McAfee and the McAfee logo, McAfee Active Protection, ePolicy Orchestrator, McAfee ePO, McAfee EMM, Foundstone, McAfee LiveSafe, McAfee QuickClean, Safe Eyes,
McAfee SECURE, SecureOS, McAfee Shredder, SiteAdvisor, McAfee Stinger, True Key, TrustedSource, VirusScan are trademarks or registered trademarks of McAfee,
LLC or its subsidiaries in the US and other countries. Other marks and brands may be claimed as the property of others.
LICENSE INFORMATION
License Agreement
NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE
GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE
CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANY YOUR SOFTWARE PACKAGING OR THAT YOU HAVE
RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEBSITE FROM WHICH YOU
DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF
APPLICABLE, YOU MAY RETURN THE PRODUCT TO MCAFEE OR THE PLACE OF PURCHASE FOR A FULL REFUND.
This section describes the McAfee® Network Security Sensors at a high-level and also describes the McAfee
M-1250/M-1450 Network Security Sensor (Sensor) in detail.
Sensors are high-performance, scalable, and exible content processing appliances built for the accurate
detection and prevention of intrusions, misuse, distributed denial of service (DDoS) attacks, and network access
control(NAC) of hosts. When deployed at key access points, a Sensor provides real-time trac monitoring to
detect malicious activity, and respond to the malicious activity as congured by the administrator.
After the Sensor is deployed and communication established, Sensors are congured and managed using the
McAfee Network Security Manager (Manager) server.
The process of conguring a Sensor and establishing communication with the Manager is described in the later
chapters of this guide. The Manager server is described in detail in the McAfee Network Security Platform Manager
Administration Guide.
Contents
About the M-1250/M-1450 Sensor
Physical description of the M-1250/M-1450 Sensor
About the M-1250/M-1450 Sensor
The M-1250 or the M-1450 Sensor provides eective network IPS functionality as well as Network Access
Control (NAC) of hosts.
®
The IPS functionality involves real-time detection and prevention of threats and known, zero-day, or encrypted
attacks. The Sensor can perform many types of attack responses, including generating alerts and packet logs,
resetting TCP connections, "scrubbing" malicious packets, and even blocking attack packets entirely before they
reach the intended target.
Network Access Control of hosts is regulating access to network resources based on host System Health level
(Standard/ DHCP NAC), identity of the user logged into the host (IBAC), or both. The Sensor also provides the
Hybrid NAC functionality where a host is rst subjected to DHCP-NAC and then Standard NAC at dierent ports
of the same Sensor. For more information on the NAC functionality and congurations of the Manager, see the
NAC Administration Guide.
Throughout this guide the terms, 'Sensor' and 'M-1250/M-1450' refer to the M-1250 or the M-1450
Sensor in general.
The M-1250/M-1450 Sensor is equipped with eight Fast Ethernet ports (or interfaces). M-1250 can monitor up to
100 Mbps, and M-1450 can monitor upto 200 Mbps of aggregated trac respectively. The M-1250/M-1450
Sensor can monitor four 10/100/1000 Mbps Ethernet segments in full-duplex mode (tap or in-line), and eight
segments in half-duplex mode (monitoring SPAN ports or hubs).
Ports on the Sensor
The M-1250/M-1450 Sensor is a one rack-unit (1RU) box equipped with the following ports:
Figure 1-1 M-1450 Sensor Front Panel
ItemDescription
1RJ-45 10/100/1000 Management port (1)
2RJ-45 Response port (1)
3RS-232C Console port (1)
4RS-232C Auxiliary port (1)
5RJ-45 10/100/1000 Ethernet Monitoring ports (8)
6External Compact Flash port (1)
7Power supply A (1)
Figure 1-2 M 1450 Sensor back panel
1
One 10/100/1000 Management port, which is used for secure communication with the Manager server.
Communication between the Sensor and the Manager server uses secure channels; these channels provide
link privacy using encryption and mutual authentication between Sensors and the Manager using public key
authentication. You assign an IP address to this Ethernet port during installation.
2
One Response port, which, when you are operating in the SPAN mode, enable you to inject response
packets back into your network, for example, through a switch or router. The Response port is also used in
the tap mode.
3
One RS-232C Console port, which is used to set up and congure the Sensor.
4
One RS-232C Auxiliary port, which may be used to dial in remotely to set up and congure the Sensor.
5
Eight 10/100/1000 Monitoring ports, which enable you to monitor eight SPAN ports or four full-duplex
tapped segments or four segments in-line. When the Sensor operates in the IPS mode, these ports operate
in stealth mode; that is, they have no IP addresses nor even a TCP/IP stack to respond to IPS detection
techniques. This renders them completely invisible to intruders. When operating in the NAC mode, the
monitoring ports can be assigned IP addresses. The monitoring ports for M-1250/M-1450 Sensor are 1A/1B,
2A/2B, 3A/3B and 4A/4B.
One External Compact Flash port. This port is used for two purposes. It is used to control optional
fail-open hardware as described in the Gigabit Optical Fail-Open Bypass Kit Guide. It is also used in
troubleshooting situations where the Sensor's internal ash is corrupted and you must reboot the Sensor
using the external compact ash. For more information, see the on-line KnowledgeBase at http://
mysupport.mcafee.com/Eservice/. Click Search the KnowledgeBase.
7
Power supply. The Sensor power supply port is located on the front side of the Sensor. The supply uses a
standard IEC port (IEC320-C13). McAfee provides a standard, 2m NEMA 5-15P (US) power cable (3 wire).
International customers are provided with a country-appropriate power cable.
Introducing Network Security Sensors
Front panel LEDs on M-1250/M-1450 Sensor
The front panel LEDs provide status information for the health of the Sensor and the activity on its ports.
The image and table that follows describe the operational M-1250/M-1450 front panel LEDs.
1
Figure 1-3 LEDs on the front panel that are used during normal operating conditions
Region in the image LEDs represented here
1Pwr, Sys, Temp, Fan, Management Port Speed, Management Port Link, Response Port
Speed, Response Port Link
210/100/1000 Monitoring Ports Speed, 10/100/1000 Monitoring Ports Link
3Flash
LEDStatus Description
PwrGreenOThe Sensor is powered on and functioning.
The Sensor is powered o.
SysGreen
Amber
TempGreen
Amber
FanGreen
Amber
Management Port Speed Green
Amber
O
Sensor is operating.
Sensor is booting. (It could also indicate a system failure.)
Inlet air temperature measured inside chassis is normal. (Chassis
temperature OK.)
Inlet air temperature measured inside chassis is too hot. (Chassis
temperature too hot.)