Deploy Cisco Cyber Vision Sensor on Switches and Routers

PDF

Deploy Cisco Cyber Vision Sensor on Switches and Routers

Deploying sensor applications

Want to summarize with AI?

Log in

Guides you through deploying Cyber Vision sensor applications across supported switches and routers, detailing automated and manual installation methods, provisioning, optional Active Discovery, and sensor management to enable real-time threat detection and network visibility.


When deployed in your network, the Cyber Vision sensor application enables real-time threat detection. It also provides ongoing visibility into industrial network assets and traffic patterns to support security and compliance objectives.

Table 1. Feature History

Feature

Release Information

Feature Description

The Sensor Management extension removal.

Release 5.6.0

When the Cisco Cyber Vision system is updated to version 5.6.0 and rebooted, the system detects the legacy sensor-management extension data and initiates migration to the sensor-host model in new UI. The sensor management extension is removed, and the sensor identity and configuration are preserved as they transition to the sensor-host model in the new UI.

You can deploy sensors on multiple network devices to expand coverage as needed.

There are multiple ways of deploying the sensor application on the supported switches and routers:

  • (Recommended) Using the sensor management extension in the Cyber Vision Center

    Note

    Starting with release 5.6.0, use the Sensor Management page in the New UI to deploy sensor applications to supported switches and routers. The Install via extension option is removed from Classic UI. However, manual sensor deployment, Docker sensor deployment, and Sensor VM deployment remain available in Classic UI.

    Sensors migrated from the Classic UI Sensor Management extension appear in the New UI with a status of Deployment successful and are no longer labeled Externally managed.

  • Onboarding and validating hosts, and then deploying sensors to each host.

  • Using the device CLI

  • Using the device Web UI

  • Bulk deployment

The sensor management extension is recommended because it offers these advantages:

  • Simple deployment: Automates installation and device configuration steps, reducing complexity for IT/OT teams.

  • Consistency: Sensors can be deployed in a standardized, repeatable manner.

Note

FIPS-compliant Cisco Cyber Vision does not support the sensor management extension.

FIPS-compliant Cisco Cyber Vision (Release 5.6.0 and later) does not support bulk sensor deployment. To deploy sensor on a FIPS-compliant Cisco Cyber Vision Center, use the manual deployment feature in the classic UI.

Manual installation using the device’s Web UI or CLI is required when the Center cannot connect to the target device because of network design or temporary issues.

This guide details the sensor extension deployment method. To deploy the sensor application using the device CLI or Web UI, see the guide for the specific device and IOS XE release:

Summary

After you complete initial configurations and traffic monitoring settings, you can prepare the network device and provision sensor applications for deployment. Use the sensor management extension in the Cyber Vision Center for efficient sensor deployment and management.

Workflow

The sensor provisioning process involves these stages. Each stage is executed separately when you choose manual deployment methods. With a sensor extension, all the stages are executed automatically using the configuration taskflow wizard.

  1. Define sensor provisioning in the Center

    The taskflow wizard for sensor provisioning involves defining these details:

    • Device serial number (required if you are not using the Sensor Management Extension in release 5.5.x or the Sensor deployment option in the New UI for release 5.6.0).

    • Device address and access credentials. The user must have Level 15 privilege access, with web UI access to deploy sensors using the sensor management extension.

    • Collection and management VLANs, ports, gateway and interfaces configured on the device for Cyber Vision.

    • Define the capture mode by selecting the type of traffic you want the sensor to analyze.

  2. Activate the provisioning file in the device

    If you use the sensor management extension, you can deploy the sensor provisioning from the Center.

    If you use the device Web UI or CLI, you must download the provisioning package from the Center and upload it to the device.

  3. (Optional) Enable Active Discovery

    To periodically monitor a specific set of protocols on devices, enable active discovery on the sensor. Define the ports that must be monitored for each protocol for best results.

    Cisco IR1101 and IR1800 routers do not support Active Discovery.

    Note

    To use Active Discovery, you must download and install the Cyber Vision sensor package that includes the feature. The name of the sensor package on Cisco Software Downloads indicates if Active Discovery is available in the package. If you have already installed a sensor with a package that doesn't include Active Discovery and wish to use this feature, you must reinstall the sensor with the correct software.

  4. Manage sensor application

    Deployed sensors are listed in the Admin > Sensors > Sensor Explorer page of the Center. You can monitor their status and manage the sensors from the Center.

    Note

    Starting from release 5.6.0 onwards, the sensor can be deployed, managed and monitored from the new UI Configuration > Sensor management. Classic UI continues to support manual sensor deployment, Docker sensor deployment, and Sensor VM deployment.

Result

When the sensor application is successfully configured and deployed, the sensor captures and analyzes network traffic in real-time. The sensor extracts and forwards security and operational insights to the Cyber Vision Center, enabling alerting, troubleshooting, and security management.


Bulk host onboarding and sensor deployment

Bulk host onboarding and sensor deployment allows you to onboard multiple hosts (switches and routers) to Cisco Cyber Vision in a single operation. It also enables you to deploy sensor applications to the onboarded hosts using a streamlined, wizard-based workflow.

It offers the following advantages:

  • Streamlines the onboarding of multiple hosts and deployment of sensor applications.

  • Minimizes manual effort for network administrators and IT operations engineers.

  • Improves operational efficiency through automated checks and simultaneous deployment.

Bulk host onboarding and sensor deployment is especially useful for large-scale deployments that require simultaneous onboarding of multiple hosts and deployment of sensor applications.

This process involves two key steps:

  • Onboard hosts to Cisco Cyber Vision

  • Deploy sensors to the hosts that have been successfully onboarded.

Table 2. Feature History Table

Feature

Release Information

Feature Description

The Sensor Management extension removal.

Release 5.6.0

The system detects the legacy sensor-management extension data and initiates migration to the sensor-host model in new UI. The sensor management extension is removed, and the sensor identity and configuration are preserved as they transition to the sensor-host model in the new UI.

Bulk host onboarding and sensor deployment on switches

Release 5.5.x

Enables you to onboard multiple switches and deploy sensor applications using a guided, wizard-based workflow.

Supported switches:

  • Cisco Catalyst IE3x00 switches

  • Cisco Catalyst 9x00 switches

  • Cisco Catalyst IE9300 Rugged Series Switches

Bulk host onboarding and sensor deployment on routers

Release 5.4.x

Bulk host onboarding and sensor deployment in Cisco Cyber Vision lets you add multiple routers at once and deploy sensor applications using a guided, wizard-based workflow. It automates reachability and readiness checks, reduces manual effort, and accelerates large-scale rollouts.


Bulk onboarding and sensor deployment capabilities

The bulk onboarding and sensor deployment feature provides these capabilities:

  • Adding multiple hosts simultaneously using a CSV file or manual entry.

  • Instantly verifying, along with other technical checks, that each host is reachable, has IOX enabled, and possesses adequate storage for sensor deployment.

  • Rapidly identifying devices that are ready for deployment, eliminating manual verification.

  • Enabling sensor deployment to ready hosts with a streamlined, wizard-based workflow.

  • Pre-selecting default settings for typical deployment scenarios, minimizing configuration overhead.

  • Offering retry options for deployment failures to maximize successful sensor rollout.

Supported devices

The bulk onboarding and sensor deployment feature currently supports the following devices:

  • Cisco IR1800 routers

  • Cisco IR1101 routers

  • Cisco Catalyst IE3x00 switches

  • Cisco Catalyst 9x00 switches

  • Cisco Catalyst IE9300 Rugged Series Switches

Note

Other platforms will be supported in the future.


Onboard hosts to Cisco Cyber Vision

Add new hosts to Cisco Cyber Vision to enable automated sensor deployment and monitoring.

Onboarding hosts prepares network devices for sensor application deployment. The CSV file can include both switch and router IP addresses and credentials.

Before you begin

Ensure these requirements are met:

  • IOS XE version 17.9 or higher is installed on the target hosts.

  • IOx services are enabled and running on the target hosts.

  • Web server is enabled on the target host.

  • NAT rules are set up to access the Cisco Cyber Vision collection interface.

  • Encapsulated Remote SPAN (ERSPAN) interfaces are set up for remote monitoring.

  • The hosts' time is synchronized with the Center or a valid NTP server.

    Cisco Cyber Vision runs readiness checks to determine whether each host is ready for sensor deployment. If a host is not yet ready, you can use the More Actions > Verify readiness menu for that host to run the checks again after correcting any issues.

Follow these steps to onboard hosts:

Procedure

  1. Go to Cyber Vision New UI > Configuration > Sensor Management.

    This section is divided into two tabs: Hosts and Sensors. The Hosts tab lists all onboarded platforms, while the Sensors tab displays your deployed sensor apps. The Sensors view also includes apps deployed via the Sensor Management extension from the Classic UI.

  2. Click Onboard host.

  3. Choose an onboarding method. To onboard multiple hosts, choose Use CSV file (recommended) or Input details manually to type them individually.

  4. If using a CSV file:

    1. Click the Use .CSV file (recommended) radio button.
    2. (Optional) Click the Download sample link to get a template for the CSV file.
    3. Upload your CSV file by clicking within the Click or drag file to this area to upload box.
  5. If manually inputting host details (limited to a maximum of 10 hosts):

    1. Click Input details manually.
    2. Enter the required host details in the fields that appear.
  6. (Optional) Enter the global credentials that are common to all hosts in the Global Credentials section.

    If you have not entered the credentials in the .CSV file, then the global credentials will be used.

  7. To complete the onboarding process, click Onboard.

The hosts are added to Cisco Cyber Vision. If you want to add more hosts, click Onboard host.

What to do next

Deploy sensor apps on the ready hosts.


Deploy sensor apps to hosts

Install sensor applications on the hosts that have been successfully onboarded and validated.

You can deploy sensor applications only on hosts marked Ready after onboarding. For switches, choose between two configuration types:

  • Simple: Uses the default deployment values displayed by the New UI for the selected host type.

  • Advanced: Uses the host list and collection-interface values from the CSV file. If supported parameters are omitted from the CSV file, the New UI uses the default deployment values for the selected host type.

Before you begin

  • Ensure that the target hosts are successfully onboarded.

  • Ensure that the host can reach Cisco Cyber Vision Center through the interface configuration used for sensor deployment. In particular, the collection interface, and any other interface specified in the deployment configuration, must be connected to the correct network and have valid addressing and routing. If an interface is configured on the wrong network or with incorrect parameters, the sensor will not be able to connect to the Center.

  • If you plan to use the advanced workflow for switches, ensure your CSV file is ready. The file must include the host list and collection interface parameters. Capture interface parameters are optional; if they are omitted, the default values displayed by the New UI for the selected host type are used.

  • Ensure that you deploy sensor apps to only one host type—routers or switches—at a time.

Follow these steps to deploy sensor apps:

Procedure

  1. Go to the Cyber Vision New UI > Configuration > Sensor Management.

  2. Select the target hosts for sensor application installation, then click Deploy sensor.

  3. For routers:

    1. Select Simple on the Choose deployment mode screen, and then click Continue.
    2. On the Simple Deployment screen, either keep the default values or enter the required details.
  4. For switches, do one of the following:

    • To use the default configuration settings, select Simple on the Choose deployment mode screen, and then click Continue. On the Simple Deployment screen, enter the required details.

      Table 3. Simple Deployment fields

      Field

      Description

      Use default values

      When checked, the system automatically applies standard network configurations and bypasses the need for manual entry.

      Collection Interface

      Specifies the network parameters for the collection interface, including IP address, Prefix, Gateway, and virtual port group number.

      Capture Interface

      Specifies the network parameters for the capture interface, including IP address, Prefix, and virtual port group number.

      Sensor Template

      Selects the configuration profile to be applied to the sensor.

      Capture Mode

      Sets the performance profile (e.g., Optimal) for data traffic capture.

    • To provide host and collection-interface parameters through a CSV file, select Advanced on the Choose deployment mode screen and upload your CSV file. Any supported parameters omitted from the CSV file use the default values displayed by the New UI for the selected host type.

  5. Click Deploy.

When the deployment is successful, the details of the sensor applications are displayed on the Sensor Management > Sensors page. To uninstall or retry sensor installation, use the Sensors page. Starting with Release 5.6.0, you can manage and monitor sensors apps migrated from the Classic UI Sensor Management extension to the sensor-host model from this page.

What to do next

Review deployment status and troubleshoot any failed installations as needed. To retry the deployment, select hosts from the list and click Retry Deployment.

After deploying the sensor application, configure the sensor settings as needed:

  • Configure the sensor capture mode in the classic UI Sensor Explorer page. Refer Set a Capture Mode in the Cisco Cyber Vision Classic UI Administration Guide, Release 5.6.0

  • Configure Snort to enable or disable intrusion detection.

  • Configure Active Discovery and specify the collection interface or additional network interfaces as required.

  • Before configuring Secure Remote Access (SRA), ensure that Active Discovery is enabled on the sensor. You can then enable or disable SRA and select the required connection method.

For detailed instructions on configuring Snort, Active Discovery, and Secure Remote Access on a sensor, refer the Cisco Cyber Vision New UI Administration Guide, Release 5.6.0.


Provision sensors using sensor management extension

Note

These steps apply to Cisco Cyber Vision release 5.5.x and earlier, where the sensor management extension is used for sensor installation and management.

Starting with Release 5.6.0, the Install via extension option is no longer available in Classic UI. Sensor deployment and management for switches and routers have transitioned to the New UI Sensor Management page. Sensors apps migrated from the Classic UI Sensor Management extension appear in the New UI with a status of Deployment successful. They are integrated into the New UI sensor-host model, where you can manage and monitor them.

Procedure

  1. Install sensor management extension.

  2. Add global device credentials.

  3. Install sensors using sensor management extension


Install sensor management extension

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Extensions.

  2. Click Import a new extension file.

  3. Choose the extension file from your local system.

What to do next

After you upload an extension file, from the Actions column, you can:

  • Update the extension to a different release.

  • Remove the extension.


Add global device credentials

Define the default credentials to be used for device access. The global credentials are used for all devices by default for sensor management workflows. When you update the credentials, the latest credentials are used to access deployed sensors as well.

The user credentials must have Level 15 access privilege, and have access to the device Web UI.

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Sensors > Sensor Explorer.

  2. Choose Manage Cisco devices > Manage credentials.

  3. To save the credentials, click Update.


Install sensors using sensor management extension

Before you begin

  • Install sensor management extension.

  • Add global device credentials.

  • Define capture and collection details for network . For instructions, see Setting up OT traffic monitoring. Capture IP and VLAN form the internal connection between the device and the sensor application. Collection IP and VLAN form the connection between the sensor application and the Cyber Vision Center.

  • Device must have Web UI set up.

  • A configuration template allows you to define the ports and protocols that the Cyber Vision sensor must monitor. While a default template is available for use, you can also create your own template.

  • Cisco IR1101 and IR1800 routers do not support Active Discovery.

  • To use Active Discovery, you must download and install the Cyber Vision sensor package that includes the feature. The name of the sensor package on Cisco Software Downloads indicates if Active Discovery is available in the package. If you have already installed a sensor with a package that doesn't include Active Discovery and wish to use this feature, you must reinstall the sensor with the correct software.

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Sensors > Sensor Explorer.

  2. Click New sensor > Install via extension to initate the installation wizard.

  3. In the Reach Cisco device page, fill out the following details to allow the Cyber Vision Center to identify and reach the device on which you want to install the sensor application:

    • (Mandatory) IP address

    • (Mandatory) Port: Typically, port 443 is the standard port for secure HTTPS traffic. However, you can choose to use a different port.

    • Center collection IP: To use the Center's current collection IP, leave the field empty. To use a different collection IP, especially in case of NAT configurations, enter the reachable IP address.

    • Sensor label: Enter a easily identifiable label for the sensor.

    • Configuration template: From the configuration template drop-down list, choose the template to apply.

    • Credentials: Choose to use global or custom credentials to reach the device.

    • Capture Mode: Choose the data you want the Cyber Vision sensor to inspect.

  4. Click Connect.

  5. In the Configure Cyber Vision IOx sensor app page, define the monitor sessions on the device by providing the required details. The fields that you see in this page change based on the device have connected to.

    Configuration field

    Device this field applies to

    • Capture (mirroring) and collection IP addresses.

    • Capture (mirroring) and collection prefix lengths.

    • (Optional) Collection gateway, if the Center and the sensor application are in different subnets.

    All switches and routers

    Note

    RSPAN configuration on Catalyst 9300.

    • Capture (mirroring) and collection VLAN numbers.

    • Disk size.

    Swiches only.

    SPAN type

    Catalyst 9x00 switches only.

    We recommend ERSPAN sessions for optimal traffic monitoring across purdue levels.

    Extra capture IP address, prefix length, and VLAN number.

    IR8340 routers only.

    The extra capture details define the connection between sensor and the AppGig virtual interface for capturing switched traffic.

  6. In the Configure Active Discovery page, choose between:

    • Passive only
    • Passive and Active Discovery and SEA

    Packages that include SEA are available for Cisco Cyber Vision Sensors Release 5.3.0 and later.

  7. (If you use the Active Discovery sensor package) To use active discovery, provide the following details:

    1. Collection interface

    2. IP address

    3. Prefix length

    4. VLAN number

  8. Click Deploy.

What to do next

Sensor deployment can take up to 15 minutes to complete. You can track the progress of the deployment in the Admin > Sensors > Management jobs page.

Create sensor configuration template

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Sensors > Templates.

  2. Click Add sensor template to initiate the template configuration wizard.

  3. In the Basic information step, add a name and description for the template.

  4. In the Protocol configuration step, in the displayed table:

    1. Choose the protocols you want to monitor by enabling or disabling the protocol entry.
    2. Where applicable, enter the port assigned for the protocol traffic.
  5. (Optional) In the Select sensors step, choose any existing sensors you want to apply the template to.

  6. In the Summary step, review your template configuration.

  7. To create the template, click Confirm.


Manual Sensor Installation

Manual sensor installation deploys the Cisco Cyber Vision sensor application directly on a supported IOS XE switch or router by using the device CLI or IOx Local Manager.

Use manual installation when the Cisco Cyber Vision Center cannot deploy the application through the sensor management extension, such as when the Center cannot reach the device management interface, when network policy blocks extension-based deployment, or when you need to test a single device before a larger rollout.

Manual installation does not replace device preparation. Before you manually install the sensor application, configure the device storage when required, synchronize the device clock, enable IOx, and configure OT traffic monitoring. The sensor must receive mirrored traffic and must be able to communicate with the Cisco Cyber Vision Center collection interface.

Note

If you install a sensor package that does not include Active Discovery and later decide to use Active Discovery, reinstall the sensor with the correct package.

Table 4. Manual Installation Methods

Method

Use this method when

What you do

IOx Local Manager

You can reach the device Web UI and prefer a guided interface for resource and interface configuration.

Upload the sensor application archive, configure the resource profile and network interfaces, start the application, create a provisioning package in Cisco Cyber Vision, and upload the provisioning package to the application data directory.

Device CLI

You need repeatable commands, remote terminal access, or cannot use the device Web UI.

Configure the hosted application, install the sensor archive from device storage, activate and start the application, create a provisioning package in Cisco Cyber Vision, and copy the provisioning package into the hosted application.

Table 5. Manual Installation Packages

Device family

Standard sensor package

Active Discovery package

Cisco IR1101 and Cisco IR1800 routers

CiscoCyberVision-IOx-aarch64-<version>.tar

Not supported on Cisco IR1101 and Cisco IR1800.

Cisco IR8340 routers

CiscoCyberVision-IOx-x86-64-<version>.tar

CiscoCyberVision-IOx-Active-Discovery-x86-64-<version>.tar

Cisco IE3300 10G, IE3400, IE9300, and IE3500 switches

CiscoCyberVision-IOx-aarch64-<version>.tar

CiscoCyberVision-IOx-Active-Discovery-aarch64-<version>.tar

Cisco Catalyst 9x00 switches

CiscoCyberVision-IOx-x86-64-<version>.tar

CiscoCyberVision-IOx-Active-Discovery-x86-64-<version>.tar


Manual Sensor Installation Workflow

Manual sensor installation separates application deployment from Center-side provisioning.

You install the IOx application on the device first, then use Cisco Cyber Vision to create a provisioning package that enrolls the sensor with the Center.

Summary

The workflow starts with device preparation and ends when the sensor is connected in Cisco Cyber Vision.

Workflow

The manual sensor installation workflow has these stages.

  1. Prepare the device.

    Configure storage if the platform requires external storage, synchronize the device clock, enable IOx, and configure traffic mirroring and collection connectivity. For traffic monitoring commands, use Setting up OT traffic monitoring and the examples in Sensor deployment examples.

  2. Select the sensor package.

    Download the package that matches the device architecture and the required feature set. Use an Active Discovery package only on platforms that support Active Discovery.

  3. Install and activate the sensor application.

  4. Create the provisioning package.

    In Cisco Cyber Vision, create a manual Cisco IOx sensor entry. The Center generates sbs-sensor-config-<serialnumber>.zip.

  5. Import the provisioning package into the device.

    Upload the package through IOx Local Manager or copy it into the hosted application with the device CLI.

  6. Verify sensor connectivity.

    Confirm that the sensor appears as Connected in Admin > Sensors > Sensor Explorer. Save the device configuration.

  7. Enable Active Discovery if required.

    If you installed an Active Discovery package and the platform supports Active Discovery, assign the sensor to an Active Discovery profile.


Install the Sensor Application with IOx Local Manager

Install the Cisco Cyber Vision sensor application by using the device Web UI and IOx Local Manager.

Use IOx Local Manager when you can reach the device Web UI and want to configure the hosted application through a graphical interface.

Before you begin

Complete the device preparation and OT traffic monitoring tasks.

Download the Cisco Cyber Vision sensor package for the device platform.

Verify that you can sign in to the device Web UI with a user account that can manage IOx applications.

Have the collection, capture, VLAN, gateway, and resource values that match the traffic monitoring configuration on the device.

Procedure

  1. Open the device Web UI in the browser, and sign in with the device credentials..

  2. Choose Configuration > Services > IOx.

  3. Sign in to IOx Local Manager.

  4. In the Applications tab, click Add New.

    1. Enter an application ID, such as CCVSensor.
    2. Upload the Cisco Cyber Vision sensor application archive.
    3. Wait until the application appears in the application list.
  5. Click Activate.

    1. Configure the resource profile.

      Use the platform guidance in the resource settings table.

    2. Configure the network interface bindings for the hosted application.

      Use the IP addresses, prefix lengths, VLAN IDs, and gateway values that match the traffic monitoring and collection settings configured on the device.

    3. Click Activate App.
  6. Return to the Applications tab and click Start.

  7. Confirm that the application state changes to RUNNING.

The sensor application is installed and running on the device. The sensor does not connect to Cisco Cyber Vision until you create and import the provisioning package.

Resource settings

Table 6. IOx Local Manager resource settings

Platform

Resource settings

Cisco IR1101, IR1800, and IR8340 with SSD

Set the disk size to at least 4 GB.

Cisco IR1101, IR1800, and IR8340 without SSD

Set the disk size to 384 MB and add Docker option --tmpfs /tmp:rw,size=128m.

Cisco IE3300 10G, IE3400, IE9300, and IE3500

Set the disk size to 1248 MB. Do not set a larger value.

Cisco Catalyst 9x00 with SSD

Set the disk size to at least 15 GB and add Docker option --rm.

Cisco Catalyst 9x00 without SSD

Set the disk size to 384 MB and add Docker option --rm --tmpfs /tmp:rw,size=128m.

Interface bindings

Table 7. IOx Local Manager interface bindings

Platform

Interface bindings

Cisco IR1101 and Cisco IR1800

Bind eth0 to VPG1 for collection/NAT traffic. Bind eth1 to VPG0 for routed ERSPAN capture traffic. Disable IPv6 on both interfaces.

Cisco IR8340

Bind eth0 to VPG1 for collection/NAT traffic. Bind eth1 to mgmt-bridge300 for switched-port mirrored traffic. Bind eth3 to VPG0 for routed ERSPAN capture traffic. If you use Active Discovery, bind eth2 to mgmt-bridge300. Disable IPv6 on all interfaces.

Cisco IE3300 10G, IE3400, IE9300, and IE3500

Bind eth0 to mgmt-bridge300 and set the collection vlan id. Bind eth1 to mgmt-bridge300 and set the mirror vlan id. Disable IPv6 on both interfaces. If you use Active Discovery, add eth2 without an IP address and disable IPv4 and IPv6.

Cisco Catalyst 9x00

Bind eth0 to mgmt-bridge300 and set the collection vlan id. Bind eth1 to mgmt-bridge300, set the mirror vlan id and enable mirror mode. Disable IPv6 on both interfaces. If you use Active Discovery, add eth2 without an IP address and disable IPv4 and IPv6.


Install the Sensor Application with the Device CLI

Install the Cisco Cyber Vision sensor application by using IOS XE CLI commands.

Use the device CLI when you need command-based installation or cannot use IOx Local Manager.

Before you begin

Complete the device preparation and OT traffic monitoring tasks.

Download the Cisco Cyber Vision sensor package for the device platform.

Copy the package to a location that the device can access, such as bootflash:, flash:, or usbflash0:.

Decide the application ID. The examples use CCVSensor.

Have the collection, capture, VLAN, gateway, and resource values that match the device traffic monitoring configuration.

Procedure

  1. Connect to the device through SSH or console.

  2. Configure the hosted application interfaces and resources.

    The following examples show common patterns. Replace the example addresses, VLAN IDs, and resource values with values for your deployment.

    Example:

    Cisco IR1101 and Cisco IR1800 without SSD:
    enable
    configure terminal
    app-hosting appid CCVSensor
    app-vnic gateway0 virtualportgroup 1 guest-interface 0
    guest-ipaddress 169.254.0.2 netmask 255.255.255.252
    app-vnic gateway1 virtualportgroup 0 guest-interface 1
    guest-ipaddress 169.254.1.2 netmask 255.255.255.252
    app-default-gateway 169.254.0.1 guest-interface 0
    app-resource docker
    run-opts 1 "--tmpfs /tmp:rw,size=128m"
    end
    
    Cisco IR8340 without SSD:
    enable
    configure terminal
    app-hosting appid CCVSensor
    app-vnic gateway0 virtualportgroup 1 guest-interface 0
    guest-ipaddress 169.254.0.2 netmask 255.255.255.252
    app-vnic gateway1 virtualportgroup 0 guest-interface 3
    guest-ipaddress 169.254.1.2 netmask 255.255.255.252
    app-vnic AppGigabitEthernet trunk
    vlan 2340 guest-interface 1
    guest-ipaddress 169.254.2.2 netmask 255.255.255.252
    app-default-gateway 169.254.0.1 guest-interface 0
    app-resource docker
    run-opts 1 "--tmpfs /tmp:rw,size=128m"
    end
    
    Cisco IE3300 10G or Cisco IE3400:
    enable
    configure terminal
    app-hosting appid CCVSensor
    app-vnic AppGigabitEthernet trunk
    guest-interface 2
    vlan <collection-vlan-id> guest-interface 0
    guest-ipaddress <sensor-collection-ip> netmask <collection-netmask>
    vlan <mirror-vlan-id> guest-interface 1
    guest-ipaddress 169.254.1.2 netmask 255.255.255.0
    app-default-gateway <collection-gateway-ip> guest-interface 0
    app-resource profile custom
    persist-disk 2048
    cpu 1400
    memory 1248
    vcpu 2
    end
    
    Cisco Catalyst 9x00:
    enable
    configure terminal
    app-hosting appid CCVSensor
    app-vnic AppGigabitEthernet trunk
    guest-interface 2
    vlan <collection-vlan-id> guest-interface 0
    guest-ipaddress <sensor-collection-ip> netmask <collection-netmask>
    vlan <mirror-vlan-id> guest-interface 1
    mirroring
    guest-ipaddress <sensor-capture-ip> netmask <capture-netmask>
    app-default-gateway <collection-gateway-ip> guest-interface 0
    app-resource profile custom
    cpu 7400
    memory 2048
    vcpu 2
    end
    
    Cisco Catalyst 9x00 without SSD:
    app-resource docker
    run-opts 1 --rm --tmpfs /tmp:rw,size=128m
  3. Install the application package.

    Example:

    app-hosting install appid CCVSensor package <storage-location>:<sensor-package-file>.tar
    
    Example:
    app-hosting install appid CCVSensor package usbflash0:CiscoCyberVision-IOx-aarch64-<version>.tar
  4. Verify that the application is deployed.

    Example:

    show app-hosting list
  5. Activate the application.

    Example:

    app-hosting activate appid CCVSensor
  6. Start the application.

    Example:

    app-hosting start appid CCVSensor
  7. Verify that the application state is RUNNING.

    Example:

    show app-hosting list

The sensor application is installed and running on the device. The sensor does not connect to Cisco Cyber Vision until you create and import the provisioning package.


Create a Sensor Provisioning Package

Create the Cisco Cyber Vision provisioning package that enrolls a manually installed Cisco IOx sensor with the Center.

Create the provisioning package after the sensor application is installed and running on the target device.

Before you begin

Configure traffic monitoring on the target device.

Install and start the sensor application on the target device.

Collect the hardware serial number.

Know whether the device uses ERSPAN or RSPAN for traffic monitoring.

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Sensors > Sensor Explorer.

  2. Select New sensor, then select Manual install.

  3. In the Cisco IOx manual installation page, enter the device and sensor details.

    Use the field descriptions table to complete the manual installation page.

  4. Select Create sensor.

  5. Select Download package.

  6. Save the provisioning package.

Cisco Cyber Vision creates a sensor entry in Sensor Explorer and downloads a provisioning package named sbs-sensor-config-<serialnumber>.zip.

Manual installation fields

Table 8. Cisco IOx manual installation fields

Field

Description

Serial number

Hardware serial number of the switch or router.

Center collection IP

Leave blank to use the Center collection IP already configured on the Center. Enter a different reachable collection IP when the deployment uses NAT or a different collection address.

Gateway

Gateway used by the sensor application, if required by the network design.

Sensor label

A label that helps you identify the sensor in Sensor Explorer.

Capture mode

The type of traffic the sensor analyzes.

Monitor session type

Use ERSPAN, or use RSPAN only when ERSPAN is not possible and the platform supports RSPAN.

What to do next

Import the provisioning package into the device through IOx Local Manager or the device CLI.


Import the Provisioning Package with IOx Local Manager

Import the Cisco Cyber Vision provisioning package into a manually installed sensor application through IOx Local Manager.

Before you begin

Create and download the provisioning package from Cisco Cyber Vision.

Confirm that the sensor application is running in IOx Local Manager.

Procedure

  1. Open the device Web UI.

  2. Choose Configuration > Services > IOx.

  3. Sign in to IOx Local Manager.

  4. In the Applications tab, locate the sensor application.

  5. Select Manage.

  6. Select App-DataDir and click Upload.

  7. Select the provisioning package, such as sbs-sensor-config-<serialnumber>.zip.

  8. In the path field, enter the exact file name, including the .zip extension and click OK.

The provisioning package is imported into the sensor application. After the sensor completes enrollment, its health status changes to Connected in Cisco Cyber Vision Sensor Explorer.


Import the Provisioning Package with the Device CLI

Import the Cisco Cyber Vision provisioning package into a manually installed sensor application by using the device CLI.

Before you begin

Create and download the provisioning package from Cisco Cyber Vision.

Copy the provisioning package to a location that the device can access, such as usbflash0:.

Confirm that the sensor application is running.

Procedure

  1. Connect to the device through SSH or console.

  2. Copy the provisioning package into the application data directory.

    Example:

    app-hosting data appid <sensor-app-name> copy <storage-location>:sbs-sensor-config-<serialnumber>.zip sbs-sensor-config-<serialnumber>.zip
    
    Example:
    app-hosting data appid CCVSensor copy usbflash0:sbs-sensor-config-<serialnumber>.zip sbs-sensor-config-<serialnumber>.zip
  3. Wait for the sensor to enroll with the Center.

The provisioning package is imported into the sensor application. After the sensor completes enrollment, its health status changes to Connected in Cisco Cyber Vision Sensor Explorer.


Verify a Manually Installed Sensor

Validate that a manually installed Cisco Cyber Vision sensor is connected and processing data.

Procedure

  1. In Cisco Cyber Vision Center, choose Admin > Sensors > Sensor Explorer.

  2. Locate the sensor that you manually installed.

  3. Confirm that the sensor health status is Connected.

  4. Confirm that the sensor processing status indicates normal processing.

  5. If the sensor is not connected, check the deployment prerequisites.

    Use the verification table to check the sensor application state, provisioning package, collection connectivity, time synchronization, and traffic monitoring configuration.

  6. Save the device configuration.

    Example:

    write mem

The sensor is connected to Cisco Cyber Vision and the device configuration is saved.

Verification checks

Table 9. Manual sensor verification checks

Check

What to verify

Sensor application state

In IOx Local Manager or with show app-hosting list, confirm that the application is running.

Provisioning package

Confirm that the package was imported into the correct application ID and that the file name is exact.

Collection connectivity

Confirm that the sensor collection interface can reach the Cisco Cyber Vision Center collection interface.

Time synchronization

Confirm that the device clock is synchronized with the Center or an NTP source.

Traffic monitoring

Confirm that SPAN, RSPAN, or ERSPAN configuration matches the sensor capture interface values.


Enable Active Discovery on a Manually Installed Sensor

Enable Active Discovery on a manually installed sensor when the platform and installed package support the feature.

Cisco IR1101 and Cisco IR1800 routers do not support Active Discovery. To use Active Discovery on a supported platform, install a sensor package that includes Active Discovery.

Before you begin

Install and provision the sensor.

Confirm that the sensor health status is Connected.

Confirm that the installed package includes Active Discovery.

Procedure

  1. From the Cisco Cyber Vision Center menu, choose Admin > Active Discovery > Profiles.

  2. Select the profile that you want to apply to the sensor.

  3. Select Edit.

  4. From the Sensors list, select the sensor.

  5. Select Update.

  6. To run the profile immediately, select the profile and select Run Once.

The Active Discovery profile runs on the sensor according to the configured schedule, or immediately if you selected Run Once.