McAfee and the McAfee logo, McAfee Active Protection, ePolicy Orchestrator, McAfee ePO, McAfee EMM, Foundstone, McAfee LiveSafe, McAfee QuickClean, Safe Eyes,
McAfee SECURE, SecureOS, McAfee Shredder, SiteAdvisor, McAfee Stinger, True Key, TrustedSource, VirusScan are trademarks or registered trademarks of McAfee,
LLC or its subsidiaries in the US and other countries. Other marks and brands may be claimed as the property of others.
LICENSE INFORMATION
License Agreement
NOTICE TO ALL USERS: CAREFULLY READ THE APPROPRIATE LEGAL AGREEMENT CORRESPONDING TO THE LICENSE YOU PURCHASED, WHICH SETS FORTH THE
GENERAL TERMS AND CONDITIONS FOR THE USE OF THE LICENSED SOFTWARE. IF YOU DO NOT KNOW WHICH TYPE OF LICENSE YOU HAVE ACQUIRED, PLEASE
CONSULT THE SALES AND OTHER RELATED LICENSE GRANT OR PURCHASE ORDER DOCUMENTS THAT ACCOMPANY YOUR SOFTWARE PACKAGING OR THAT YOU HAVE
RECEIVED SEPARATELY AS PART OF THE PURCHASE (AS A BOOKLET, A FILE ON THE PRODUCT CD, OR A FILE AVAILABLE ON THE WEBSITE FROM WHICH YOU
DOWNLOADED THE SOFTWARE PACKAGE). IF YOU DO NOT AGREE TO ALL OF THE TERMS SET FORTH IN THE AGREEMENT, DO NOT INSTALL THE SOFTWARE. IF
APPLICABLE, YOU MAY RETURN THE PRODUCT TO MCAFEE OR THE PLACE OF PURCHASE FOR A FULL REFUND.
This section describes the McAfee® Network Security Sensors at a high-level and also describes the McAfee
M-2850/M-2950 Network Security Sensor (Sensor) in detail.
Sensors are high-performance, scalable, and exible content processing appliances built for the accurate
detection and prevention of intrusions, misuse, distributed denial of service (DDoS) attacks, and network access
control(NAC) of hosts. When deployed at key access points, a Sensor provides real-time trac monitoring to
detect malicious activity, and respond to the malicious activity as congured by the administrator.
After the Sensor is deployed and communication established, Sensors are congured and managed using the
McAfee Network Security Manager (Manager) server.
The process of conguring a Sensor and establishing communication with the Manager is described in the later
chapters of this guide. The Manager server is described in detail in the McAfee Network Security Platform Manager
Administration Guide.
Contents
About the M-2850/M-2950 Sensor
M-2850/M-2950 key features
M-2850/M-2950 physical description
About the M-2850/M-2950 Sensor
The M-2850/M-2950 Sensor provides eective network access control (NAC) of hosts.
®
The M-2850/M-2950 Sensor provides eective network IPS functionality as well as network access control (NAC)
of hosts.
The IPS functionality involves providing real-time detection and prevention of threats and known, zero-day, or
encrypted attacks. The Sensor can perform many types of attack responses, including generating alerts and
packet logs, resetting TCP connections, "scrubbing" malicious packets, and blocking attack packets entirely
before they reach the intended target.
NAC hosts involves regulating access to network resources based on host Operational Status level (Standard/
DHCP NAC), identity of the user logged into the host (IBAC) or both, and OOB NAC (L2, L3 ). The Sensor also
provides the Hybrid NAC functionality where a host is rst subjected to DHCP-NAC and then Standard NAC at
dierent ports of the same Sensor. For more information on the NAC functionality and congurations of the
Manager, see McAfee® Network Security Platform NAC Administration Guide.
Throughout this guide, the terms 'Sensor' and 'M-2850/M-2950' refer to the M-2850 or the M-2950 Sensor in
general.
1 RJ-45 10/100/1000 Management port1 RJ-45 10/100/1000 Management port
12 SFP one gigabit Ethernet monitoring ports12 SFP one gigabit Ethernet monitoring ports
6 RJ-11 fail-open Control ports6 RJ-11 fail-open Control ports
1 Response port1 Response port
Dual power supplyDual power supply
External Compact Flash portExternal Compact Flash port
M-2850/M-2950 physical description
A high-port density M-2850/M-2950 Sensor, is designed for high bandwidth links, and is equipped with twenty
Fast Ethernet ports (or interfaces). This Sensor can monitor ten 1 Gbps Ethernet segments in full-duplex mode
(tap or in-line), and twenty segments in half-duplex mode (monitoring SPAN ports or hubs). M-2850/M-2950 can
monitor upto 600 Mbps of aggregate trac.
M-2850/M-2950 Sensor supports both built-in fail-open as well as conguring of external fail-open hardware.
Both passive and active fail-open kits (sold separately) are supported.
Ports on the Sensor
The M-2850/M-2950 Sensor is a 2RU (2 rack unit) and is equipped with the following components.
One RJ-45 10/100/1000 Management port, which is used for communication with the Manager server. You
can assign an IP address to this port during installation.
2
One RS-232C Console port, which is used to set up and congure the Sensor using the CLI.
3
One RS-232C Auxiliary port, which may be used to dial in remotely to set up and congure the Sensor.
4
Six RJ-11 fail-open Control ports, designed for use the Optical fail-open bypass kit. Both optical and copper
kits can use these ports if congured in passive fail-open mode. The ports are marked X1, X2, X3, X4, X5, X6,
are used in conjunction with ports 1A/1B, 2A/2B, 3A/3B, 4A/4B, 5A/5B, 6A/6B, respectively.
5
Twelve small form-factor pluggable (SFP) 1 Gigabit Monitoring ports, which enable you to monitor ten
Ethernet segments in-line.
If you choose to run in fail-over mode, port 6A is used to interconnect with a standby M-2850/M-2950
Sensor.
The gigabit ports of the M-2850/M-2950 running in In-line mode fail closed, meaning that if the Sensor fails, it
will interrupt/block data ow. Refer to the Gigabit Fail-Open Bypass Kit Guide for more information.
6
One External Compact Flash port. This port is used only for ash recovery purposes. That is, this port is
used in troubleshooting situations where the Sensor's internal ash is corrupted and you need to reboot the
Sensor through the external compact ash. For more information, see the on-line KnowledgeBase at http://
mysupport.mcafee.com/Eservice/, where you need to click Search the KnowledgeBase.
7
Four front panel LEDs, The LEDs which indicate the Sensor's general operational status.
8
Four RJ-45 10/100/1000 Ethernet Monitoring port, which enable you to monitor four Ethernet segments
in-line. Also, built-in fail-open is available on ports 7-10.
9
Four Bypass LEDs, which indicate the bypass status of the Sensor.
10
Primary Power Supplies—PWR A (included). Power supply A is included with each Sensor. The supply uses
a standard IEC port (IEC320-C13). McAfee provides a standard; 2m NEMA 5-15P (US) power cable (3 wire).
International customers must procure a country-appropriate power cable.
Power Supplies—PWR B (optional, and can be purchased separately). Power supply B is a hot-swappable,
redundant power supply. This power supply also uses a standard IEC320-C13 port, and you can use the
McAfee--provided cable or acquire one that meets your specic needs.
12
Five Back panel LEDs. The LEDs which indicate the Sensor's fan and power supply operational status.
Front and back panel LEDs
Figure 1-3 Front panel LEDs
Figure 1-4 Back panel LEDs
Region in the image LEDs represented here
1Sys, Temp, Flash, Fan
2Power A
3Back panel fan LEDs
4Management Port Speed, Management Port Link, Response Port Speed, Response Port
Link
5Gigabit Ports (SFP) Act, Gigabit Ports (SFP) Link
6Fail-Open Control Port FO, Fail-Open Control Port Err
7Bypass LEDs
The front panel LEDs provide status information for the health of the Sensor and the activity on its ports. The
back panel LEDs provide information regarding the Sensor fans and the power supply.
The following tables describe the front and back panel LEDs of M-2850/M-2950:
LEDStatus Description
SysGreen
Amber
Temp Green
Amber
Sensor is operating.
Sensor is booting. (It could also indicate a system failure.)
Inlet air temperature measured inside chassis is normal. (Chassis temperature OK.)
Inlet air temperature measured inside chassis is too hot. (Chassis temperature too hot.)