Skip to content

Commit 4723027

Browse files
authored
Merge pull request #221311 from yoninalmsft/split-ot-install
Split up OT install software doc
2 parents bb4df2b + 43d3495 commit 4723027

16 files changed

+467
-418
lines changed

.openpublishing.redirection.defender-for-iot.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,10 @@
11
{
22
"redirections": [
3+
{
4+
"source_path_from_root": "/articles/defender-for-iot/organizations/how-to-install-software.md",
5+
"redirect_url": "/azure/defender-for-iot/organizations/ot-deploy/install-software-ot-sensor",
6+
"redirect_document_id": false
7+
},
38
{
49
"source_path_from_root": "/articles/defender-for-iot/organizations/how-to-create-and-manage-users.md",
510
"redirect_url": "/azure/defender-for-iot/organizations/manage-users-overview",
@@ -117,7 +122,7 @@
117122
},
118123
{
119124
"source_path_from_root": "/articles/defender-for-iot/how-to-install-software.md",
120-
"redirect_url": "/azure/defender-for-iot/organizations/how-to-install-software",
125+
"redirect_url": "/azure/defender-for-iot/organizations/ot-deploy/install-software-ot-sensor",
121126
"redirect_document_id": false
122127
},
123128
{

articles/defender-for-iot/organizations/TOC.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -182,8 +182,14 @@
182182
href: how-to-manage-subscriptions.md
183183
- name: Onboard OT sensors
184184
href: onboard-sensors.md
185-
- name: Install OT system software
186-
href: how-to-install-software.md
185+
- name: Install OT monitoring software
186+
items:
187+
- name: Install OT sensor software
188+
href: ot-deploy/install-software-ot-sensor.md
189+
- name: Install on-premises management console software
190+
href: ot-deploy/install-software-on-premises-management-console.md
191+
- name: Validate after installation
192+
href: ot-deploy/post-install-validation-ot-software.md
187193
- name: Activate and set up your sensor
188194
href: how-to-activate-and-set-up-your-sensor.md
189195
- name: Deploy OT certificates

articles/defender-for-iot/organizations/appliance-catalog/virtual-management-hyper-v.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ Before you begin the installation, make sure you have the following items:
2424

2525
- Available hardware resources for the virtual machine. For more information, see [OT monitoring with virtual appliances](../ot-virtual-appliances.md).
2626

27-
- The on-premises management console software [downloaded from Defender for IoT in the Azure portal](../how-to-install-software.md#download-software-files-from-the-azure-portal)
27+
- The on-premises management console software [downloaded from Defender for IoT in the Azure portal](../ot-deploy/install-software-on-premises-management-console.md#download-software-files-from-the-azure-portal).
2828

2929
Make sure the hypervisor is running.
3030

@@ -78,7 +78,7 @@ This procedure describes how to create a virtual machine for your on-premises ma
7878

7979
The VM will start from the ISO image, and the language selection screen will appear.
8080

81-
1. Continue with the [generic procedure for installing on-premises management console software](../how-to-install-software.md#install-ot-monitoring-software).
81+
1. Continue with the [generic procedure for installing on-premises management console software](../ot-deploy/install-software-on-premises-management-console.md).
8282

8383
## Next steps
8484

@@ -88,4 +88,4 @@ Then, use any of the following procedures to continue:
8888

8989
- [Purchase sensors or download software for sensors](../onboard-sensors.md#purchase-sensors-or-download-software-for-sensors)
9090
- [Download software for an on-premises management console](../how-to-manage-the-on-premises-management-console.md#download-software-for-the-on-premises-management-console)
91-
- [Install software](../how-to-install-software.md)
91+
- [Install Microsoft Defender for IoT on-premises management console software](../ot-deploy/install-software-on-premises-management-console.md)

articles/defender-for-iot/organizations/appliance-catalog/virtual-management-vmware.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ The on-premises management console supports both VMware and Hyper-V deployment o
2424

2525
- Available hardware resources for the virtual machine. For more information, see [OT monitoring with virtual appliances](../ot-virtual-appliances.md).
2626

27-
- The on-premises management console software [downloaded from Defender for IoT in the Azure portal](../how-to-install-software.md#download-software-files-from-the-azure-portal)
27+
- The on-premises management console software [downloaded from Defender for IoT in the Azure portal](../ot-deploy/install-software-on-premises-management-console.md#download-software-files-from-the-azure-portal).
2828

2929
Make sure the hypervisor is running.
3030

@@ -64,8 +64,7 @@ This procedure describes how to create a virtual machine for your on-premises ma
6464

6565
The VM will start from the ISO image, and the language selection screen will appear.
6666

67-
1. Continue with the [generic procedure for installing on-premises management console software](../how-to-install-software.md#install-ot-monitoring-software).
68-
67+
1. Continue with the [generic procedure for installing on-premises management console software](../ot-deploy/install-software-on-premises-management-console.md).
6968

7069
## Next steps
7170

@@ -75,4 +74,4 @@ Then, use any of the following procedures to continue:
7574

7675
- [Purchase sensors or download software for sensors](../onboard-sensors.md#purchase-sensors-or-download-software-for-sensors)
7776
- [Download software for an on-premises management console](../how-to-manage-the-on-premises-management-console.md#download-software-for-the-on-premises-management-console)
78-
- [Install software](../how-to-install-software.md)
77+
- [Install Microsoft Defender for IoT on-premises management console software](../ot-deploy/install-software-on-premises-management-console.md)

articles/defender-for-iot/organizations/appliance-catalog/virtual-sensor-hyper-v.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ The on-premises management console supports both VMware and Hyper-V deployment o
2727

2828
- Available hardware resources for the virtual machine. For more information, see [OT monitoring with virtual appliances](../ot-virtual-appliances.md).
2929

30-
- The OT sensor software [downloaded from Defender for IoT in the Azure portal](../how-to-install-software.md#download-software-files-from-the-azure-portal).
30+
- The OT sensor software [downloaded from Defender for IoT in the Azure portal](../ot-deploy/install-software-ot-sensor.md#download-software-files-from-the-azure-portal).
3131

3232
Make sure the hypervisor is running.
3333

@@ -53,7 +53,7 @@ This procedure describes how to create a virtual machine by using Hyper-V.
5353

5454
1. Select **Specify Generation** > **Generation 1**.
5555

56-
1. Specify the memory allocation [according to your organization's needs](../ot-appliance-sizing.md), in standard RAM denomination (eg. 8192, 16384, 32768). Do not enable **Dyanmic Memory**.
56+
1. Specify the memory allocation [according to your organization's needs](../ot-appliance-sizing.md), in standard RAM denomination (eg. 8192, 16384, 32768). Do not enable **Dynamic Memory**.
5757

5858
1. Configure the network adaptor according to your server network topology. Under the "Hardware Acceleration" blade, disable "Virtual Machine Queue" for the monitoring (SPAN) network interface.
5959

@@ -81,7 +81,7 @@ This procedure describes how to create a virtual machine by using Hyper-V.
8181

8282
The VM will start from the ISO image, and the language selection screen will appear.
8383

84-
1. Continue with the [generic procedure for installing sensor software](../how-to-install-software.md#install-ot-monitoring-software).
84+
1. Continue with the [generic procedure for installing sensor software](../how-to-install-software.md).
8585

8686

8787

@@ -93,4 +93,4 @@ Then, use any of the following procedures to continue:
9393

9494
- [Purchase sensors or download software for sensors](../onboard-sensors.md#purchase-sensors-or-download-software-for-sensors)
9595
- [Download software for an on-premises management console](../how-to-manage-the-on-premises-management-console.md#download-software-for-the-on-premises-management-console)
96-
- [Install software](../how-to-install-software.md)
96+
- [Install OT monitoring software on OT sensors](../ot-deploy/install-software-ot-sensor.md)

articles/defender-for-iot/organizations/appliance-catalog/virtual-sensor-vmware.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ Before you begin the installation, make sure you have the following items:
2424

2525
- Available hardware resources for the virtual machine. For more information, see [OT monitoring with virtual appliances](../ot-virtual-appliances.md).
2626

27-
- The OT sensor software [downloaded from Defender for IoT in the Azure portal](../how-to-install-software.md#download-software-files-from-the-azure-portal).
27+
- The OT sensor software [downloaded from Defender for IoT in the Azure portal](../ot-deploy/install-software-ot-sensor.md#download-software-files-from-the-azure-portal).
2828

2929
- Traffic mirroring configured on your vSwitch. For more information, see [Configure traffic mirroring with a ESXi vSwitch](../traffic-mirroring/configure-mirror-esxi.md).
3030

@@ -68,7 +68,7 @@ This procedure describes how to create a virtual machine by using ESXi.
6868

6969
The VM will start from the ISO image, and the language selection screen will appear.
7070

71-
1. Continue with the [generic procedure for installing sensor software](../how-to-install-software.md#install-ot-monitoring-software).
71+
1. Continue with the [generic procedure for installing sensor software](../ot-deploy/install-software-ot-sensor.md).
7272

7373

7474
## Next steps

articles/defender-for-iot/organizations/faqs-ot.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@ For more information, see [Activate and set up your sensor](how-to-activate-and-
6161

6262
## How do I check the sanity of my deployment
6363

64-
After installing the software for your sensor or on-premises management console, you'll want to perform the [Post-installation validation](how-to-install-software.md#post-installation-validation).
64+
After installing the software for your sensor or on-premises management console, you'll want to perform the [Post-installation validation](ot-deploy/post-install-validation-ot-software.md).
6565

6666
You can also use our [UI and CLI tools](how-to-troubleshoot-the-sensor-and-on-premises-management-console.md#check-system-health) to check system health and review your overall system statistics.
6767

articles/defender-for-iot/organizations/how-to-activate-and-set-up-your-on-premises-management-console.md

Lines changed: 30 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -139,22 +139,22 @@ Ensure that sensors send information to the on-premises management console. Make
139139

140140
Two options are available for connecting Microsoft Defender for IoT sensors to the on-premises management console:
141141

142-
- Connect from the sensor console.
143-
- Connect by using tunneling.
142+
- [Connect from the sensor console](#connect-sensors-to-the-on-premises-management-console-from-the-sensor-console)
143+
- [Connect sensors by using tunneling](#connect-sensors-by-using-tunneling)
144144

145-
After connecting, you must set up a site with these sensors.
145+
After connecting, you must [set up a site](#set-up-a-site) with these sensors.
146146

147147
### Connect sensors to the on-premises management console from the sensor console
148148

149-
To connect sensors to the on-premises management console from the sensor console:
149+
**To connect sensors to the on-premises management console from the sensor console**:
150150

151-
1. On the on-premises management console, select **System Settings**.
151+
1. In the on-premises management console, select **System Settings**.
152152

153153
1. Copy the string in the **Copy Connection String** box.
154154

155155
:::image type="content" source="media/how-to-manage-sensors-from-the-on-premises-management-console/connection-string.png" alt-text="Screenshot that shows copying the connection string for the sensor.":::
156156

157-
1. On the sensor, go to **System Settings** and select **Connection to Management Console** :::image type="icon" source="media/how-to-manage-sensors-from-the-on-premises-management-console/connection-to-management-console.png" border="false":::
157+
1. On the sensor, go to **System Settings** > **Connection to Management Console**.
158158

159159
1. Paste the copied connection string from the on-premises management console into the **Connection string** box.
160160

@@ -164,55 +164,55 @@ To connect sensors to the on-premises management console from the sensor console
164164

165165
### Connect sensors by using tunneling
166166

167-
Enable a secured tunneling connection between organizational sensors and the on-premises management console. This setup circumvents interaction with the organizational firewall. As a result, it reduces the attack surface.
167+
Enhance system security by preventing direct user access to the sensor. Instead of direct access, use proxy tunneling to let users access the sensor from the on-premises management console with a single firewall rule. This technique narrows the possibility of unauthorized access to the network environment beyond the sensor. The user's experience when signing in to the sensor remains the same.
168168

169169
Using tunneling allows you to connect to the on-premises management console from its IP address and a single port (9000 by default) to any sensor.
170170

171-
:::image type="content" source="media/how-to-activate-and-set-up-your-on-premises-management-console/tunneling-diagram.png" alt-text="Screenshot that shows a tunneling diagram for connecting sensors to the on-premises management console.":::
171+
For example, the following image shows a sample architecture where users access the sensor consoles via the on-premises management console.
172172

173-
To set up tunneling at the on-premises management console:
173+
:::image type="content" source="media/tutorial-install-components/sensor-system-graph.png" alt-text="Screenshot that shows access to the sensor." border="false":::
174174

175-
1. Sign in to the on-premises management console and run the following command:
175+
**To set up tunneling at the on-premises management console**:
176+
177+
1. Sign in to the on-premises management console's CLI with the *cyberx* or the *support* user credentials and run the following command:
176178

177179
```bash
178-
cyberx-management-tunnel-enable
180+
sudo cyberx-management-tunnel-enable
179181

180182
```
181183

184+
For more information on users, see [Default privileged on-premises users](roles-on-premises.md#default-privileged-on-premises-users).
185+
182186
1. Allow a few minutes for the connection to start.
187+
188+
When tunneling access is configured, the following URL syntax is used to access the sensor consoles: `https://<on-premises management console address>/<sensor address>/<page URL>`
183189

184190
You can also customize the port range to a number other than 9000. An example is 10000.
185191

186-
To use a new port:
187-
188-
1. Sign in to the on-premises management console and run the following command:
192+
**To use a new port**:
189193

190-
```bash
191-
sudo cyberx-management-tunnel-enable --port 10000
192-
193-
```
194+
Sign in to the on-premises management console and run the following command:
194195

195-
1. Disable the connection, when required.
196+
```bash
197+
sudo cyberx-management-tunnel-enable --port 10000
198+
199+
```
196200

197-
To disable:
201+
**To disable the connection**:
198202

199203
Sign in to the on-premises management console and run the following command:
200204

201-
```bash
202-
cyberx-management-tunnel-disable
205+
```bash
206+
cyberx-management-tunnel-disable
203207
204-
```
208+
```
205209

206210
No configuration is needed on the sensor.
207211

208-
To view log files:
209-
210-
Review log information in the log files.
211-
212-
To access log files:
212+
**To access the tunneling log files**:
213213

214-
1. Sign in to the on-premises management console and go to */var/log/apache2.log*.
215-
1. Sign in to the sensor and go to */var/cyberx/logs/tunnel.log*.
214+
1. **From the on-premises management console**: Sign in and go to */var/log/apache2.log*.
215+
1. **From the sensor**: Sign in and go to */var/cyberx/logs/tunnel.log*.
216216

217217
## Set up a site
218218

0 commit comments

Comments
 (0)