: Appliance configuration 151 Modify the hostname and DNS configuration 151 Modify the IPv4 address configuration Tanium Inc. All Rights Reserved Page 7

8 Modify the NTP configuration 152 Modify the time zone configuration 153 Change from a static IP address to DHCP (VM-only) 153 Reference: File share mounts 154 Reference: Appliance security 157 Enable/disable factory reset 157 Manage the SSH trusted host list 159 Reference: Diagnostic menus 160 Use the Tanium Support menu 161 Use the Status menus 162 Display system status 163 Display Tanium status 164 Display appliance status 164 Reference: Tanium Appliance specifications 166 Tanium Server Appliance (small) 166 Tanium Server Appliance (medium) 166 Tanium Server Appliance (large) 167 Tanium Server Appliance (extra large) 167 Tanium Module Server Appliance (small, medium, large) 168 Tanium Module Server Appliance (extra large) 168 Change log Tanium Inc. All Rights Reserved Page 8

9 Overview You can deploy a Tanium Appliance in any of the following Appliance roles: Tanium Server The core server that communicates with clients. The Tanium Server also runs the UI console and API services and communicates with all other platform and solution components, as well as the content.tanium.com servers that host Tanium content packs and Tanium solution module import packages. The Tanium Server depends on a database server that is installed when the Tanium Server Role is installed. Tanium Module Server A dedicated server to run application services and store files for Tanium solution modules. It is installed on a separate appliance to prevent intentional or accidental scripts from having a direct impact on the Tanium Server. All-in-One Tanium Server, Tanium Module Server, and database server on the same appliance. An All-in-One deployment is supported only for proof-of-concept (POC) deployments. Tanium Zone Server A server typically deployed in an enterprise DMZ network to proxy traffic between Tanium Clients that reside on limited-access networks and a Tanium Server that resides on the trusted core network Tanium Inc. All Rights Reserved Page 9

10 Topology In an enterprise production deployment, the Tanium Server and Tanium Module Server reside on separate Tanium Appliances. Figure 1: Enterprise production or enterprise lab deployment 2017 Tanium Inc. All Rights Reserved Page 10

11 Prerequisites This topic summarizes prerequisites to Tanium Appliance installation. License A license is bound to the hostname(s) that you assign to the Tanium Server(s). For HA deployments, both hostnames are used in the license data. Let your technical account manager (TAM) know if the hostnames provisioned for the Tanium Server(s) are changed. SSL certificates The connections to the Tanium Console or SOAP and REST APIs, the connections between Tanium Server and Tanium Module Server, and connections to the Module Server are secured with SSL/TLS certificate and key exchanges. The installation process uses selfsigned certificates. We recommend that you verify the installation with the self-signed certificates before you replace them with your commercial or enterprise CA certificates. Doing this facilitates troubleshooting by separating potential installation issues and SSL issues. For more information on SSL certificate requirements, see the Tanium Core Platform Installation Guide. Network connectivity and firewall Tanium components use TCP/IP to communicate over IPv4 networks. IPv6 is not supported. You must work with your network administrator to ensure that the Tanium components are provisioned IP addresses and that DNS can be used to resolve hostnames. The following table summarizes the Tanium processes and default values for ports used in Tanium core platform communication. Network firewalls might need to be configured to allow the specified processes to send/receive TCP via the ports listed. For a detailed explanation, see the Tanium Core Platform Installation Guide. Table 1: Network communication ports used by Tanium components Components Processes Inbound Port Destination Port Tanium Server taniumserver 443, 8443, , 443, Tanium Module Server taniummoduleserver , 443, Tanium Inc. All Rights Reserved Page 11

12 Components Processes Inbound Port Destination Port Tanium Zone Server taniumzoneserver Tanium Zone Server Hub taniumzoneserver Tanium Client TaniumClient.exe, TaniumClient, taniumclient Tanium Client Deployment Tool (CDT) TaniumClientDeploy.exe 22, 135, 445 Unmanaged Asset CDT platform-specific methods (during deployment only) 22, 135, 445 In addition, the installation and management of the appliance requires communication over common network service ports. The following table shows the default ports for these services. Table 2: Appliance network service ports Services Inbound port Destination port DNS 53/tcp, 53/udp ESP (HA cluster) 50/ip 50/ip IKE (HA cluster) 500/udp, 4500/udp 500/udp, 4500/udp LDAP (optional) NTP 389/tcp, 636/tcp 123/udp SSH, SCP, SFTP 22/tcp 22/tcp SNMP (optional) 161/tcp syslog (optional) 514/udp Internet access (direct or by proxy) During both installation and ongoing operations, the Tanium Server must be able to connect to to import updates to Tanium core components and 2017 Tanium Inc. All Rights Reserved Page 12

13 modules. The Tanium Server may need to connect to additional locations, based on the components you import. The following table lists URLs that are accessed by Tanium Server. Import type Components URLs Any Any Content Initial Content Managed Applications Windows Security Patch Management IR Gatherer Modules IR Patch IOC Detect Labs Content EMET IR Memory MSERT Stinger Symantec Notes: If a Tanium content pack or solution module is not listed, it means no additional URLs are required for it. Previous Tanium Server versions required access to Tanium Server 7.0 and later do not require access to this site Tanium Inc. All Rights Reserved Page 13

14 If your enterprise security policy does not allow Tanium Server to access these locations directly, you can use proxy servers. See the Tanium Core Platform User Guide. If your enterprise network uses SSL intercept technologies, such as man-in-the-middle (MITM) proxies, you must configure them so that they do not prevent the Tanium Server and Tanium Module Server from downloading files from these locations. If you plan to deploy Tanium into an air-gapped environment, consult with your TAM Tanium Inc. All Rights Reserved Page 14

15 Getting started 1. Install the Tanium Appliance into a machine room and configure bootstrap network settings. For details, see the Tanium Appliance Quick Start Guide. 2. Connect to the TanOS console using SSH and configure basic network, host, and user settings. See Configuring network, host, and user settings on page Install the Tanium servers. See: Installing Tanium Server on page 32 Installing Tanium Module Server on page 36 Installing Tanium Zone Server on page Install the license file. See Installing the license file on page Verify the installation. See Verifying the deployment on page Tanium Inc. All Rights Reserved Page 15

16 Configuring network, host, and user settings You must configure basic network, host, and user settings before you can install a Tanium Appliance role. Configure temporary bootstrap network settings The Tanium Appliance Quick Start Guide describes how to install the appliance into a machine room and configure bootstrap network settings so that you can make a remote SSH connection and complete the setup and Appliance role installation from your desk. The Quick Start steps are repeated here to give context to the starting point for your initial workflows. Before you begin Connect a keyboard, video, and mouse (KVM) to the console port. Obtain an IPv4 address from your network administrator and be prepared to specify the IP address, subnet mask (dotted-decimal), and default gateway IP address. Configure the temporary settings 1. Power on the appliance. The boot and start-up processes take a few minutes. 2. When prompted to log in, specify the user name tanuser and the default password Tanium Tanium Inc. All Rights Reserved Page 16

17 3. When prompted, indicate that you want to configure temporary settings. 4. Specify the IPv4 address, subnet mask, and default gateway IP address. The TanOS console confirms that the settings are applied and logs you out. Configure network and host settings Network and host settings enable the appliance to establish connections with other computers in your local network and with other servers and hosts on the Internet. Specify appropriate settings for the network in which the appliance is deployed. Before you begin Your local "management computer" must be connected to a subnet that can reach the appliance IP address Tanium Inc. All Rights Reserved Page 17

18 Your management computer must have an SSH client application or terminal emulator that can make a client connection to the appliance. Be ready to specify the static IP address, subnet mask (dotted-decimal), default gateway IP address, hostname, domain name, primary and secondary DNS servers, NTP server(s), and time zone settings. You must have an SSH client such as PuTTY to log into the TanOS console. The latest version of PuTTY was used in testing. You must have an SSH key generator such as PuTTYgen to generate keys for the tancopy user. The latest version of PuTTYgen was used in testing. You must have an SFTP client such as WinSCP to copy files to and from the appliance. The latest version of WinSCP was used in testing. Configure the network and host settings 1. Make an SSH connection to the appliance IP address that was configured in the previous step. 2. When prompted to log in, specify the user name tanadmin and the default password Tanium1. 3. When prompted, indicate that you want to complete the initial configuration Tanium Inc. All Rights Reserved Page 18

19 4. Accept the end-user license agreement (EULA). 5. Specify network and host configuration settings. The console displays a notice that the passwords will be reset and the system restarted. You must configure a new password the next time you log in. Configure user access TanOS has a few built-in user accounts that you use to access the appliance operating system and perform tasks. Before you install a Tanium Appliance role, you must configure new passwords or add SSH keys to authenticate access for the following accounts: tanuser: Can make an SSH connection with password authentication to the TanOS console and access status menus Tanium Inc. All Rights Reserved Page 19

20 tanadmin: Can make an SSH connection with password authentication to the TanOS console and access all menus. tancopy: Can make an SFTP connection with SSH key authentication to TanOS and copy files to and from the /incoming and /outgoing directories. Before you begin Be ready to specify new passwords for the tanuser and tanadmin accounts. The password string must be at least 10 characters long and have at least 1 uppercase character, 1 lowercase character, 1 numeric character, and 1 nonalphanumeric character. You must have an SSH client to log into the TanOS console and an SFTP client to copy files to and from the appliance. You must have an SSH key generator to generate keys for the tancopy user. Change the default passwords 1. Log into the TanOS console as tanuser and then follow the prompts to change the password. 2. Log into the TanOS console as tanadmin and then follow the prompts to change the password. Add SSH keys for the tancopy account IMPORTANT: This procedure adds an authorized key for the tancopy user to the appliance configuration. The purpose of this key is to enable you to use an SFTP client on your management computer to copy files to the /incoming and from the /outgoing directories on the appliance. In the Tanium Module Server and HA active-active installations, you are instructed to add a different authorized key for the tancopy user. Be careful not to mistake one for the other. The authorized keys serve different purposes. Both are required Tanium Inc. All Rights Reserved Page 20

21 1. Use an SSH key generator such as PuTTYgen to generate a public/private key pair. 2. In PuTTYgen, select all of the text in the Public key for pasting into OpenSSH authorized_keys file box and copy it to the clipboard. IMPORTANT: In an SSH key exchange, the keys must match precisely as expected, including line endings. For this reason, the PuTTy documentation recommends loading the key in PuttyGen and copying it from the Public key for pasting... box instead of copying it from an open file Tanium Inc. All Rights Reserved Page 21

22 3. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 22

23 4. Enter C to go to the User Administration menu. 5. Enter 3 to go to the SSH Key Management menu Tanium Inc. All Rights Reserved Page 23

24 6. Enter the line number for the tancopy user to display the key management menu for this user. 7. Enter 3 to go to the Authorized Keys menu. 8. Enter 2 and then follow the prompts to paste the public key generated in Step Tanium Inc. All Rights Reserved Page 24

25 9. To test it, on your management computer, set up an SFTP client such as WinSCP to connect to the Tanium Server appliance: a. Specify tancopy for user name. b. Click the Advanced button Tanium Inc. All Rights Reserved Page 25

26 c. Under SSH, browse and select the private key that pairs with the public key uploaded to the appliance. You should be able to connect to the appliance /incoming and /outgoing directories Tanium Inc. All Rights Reserved Page 26

27 Note: You might see permission denied messages because WinSCP attempts to read the listing of the /incoming directory. This is expected. The user tancopy has permission to write to /incoming but not read /incoming Tanium Inc. All Rights Reserved Page 27

28 Installing a Tanium All-in-One role In an All-in-One deployment, the Tanium Server, the Tanium Module Server, and a database server reside on the same Tanium Appliance. All-in-One deployments are supported only for proof-of-concept (POC) demonstrations. Figure 2: All-in-One deployment The All-in-One role installation creates the necessary component servers, SSL certificates, SSH keys, and configuration files. Before you begin Make sure: Basic network, host, and user settings are configured. See Configuring network, host, and user settings on page 16. Network firewalls rules allow Tanium processes to communicate as expected. See Network connectivity and firewall on page Tanium Inc. All Rights Reserved Page 28

29 Install the Tanium Server All-in-One role 1. Log in as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 29

30 2. Enter 1 to go to the Tanium Installation menu. 3. Enter 1 to initiate an All-in-One installation Tanium Inc. All Rights Reserved Page 30

31 4. When prompted, specify a password for the initial Tanium Console user (tanium). 5. Enter YES to continue with the installation. The installation is completed in about 30 seconds. Next steps 1. Download the Tanium Server public key file on page 127 so you can include it in Tanium Client installation packages. 2. Installing the license file on page Verifying the deployment on page Tanium Inc. All Rights Reserved Page 31

32 Installing Tanium Server The Tanium Server role installation creates the Tanium Server and database server, SSL certificates, SSH keys, and Tanium Server configuration file. Before you begin Make sure: Basic network, host, and user settings are configured. See Configuring network, host, and user settings on page 16. Network firewalls rules allow Tanium processes to communicate as expected. See Network connectivity and firewall on page Tanium Inc. All Rights Reserved Page 32

33 Install Tanium Server 1. Log into the Tanium Server appliance as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 33

34 2. Enter 1 to go to the Tanium Installation menu. 3. Enter 2 to install the Tanium Server Tanium Inc. All Rights Reserved Page 34

35 4. When prompted, specify a password for the initial Tanium Console user (tanium). 5. Enter YES to continue with the installation. The installation is completed in about 30 seconds. Next steps 1. Download the Tanium Server public key file on page 127 so you can include it in Tanium Client installation packages. 2. Installing Tanium Module Server on page Tanium Inc. All Rights Reserved Page 35

36 Installing Tanium Module Server The Tanium Module Server role installation creates the Tanium Module Server, SSL certificate, and configuration file. The workflow described here also configures the Tanium Server to use the remote Module Server. In this workflow, the required certificate files are copied from the Tanium Server to the Module Server, the configuration files are updated, and the services are restarted. Before you begin Make sure: Basic network, host, and user settings are configured. See Configuring network, host, and user settings on page 16. Network firewalls rules allow communication between Tanium Server and Tanium Module Server on TCP port Add required SSH keys An SSH key exchange is used to securely copy files from the Tanium Server to the remote Module Server during installation. 1. Start two SSH terminal sessions so you can copy and paste between them: Tanium Server Tanium Module Server 2017 Tanium Inc. All Rights Reserved Page 36

37 2. Log into the Tanium Server appliance as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 37

38 3. Enter C to go to the User Administration menu. 4. Enter 3 to go to the SSH Key Management menu Tanium Inc. All Rights Reserved Page 38

39 5. Enter the line number for tanadmin to display the key management menu for this user. 6. Enter 2 to display the public key. 7. Copy the contents of the public key to the clipboard. 8. Log into the Tanium Module Server appliance as the user tanadmin. 9. Enter C to go to the User Administration menu. 10. Enter 3 to go to the SSH Key Management menu. 11. Enter the line number for the tancopy user Tanium Inc. All Rights Reserved Page 39

40 12. Enter 3 to go to the Authorized Keys menu. 13. Enter 2 and then follow the prompts to paste the contents of the Tanium Server tanadmin user public key file you copied in Step Tanium Inc. All Rights Reserved Page 40

41 Install the Tanium Module Server 1. Log into the Module Server appliance as the user tanadmin. 2. Enter 1 to go to the Tanium Installation menu. 3. Enter 3 to install the Tanium Module Server. The installation is completed in about 30 seconds Tanium Inc. All Rights Reserved Page 41

42 Configure the Tanium Server to use the remote Module Server 1. Log into the Tanium Server appliance as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 42

43 3. Enter A to go to the Configure Remote Module Server menu. 4. Enter 1 and then follow the prompts to configure the Tanium Server to use the remote Module Server Tanium Inc. All Rights Reserved Page 43

44 Enable the remote Module Server 1. Log into the Tanium Module Server appliance as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter A to go to the Configure Remote Module Server menu. 4. Enter 2 and then follow the prompts to enable the remote Module Server and to configure its connection with the Tanium Server. For active-active deployments, be sure to specify the IP address, hostname, and domain for both Tanium Servers. Next steps Installing Tanium Zone Server on page 45 (if applicable). Installing the license file on page Tanium Inc. All Rights Reserved Page 44

45 Installing Tanium Zone Server The Tanium Zone Server role installation creates the Tanium Zone Server and configuration file. The workflow described here also installs the Tanium Zone Server Hub Add-On and configures the Zone Server Hub to listen for connections from the Zone Server. Overview In Tanium deployments, Tanium Clients initiate communication with the Tanium Server. Your enterprise network security policies likely do not allow endpoints that reside in the untrusted network to initiate connections to resources that reside in the internal network, such as the Tanium Server. To enable the Tanium Server to manage these endpoints, you can deploy one or more Tanium Zone Servers in the DMZ to proxy communication from the external endpoints. The figure below illustrates Zone Server communication. The Zone Server is installed as a service, typically on an existing, shared device in the DMZ. It communicates with the Tanium Server through a Zone Server Hub process that you install as an add-on to the Tanium Server appliance. You set up external clients to register with the Zone Server as if it were the primary Tanium Server. To optimize performance as much as possible, the Zone Server is designed to cache sensor definitions, configuration information, and the files packaged in actions. It provides these resources to clients without having to re-request them from the Tanium Server. IMPORTANT: When using Tanium to manage external clients, be mindful that they might not have the same access to internal resources as internal clients. Target actions so that external clients are not instructed to attempt to access resources on the internal network, like an Active Directory server, or package files staged on an internal URL Tanium Inc. All Rights Reserved Page 45

46 Figure 3: Zone Server deployment Before you begin Make sure: Basic network, host, and user settings are configured. See Configuring network, host, and user settings on page 16. Network firewalls rules allow communication between the Zone Server hub and Zone Server on TCP port You have a copy of the Tanium Server public key file (tanium.pub) that you can upload to the Zone Server. See Download the Tanium Server public key file on page 127. Install the Tanium Zone Server This section provides procedures for the following workflow: 1. Deploy one or more Zone Server appliances in the DMZ. 2. Install the Zone Server hub add-on on the Tanium Server appliance and configure a Zone Server list that defines the Zone Servers with which it can communicate Tanium Inc. All Rights Reserved Page 46

47 Install the Zone Server 1. Log into the Zone Server appliance as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 47

48 2. Enter 1 to go to the Tanium Installation menu. 3. Enter 4 to install the Tanium Zone Server. The installation is completed in about 30 seconds. Import the Tanium Server public key file to the Zone Server 1. On your management computer, set up an SFTP client such as WinSCP to connect to the Tanium Zone Server appliance: 2017 Tanium Inc. All Rights Reserved Page 48

49 a. Specify tancopy for user name. b. Click the Advanced button Tanium Inc. All Rights Reserved Page 49

50 c. Under SSH, browse and select the private key that pairs with the public key uploaded to the appliance in Configure user access on page Use SFTP to copy the tanium.pub file to the /incoming directory on the Zone Server appliance Tanium Inc. All Rights Reserved Page 50

51 3. Log into the Zone Server appliance as the user tanadmin. 4. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 51

52 5. Enter 6 and then follow the prompts to copy the Tanium Server public key file (tanium.pub) into the Zone Server installation directory. Install the Zone Server hub After you have installed the Tanium Server role on a Tanium Appliance, you can install the Zone Server Hub Add-On Tanium Inc. All Rights Reserved Page 52

53 1. Log into the Tanium Server appliance as the user tanadmin. 2. Enter 1 to go to the Tanium Installation menu Tanium Inc. All Rights Reserved Page 53

54 3. Enter A and then follow the prompts to install the Tanium Zone Server Hub Add-On. The installation is completed in about 30 seconds. Edit the Zone Server List 1. Log into the Tanium Server appliance as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 54

55 3. Enter 2 to go to the Configuration Files menu. 4. Enter 9 to edit the zoneserverlist.txt file. 5. Add the IP address or FQDN for each Zone Server and save the file. Next steps Installing the license file on page Tanium Inc. All Rights Reserved Page 55

56 Installing the license file You install the Tanium license file on the appliance that hosts the Tanium Server. Tip: Install the license file before you log into the Tanium Console for the first time so that Tanium Interact is installed automatically during the Tanium Console launch. Before you begin Your management computer must have an SFTP client such as WinSCP to copy files to and from the appliance. You must generate a public/private key pair to use with the tancopy user and upload the public key to the Tanium Server Appliance as described in Configure user access on page 19. Upload the license file 1. On your management computer, set up an SFTP client such as WinSCP to connect to the Tanium Server appliance: a. Specify tancopy for user name Tanium Inc. All Rights Reserved Page 56

57 b. Click the Advanced button. c. Under SSH, browse and select the private key that pairs with the public key uploaded to the appliance in Configure user access on page Tanium Inc. All Rights Reserved Page 57

58 2. Use SFTP to copy your license file (tanium.license) to the /incoming directory on the appliance Tanium Inc. All Rights Reserved Page 58

59 Install the license 1. Log into the Tanium Server appliance as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 59

60 2. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 60

61 3. Enter 4 and then follow the prompts to install the license. Next steps Verifying the deployment on page Tanium Inc. All Rights Reserved Page 61

62 Verifying the deployment Log into the Tanium Console to verify proper communication among deployment components: Successful installation of Tanium content packs verifies communication with content.tanium.com. Successful installation of Tanium Interact verifies communication between the Tanium Server and Tanium Module Server. Successful registration by Tanium Clients verifies communication with clients. Successful registration by a Tanium Client configured to use the Zone Server address verifies communication between the Zone Server and Zone Server hub service. Log into the Tanium Console 1. In a web browser, go to to log into the Tanium Console Tanium Inc. All Rights Reserved Page 62

63 Tanium_Server_FQDN is the fully-qualified domain name for the Tanium Server appliance. The default port is 8843, and it is redirected to 443. You do not have to specify port if you use the default. 2. Enter the user name tanium and the password you set when you installed the Tanium Server. When you first log into the Tanium Console, it automatically initiates the following actions: Imports the Initial Content - Base content pack. The Initial Content packs include the sensors, packages, saved questions, and dashboards that are essential for getting started with Tanium. Imports the Client Maintenance content pack. The Client Maintenance pack includes the sensors, packages, actions, and saved questions that are used to perform hygiene checks on Tanium Clients. Imports the Interact workbench. The Interact workbench includes the user interface for questions and results. Deploy the Tanium Client to your lab computers This installation guide includes a brief section on deploying Tanium Clients so that you can use basic client-server registration to verify successful installation of the Tanium core server components. For comprehensive information on client deployment options, see the Tanium Client Deployment Guide. Before you begin Make sure: You have a Windows computer on which you can install the Tanium Client Deployment Tool (CDT). Network firewalls rules allow the Tanium CDT to make connections to the target endpoints. See the Tanium Core Platform Installation Guide Reference: Network ports. You know the username and password of an administrator account that can log into the target endpoint and install the Tanium Client. You have downloaded the Tanium Server public key file so you can include it in Tanium Client installation packages Tanium Inc. All Rights Reserved Page 63

64 Install the Tanium Client Deployment Tool 1. Download the Tanium Client Deployment Tool. Click here to begin the download. 2. Run the installer. The installation wizard prompts you for one value the installation directory. The default is C:\Program Files (x86)\tanium\tanium Client Deployment Tool. 3. Select Start > Tanium Client Deployment Tool to open the tool. Upon initialization, the tool prompts you to download the latest endpoint software from content.tanium.com Tanium Inc. All Rights Reserved Page 64

65 4. Click OK to download the latest endpoint software. 5. If you plan to use Microsoft PSExec to push Tanium Client to endpoints: a. When prompted, follow the link to download PSTools from the Microsoft download site Tanium Inc. All Rights Reserved Page 65

66 b. Unzip the package and copy the PsExec.exe and PSExec64.exe files to the CDT installation directory. c. Restart the Tanium CDT. Deploy the Tanium Client 1. Open the Tanium CDT. 2. Configure the following settings. Username/Password Local or domain user with administrative privileges on the targeted endpoints. The deployment tool uses this account when it connects to the targeted endpoint and executes the client installer. Tanium.pub Server Name Path to the Tanium Server public key file (tanium.pub). The FQDN for the Tanium Server. Specify a comma-separated list. For example, ts1.example.com,ts2.example.com. Port Log Verbosity Level Execution Method Specify 1 for this initial deployment. Level 1 writes a minimal logs that might be useful if there are issues with the initial deployment. Select PSEXEC if you downloaded it in the previous procedure. 3. Use the Computer List tab to specify the computer names, IP addresses or IP address ranges for a few endpoints in your lab Tanium Inc. All Rights Reserved Page 66

67 4. Click Install to deploy the client to a few host computers in your lab. Verify the basic deployment 1. In Interact, verify the endpoints respond to the following query: Get Computer Name and Tanium Server Name from all machines 2. Review the results grid to verify that all clients on which Tanium Client software was deployed are now reporting Tanium Inc. All Rights Reserved Page 67

68 3. You can also go to the System Status page to review recent client registration details. Go to Administration > System Status to display the page. Verify the Zone Server deployment 1. Use the Tanium CDT to deploy the Tanium Client to a client in your lab. In the configuration, for Tanium Server, specify the Zone Server FQDN (appliancezs.tam.local in this example) Tanium Inc. All Rights Reserved Page 68

69 2. In Interact, ask Get Computer Name and Tanium Server Name from all machines and verify that the Tanium Client on the Zone Server is reporting via the Tanium 2017 Tanium Inc. All Rights Reserved Page 69

70 Zone Server Tanium Inc. All Rights Reserved Page 70

71 Installing Tanium Server in an active-active cluster High-availability (HA) features support Tanium Server availability even when there is a failure or scheduled maintenance. The active-active cluster setup workflow installs the Tanium Server and a database server on each appliance, makes updates in the configuration files, and copies the license file, SSL certificates, and SSH public/private key pair from the first appliance to the second appliance. Overview HA clustering is not required to scale Tanium capacity or to improve performance. You can size the host system hardware and OS of standalone platform servers to meet your capacity and performance requirements. Rather, the Tanium Core Platform supports HA activeactive clustering of Tanium Server to ensure continuous availability in the event of an outage or scheduled maintenance. The following figure shows an HA topology. In an active-active deployment: Tanium Clients use a Tanium Server list to automatically find a backup server in the event the first Tanium Server assigned to them is unavailable. The Tanium Servers read and write to the database co-located on the first appliance. Data is periodically replicated from the first appliance database to the second appliance database. The local authentication user configuration is periodically synchronized between the two appliances. IPsec ensures end-to-end security between the two appliances. Each cluster member has a Tanium Console with its own URL. Tanium solution modules are installed on a shared Module Server. However, they must be imported in each Tanium Console in order to be accessed from each. The order in which you import solution modules into the Tanium Console determines the order in which they are displayed in the navigation menu. We recommend you import the modules in the same order on TaniumServer01 as you will on TaniumServer02 so that the menus are in the same order Tanium Inc. All Rights Reserved Page 71

72 Each server passes Tanium messages (for example, answers to questions) to the other cluster members. Package files that are uploaded to one member are synchronized to the other cluster members. HA is not supported for Tanium Module Server. You might want to provision a cold standby that you can bring into service to replace the Module Server in the event of hardware failure. Follow database administration best practices to ensure availability of the database server and that the Tanium databases and related database objects are backed up routinely. Figure 4: HA topology HA cluster requirements and limitations An HA deployment has the following requirements: Each Tanium Server must run the same software version, including build number (for example, each must have build number ). Each Tanium Server in the cluster must meet or exceed the requirements for the total number of endpoints targeted by your deployment. (Each must be able to independently handle load from the full deployment in the event of failure.) 2017 Tanium Inc. All Rights Reserved Page 72

73 The cluster members must be able to connect to each other via a reliable Ethernet connection. A minimum 1 Gbps connection is required. Each cluster member must be able to access the Internet to download files from designated domains. Access can be direct or made through a proxy server. Each cluster member must be able to connect to the shared Module Server. Before you begin Make sure: Basic network, host, and user settings are configured on both appliances. See Configuring network, host, and user settings on page 16. We recommend you allocate a network interface on each Tanium Server appliance for the HA cluster communication. Specify the IP addresses of the HA interfaces when you configure the IPsec tunnel. Specify the IP addresses of the Tanium traffic interfaces when you configure the HA cluster IP addresses. Your network security administrator has configured security rules to allow communication on the TCP ports that the Tanium core platform components use. In addition to the ports used by individual Tanium Servers, a Tanium Server in an HA cluster sends and receives HA-related data over an IPsec connection. The network security rules must allow ESP (50/ip) and IKE (500/udp, 4500/udp). Add required SSH keys An SSH key exchange is used to securely copy files from the first Tanium Server to the second Tanium Server during installation. 1. Start two SSH terminal sessions so you can copy and paste between them: First Tanium Server Second Tanium Server 2017 Tanium Inc. All Rights Reserved Page 73

74 2. Log into the first Tanium Server appliance as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 74

75 3. Enter C to go to the User Administration menu. 4. Enter 3 to go to the SSH Key Management menu Tanium Inc. All Rights Reserved Page 75

76 5. Enter the line number for tanadmin to display the key management menu for this user. 6. Enter 2 to display the public key. 7. Copy the contents of the public key to the clipboard. 8. Log into the second Tanium Server appliance as the user tanadmin. 9. Enter C to go to the User Administration menu. 10. Enter 3 to go to the SSH Key Management menu. 11. Enter the line number for the tancopy user Tanium Inc. All Rights Reserved Page 76

77 12. Enter 3 to go to the Authorized Keys menu. 13. Enter 2 and then follow the prompts to paste the contents of the Tanium Server tanadmin user public key file you copied in Step 7. Set up the IPsec tunnel IPsec is used to ensure end-to-end security between the two appliances. 1. Start two SSH terminal sessions so you can copy and paste between them: First Tanium Server Second Tanium Server 2. Log into the first Tanium Server appliance as the user tanadmin Tanium Inc. All Rights Reserved Page 77

78 3. Enter A to go to the Appliance Configuration menu. 4. Enter 2 to go to the IP Configuration menu Tanium Inc. All Rights Reserved Page 78

79 5. Enter 2 to go to the IPsec menu. 6. Log into the second Tanium Server appliance as the user tanadmin. 7. Go to the IPsec menu. 8. Enter 1 to display the local IPsec host key. 9. Copy it to the clipboard. 10. Go back to the first appliance Tanium Inc. All Rights Reserved Page 79

80 11. Enter 3 and follow the prompts to configure this side of the IPsec tunnel. Paste the IPsec host key for the second appliance. 12. Enter 1 to display the local IPsec host key for the first appliance and copy it to the clipboard so you can paste it into the configuration for the second appliance. 13. Go back to the second appliance. 14. Go to the IPsec menu. 15. Enter 3 and follow the prompts to configure this side of the IPsec tunnel. Paste the IPsec host key for the first appliance. 16. Enter 6 to test the connection from this side. 17. Go back to the first appliance. 18. Enter 6 to test the connection from this side Tanium Inc. All Rights Reserved Page 80

81 Deploy the HA cluster 1. Complete the installation for the first Tanium Server as described in Installing Tanium Server on page Install the license file. See Installing the license file on page Complete the installation for the Tanium Module server as described in Installing Tanium Module Server on page 36. When you configure the remote Module Server, be sure to specify the host, domain, and IP address of both Tanium Servers. 4. Complete the installation for the second Tanium Server as described in Installing Tanium Server on page Log into the first Tanium Server appliance as the user tanadmin. 6. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 81

82 7. Enter B to go to the Cluster Configuration menu. 8. Enter 1 and then follow the prompts to configure the connection with the second member and initialize the HA cluster Tanium Inc. All Rights Reserved Page 82

83 9. Log into the second Tanium Server appliance as the user tanadmin. 10. Enter 2 to go to the Tanium Operations menu. 11. Enter B to go to the Cluster Configuration menu. 12. Enter 2 and then follow the prompts to configure the connection with the first member and join the HA cluster. Verify the installation 1. Deploy the Tanium Client to endpoints. When you configure client settings, specify both server names so the Tanium Clients use the ServerNameList setting to select a Tanium Server. See the Tanium Client Deployment Guide Tanium Inc. All Rights Reserved Page 83

84 2. In Interact, ask Get Computer Name and Tanium Server Name from all machines and verify that both Tanium Servers are active. 3. Verify that both servers can download packages with URL-specified files when such a package is created or imported. Distribute Copy Tools is an example of a package with URL-specified files: a. Go to Authoring > Packages. b. Select the row for Distribute Copy Tools. c. Click Status and check that the files have been downloaded and are now cached on both servers. 4. Create a new package and specify a locally uploaded file. After you have saved the package, wait a moment for HA sync to occur, and then check that the files are 2017 Tanium Inc. All Rights Reserved Page 84

85 downloaded and cached by both servers Tanium Inc. All Rights Reserved Page 85

86 Upgrading Tanium server software You can use TanOS to install an upgrade of Tanium Server, Tanium Module Server, or Tanium Zone Server software. Before you begin Read the release notes for all of the core platform software versions that were released after your current version to stay informed about expected behavior. Your Tanium Technical Account Manager (TAM) will let you know when upgrades are advised and can assist you with the upgrade. Your TAM will provide the upgrade package files. All servers must have the same version number (for example, ), so you must be ready to upgrade all Tanium servers in your environment. Import the latest version of the solutions. The latest version has been tested with the target server version. Make sure the current deployment is working as expected. Back up the database. Back up the appliance. Upgrade Tanium server software 1. Use SFTP to copy the Tanium server RPM file to the /incoming directory on the appliance. 2. Log into the TanOS console as the user tanadmin Tanium Inc. All Rights Reserved Page 86

87 3. Enter 1 to go to the Tanium Installation menu Tanium Inc. All Rights Reserved Page 87

88 4. Enter u to go to the software upgrade page. Follow the prompts to complete the upgrade Tanium Inc. All Rights Reserved Page 88

89 Troubleshooting the installation 1. Run the Health Check. 2. Check whether a Tanium service or networking needs to be restarted. 3. Review logs. 4. Review the configuration. 5. Run Tanium Support Gather. 6. Examine OS processes and files written to the filesystem. 7. Perform a software reset. Run the Health Check 1. From the tanadmin menu, enter 3 to go to the Tanium Support menu. 2. Enter 4 to run the health check. Welcome tanadmin to appliance-ts1.tam.local >>> Tanium Support menu <<< 1: Tanium Log Files 2: Database Monitoring 3: Run Network Diagnostics 4: Run Health Check 5: Display Last Scheduled Health Check Results 6: Appliance Hardware Report A: Generate T.H.A.T Report B: Run TSG (Tanium Support Gatherer) C: Copy Core Files H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select: 4 Launching Health Check... >>> Tanium Support -> Run Health Check <<< Current date: UTC (day-month-year) Current time: 05:30:27 Uptime: 05:30:27 up 8:11, 1 user, load average: 1.15, 1.44, 1.23 >>> Operating System health (will take 7-10 seconds) <<< 2017 Tanium Inc. All Rights Reserved Page 89

90 CPU: pass Memory: pass Swap: pass Partition /: pass Partition /boot: pass Partition /var: pass Partition /var/log: pass Partition /var/log/audit: pass Partition /opt: pass Partition /tmp: pass Partition /home: pass >>> User health <<< user tanium: pass user tanadmin: pass user tanuser: pass user tancopy: pass user tanfactory: pass user tanium (OTP): pass (not active) >>> Network health (will take 5-7 seconds) <<< default gateway: pass name resolution: pass L2 check ens33: pass L2 check ens34: pass L2 check ens38: pass mount /opt/mounts/connect: pass (not configured) mount /opt/mounts/detect: pass (not configured) >>> Service health <<< ntpd service: fail (system status failure) rsyslog service: pass iptables service: pass sshd service: pass ipsec service: pass local auth service: pass >>> Application health <<< taniumserver.service: pass taniumserver.service: pass (iptables) taniumserver.service: pass (clients connected) taniumserver.service: pass (database connected) taniummoduleserver.service: pass (does not exist/not installed) taniumzoneserver.service: pass (does not exist/not installed) executed checks: 36 failed checks: 1 new health status setting: warning >>> End Health Check <<< Press enter to continue... Restart services or networking Check whether a Tanium service needs to be restarted Tanium Inc. All Rights Reserved Page 90

91 Restart services 1. From the tanadmin menu, enter 2 to go to the Tanium Operations menu. 2. Enter 1 to go to the Tanium Service Control menu. 3. Enter the line number of the service you want to manage to display the service commands. 4. Type the number of a service control command to issue it. Welcome tanadmin to appliance-ts1.tam.local >>> Tanium Operations -> Tanium Service Control <<< # Service State Status 1 ipsec enabled started 2 postgresql-9.5 enabled started 3 slapd enabled started 4 taniumserver enabled started H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select a line number or menu item: Restart networking 1. From the tanadmin menu, enter A to go to the Appliance Configuration menu. 2. Enter 2 to go to the IP Configuration menu. 3. Enter 4 to restart networking. >>> Appliance Configuration -> IP Configuration -> Restart Networking <<< About to restart networking on the appliance. Warning: service interruptions will occur! If an IP address change was pending, you will need to connect to the new IP address. Would you like to restart networking? [YES/NO]: yes Restarting networking... Network restart completed. Press enter to continue Tanium Inc. All Rights Reserved Page 91

92 Review logs 1. From the tanadmin menu, enter 3 to go to the Tanium Support menu. 2. Enter 1 to go to the Log Files menu. 3. Select an item to view the log. You can use commands similar to ex editor commands to search for patterns (keywords). >>> Tanium Support -> Log files <<< Not all log files will be available with each server role! Note: to access module specific logfiles, please use TSG 1: Tanium Service Log file 2: Tanium Service RBAC file 3: Tanium Service TDL Log file : Tanium Module Service Log file 5: Tanium Module Service TDL Log file : Tanium Zone Service Log file : Tanium Postgres Log file H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select: 3 Calling Tanium Service TDL Log file... >>> Tanium Support -> Log files -> View <<< About to open a copy of the current log file - enter "q" to exit T20:34:50.267Z[00:007565:] Begin Log (TDownloader) T20:34:50.313Z[00:007572:] Begin Log (TDownloader) T20:34:50.384Z[00:007575:] Begin Log (TDownloader) T20:34:50.412Z[00:007579:] Begin Log (TDownloader) T20:34:50.411Z[00:007577:] Begin Log (TDownloader) T20:34:52.293Z[00:007582:] Begin Log (TDownloader) T20:34:52.339Z[00:007580:] Begin Log (TDownloader) T20:34:52.370Z[00:007584:] Begin Log (TDownloader) T20:34:52.399Z[00:007589:] Begin Log (TDownloader) T20:34:52.395Z[00:007586:] Begin Log (TDownloader) T20:34:52.623Z[00:007589:] Finished with status 200 (SUCCESS) for URL progress file id=(pfid=5) T20:34:52.623Z[00:007589:] End Log (TDownloader) T20:34:52.655Z[00:007586:] Finished with status 200 (SUCCESS) for URL [...] progress file id=(pfid=9) T20:34:52.655Z[00:007586:] End Log (TDownloader) T20:34:52.660Z[00:007584:] Finished with status 200 (SUCCESS) for URL progress file id=(pfid=7) T20:34:52.660Z[00:007584:] End Log (TDownloader) 2017 Tanium Inc. All Rights Reserved Page 92

93 T20:34:52.686Z[00:007580:] Finished with status 200 (SUCCESS) for URL progress file id=(pfid=8) /tmp/log0.txt Review the configuration 1. From the tanadmin menu, enter 2 to go to the Tanium Operations menu. 2. Enter 2 to go to the Configuration Files menu. 3. Enter the line number of the action you want to take. Welcome root to appliance-ts2.tam.local >>> Tanium Operations -> Configuration files <<< 1: View Tanium Server INI 2: Edit Tanium Server INI 3: Set Tanium Server TDL LogLevel H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select: 2 Calling edit Tanium Server INI >>> Tanium Operations -> Configuration files -> Edit TaniumServer.ini <<< LogVerbosityLevel=1 TrustedCertPath=/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem ConsoleSettingsJSON=/opt/Tanium/TaniumServer/http/config/console.json LogPath=/opt/Tanium/TaniumServer/Logs ServerPort=17472 ServerSOAPPort=8443 AddressMask= ModuleServer= ModuleServerPort=17477 SQLConnectionString=postgres: @user=postgres password=sgtfer2bcajqwgjd6av7wdq dbname=tanium sslmode=require AuthenticationPlugin=InternalPython:tanium_pam4/pam_workflow.py Version= TrustedHostList=appliance-ts1.tam.local,appliance-ts2.tam.local ~ ~ ~ ~ ~ ~ ~ ~ 2017 Tanium Inc. All Rights Reserved Page 93

94 ~ ~ ~ ~ ~ / Run Tanium Support Gatherer The Tanium Support Gatherer (TSG) collects system status, process status, network interface status, and so on, to help your Tanium Technical Account Manager (TAM) evaluate possible appliance or Tanium server issues. 1. From the tanadmin menu, enter 3 to go to the Tanium Support menu. 2. Enter B to run the TSG. >>> Tanium Support menu <<< 1: Tanium Log Files 2: Run PG_TOP 3: Run Diagnostics 4: Run Health Check 5: Display Last Scheduled Health Check Results 6: Appliance Hardware Report A: Generate T.H.A.T Report B: Run TSG (Tanium Support Gatherer) H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select: b Launching TSG... >>> Tanium Support -> Run TSG (Tanium Support Gatherer)<<< Current date: UTC (day-month-year) /opt/tanos_shell/tsg/tsg Making output dir /opt/tanos_shell/tsg/tsg Requested All Making the output DIR Running commands for db [...] Copying TaniumServer log0.txt Can't find the TaniumModuleServer log0.txt Can't find the TaniumZoneServer log0.txt 2017 Tanium Inc. All Rights Reserved Page 94

95 Creating zip file adding: tsg /auth.log (deflated 53%) adding: tsg /db.log (deflated 82%) adding: tsg /hw.log (deflated 77%) adding: tsg /net.log (deflated 85%) adding: tsg /os.log (deflated 81%) adding: tsg /tms.log (deflated 76%) adding: tsg /ts.log (deflated 72%) adding: tsg /ts_log0.txt (deflated 97%) adding: tsg /tzs.log (deflated 64%) Pub directory does not exist. Do you want to create? [YES/NO]: yes Copying to the http directory You can get the file from Completed the TSG run Press enter to continue... The last stanza of the output shows the location where you can download the encrypted and compressed archive file. For example: Examine OS processes and files In rare cases, you or your TAM might need to examine OS processes and files written to the filesystem. You must follow a special procedure to request shell access. 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 95

96 2017 Tanium Inc. All Rights Reserved Page 96

97 2. Enter B to go to the Appliance Maintenance menu. 3. Enter 5 to go to the Shell Access (restricted) menu Tanium Inc. All Rights Reserved Page 97

98 4. Enter 1 and follow the prompts to generate a challenge key. Remember the "challenge password" you specify. You will need it to validate the response in a later step. The challenge key is written to the /outgoing folder. 5. Use SFTP to copy the request file from the /outgoing directory to your local computer. 6. the file and TanOS version information to your TAM. Your TAM will send you a response file Tanium Inc. All Rights Reserved Page 98

99 7. Use SFTP to copy the response file to the /incoming directory. 8. At the Appliance Maintenance > Shell menu prompt, enter 2 and then follow the prompts to validate the response. Specify the "challenge password" provided in a previous step Tanium Inc. All Rights Reserved Page 99

100 The Shell menu now has additional options. 9. Enter 3 to launch the shell. 10. Enter exit to close the shell. 11. When you are finished troubleshooting, go to the Shell Access (restricted) menu and enter 4 to remove the shell key. Perform a software reset The Appliance Maintenance > Reset menu has two options: Perform a software reset to erase the Tanium application software. Perform a factory reset only if you want to erase both the configuration and the installed software Tanium Inc. All Rights Reserved Page 100

101 1. From the tanadmin menu, enter B to go to the Appliance Maintenance menu. 2. Enter 2 to go to the Reset menu. 3. Enter the appropriate option. Welcome tanadmin to appliance-ts1.tam.local >>> Appliance Maintenance -> Reset <<< 1: Software reset (remove all Tanium application software) 2: Factory reset (remove software and configurations) H: Help R: Return to main menu TanOS Version: TanOS TanOS_Shell Version: Please select: 2017 Tanium Inc. All Rights Reserved Page 101

102 Managing user access The TanOS special users tanadmin, tancopy, tanfactory, and tanuser are not Tanium Console users. TanOS access requirements are enforced. Apart from special users, TanOS hosts a local authentication service that can be used for Tanium Console user authentication. You can create and delete users and manage their passwords. In addition, you can configure Tanium Console authentication against your enterprise LDAP server. For details on using LDAP, see the Tanium Core Platform User Guide. Change TanOS user passwords The TanOS special users tanadmin, tanuser, and tanfactory can make passwordauthenticated SSH connections to the TanOS console. The passwords for TanOS special users must be changed every 45 days. You can also change the passwords whenever it is necessary. The password string must be at least 10 characters long and have at least 1 uppercase character, 1 lowercase character, 1 numeric character, and 1 nonalphanumeric character Tanium Inc. All Rights Reserved Page 102

103 Change the tanadmin password 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 103

104 2. Enter P and then follow the prompts to change the password. After the password has been changed, you are logged out. Reset the tanuser password 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu Tanium Inc. All Rights Reserved Page 104

105 3. Enter 1 and then follow the prompts to reset the password. Reset the tanfactory password 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter 2 and then follow the prompts to reset the password. Manage SSH keys The installation process generates a public/private SSH key pair for the tanadmin user. You can use the SSH Key menu to regenerate this pair, generate keys for the other TanOS 2017 Tanium Inc. All Rights Reserved Page 105

106 special users, add authorized keys to support inbound user connections, and display the public key so you can copy and paste it into other appliance configurations as described in some of the installation procedures in this guide. Before you begin You must have an SSH client to log into the TanOS console and an SFTP client such as WinSCP to copy files to and from the appliance. You must have an SSH key generator such as PuTTYgen to generate keys for the tancopy user. Generate keys 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter 3 to go to the SSH Key Management menu. 4. Enter the line number for tancopy to display the key management menu for this user Tanium Inc. All Rights Reserved Page 106

107 5. Enter 1 to generate a public/private key pair. Add authorized keys 1. Use an SSH key generator such as PuTTYgen to generate a public/private key pair. 2. In PuTTYgen, select all of the text in the Public key for pasting into OpenSSH authorized_keys file box and copy it to the clipboard. 3. Log into the TanOS console as the user tanadmin. 4. Enter C to go to the User Administration menu. 5. Enter 2 to go to the SSH Key Management menu Tanium Inc. All Rights Reserved Page 107

108 6. Enter the line number for the tancopy user to display the key management menu for this user. 7. Enter 3 to go to the Authorized Keys menu. 8. Enter 2 and then follow the prompts to add the contents of the public key generated in Step 1. Display public keys 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter 3 to go to the SSH Key Management menu. 4. Enter the line number for the tancopy user to display the key management menu for this user Tanium Inc. All Rights Reserved Page 108

109 5. Enter 2 to display the public key. Configure the local authentication service You can use the local authentication service to set up Tanium Console user accounts for demo or testing purposes. Tanium recommends you configure the Tanium Console to use an external LDAP server to authenticate Tanium users. For details, see the Tanium Core Platform User Guide. Note: The Local Authentication Service menu is available only after you install the Tanium Server role. It is not available when other roles are installed. Add a local user 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu Tanium Inc. All Rights Reserved Page 109

110 3. Enter A to go to the Local Authentication Service menu. 4. Enter 1 and then follow the prompts to add a local user Tanium Inc. All Rights Reserved Page 110

111 Set a user password 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter A to go to the Local Authentication Service menu. 4. Enter 2 to display the Manage Local Users menu. 5. Enter the user line number to display the user menu. 6. Enter 2 and then follow the prompts to set the user password. Delete a user 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter A to go to the Local Authentication Service menu. 4. Enter 2 and to display the Manager Local Users menu. 5. Enter the user line number to display the user menu. 6. Enter 1 and then follow the prompts to delete the user Tanium Inc. All Rights Reserved Page 111

112 Disable the local authentication service 1. Log into the TanOS console as the user tanadmin. 2. Enter C to go to the User Administration menu. 3. Enter A to go to the Local Authentication Service menu. 4. Enter A and then follow the prompts to enable or disable the local authentication service Tanium Inc. All Rights Reserved Page 112

113 Configuring syslog You can forward appliance logs to a remote syslog server. Figure 5: A syslog reader To configure syslog forwarding: 2017 Tanium Inc. All Rights Reserved Page 113

114 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 114

115 2. Enter A to display the Appliance Configuration menu. 3. Enter 5 to display the Syslog Configuration menu Tanium Inc. All Rights Reserved Page 115

116 4. Enter 2 and then specify the IP address, port, and protocol for the remote syslog server Tanium Inc. All Rights Reserved Page 116

117 Configuring SNMP SNMP is enabled by default. You can configure SNMPv3 credentials for the user tanuser. This user can make a remote SNMP connection to the appliance to walk the MIB from a remote host or SNMP manager. Figure 6: SNMP walk To configure SNMPv3 access: 2017 Tanium Inc. All Rights Reserved Page 117

118 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 118

119 2. Enter A to display the Appliance Configuration menu. 3. Enter 6 and then follow the prompts to change the SNMPv3 credentials for tanuser Tanium Inc. All Rights Reserved Page 119

120 Reference: Certificate and key files Some deployment tasks instruct you to import/export SSL certificate and key files. Before you begin Your management computer must have an SFTP client such as WinSCP to copy files to and from the appliance. You must generate a public/private key pair to use with the tancopy user and upload the public key to the Tanium Appliance as described in Configure user access on page 19. Install a CA certificate file You can replace the self-signed certificates generated by the Tanium Server and Tanium Module Server installers with an SSL certificate issued by a commercial or enterprise certificate authority (CA). For details on certificate requirements, including the filenames expected in the Tanium installations, see the Tanium Core Platform Installation Guide Tanium Inc. All Rights Reserved Page 120

121 Upload the CA certificate file 1. Set up an SFTP client to connect to the Tanium appliance: a. Specify tancopy for user name. b. Click the Advanced button Tanium Inc. All Rights Reserved Page 121

122 c. Under SSH, browse and select the private key that pairs with the public key uploaded to the appliance in Configure user access on page Use SFTP to copy the SOAP certificate and key files to the /incoming directory on the appliance Tanium Inc. All Rights Reserved Page 122

123 Install the SOAP certificate file 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 123

124 2. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 124

125 3. Enter 5 to go to the Install Custom SOAP Cert procedure. 4. Follow the prompts to install the certificate and key files you uploaded in the previous procedure Tanium Inc. All Rights Reserved Page 125

126 Manage content signing keys 1. Log into the TanOS console as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 6 to go to the Manage Custom Signing Keys menu. 4. Use the menus to add, remove, or list the key files. Download the content signing key utility 1. Log into the TanOS console as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 6 to go to the Manage Custom Signing Keys menu. 4. Enter 1 to copy the KeyUtility.exe and related files to a zip file in the /outgoing directory Tanium Inc. All Rights Reserved Page 126

127 5. Use SFTP to copy the file from the /outgoing directory to your local computer. Download the Tanium Server public key file Download the Tanium Server public key file so you can include it in Tanium Client installation packages. 1. Log into the TanOS console as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 7 to go to the Download Public Key procedure. 4. Follow the prompts to copy the public key to the /outgoing directory Tanium Inc. All Rights Reserved Page 127

128 5. Use SFTP to copy the tanium.pub file from the /outgoing directory on the appliance to your management computer. Import the Tanium public/private key pair When you migrate an existing deployment to new installations, you might want to migrate the Tanium Server public/private key pair to avoid redistributing the tanium.pub key file to Tanium Clients. Upload the public and private key files 1. Add the public/private key pair you want to copy to a passphrase-protected tanum.zip file. 2. Set up an SFTP client to connect to the Tanium Server appliance: 2017 Tanium Inc. All Rights Reserved Page 128

129 Specify tancopy for user name. Click the Advanced button Tanium Inc. All Rights Reserved Page 129

130 Under SSH, browse and select the private key that pairs with the public key uploaded to the appliance in Configure user access on page Use SFTP to copy the tanium.zip file to the /incoming directory on the Tanium Server appliance Tanium Inc. All Rights Reserved Page 130

131 Replace the public and private keys 1. Log into the TanOS console as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 8 and then follow the prompts to import the zip file and install the keys Tanium Inc. All Rights Reserved Page 131

132 Reference: Tanium Service Control menu Tanium component servers and the database server can be managed with common service control commands: Start Stop Restart Disable Enable To issue a command: 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 132

133 2. Enter 2 to go to the Tanium Operations menu Tanium Inc. All Rights Reserved Page 133

134 3. Enter 1 to go to the Tanium Service Control menu. 4. Enter the line number of the service you want to manage to display the service commands. 5. Type the number of a service control command to issue it Tanium Inc. All Rights Reserved Page 134

135 Reference: Server configuration files You can use the Configuration Files menu to change the log level or the Tanium component server configuration settings. Contact your Tanium Technical Account Manager (TAM) before changing Tanium configuration settings. To edit a configuration file: 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 135

136 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 2 to go to the Configuration Files menu Tanium Inc. All Rights Reserved Page 136

137 4. Use the menu to view and edit Tanium server configuration files. To change the Tanium Server port: 1. Log into the TanOS console of the Tanium Server appliance as the user tanadmin. 2. Enter 2 to go to the Tanium Operations menu. 3. Enter 3 and then follow the prompts to change the Tanium Server port Tanium Inc. All Rights Reserved Page 137

138 TaniumServer.ini reference In general, you do not need to edit the Tanium Server configuration settings. During troubleshooting, your Tanium Technical Account Manager (TAM) might advise you to review and modify the settings described in the following table. Table 3: Settings Tanium Server settings Guidelines AddressMask Hexadecimal value of a subnet CIDR that delineates the clients that belong to a chain. Do not change this setting unless instructed to do so by your TAM. BypassCRLCheckHostLi st BypassProxyHostList Use this setting to list servers that should be trusted without CRL checking. Unless a server is specified in this list, the Tanium Server performs a CRL check and does not download files from a server that does not pass. If you configure a proxy server, you might need to configure exceptions so that connections to specified hosts do not go through the proxy server. For example, a proxy server should not be used for traffic between Tanium Servers in an active-active cluster. A proxy server can cause problems with other traffic to a destination Tanium Server. For example, a package configuration can specify file URIs that are local to the Tanium Server. It is important to bypass the proxy server for these URIs. Use this setting to specify destinations that should not use the proxy servers. In most cases, specify localhost, , and all Tanium Server names and IP addresses. For example: ts1.example.com, ts2.example.com,localhost, , , Version and later support wildcards. ConsoleSettingsJSON LogPath Path to the console settings file. The default is /opt/tanium/taniumserver/logs Tanium Inc. All Rights Reserved Page 138

139 Settings LogVerbosityLevel Guidelines Log verbosity level: 0: Logging disabled. 1: Normal log level. 41: Recommended during troubleshooting. >= 91: Most detailed log level. Enable for short periods of time only. ModuleServer Module Server IP address. ModuleServerPort Module Server port. The default is ProxyPassword ProxyPort ProxyType ProxyServer ProxyUserid ServerPort ServerSOAPPort SQLConnectionString Account password. Required if a Basic proxy is configured. Port number of the proxy server. Basic or NTLM. IP address of the proxy server. Account username to establish the connection with the proxy server. Required if a Basic proxy is configured. NTLM proxies use the credentials of the user context that runs the Tanium Server service. Tanium Server port. The server listens for Tanium Clients on this port. The default is Do not change the ServerPort setting in the TaniumServer.ini configuration file; instead, use the Tanium Operations > Change Tanium Port menu. Tanium Console and SOAP API port. The default is Port 443 redirects to this Database server connection information. Example: postgres: @user=postgres password= dbname=tanium ssl mode=required port=5432 TrustedHostList Use this setting to list hosts that should be trusted without a valid SSL certificate. The Tanium Server does not download files from a server without a valid SSL certificate, unless it is included in this list. Add the FQDN or IP address of any servers you want to trust. In an Active/Active cluster, specify the FQDN for both Tanium Servers. Version and later support wildcards Tanium Inc. All Rights Reserved Page 139

140 Settings Version Guidelines Tanium Server version number. TaniumModuleServer.ini reference In general, you do not need to edit the Tanium Module Server configuration settings. During troubleshooting, your TAM might advise you to review and modify settings described in the following table. Table 4: Settings Tanium Module Server settings Guidelines BypassCRLCheckHostLi st BypassProxyHostList Use this setting to list servers that should be trusted without CRL checking. Unless a server is specified in this list, the Tanium Server performs a CRL check and does not download files from a server that does not pass. If you configure a proxy server, you might need to configure exceptions so that connections to specified hosts do not go through the proxy server. For example, a proxy server should not be used for traffic between Tanium Servers in an active-active cluster. A proxy server can cause problems with other traffic to a destination Tanium Server. For example, a package configuration can specify file URIs that are local to the Tanium Server. It is important to bypass the proxy server for these URIs. Use this setting to specify destinations that should not use the proxy servers. In most cases, specify localhost, , and all Tanium Server names and IP addresses. For example: ts1.example.com, ts2.example.com,localhost, , , Version and later support wildcards Tanium Inc. All Rights Reserved Page 140

141 Settings LogVerbosityLevel Guidelines Log verbosity level: 0: Logging disabled. 1: Normal log level. 41: Recommended during troubleshooting. >= 91: Most detailed log level. Enable for short periods of time only. ProxyPassword Account password. Required if a Basic proxy is configured. Note: The Proxy settings have entries only if a proxy server has been manually configured. ProxyPort ProxyType ProxyServer ProxyUserid ServerName Port number of the proxy server. Basic or NTLM. IP address of the proxy server. Account username to establish the connection with the proxy server. Required if a Basic proxy is configured. NTLM proxies use the credentials of the user context that runs the Tanium Server service indicates bind to all network adapters. ServerPort Module Server port. The default is TrustedHostList Use this setting to list hosts that should be trusted without a valid SSL certificate. The Tanium Server does not download files from a server without a valid SSL certificate, unless it is included in this list. Add the FQDN or IP address of any servers you want to trust. In an Active/Active cluster, specify the FQDN for both Tanium Servers. Version and later support wildcards. Version Tanium Module Server version number. TaniumZoneServer.ini reference In general, you do not need to edit the Tanium Zone Server configuration settings. During troubleshooting, your TAM might advise you to review and modify settings described in the following table Tanium Inc. All Rights Reserved Page 141

142 Table 5: Tanium Zone Server settings Settings Guidelines LogVerbosityLevel Log verbosity level: 0: Logging disabled. 1: Normal log level. 41: Recommended during troubleshooting. >= 91: Most detailed log level. Enable for short periods of time only. ServerName Tanium Server fully qualified domain name. ServerPort Tanium Server Port. The default is Version ZoneHubFlag Tanium Zone Server version number. 0 if not the hub; 1 if the hub Tanium Inc. All Rights Reserved Page 142

143 Reference: Appliance Maintenance menu You can use the Appliance Maintenance menu to perform backup and restore, factory reset, TanOS upgrade, and system reboot or shutdown. Back up and restore The backup procedure uses the rsync utility to copy the active partition to a backup partition. The restore procedure boots the system from the backup partition. Back up 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 143

144 2. Enter B to go to the Appliance Maintenance menu. 3. Enter 1 to go to the Backup/Restore menu Tanium Inc. All Rights Reserved Page 144

145 4. Enter 1 and then follow the prompts to complete the backup. Restore 1. Log into the TanOS console as the user tanadmin. 2. Enter B to go to the Appliance Maintenance menu. 3. Enter 1 to go to the Backup/Restore menu. 4. Enter 4 and then follow the prompts to complete the restore. Perform a software reset The Appliance Maintenance > Reset menu has two options: Perform a software reset to erase the Tanium application software. Perform a factory reset only if you want to erase both the appliance configuration and the Tanium software Tanium Inc. All Rights Reserved Page 145

146 1. From the tanadmin menu, enter B to go to the Appliance Maintenance menu. 2. Enter 2 to go to the Reset menu. 3. Enter 1 to perform a software reset Tanium Inc. All Rights Reserved Page 146

147 Upgrade the TanOS shell The TanOS shell is the TanOS menu system. Your Tanium Technical Account Manager (TAM) will let you know when upgrades are advised and can assist you with the upgrade. 1. Use SFTP to copy the TanOS shell RPM file to the /incoming directory on the appliance. 2. Log into the TanOS console as the user tanadmin. 3. Enter B to go to the Appliance Maintenance menu Tanium Inc. All Rights Reserved Page 147

148 4. Enter 4 and then follow the prompts to complete the upgrade. Clean SFTP and cores directories 1. Log into the TanOS console as the user tanadmin. 2. Enter B to go to the Appliance Maintenance menu. 3. Enter A to go to the Clean Directories menu Tanium Inc. All Rights Reserved Page 148

149 4. Enter 1 and follow the prompts to delete files in the SFTP /incoming and /outgoing directories; or enter 2 and follow the prompts to delete files from cores. Reboot or shut down Tasks you complete with TanOS menus typically do not require you to reboot the system. Reboot might be required during troubleshooting workflows. Shutdown turns off the system and powers down the appliance. CAUTION: You must have physical access to the appliance to power it on. Do not perform a system shutdown unless you are prepared to power the appliance back on. Reboot 1. Log into the TanOS console as the user tanadmin. 2. Enter B to go to the Appliance Maintenance menu. 3. Enter B to go to the Reboot/Shutdown menu. 4. Enter 1 to reboot the appliance. Shut down 1. Log into the TanOS console as the user tanadmin. 2. Enter B to go to the Appliance Maintenance menu Tanium Inc. All Rights Reserved Page 149

150 3. Enter B to go to the Reboot/Shutdown menu. 4. Enter 2 to shut down the appliance Tanium Inc. All Rights Reserved Page 150

151 Reference: Appliance configuration You configure basic host and network setting when you complete the initial configuration. You can use the TanOS Appliance Configuration menu to modify the configuration. Modify the hostname and DNS configuration 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 151

152 2. Enter A to display the Appliance Configuration menu. 3. Enter 1 and then follow the prompts to change the hostname or DNS service configuration. Modify the IPv4 address configuration 1. Log into the TanOS console as the user tanadmin. 2. Enter A to display the Appliance Configuration menu. 3. Enter 2 and then follow the prompts to change the IPv4 configuration. Modify the NTP configuration 1. Log into the TanOS console as the user tanadmin. 2. Enter A to display the Appliance Configuration menu. 3. Enter 3 and then follow the prompts to change the NTP configuration Tanium Inc. All Rights Reserved Page 152

153 Modify the time zone configuration 1. Log into the TanOS console as the user tanadmin. 2. Enter A to display the Appliance Configuration menu. 3. Enter 4 and then follow the prompts to change the time zone configuration. Change from a static IP address to DHCP (VM-only) 1. Log into the TanOS console as the user tanadmin. 2. Enter A to display the Appliance Configuration menu. 3. Enter 8 and then follow the prompts to use DHCP Tanium Inc. All Rights Reserved Page 153

154 Reference: File share mounts Tanium Connect (Connect) and Tanium IOC Detect (Detect) write consumable files to disk. You can configure the Tanium Server to copy these files to a Common Internet File System (CIFS) or Network File System (NFS) share. 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 154

155 2. Enter A to display the Appliance Configuration menu Tanium Inc. All Rights Reserved Page 155

156 3. Enter 7 to display the Share Configuration menu. 4. Use the menu to add, delete, and list file shares Tanium Inc. All Rights Reserved Page 156

157 Reference: Appliance security You can use the Security menu to enable/disable factory reset and SSH trusted host list configurations. Enable/disable factory reset 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 157

158 2. Enter A to display the Appliance Configuration menu. 3. Enter A to display the Security menu Tanium Inc. All Rights Reserved Page 158

159 4. Enter 1 and then follow the prompts to disable the tanfactory account that is used to perform a factory reset. Manage the SSH trusted host list 1. Log into the TanOS console as the user tanadmin. 2. Enter A to display the Appliance Configuration menu. 3. Enter A to display the Security menu. 4. Enter 2 and then follow the prompts to manage the SSH trusted hosts list Tanium Inc. All Rights Reserved Page 159

160 Reference: Diagnostic menus TanOS includes the following diagnostic menus. Tanium Support Menu Tanium Log Files Database Monitoring Run Network Diagnostics Run Health Check Display Last Scheduled Health Check Results Appliance Hardware Report Generate T.H.A.T Report Run TSG Copy Core Files Usage Review logs. Run the Postgres top command. Use ping, nslookup, and IPsec check utilites. Check the status of network services and Tanium services. A health check is run automatically every 15 minutes. Use this option to view previous results. Check hardware status. Generate the Tanium Hygiene Assessment Tool report. Run the Tanium Support Gatherer (TSG) scripts. The output is written to a file you can share with your Tanium Technical Account Manager (TAM) or Tanium Support. Copy any core dump files to the /outgoing folder so they can be copied by the tancopy user. Status System Status Display OS or network status. Tanium Status Appliance Status Displays the status of Tanium processes. Display appliance version information, OS status, or hardware status Tanium Inc. All Rights Reserved Page 160

161 Use the Tanium Support menu 1. Log into the TanOS console as the user tanadmin. The TanOS console displays the tanadmin menu Tanium Inc. All Rights Reserved Page 161

162 2. Enter 3 to go to the Tanium Support menu. 3. Use the menu to run a report. Use the Status menus System Status shows OS and network status. Tanium Status shows Tanium component status. Appliance Status shows appliance version information, OS status, or hardware status Tanium Inc. All Rights Reserved Page 162

163 Display system status 1. Log into the TanOS console as the user tanadmin. 2. Enter 4 to go to the Status menu. 3. Enter 1 to display the System Status menu. 4. Enter 1 to display OS status or 2 to display network status Tanium Inc. All Rights Reserved Page 163

164 Display Tanium status 1. Log into the TanOS console as the user tanadmin. 2. Enter 4 to go to the Status menu. 3. Enter 3 to display Tanium component status. Display appliance status 1. Log into the TanOS console as the user tanadmin. 2. Enter 4 to go to the Status menu Tanium Inc. All Rights Reserved Page 164

165 3. Enter 4 to display the Appliance Status menu. 4. Use the menu to display appliance version information, OS status, or hardware status Tanium Inc. All Rights Reserved Page 165

Tanium IaaS Cloud Solution Deployment Guide for Microsoft Azure

Tanium IaaS Cloud Solution Deployment Guide for Microsoft Azure Tanium IaaS Cloud Solution Deployment Guide for Microsoft Azure Version: All December 21, 2018 The information in this document is subject to change without notice. Further, the information provided in

More information

Installing and Configuring vcloud Connector

Installing and Configuring vcloud Connector Installing and Configuring vcloud Connector vcloud Connector 2.6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Tanium Core Platform Installation Guide

Tanium Core Platform Installation Guide Tanium Core Platform Installation Guide Version 7.1.314.XXXX December 18, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is

More information

Cisco Meeting Management

Cisco Meeting Management Cisco Meeting Management Cisco Meeting Management 1.1 User Guide for Administrators September 19, 2018 Cisco Systems, Inc. www.cisco.com Contents 1 Introduction 4 1.1 The software 4 2 Deployment overview

More information

Installing and Configuring vcloud Connector

Installing and Configuring vcloud Connector Installing and Configuring vcloud Connector vcloud Connector 2.5.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Tanium Network Quarantine User Guide

Tanium Network Quarantine User Guide Tanium Network Quarantine User Guide Version 1.0.2 August 14, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is provided as

More information

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3. Installing and Configuring VMware Identity Manager Connector 2018.8.1.0 (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.3 You can find the most up-to-date technical documentation on

More information

VMware Identity Manager Connector Installation and Configuration (Legacy Mode)

VMware Identity Manager Connector Installation and Configuration (Legacy Mode) VMware Identity Manager Connector Installation and Configuration (Legacy Mode) VMware Identity Manager This document supports the version of each product listed and supports all subsequent versions until

More information

Silver Peak EC-V and Microsoft Azure Deployment Guide

Silver Peak EC-V and Microsoft Azure Deployment Guide Silver Peak EC-V and Microsoft Azure Deployment Guide How to deploy an EC-V in Microsoft Azure 201422-001 Rev. A September 2018 2 Table of Contents Table of Contents 3 Copyright and Trademarks 5 Support

More information

Tanium Discover User Guide. Version 2.x.x

Tanium Discover User Guide. Version 2.x.x Tanium Discover User Guide Version 2.x.x June 27, 2017 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is

More information

Cisco TelePresence Video Communication Server Basic Configuration (Single VCS Control)

Cisco TelePresence Video Communication Server Basic Configuration (Single VCS Control) Cisco TelePresence Video Communication Server Basic Configuration (Single VCS Control) Deployment Guide Cisco VCS X7.2 D14524.03 August 2012 Contents Introduction 3 Example network deployment 3 Internal

More information

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2

Deploying VMware Identity Manager in the DMZ. JULY 2018 VMware Identity Manager 3.2 Deploying VMware Identity Manager in the DMZ JULY 2018 VMware Identity Manager 3.2 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

Tanium Discover User Guide. Version 2.5.1

Tanium Discover User Guide. Version 2.5.1 Tanium Discover User Guide Version 2.5.1 May 07, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is believed

More information

Tanium Protect User Guide. Version 1.0.7

Tanium Protect User Guide. Version 1.0.7 Tanium Protect User Guide Version 1.0.7 February 16, 2017 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and

More information

vcenter Server Appliance Configuration Update 1 Modified on 04 OCT 2017 VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5

vcenter Server Appliance Configuration Update 1 Modified on 04 OCT 2017 VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5 Update 1 Modified on 04 OCT 2017 VMware vsphere 6.5 VMware ESXi 6.5 vcenter Server 6.5 You can find the most up-to-date technical documentation on the VMware Web site at: https://docs.vmware.com/ The VMware

More information

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3

Deploying VMware Identity Manager in the DMZ. SEPT 2018 VMware Identity Manager 3.3 Deploying VMware Identity Manager in the DMZ SEPT 2018 VMware Identity Manager 3.3 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have

More information

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6 Getting Started Guide Copyright 2017 SonicWall Inc. All rights reserved. SonicWall is a trademark or registered trademark of SonicWall Inc.

More information

Horizon DaaS Platform 6.1 Service Provider Installation - vcloud

Horizon DaaS Platform 6.1 Service Provider Installation - vcloud Horizon DaaS Platform 6.1 Service Provider Installation - vcloud This guide provides information on how to install and configure the DaaS platform Service Provider appliances using vcloud discovery of

More information

IPMI Configuration Guide

IPMI Configuration Guide IPMI Configuration Guide 1. Introduction of IPMI Server Manager... 2 2. IPMI Server Manager GUI Overview... 3 1 1. Introduction of IPMI Server Manager IPMI Server Manager allows remote access of computers

More information

DameWare Server. Administrator Guide

DameWare Server. Administrator Guide DameWare Server Administrator Guide About DameWare Contact Information Team Contact Information Sales 1.866.270.1449 General Support Technical Support Customer Service User Forums http://www.dameware.com/customers.aspx

More information

Cisco CSPC 2.7.x. Quick Start Guide. Feb CSPC Quick Start Guide

Cisco CSPC 2.7.x. Quick Start Guide. Feb CSPC Quick Start Guide CSPC Quick Start Guide Cisco CSPC 2.7.x Quick Start Guide Feb 2018 2018 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public. Page 1 of 17 Contents Table of Contents 1. INTRODUCTION

More information

VMware Identity Manager Cloud Deployment. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager

VMware Identity Manager Cloud Deployment. DEC 2017 VMware AirWatch 9.2 VMware Identity Manager VMware Identity Manager Cloud Deployment DEC 2017 VMware AirWatch 9.2 VMware Identity Manager You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

VMware Identity Manager Cloud Deployment. Modified on 01 OCT 2017 VMware Identity Manager

VMware Identity Manager Cloud Deployment. Modified on 01 OCT 2017 VMware Identity Manager VMware Identity Manager Cloud Deployment Modified on 01 OCT 2017 VMware Identity Manager You can find the most up-to-date technical documentation on the VMware Web site at: https://docs.vmware.com/ The

More information

Cisco TelePresence VCS Cluster Creation and Maintenance

Cisco TelePresence VCS Cluster Creation and Maintenance Cisco TelePresence VCS Cluster Creation and Maintenance Deployment Guide Cisco VCS X8.5 Cisco TMS 13.2 or later December 2014 Contents Introduction 4 Prerequisites 5 Upgrading an X7.1 or later cluster

More information

Cisco Meeting Management

Cisco Meeting Management Cisco Meeting Management Cisco Meeting Management 1.0 Installation and Configuration Guide December 20, 2017 Cisco Systems, Inc. www.cisco.com Contents 1 Introduction 4 2 Before you start 5 2.1 Deployment

More information

Cisco Expressway Cluster Creation and Maintenance

Cisco Expressway Cluster Creation and Maintenance Cisco Expressway Cluster Creation and Maintenance Deployment Guide Cisco Expressway X8.6 July 2015 Contents Introduction 4 Prerequisites 5 Upgrading an X8.n cluster to X8.6 6 Prerequisites 6 Upgrade Expressway

More information

Tanium Map User Guide. Version 1.0.0

Tanium Map User Guide. Version 1.0.0 Tanium Map User Guide Version 1.0.0 September 06, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is

More information

Pexip Infinity and Amazon Web Services Deployment Guide

Pexip Infinity and Amazon Web Services Deployment Guide Pexip Infinity and Amazon Web Services Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring AWS security groups 4 Deploying a Management Node in AWS 6 Deploying a Conferencing Node

More information

SonicWALL Security Appliances. SonicWALL SSL-VPN 200 Getting Started Guide

SonicWALL Security Appliances. SonicWALL SSL-VPN 200 Getting Started Guide SonicWALL Security Appliances SonicWALL SSL-VPN 200 Getting Started Guide SonicWALL SSL-VPN 200 Appliance Getting Started Guide This Getting Started Guide contains installation procedures and configuration

More information

Sophos Virtual Appliance. setup guide

Sophos Virtual  Appliance. setup guide Sophos Virtual Email Appliance setup guide Contents Installing a virtual appliance...1 Prerequisites...3 Enabling Port Access...4 Downloading Virtual Appliance Files... 7 Determining Disk Space and Memory

More information

Configuring High Availability (HA)

Configuring High Availability (HA) 4 CHAPTER This chapter covers the following topics: Adding High Availability Cisco NAC Appliance To Your Network, page 4-1 Installing a Clean Access Manager High Availability Pair, page 4-3 Installing

More information

Recovery Guide for Cisco Digital Media Suite 5.4 Appliances

Recovery Guide for Cisco Digital Media Suite 5.4 Appliances Recovery Guide for Cisco Digital Media Suite 5.4 Appliances September 17, 2012 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408

More information

vcenter Server Appliance Configuration Modified on 17 APR 2018 VMware vsphere 6.7 VMware ESXi 6.7 vcenter Server 6.7

vcenter Server Appliance Configuration Modified on 17 APR 2018 VMware vsphere 6.7 VMware ESXi 6.7 vcenter Server 6.7 vcenter Server Appliance Configuration Modified on 17 APR 2018 VMware vsphere 6.7 VMware ESXi 6.7 vcenter Server 6.7 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Cisco Unified Operating System Administration Web Interface for Cisco Emergency Responder

Cisco Unified Operating System Administration Web Interface for Cisco Emergency Responder Cisco Unified Operating System Administration Web Interface for Cisco Emergency Responder These topics describe the Cisco Unified Operating System (OS) Administration web interface for Cisco Emergency

More information

VMware AirWatch Content Gateway for Linux. VMware Workspace ONE UEM 1811 Unified Access Gateway

VMware AirWatch Content Gateway for Linux. VMware Workspace ONE UEM 1811 Unified Access Gateway VMware AirWatch Content Gateway for Linux VMware Workspace ONE UEM 1811 Unified Access Gateway You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Tanium Asset User Guide. Version 1.1.0

Tanium Asset User Guide. Version 1.1.0 Tanium Asset User Guide Version 1.1.0 March 07, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is believed

More information

VMware AirWatch Content Gateway Guide for Linux For Linux

VMware AirWatch Content Gateway Guide for Linux For Linux VMware AirWatch Content Gateway Guide for Linux For Linux Workspace ONE UEM v9.7 Have documentation feedback? Submit a Documentation Feedback support ticket using the Support Wizard on support.air-watch.com.

More information

Cloud Link Configuration Guide. March 2014

Cloud Link Configuration Guide. March 2014 Cloud Link Configuration Guide March 2014 Copyright 2014 SOTI Inc. All rights reserved. This documentation and the software described in this document are furnished under and are subject to the terms of

More information

Dell Storage Manager 2016 R3 Installation Guide

Dell Storage Manager 2016 R3 Installation Guide Dell Storage Manager 2016 R3 Installation Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either

More information

Pexip Infinity and Amazon Web Services Deployment Guide

Pexip Infinity and Amazon Web Services Deployment Guide Pexip Infinity and Amazon Web Services Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring AWS security groups 4 Deploying a Management Node in AWS 6 Deploying a Conferencing Node

More information

HySecure Quick Start Guide. HySecure 5.0

HySecure Quick Start Guide. HySecure 5.0 HySecure Quick Start Guide HySecure 5.0 Last Updated: 25 May 2017 2012-2017 Propalms Technologies Private Limited. All rights reserved. The information contained in this document represents the current

More information

Barracuda Link Balancer

Barracuda Link Balancer Barracuda Networks Technical Documentation Barracuda Link Balancer Administrator s Guide Version 2.3 RECLAIM YOUR NETWORK Copyright Notice Copyright 2004-2011, Barracuda Networks www.barracuda.com v2.3-111215-01-1215

More information

Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.5

Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.5 Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.5 First Published: 2018-03-30 Summary Steps Setting up your Cisco Cloud Services Platform 2100 (Cisco CSP 2100) and creating services consists

More information

Cisco Expressway with Jabber Guest

Cisco Expressway with Jabber Guest Cisco Expressway with Jabber Guest Deployment Guide First Published: Decemeber 2016 Cisco Expressway X8.9 Cisco Jabber Guest Server 10.6.9 (or later) Cisco Systems, Inc. www.cisco.com Contents Preface

More information

PlateSpin Transformation Manager Appliance Guide. June 2018

PlateSpin Transformation Manager Appliance Guide. June 2018 PlateSpin Transformation Manager Appliance Guide June 2018 Legal Notice For information about legal notices, trademarks, disclaimers, warranties, export and other use restrictions, U.S. Government rights,

More information

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0)

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) Installation and Configuration Guide: UDP Director VE v6.9.0 2016 Cisco Systems, Inc. All rights reserved.

More information

Cisco Meeting Management

Cisco Meeting Management Cisco Meeting Management Cisco Meeting Management 1.1 Installation and Configuration Guide September 19, 2018 Cisco Systems, Inc. www.cisco.com Contents 1 Introduction 4 2 Before you start 5 2.1 Capacity

More information

File Reputation Filtering and File Analysis

File Reputation Filtering and File Analysis This chapter contains the following sections: Overview of, page 1 Configuring File Reputation and Analysis Features, page 5 File Reputation and File Analysis Reporting and Tracking, page 14 Taking Action

More information

Pexip Infinity and Google Cloud Platform Deployment Guide

Pexip Infinity and Google Cloud Platform Deployment Guide Pexip Infinity and Google Cloud Platform Deployment Guide Contents Introduction 1 Deployment guidelines 2 Configuring your Google VPC network 4 Obtaining and preparing disk images for GCE Virtual Machines

More information

Lenovo ThinkAgile XClarity Integrator for Nutanix Installation and User's Guide

Lenovo ThinkAgile XClarity Integrator for Nutanix Installation and User's Guide Lenovo ThinkAgile XClarity Integrator for Nutanix Installation and User's Guide Version 1.0 Note Before using this information and the product it supports, read the information in Appendix A Notices on

More information

Cisco Expressway Registrar

Cisco Expressway Registrar Cisco Expressway Registrar Deployment Guide First Published: July 2016 Last Updated: August 2016 Cisco Expressway X8.8 Cisco Systems, Inc. www.cisco.com 2 Preface Preface Change History Table 1 Deployment

More information

Migrating vrealize Automation 6.2 to 7.2

Migrating vrealize Automation 6.2 to 7.2 Migrating vrealize Automation 6.2 to 7.2 vrealize Automation 7.2 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition.

More information

akkadian Global Directory 3.0 System Administration Guide

akkadian Global Directory 3.0 System Administration Guide akkadian Global Directory 3.0 System Administration Guide Updated July 19 th, 2016 Copyright and Trademarks: I. Copyright: This website and its content is copyright 2014 Akkadian Labs. All rights reserved.

More information

Tanium Asset User Guide. Version 1.3.1

Tanium Asset User Guide. Version 1.3.1 Tanium Asset User Guide Version 1.3.1 June 12, 2018 The information in this document is subject to change without notice. Further, the information provided in this document is provided as is and is believed

More information

The Balabit s Privileged Session Management 5 F5 Azure Reference Guide

The Balabit s Privileged Session Management 5 F5 Azure Reference Guide The Balabit s Privileged Session Management 5 F5 Azure Reference Guide March 12, 2018 Abstract Administrator Guide for Balabit s Privileged Session Management (PSM) Copyright 1996-2018 Balabit, a One Identity

More information

Polycom RealPresence Distributed Media Application (DMA ) System

Polycom RealPresence Distributed Media Application (DMA ) System GETTING STARTED GUIDE 10.0 October 2018 3725-76311-001Q Polycom RealPresence Distributed Media Application (DMA ) System Copyright 2018, Polycom, Inc. All rights reserved. No part of this document may

More information

CloudLink SecureVM. Administration Guide. Version 4.0 P/N REV 01

CloudLink SecureVM. Administration Guide. Version 4.0 P/N REV 01 CloudLink SecureVM Version 4.0 Administration Guide P/N 302-002-056 REV 01 Copyright 2015 EMC Corporation. All rights reserved. Published June 2015 EMC believes the information in this publication is accurate

More information

Authentication Services ActiveRoles Integration Pack 2.1.x. Administration Guide

Authentication Services ActiveRoles Integration Pack 2.1.x. Administration Guide Authentication Services ActiveRoles Integration Pack 2.1.x Administration Guide Copyright 2017 One Identity LLC. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright.

More information

IronKey EMS On-Prem 7.1 Quick Start Guide

IronKey EMS On-Prem 7.1 Quick Start Guide IronKey EMS On-Prem 7.1 Quick Start Guide Last Updated June 2017 System Requirements Requirement Description Database Microsoft SQL Server 2005, Microsoft SQL Server 2008, or Microsoft SQL Server 2012,

More information

AppController :21:56 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

AppController :21:56 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement AppController 2.6 2014-03-18 13:21:56 UTC 2014 Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement Contents AppController 2.6... 6 About This Release... 8 Getting Started...

More information

KACE Systems Deployment Appliance 5.0. Administrator Guide

KACE Systems Deployment Appliance 5.0. Administrator Guide KACE Systems Deployment Appliance 5.0 Administrator Guide Table of Contents About the KACE Systems Deployment Appliance...10 Getting started... 11 Tasks for getting started using the KACE SDA... 11 About

More information

Direct Upgrade Procedure for Cisco Unified Communications Manager Releases 6.1(2) 9.0(1) to 9.1(x)

Direct Upgrade Procedure for Cisco Unified Communications Manager Releases 6.1(2) 9.0(1) to 9.1(x) Direct Upgrade Procedure for Cisco Unified Communications Manager Releases 6.1(2) 9.0(1) to 9.1(x) First Published: May 17, 2013 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose,

More information

Cisco Unified Operating System Administration Web Interface

Cisco Unified Operating System Administration Web Interface Cisco Unified Operating System Administration Web Interface ServerGroup, page 1 Hardware, page 2 Network Configuration, page 3 Software Packages, page 4 System, page 5 IP Preferences, page 6 Ethernet Configuration,

More information

HYCU SCOM Management Pack for F5 BIG-IP

HYCU SCOM Management Pack for F5 BIG-IP USER GUIDE HYCU SCOM Management Pack for F5 BIG-IP Product version: 5.5 Product release date: August 2018 Document edition: First Legal notices Copyright notice 2015-2018 HYCU. All rights reserved. This

More information

vcenter Server Installation and Setup Modified on 11 MAY 2018 VMware vsphere 6.7 vcenter Server 6.7

vcenter Server Installation and Setup Modified on 11 MAY 2018 VMware vsphere 6.7 vcenter Server 6.7 vcenter Server Installation and Setup Modified on 11 MAY 2018 VMware vsphere 6.7 vcenter Server 6.7 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

Cisco WebEx Meetings Server Administration Guide Release 1.5

Cisco WebEx Meetings Server Administration Guide Release 1.5 First Published: August 16, 2013 Last Modified: April 18, 2014 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS

More information

vrealize Operations Management Pack for NSX for Multi-Hypervisor

vrealize Operations Management Pack for NSX for Multi-Hypervisor vrealize Operations Management Pack for This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition. To check for more

More information

Cisco Terminal Services (TS) Agent Guide, Version 1.0

Cisco Terminal Services (TS) Agent Guide, Version 1.0 First Published: 2016-08-29 Last Modified: 2018-01-30 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Testing and Restoring the Nasuni Filer in a Disaster Recovery Scenario

Testing and Restoring the Nasuni Filer in a Disaster Recovery Scenario Testing and Restoring the Nasuni Filer in a Disaster Recovery Scenario Version 7.8 April 2017 Last modified: July 17, 2017 2017 Nasuni Corporation All Rights Reserved Document Information Testing Disaster

More information

vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7

vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7 vcenter Server Installation and Setup Update 1 Modified on 30 OCT 2018 VMware vsphere 6.7 vcenter Server 6.7 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

PCoIP Connection Manager for Amazon WorkSpaces

PCoIP Connection Manager for Amazon WorkSpaces PCoIP Connection Manager for Amazon WorkSpaces Version 1.0.7 Administrators' Guide TER1408002-1.0.7 Introduction Amazon WorkSpaces is a fully managed cloud-based desktop service that enables end users

More information

Polycom RealPresence Resource Manager System

Polycom RealPresence Resource Manager System Upgrade Guide 8.2.0 July 2014 3725-72106-001E Polycom RealPresence Resource Manager System Copyright 2014, Polycom, Inc. All rights reserved. No part of this document may be reproduced, translated into

More information

Cisco UCS C-Series IMC Emulator Quick Start Guide. Cisco IMC Emulator 2 Overview 2 Setting up Cisco IMC Emulator 3 Using Cisco IMC Emulator 9

Cisco UCS C-Series IMC Emulator Quick Start Guide. Cisco IMC Emulator 2 Overview 2 Setting up Cisco IMC Emulator 3 Using Cisco IMC Emulator 9 Cisco UCS C-Series IMC Emulator Quick Start Guide Cisco IMC Emulator 2 Overview 2 Setting up Cisco IMC Emulator 3 Using Cisco IMC Emulator 9 Revised: October 6, 2017, Cisco IMC Emulator Overview About

More information

Configuring Cisco TelePresence Manager

Configuring Cisco TelePresence Manager CHAPTER 3 Revised: November 27, 2006, First Published: November 27, 2006 Contents Introduction, page 3-1 System Configuration Tasks, page 3-2 Security Settings, page 3-3 Database, page 3-4 Room Phone UI,

More information

Dolby Conference Phone. Configuration guide for BT MeetMe with Dolby Voice

Dolby Conference Phone. Configuration guide for BT MeetMe with Dolby Voice Dolby Conference Phone Configuration guide for BT MeetMe with Dolby Voice Version 3.2 17 May 2017 Copyright 2017 Dolby Laboratories. All rights reserved. Dolby Laboratories, Inc. 1275 Market Street San

More information

akkadian Provisioning Manager Express

akkadian Provisioning Manager Express akkadian Provisioning Manager Express Version 4.11.04 Release Notes September 14 th, 2017 Copyright and Trademarks: I. Copyright: This website and its content is copyright 2017 Akkadian Labs, LLC. All

More information

Cisco Meeting Management

Cisco Meeting Management Cisco Meeting Management Cisco Meeting Management 1.0 Release Notes December 07, 2017 Cisco Systems, Inc. www.cisco.com Contents 1 Introduction 4 1.1 The software 4 2 Deploying Meeting Management with

More information

VMware vfabric Data Director Installation Guide

VMware vfabric Data Director Installation Guide VMware vfabric Data Director Installation Guide vfabric Data Director 1.0.1 This document supports the version of each product listed and supports all subsequent versions until the document is replaced

More information

App Orchestration 2.0

App Orchestration 2.0 App Orchestration 2.0 Getting Started with Citrix App Orchestration 2.0 Prepared by: Jenny Berger Commissioning Editor: Erin Smith Version: 1.0 Last Updated: April 4, 2014 Page 1 Contents Welcome to App

More information

Nokia Intrusion Prevention with Sourcefire Appliance Quick Setup Guide. Sourcefire Sensor on Nokia v4.8

Nokia Intrusion Prevention with Sourcefire Appliance Quick Setup Guide. Sourcefire Sensor on Nokia v4.8 Nokia Intrusion Prevention with Sourcefire Appliance Quick Setup Guide Sourcefire Sensor on Nokia v4.8 Part No. N450000774 Rev 001 Published September 2008 COPYRIGHT 2008 Nokia. All rights reserved. Rights

More information

Cisco Terminal Services (TS) Agent Guide, Version 1.1

Cisco Terminal Services (TS) Agent Guide, Version 1.1 First Published: 2017-05-03 Last Modified: 2017-10-13 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Deploy Webex Video Mesh

Deploy Webex Video Mesh Video Mesh Deployment Task Flow, on page 1 Install Webex Video Mesh Node Software, on page 2 Log in to the Webex Video Mesh Node Console, on page 4 Set the Network Configuration of the Webex Video Mesh

More information

VMware vfabric Data Director Installation Guide

VMware vfabric Data Director Installation Guide VMware vfabric Data Director Installation Guide vfabric Data Director 2.5 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by

More information

SonicWall SMA 8200v. Getting Started Guide

SonicWall SMA 8200v. Getting Started Guide SonicWall SMA 8200v Getting Started Guide Copyright 2017 SonicWall Inc. All rights reserved. SonicWall is a trademark or registered trademark of SonicWall Inc. and/or its affiliates in the U.S.A. and/or

More information

Configuring the SMA 500v Virtual Appliance

Configuring the SMA 500v Virtual Appliance Using the SMA 500v Virtual Appliance Configuring the SMA 500v Virtual Appliance Registering Your Appliance Using the 30-day Trial Version Upgrading Your Appliance Configuring the SMA 500v Virtual Appliance

More information

The Privileged Appliance and Modules (TPAM) 1.0. Diagnostics and Troubleshooting Guide

The Privileged Appliance and Modules (TPAM) 1.0. Diagnostics and Troubleshooting Guide The Privileged Appliance and Modules (TPAM) 1.0 Guide Copyright 2017 One Identity LLC. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in

More information

Cisco Expressway Authenticating Accounts Using LDAP

Cisco Expressway Authenticating Accounts Using LDAP Cisco Expressway Authenticating Accounts Using LDAP Deployment Guide Cisco Expressway X8.5 December 2014 Contents Introduction 3 Process summary 3 LDAP accessible authentication server configuration 4

More information

Symantec Protection Center Getting Started Guide. Version 2.0

Symantec Protection Center Getting Started Guide. Version 2.0 Symantec Protection Center Getting Started Guide Version 2.0 Symantec Protection Center Getting Started Guide The software described in this book is furnished under a license agreement and may be used

More information

Storage Manager 2018 R1. Installation Guide

Storage Manager 2018 R1. Installation Guide Storage Manager 2018 R1 Installation Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either

More information

Cisco Prime Collaboration Deployment

Cisco Prime Collaboration Deployment Install System Requirements for Installation, page 1 Browser Requirements, page 2 IP Address Requirements, page 2 Virtualization Software License Types, page 3 Frequently Asked Questions About the Installation,

More information

Installation and Configuration Guide

Installation and Configuration Guide CYBERSECURITY, EVOLVED EdgeWave iprism Web Security Installation and Configuration Guide V8.0 15333 Avenue of Science, Suite 100 San Diego, CA 92128 Give us a call 1-855-881-2004 Send us an email: info@edgewave.com

More information

Cisco WebEx Meetings Server Administration Guide

Cisco WebEx Meetings Server Administration Guide First Published: October 23, 2012 Last Modified: October 23, 2012 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800

More information

vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017

vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017 vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017 vrealize Suite Lifecycle Manager 1.0 Installation and Management You can find the most up-to-date technical documentation

More information

Interdomain Federation for the IM and Presence Service, Release 10.x

Interdomain Federation for the IM and Presence Service, Release 10.x First Published: 2014-01-29 Last Modified: 2018-11-05 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.0

Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.0 Cisco Cloud Services Platform 2100 Quick Start Guide, Release 2.2.0 First Published: 2017-03-15 Last Modified: 2017-08-03 Summary Steps Setting up your Cisco Cloud Services Platform 2100 (Cisco CSP 2100)

More information

Cisco Terminal Services (TS) Agent Guide, Version 1.1

Cisco Terminal Services (TS) Agent Guide, Version 1.1 First Published: 2017-05-03 Last Modified: 2017-12-19 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Backup and Restore Guide for Cisco Unified Communications Domain Manager 8.1.3

Backup and Restore Guide for Cisco Unified Communications Domain Manager 8.1.3 Communications Domain Manager 8.1.3 First Published: January 29, 2014 Last Modified: January 29, 2014 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

IBM Single Sign On for Bluemix Version December Identity Bridge Configuration topics

IBM Single Sign On for Bluemix Version December Identity Bridge Configuration topics IBM Single Sign On for Bluemix Version 2.0 28 December 2014 Identity Bridge Configuration topics IBM Single Sign On for Bluemix Version 2.0 28 December 2014 Identity Bridge Configuration topics ii IBM

More information

ECDS MDE 100XVB Installation Guide on ISR G2 UCS-E and VMWare vsphere Hypervisor (ESXi)

ECDS MDE 100XVB Installation Guide on ISR G2 UCS-E and VMWare vsphere Hypervisor (ESXi) ECDS MDE 100XVB Installation Guide on ISR G2 UCS-E and VMWare vsphere Hypervisor (ESXi) Revised: November, 2013 Contents Overview, page 1 Guidelines and Limitations, page 1 Prerequisites, page 2 Installation

More information

Polycom RealPresence Resource Manager System, Virtual Edition

Polycom RealPresence Resource Manager System, Virtual Edition Getting Started Guide 8.3.0 December 2014 3725-72114-001B Polycom RealPresence Resource Manager System, Virtual Edition Copyright 2014, Polycom, Inc. All rights reserved. No part of this document may be

More information