The following guide is specifically designed to cater to customers who utilize on-premises servers, either in hybrid mode or for full on-premises deployment.
Installation on VM (Virtual Machine): hyper-v of VMware (according to the following specifications).
System Requirement
At least 8 CPU cores.
16-32 Gigabytes of memory (RAM).
Hardisk of 512-1024 Gigabytes.
2 network interfaces:
One interface for scanning (in case of multiple VLANs, the system must be connected to trunk IEEE 802.1Q which contains all the VLANs to scan).
The second interface is for IDS and must be dedicated to the system – connected to the central switch that supports Port Mirroring – To receive traffic duplication for early detection of suspicious behavior.
Network Settings Requirement
IP address, subnet mask, and default gateway for system management.
In the case of multiple VLANs: Ip address, subnet mask, and VLAN ID are required for each VLAN.
It is recommended that the management address will be in the native VLAN.
Make sure there’s access to the core switch (user/password) to configure various settings (port mirroring etc.).
Identify the port from which the backbone is connected to the firewall.
A free port must be assigned in the core switch for the port mirroring configuration.
CyFox communicates with the license and updates servers regularly, add Firewall rules (if necessary) to allow
access to the following addresses in ports 80 and 443 TCP: 82.166.80.236 and 62.90.227.179.
GPO Settings
CyFox can access Microsoft devices directly through WMI.
GPO must be configured on the Domain Controller to enable WMI access across all hosts.
Additionally, prepare a user with admin privileges in the domain for CyFox.
CyFox settings for managed SOC services
For SOC services (if acquired) please open UDP port 2514 from the CyFox server to: 31.133.100.151.
Download and install CyFox
Download and install CyFox, click here.
For an initial/extended license please contact our sales team.
The ISO should also be uploaded to the ESXi Datastore for installation.
Access for CyFox support team
To allow access for support and maintenance, open ports 22 and 7443 TCP for addresses: 212.150.108.5, 62.0.131.49 to the CyFox server in your Firewall.
If the ports are already in use by VIP, you can port forward to other ports and update us.
During the installation process, it is essential to have an IT representative available who can provide remote access and configure network settings as necessary.
Download
You can access the guide by downloading the attached file