Jump to content

Recommended Posts

Posted

If a WinSuricata Host is reinstalled, the Host will generate a new registration key causing the Remote Node's to stop communicating with the newly installed Host.

This does not normally require reinstalling the Remote Node. WinSuricata includes the WinSuricata Node Key Updater in the Host's management console specifically for this situation. The utility allows an existing Remote Node to receive the new registration information from the Host and update its EveBox Agent configuration without performing a complete Node installation.

Important — Each Remote Node Must Be Updated Individually

This procedure demonstrates the complete recovery process for one Remote Node.

If a Host has multiple Remote Nodes that need to be reconnected, this procedure must be completed separately for every Remote Node.

Each Remote Node has its own:

  • Remote Node Alias

  • Remote Node IP address

  • Registration key

  • EveBox Agent configuration

Updating one Remote Node does not update any other Remote Nodes.

For example, if a Host has Remote-01, Remote-02, and Remote-03, each Node that needs to reconnect must go through its own key-recovery process.


Step 1 — Generate the New Node Registration on the Host

On the newly installed WinSuricata Host, open the WinSuricata Management Console.

Go to the Remote Node configuration area and select:

Host Detected - Add Remote Node

Enter the information for the specific Remote Node being recovered:

  • Remote Node Alias: Enter the existing alias assigned to that Node.

  • Remote Node IP: Enter the IP address of that Node.

The Management Console will generate the new Node registration information using the Host's current registration key.

The generated registration files are stored on the Host under:

$WinIDSRoot\Nodes\<Remote Alias>

For example:

D:\WinSuricata\Nodes\date-Remote-01

The Node-specific folder contains the registration information required to update that particular Remote Node.


Step 2 — Copy the New Registration Files to the Node Temp Folder

Before the Remote Node can reconnect to the Host the new key file must be added.

Transfer the two files below from the Host to the Node:

For example:

D:\WinSuricata\Nodes\Date-Remote-01\
    Remote-01-NodeConfig.json
    root-ca.pem

Copy the required files to:

D:\WinSuricata\Temp\
    Remote-01-NodeConfig.json
    root-ca.pem

Important

The Management Console will not display the option to reinstall/update the Node key until the required registration files have been detected in $WinIDSRoot\Temp folder.


Step 3 — Use the Management Console to Reinstall the Node Key

Once the registration files have been placed in the Node's Temp folder, open or refresh the WinSuricata Management Console.

The Node key reinstallation/update option will now be available because the required registration files have been detected.

Select the option to reinstall/update the Node key.

The Management Console will use the registration information found in the Temp folder to reconnect the Node to the Host.


Step 4 — Verify the Remote Node

After the Node Key Updater completes, verify that the EveBox Agent service is running on the Remote Node.

The Node should now be using the Host's current registration key and should be able to reconnect to the Host.

Allow a few moments for the Node to reconnect and begin sending events.


Step 5 — Repeat the Process for Every Remote Node

If additional Remote Nodes were connected to the Host before the Host was reinstalled, repeat Steps 1 through 6 for every Remote Node that needs to reconnect.

For each Remote Node:

  1. On the new Host generate the Node registration information using its existing alias and IP address.

  2. Locate its registration files under $WinIDSRoot\Nodes\<Remote Alias>.

  3. Copy the required registration files to $WinIDSRoot\Temp on the Node.

  4. Run the WinSuricata Node Key Updater from the Management console on that Node.

  5. Verify that the EveBox Agent reconnects.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.