Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

Sensors

Want to summarize with AI?

Log in

Details sensor management, including using the Sensor Explorer, filtering and sorting, reviewing sensor statuses, managing features such as installation and updates, handling credentials, organizing sensors, setting capture modes, and managing deployment tokens, templates, and management jobs


Sensors in Cisco Cyber Vision are devices or applications deployed at strategic points within the industrial network to capture and analyze network traffic.

Sensors communicate with the Cyber Vision Center to send metadata extracted from industrial network traffic, enabling deep packet inspection and network visibility.


Sensor Explorer

The Sensor Explorer is a management interface that enables the administration of sensors monitoring industrial network traffic.

  • Supports installation and configuration of sensors.

  • Provides visibility into sensor status and network data.

  • Facilitates management of both online and offline traffic capture modes.

Sensor Operational Modes

Sensors operate in specific modes depending on the deployment requirements and hardware capabilities:

  • Online mode : A sensor is placed at a strategic network point to continually capture traffic. Applicable to Cisco IE3400, IE3300 10G, Cisco IC3000, Catalyst 9300, and Cisco IR1101.

  • Offline mode : A sensor is connected to isolated or difficult-to-access network points to occasionally capture traffic on a USB drive for import into Cisco Cyber Vision. Only applicable to Cisco IC3000.

Table 1. Feature History

Feature

Release Information

Feature Description

Sensor Management extension removal

Release 5.6.0

The Sensor Management extension is no longer available. Sensors that were previously deployed through the Sensor Management extension are now fully managed from the Sensors Management page in the new UI.

Note

When the Cisco Cyber Vision system is updated to version 5.6.0 and rebooted, the legacy Sensor Management extension is removed. Sensors previously deployed using the Sensor Management extension are integrated into the sensor-host model in the new UI.

Manual sensor deployment, Docker sensors deployment, and Sensor VM deployment are only supported in the Sensor Explorer page.


Filter and Sort the Sensor List

Filtering

Use the Filter button to filter the folders and sensors in the list by label, IP address, version, location, health, and processing status.

Sorting

The sort icons next to the column titles allow you to organize sensors by label, IP address, version, location, health, and processing status in either alphabetical or ascending/descending order. The icons appear when you hover over them or apply them.

Follow these steps to filter sensor list.

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. Click the Filter icon from the top-right corner of the table.

  3. Type in the field or select from the drop-down menu to locate the folder(s) or sensor(s).

  4. Click Apply.


Sensor statuses

Use sensor status indicators to track the enrollment stage of each sensor, check its connection to the Center, and monitor or troubleshoot deployments. Two sensor status types are available.

  • Health status: Shows the sensor’s progress in the enrollment and authorization process.

  • Processing status: Shows the current state of network data processing and communication between a sensor and the Center.

Table 2. Health status indicators

Indicator

Description

New

The sensor's initial status when first detected. The sensor requests an IP address from the DHCP server.

Request Pending

The sensor has requested a certificate and is waiting for authorization to enroll.

Authorized

The sensor has just been authorized by an administrator or product user. Remains briefly before changing to Enrolled.

Enrolled

The sensor is successfully connected with the Center and has a certificate and private key.

Disconnected

The sensor is enrolled but not connected to the Center (may be offline or there may be a network issue).

Bad Credentials

The sensor is enrolled but credentials to access the Local Manager are not correct.

Table 3. Processing status indicators

Indicator

Description

Disconnected

The sensor is enrolled but not connected to the Center (shut down, problem, or network issue).

Not enrolled

The sensor is not enrolled (Health status is New or Request Pending). You must enroll the sensor to operate it.

Normally processing

The sensor is connected to the Center; data is being sent and processed.

Waiting for data

The sensor is connected; the Center has processed all data and is waiting for more to be sent.

Pending data

The sensor is connected; the sensor attempts to send data but the Center is processing other data.


Sensors Features

Provides a comprehensive list of sensor management features accessible through the Sensor Explorer interface to facilitate traffic analysis, configuration, and system maintenance.

The following features are available for managing sensors:

  • Start recording : Records a traffic capture on the sensor for traffic analysis or troubleshooting.

    Note
    This feature is targeted for short captures only. Performing long captures may cause the sensor overload and packets loss.
  • Move to : Moves the sensor through different folders. For more information, refer to Organize sensors .

  • Download package : Provides a configuration file for manual sensor deployment. Only applicable to the Cisco IC3000. Refer to its Installation Guide .

  • Capture Mode : Sets a filter on a sensor sending data to the Center. Refer to the procedure for Setting a capture mode .

  • Redeploy : Reconfigures the sensor, such as changing its IP address.

  • Enable IDS : Enables the SNORT engine embedded in some sensors to analyze traffic using SNORT rules.

  • Reboot : Reboots the sensor in case of a malfunction.

  • Shutdown : Triggers a clean shutdown of the sensor from the GUI.

    Note
    After performing a shutdown, you must switch the sensor ON directly and manually on the hardware.
  • Uninstall : Removes an uninstalled sensor from the list or fully uninstalls a sensor, depending on the model or deployment mode.


Access sensor features

The Sensor Explorer page provides several features to manage and use your sensors. Some buttons are accessible directly from the Sensor Explorer page to manage one or more sensors, while other buttons become available when clicking a sensor in the list.

Follow these steps to access sesnor features.

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. Click the sensor name from the Label column.

    A right-side panel appears with all the features.


Install sensor

Use the Sensor Explorer page to begin installing a sensor.

Note

When the Cisco Cyber Vision system is updated to version 5.6.0 and rebooted, the legacy sensor management extension is removed. Sensors deployed through the sensor management extension are fully integrated into the sensor-host model in the new UI. Go to the Sensor Management page to onboard, manage, and monitor sensors.

Docker sensors and Sensor VM are supported only on the Sensor Explorer page.

Procedure

  1. Choose Admin > Sensors > Sensor Explorer from the main menu.

  2. Select a sensor installation method.

    Choose one of the following methods:

    • Install a sensor manually.

    • Capture traffic with an offline sensor. This method applies only to Cisco IC3000.

      For more information about installing a sensor, refer to the corresponding Sensor Installation Guide.

    • Install a Cisco Cyber Vision Sensor on an appliance that runs Ubuntu and Docker.

    • Deploy a Cisco Cyber Vision Sensor VM as a virtual-machine-based sensor.

You have accessed the Sensor Explorer page and identified a supported sensor installation method.


Sensor self-update workflow

Cisco Cyber Vision allows sensor updates regardless of the installation method, and provides the necessary foundation for sensor self-updates. The self-update feature will be functional only in future releases.

Summary

When the feature is available, sensor self-update automatically updates the sensors that you select.

Workflow

When the feature is available, sensor self-update progresses through the following stages.

  1. You select the sensors to update.

  2. The Center adds a new job to the sensor queue.

  3. Each sensor automatically collects and validates the update file.

  4. The sensor restarts with the new version.


Update warnings

In the Cisco Cyber Vision Center on the Sensor Explorer page, you receive an alert to update the sensor. When this occurs, the latest version number appears in red, and a blue arrow with a tooltip indicates the sensor is upgradeable.

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. Click the sensor that is upgradeble from the Label column.

  3. View the right side panel that appears with sensor details.

  4. Click Update.


Update Sensors

Procedure

  1. From the main menu, choose Admin > Senors > Sensor Explorer.

  2. Check the checkboxes to select multiple sensors.

  3. Click the drop-down arrow of the More Actions button.

  4. Click Update sensors from the drop-down list.

    The UPDATE SENSORS pop-up appears.

  5. Click OK .

    During the update, a blue circle appears in the Update status column. After the update is complete, the version number turns black, and a green symbol appears in the same column.


View update failure details

If the update is unsuccessful, the Update Status column displays a red cross and a detailed message.

Procedure

  1. Choose Admin > Sensors > Sensor Explorer from the main menu.

  2. Hover over the red cross in the Update Status column.

The update failure details are displayed.


Manage credentials

Register global credentials in Cisco Cyber Vision after you configure or change them in Local Manager.

When you register global credentials, you enter them once in Cisco Cyber Vision. Cisco Cyber Vision uses them for actions that require them .

Only one set of global credentials can be used per Cisco Cyber Vision instance. You cannot use different global credentials for multiple sets of sensors in a single instance. If multiple sensor administrators use global credentials, they must use the same credentials registered in Cisco Cyber Vision. You can use global credentials for one set of sensors while other sensors use their own credentials.

Global credentials are stored in Cisco Cyber Vision but are set at the switch level in Local Manager.

Note

If you lose your global credentials, you must refer to switch customer support and documentation.

Before you begin

Configure the global credentials in Local Manager.

Procedure

  1. Choose Admin > Sensors > Sensor Explorer from the main menu.

  2. Select Manage Cisco devices.

  3. Select Manage credentials from the drop-down list.

    The SET GLOBAL CREDENTIALS window appears.

  4. Enter your Login and Password.

  5. Select Update.

Cisco Cyber Vision uses the registered global credentials for actions that require them, including installing and updating sensors.


Organize sensors

Use folders to organize sensors by location, person in charge, or sensor type, such as disconnected sensors.

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. Select Organize, and select + Create folder from the drop-down list.

  3. Enter a name in the folder name field.

  4. (Optional) Enter values in the Location and Description fields.

  5. Select Ok.

    A success message appears, and the new folder appears in the sensor list.

  6. Select the checkbox for the sensor that you want to move.

  7. Select Move selection to.

    The Move selection to pop-up appears.

  8. Select the drop-down arrow for the Destination field.

    Use one of the following options:

    • Select the required folder to move the sensor.

    • Select +New folder to create a folder and move the sensor.

    • Select Root to move the sensor back to the primary list.

  9. Select Ok.

    After you move a sensor into the folder, its version, health status, and processing status appear on the folder line. If you move a sensor in a disconnected state into the folder, its information appears on the folder line instead of the connected sensor information. Sensor statuses that indicate lower security are prioritized to draw your attention.


Capture modes

Capture modes use filters on each sensor to define which types of incoming packets the sensor analyzes. You can set a different filter on each sensor according to your needs.

Use capture modes to focus monitoring on relevant traffic and reduce load on the Center. Capture Mode can improve Cisco Cyber Vision performance on large networks.

Table 4. Capture mode descriptions

Capture mode

Description

ALL

The sensor analyzes all incoming flows without applying a filter and stores all flows in the Center database.

OPTIMAL (Default)

The filter selects the most relevant flows based on Cisco Cyber Vision expertise. It does not record multicast flows. Use this capture mode for long-term capture and monitoring.

INDUSTRIAL ONLY

The filter selects only industrial protocols such as Modbus, S7, and EtherNet/IP. The sensor does not analyze IT flows on the monitored network, and they do not appear in the GUI.

CUSTOM (advanced users)

Use this capture mode to fully customize the filter. Use tcpdump syntax to define filtering rules. For example, a firewall filter can remove network management flows (SNMP): not (port 161 and host 10.10.10.10), where 10.10.10.10 is the network management platform.


Set a capture mode

Set a Capture Mode for a sensor from the Sensor Explorer page.

Capture Mode selects which network communications a sensor analyzes.

Note

You can also set a capture mode in the installation wizard when enrolling sensors during Center installation. This option is recommended if you already know which filter to set.

Before you begin

Allow SSH connections from the Center to the sensors.

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. Select the sensor name in the Label column.

    The right-side panel appears with the sensor details.

  3. Select Capture mode.

    The CAPTURE MODE window appears.

  4. Select the radio button for the Capture Mode that you want to use.

The sensor uses the selected Capture Mode to determine which network communications it analyzes.


Sensor geolocation data

Sensor geolocation data is the GPS coordinates (longitude and latitude) of CV sensor applications deployed on network devices. This data enables accurate mapping and visualization of the platform hosting the CV sensor application, supporting effective monitoring, management, and optimization of geographically distributed deployments.

GPS coordinates configuration

You can configure GPS coordinates on sensors in two ways, depending on the platform's hardware capabilities:

  • Platforms without the capability to gather GPS coordinates by themselves require manual input of the GPS coordinates on the UI. You can set the coordinates on the Sensor Explorer page. For more information, see Configure GPS coordinates on sensors.

  • Platforms with the capability to gather GPS coordinates by themselves can automatically discover and update their GPS coordinates. Once the GPS module is activated on the platform, the sensors will seamlessly display the GPS data received from the GPS module, ensuring the coordinates are always current without further manual intervention. For more information, see Enable the GPS module on the platform.


Enable the GPS module on the platform

Activate the GPS module on the platform to continuously transmit GPS data to the CV Center for sensor geolocation.

Use CLI commands on a Cisco router to configure the cellular controller to transmit GPS NMEA (National Marine Electronics Association) data to a specific IP destination over UDP.

Before you begin

  • Verify the correct cellular controller interface name and number (For example, Cellular 0/1/0).

  • Obtain the Capture VPG IP address and the sensor's Capture IP address (from eth1 of the IOx app).

Follow these steps to enable GPS module on your platform:

Procedure

  1. Log in to the router using SSH.

  2. Enter the privileged EXEC mode.

    router# enable
    Password:
    router#
  3. Enter Global Configuration Mode:

    router# configure terminal
    Enter configuration commands, one per line. End with CNTL/Z.
    router(config)#
  4. Specify the satellite from which GPS data needs to be collected.

    router(config-if)# lte gps constellation gnss
  5. Enable GPS on the device.

    router(config-if)# lte gps nmea
  6. Configure transmission of GPS NMEA data over UDP:

    lte gps nmea ip udp <Capture_VPG_IP> <Sensor_Capture_IP> 5555 stream 1

    Replace <Capture_VPG_IP> and <Sensor_Capture_IP> with the actual IP addresses of your device. 5555 is the port number.

The GPS module begins transmitting NMEA data over UDP to the specified destination, and the CV sensors display current GPS coordinates in the GPS Coordinates field. When you hover over the value, an indicator confirms that the sensor is in GPS mode.

What to do next

Verify GPS data reception at the target IP. Confirm that the coordinates are current on the Sensor Explorer page.

For more information on enabling the GPS module on a router, see Configuring GPS in the Cellular Pluggable Interface Module Configuration Guide.


Configure GPS coordinates on sensors

Manually assign GPS location data to sensors for better geographic mapping and device management.

Configure GPS coordinates on sensors when deploying new sensors on network devices.

Before you begin

  • Identify the sensors you want to set or update with GPS coordinates.

  • Obtain the correct latitude and longitude values for each sensor location.

Follow these steps to manually set GPS coordinates on sensors:

Procedure

  1. From the main menu, choose Admin > Sensors > Sensor Explorer.

  2. On the Sensor Explorer page, click the sensor whose GPS coordinates you want to set.

  3. On the right side, click the pencil icon next to GPS Coordinates.

  4. In the SENSOR COORDINATES window, enter the latitude and longitude values. Click Check on map to verify the entered values.

  5. Once the values are verified, click Add.

  6. (Optional) To update or delete the values, click the pencil icon again.

The GPS coordinates you set appear in the GPS Coordinates field. When you hover over the value, an indicator confirms that the coordinates were set manually.


Deploying sensors with deployment tokens

Use Zero Touch Provisioning with third-party tools such as Cisco Catalyst WAN Manager. Refer to the Cisco Catalyst WAN Manager documentation on cisco.com to complete sensor deployment.

On the Deployment Tokens page, you can create, edit, enable, disable, and delete deployment tokens for Zero Touch Provisioning.

To access the Deployment Tokens page, choose Admin > Sensors > Deployment Tokens from the main menu.

Summary

Zero Touch Provisioning automates Cisco Cyber Vision deployment on batches of sensors by using deployment tokens with third-party tools such as Cisco Catalyst WAN Manager.

Workflow

These stages describe how deployment tokens are used to deploy sensors.

  1. You create a deployment phase that groups tokens and specifies their number of uses and expiration time.

  2. The application requests a token that is valid for its application type.

    A token contains the application name and a PSK (pre-shared key).

  3. After Cisco Catalyst WAN Manager is configured, it deploys sensors and applies parameters that allow each sensor to onboard itself on Center.

  4. Sensors present the PSK to Center, and Center then delivers the information necessary for enrollment.

  5. Deployment fails if the number of sensors exceeds the number of tokens or if deployment occurs after the expiration time.

  6. If deployment fails, you can edit the deployment phase to modify the number of uses and extend the expiration time.


Deployment files for sensors

Use this reference to identify the deployment file for each supported sensor platform.

Table 5. Deployment files by sensor

Sensors

Deployment files

IE3x00, IR1101, IR18xx, IE9300

cviox-aarch64.tar

IE3x00, IR1101, IR18xx, IE9300 with Active Discovery

cviox-active-discovery-aarch64.tar

IC3000

cviox-ic3000-x86-64.tar

IC3000 with Active Discovery

cviox-active-discovery-x86-64.tar

Catalyst 9300, 9400, IR8340

cviox-x86-64.tar

Catalyst 9300, 9400, IR8340 with Active Discovery

cviox-active-discovery-x86-64.tar


Create deployment tokens

Procedure

  1. From the main menu, choose Admin > Sensors > Deployment Tokens

    The Deployment Tokens page appears.

  2. Click Add Tokens.

    The Add new deployment tokens panel appears.

  3. In the Add new deployment tokens panel, enter a name for the deployment phase.

  4. Enter a value in Number of uses that corresponds to the number of devices to deploy.

  5. Set the Expiration time for the token.

  6. Select the Enabled toggle to enable the token and continue the deployment process.

  7. Click Create.

The deployment phase with tokens for each device type appears.

Note

You can view, copy, edit, disable, and delete the token.

What to do next

Refer to Cisco Catalyst WAN Manager documentation on cisco.com to continue and complete sensor deployment.


Templates

A sensor template is a configuration that defines protocol Deep Packet Inspection (DPI) engines and UDP/TCP port mappings for a Cisco Cyber Vision sensor.

You can create and configure sensor templates, then assign them to specific sensors.

  • Enable or disable protocol DPI engines.

  • Map UDP and TCP ports for packets of each protocol received by the sensor.

Protocol DPI engines

Enable or disable a protocol DPI engine to select which protocols to analyze.

Disable a protocol DPI engine to avoid false positives in Cisco Cyber Vision. A false positive occurs when a protocol appears in the user interface but is not present because other non-standardized protocols can use the same UDP/TCP ports.

Default template

The Default template disables some protocols because they are not commonly used or are specific to fields such as transportation.

The Default template applies to all compatible sensors.

UDP and TCP port mappings

Although UDP/TCP port configurations are mostly standardized, conflicts can occur for field-specific protocols or protocols with limited use. Map UDP/TCP port numbers to send packets to the correct DPI engine for accurate analysis and representation in the user interface.

Sending a protocol packet to the wrong port causes related information to appear in Security Insights/Flows without a tag.

Template assignment and deployment

A sensor can be associated with only one template.

Template deployment fails in the following situations:

  • The sensor is disconnected.

  • The sensor has connection issues.

  • The sensor version is too old.


Create a template

Procedure

  1. Choose Admin > Sensors > Templates from the main menu.

  2. Select Add sensor template.

    The CREATE SENSOR TEMPLATE window appears.

  3. Enter a name for the template.

    You can optionally add a description.

  4. Click Next, then type the protocol that you want to configure in the search bar.

    The list of protocol DPI engines and their basic configurations appears.

  5. Under the Port Mapping column, select pen for the protocol, enter the port numbers, and click OK.

    Note

    If you have continuous port numbers, you can enter a port range. For example, type 15000-15003 for ports 15000, 15001, 15002, and 15003.

    The port number is added to the protocol's default settings.

  6. Enable Displayed modified only to quickly find the protocol, and click Next.

  7. Select the checkboxes for the sensors to which you want to apply the template, and click Next.

  8. Review the template configuration, and click Confirm.

The configuration is sent to the sensors. Configuration deployment can take a few moments.

The OPCUA template appears in the template list with its two assigned sensors.


Export templates

Export a template when you need to migrate it to another center.

Procedure

  1. From the main menu, choose Admin > Sensors > Templates .

  2. Locate the template that you want to export, then hover over the ellipsis in the Actions column.

  3. Select Export from the drop-down list.

    The system downloads the template to a local location.


Import a template

Import a sensor template and apply it to selected sensors.

Procedure

  1. From the main menu, choose Admin > Sensors > Templates .

  2. Click Import sensor template.

    The local system folder opens.

  3. Select the template, and then click Open.

    The system displays the imported template on the Configuration Template page.

  4. Locate the template, and then hover over the in the Actions column.

  5. Select Edit from the drop-down list.

  6. On the Select sensors tab, select the sensors to which you want to apply the template.

  7. Click Next.

  8. Verify the details, and then click Update.

    The template recovers all changes made in the previous center and is applied to the selected sensors.