Title: Tripwire Enterprise Server Getting Started
1Tripwire Enterprise Server Getting Started
- Doreen Meyer and Vincent Fox
- UC Davis, Information and Education Technology
- June 6, 2006
2Tripwire Topics
- Introduction
- Demonstration
- Product description
- UC Tripwire license
- Hardware requirements
3Tripwire Topics
- Documentation
- How to .
- Server deployment considerations
- Next steps
- Contact information
4Introduction
- What is Tripwire?
- Why use Tripwire?
- Is it difficult to deploy Tripwire?
5What is Tripwire?
- Tripwire Enterprise audits changes by detecting
all changes, reconciling these changes with
authorized changes, and reporting on change
activity. Agents can be any platform, including
network devices like switches and routers.
6Why Use Tripwire?
- Monitors important file and registry values and
properties (like access times, flags, owner, etc) - Enables Admins to detect files that are added,
modified or deleted - Provides a history of what changes during patching
7Is it difficult to deploy?
- Training sessions are helpful
- It will take time to tune the rule set for your
systems - You will need to incorporate Tripwire steps into
system change and patching procedures as well as
daily log checks
8Demonstration
9Product Description
- Versions
- Components
- Operating Systems - Server
- Operating Systems - Client
10Versions
- Tripwire for Servers/Tripwire Manager
- Tripwire Enterprise 5.2 (5.5 just released).
Adds reporting, multi-user, hosts network
devices - This course focuses on Tripwire Enterprise
11TE Components
- File Server
- Network Devices
- Desktop
- Directory (Active Directory, Sun One)
- Database (Oracle)
- UC licensed component
12What can it operate on?
13Server Platform
- Solaris sparc 8, 9,10
- Windows 2000 Server
- Windows 2003 Server
- Red Hat Linux Enterprise 3, 4 AS ES
14Operating Systems - Client
- Windows NT 4.0 SP6a
- Windows XP Professional (Service Pack 2)
- Windows 2000 Professional Server (Service Pack
4) - Windows 2003 Server (Service Pack 1)
- Windows 2003 Server x64 Edition (Standard,
Enterprise Datacenter)
15Operating Systems - Client
- Solaris sparc 8, 9,10
- Red Hat Linux Enterprise 3, 4 AS ES
- IBM AIX 5.1, 5.2, or 5.3
- HP-UX 11, 11i v1, 11i v2
- SUSE Linux Enterprise Server 9
- Cent OS 4.2
- Fedora Core 2
16UCOP Tripwire License
- UCOP License
- Product options
- How to request the software
17UCOP License
- UCOP license, 5000 licensed nodes
- Funded through April, 2007
- IET subsidized the campus license, 10,000.00
for three years - Software Licensing will work on a future license
agreement
18Requesting the Software
- Fill out the form available on the software
licensing web site - Dept name
- Requester information (contact info for person
who will be receiving the license) - License exchange or new license?
19Requesting the Software
- Server housing DB and web interface Tripwire
Enterprise Server. Order 1. - Clients that will be monitored Tripwire
Enterprise Server/FS. Order 1 for each client. - Network devices that will be monitored Tripwire
Enterprise Network Device. Order at least 1.
20Requesting the Software
- Email your request to software_at_ucdavis.edu before
300 PM on June 7 to receive the software license
and download URL by June 9. - The download URL will allow you to generate a
certificate for the server and download the
software.
21Hardware
- Server Requirements - Windows
- Server Requirements - Solaris
- Server Requirements - Linux
22Server Requirements - Windows
- 3.0 GHz x86 processor or compatible
- 2 GB RAM
- 2 SATA or SCSI hard drives
- 3.2 GB free disk space
- 4 GB Data storage space
- 256 color display
23Server Requirements - Linux
- 3.0 GHz x86 processor or compatible
- 2 GB RAM
- 2 SATA or SCSI hard drives
- 3.2 GB free disk space
- 4 GB Data storage space
- 256 color display
24Server Requirements - Solaris
- 900 MHz UltraSPARC III processor
- 2 GB RAM
- 2 SCSI hard drives
- 3.2 GB free disk space
- 4 GB Data storage space
- X-Windows capable display
- 256 color display
25How To
- Acquire and download software
- Install server software
- Change passwords
- Secure your tripwire server
26Getting Tripwire software
- Upon licensing you will be sent a link in email
to your products, follow this link. - Download te_server and all agents. The server
zip file will also contain all documentation
files.
27Installing Tripwire Server
- Needs to be installed on console!
- Pick install location with enough space,
especially if running database on same server.
28Installing Tripwire Server
- Use name to be advertised (e.g. FQDN)
29Installing Tripwire Server
- Ports, pick and record choices
30Installing Tripwire Server
- Services pw - server/client interaction
31Installing Tripwire Server
- Wait a bit for service to initialize!
- Access web console, e.g.
- https//localhost1443/
32Installing Tripwire Server
- First thing it wants is license cert!
33Installing Tripwire Server
- Follow license link, generate cert
34Installing Tripwire Server
- Change admin account password!
- Store new admin account password
- Add new admin user(s) for daily work
35Tripwire Firewall changes
- Open https port to all hosts you will
administrate from - Open Services port to all hosts that will run the
agent.
36Tripwire information
- 3 PDF files included in server zip file, also on
class CD. - Mailing list?
37Assignment, due July 12
- Order Tripwire software by June 7
- Install Tripwire software on a server
- Think about Why are you using Tripwire? It
will guide your decisions on rules, nodes, users - How should you group your nodes/systems?
38Assignment, due July 12
- Who should have access to Tripwire?
- What kind of reports will be helpful?
39July Training Schedule
- July 12 adding and configuring a node using the
basic rule set - July 19 rules, tasks, and actions
- July 26 reports, dashboard, deployment steps
40QA
41Contact Information
- Vincent Fox vfox_at_ucdavis.edu
- Doreen Meyer dimeyer_at_ucdavis.edu
- Robert Ono, raono_at_ucdavis.edu
- software_at_ucdavis.edu
- support_at_tripwire.com