Morpheus Posted 43 minutes ago Report Posted 43 minutes ago If a WinSuricata Host is reinstalled, the Host will generate a new registration key causing the Remote Node's to stop communicating with the newly installed Host. This does not normally require reinstalling the Remote Node. WinSuricata includes the WinSuricata Node Key Updater in the Host's management console specifically for this situation. The utility allows an existing Remote Node to receive the new registration information from the Host and update its EveBox Agent configuration without performing a complete Node installation. Important — Each Remote Node Must Be Updated Individually This procedure demonstrates the complete recovery process for one Remote Node. If a Host has multiple Remote Nodes that need to be reconnected, this procedure must be completed separately for every Remote Node. Each Remote Node has its own: Remote Node Alias Remote Node IP address Registration key EveBox Agent configuration Updating one Remote Node does not update any other Remote Nodes. For example, if a Host has Remote-01, Remote-02, and Remote-03, each Node that needs to reconnect must go through its own key-recovery process. Step 1 — Generate the New Node Registration on the Host On the newly installed WinSuricata Host, open the WinSuricata Management Console. Go to the Remote Node configuration area and select: Host Detected - Add Remote Node Enter the information for the specific Remote Node being recovered: Remote Node Alias: Enter the existing alias assigned to that Node. Remote Node IP: Enter the IP address of that Node. The Management Console will generate the new Node registration information using the Host's current registration key. The generated registration files are stored on the Host under: $WinIDSRoot\Nodes\<Remote Alias> For example: D:\WinSuricata\Nodes\date-Remote-01 The Node-specific folder contains the registration information required to update that particular Remote Node. Step 2 — Copy the New Registration Files to the Node Temp Folder Before the Remote Node can reconnect to the Host the new key file must be added. Transfer the two files below from the Host to the Node: For example: D:\WinSuricata\Nodes\Date-Remote-01\ Remote-01-NodeConfig.json root-ca.pem Copy the required files to: D:\WinSuricata\Temp\ Remote-01-NodeConfig.json root-ca.pem Important The Management Console will not display the option to reinstall/update the Node key until the required registration files have been detected in $WinIDSRoot\Temp folder. Step 3 — Use the Management Console to Reinstall the Node Key Once the registration files have been placed in the Node's Temp folder, open or refresh the WinSuricata Management Console. The Node key reinstallation/update option will now be available because the required registration files have been detected. Select the option to reinstall/update the Node key. The Management Console will use the registration information found in the Temp folder to reconnect the Node to the Host. Step 4 — Verify the Remote Node After the Node Key Updater completes, verify that the EveBox Agent service is running on the Remote Node. The Node should now be using the Host's current registration key and should be able to reconnect to the Host. Allow a few moments for the Node to reconnect and begin sending events. Step 5 — Repeat the Process for Every Remote Node If additional Remote Nodes were connected to the Host before the Host was reinstalled, repeat Steps 1 through 6 for every Remote Node that needs to reconnect. For each Remote Node: On the new Host generate the Node registration information using its existing alias and IP address. Locate its registration files under $WinIDSRoot\Nodes\<Remote Alias>. Copy the required registration files to $WinIDSRoot\Temp on the Node. Run the WinSuricata Node Key Updater from the Management console on that Node. Verify that the EveBox Agent reconnects.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now