{"id":36669,"date":"2019-10-31T22:13:01","date_gmt":"2019-10-31T19:13:01","guid":{"rendered":"https:\/\/prohoster.info\/blog\/stealthwatch-razvertyvanie-i-nastrojka-chast-2\/"},"modified":"2019-10-31T22:13:01","modified_gmt":"2019-10-31T19:13:01","slug":"stealthwatch-razvertyvanie-i-nastrojka-chast-2","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-razvertyvanie-i-nastrojka-chast-2","title":{"rendered":"StealthWatch: deployment and configuration. Part 2","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/6d2c187b799a2f811e24d36e2ab48c77.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nHello, colleagues! Having defined the minimum requirements for deploying StealthWatch in <noindex><a rel=\"nofollow\" href=\"http:\/\/habr.com\/ru\/company\/tssolution\/blog\/458626\/\">the previous part<\/a><\/noindex>, we can begin product deployment.<\/p>\n<h3>1. Methods of deploying StealthWatch<\/h3>\n<p>\nThere are several ways to 'touch' StealthWatch: <\/p>\n<ul>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/dcloud.cisco.com\/\">dcloud<\/a><\/noindex> \u2013 cloud-based lab service;<\/li>\n<li>Cloud Based: <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cisco.com\/c\/en\/us\/products\/security\/stealthwatch\/security-visibility-assessment.html\">Stealthwatch Cloud Free Trial <\/a><\/noindex> \u2013 here, Netflow from your device will flow into the cloud and will be analyzed by StealthWatch software there; <\/li>\n<li>On-premise POV (<noindex><a rel=\"nofollow\" href=\"https:\/\/cep.cloudapps.cisco.com\/case\">GVE request<\/a><\/noindex>) \u2013 the approach I took, you will receive 4 OVF files of virtual machines with built-in licenses for 90 days, which can be deployed on a dedicated server in your corporate network. <\/li>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nDespite the multitude of downloaded virtual machines, only 2 are sufficient for a minimal working configuration: StealthWatch Management Console and FlowCollector. However, if there is no network device that can export Netflow to FlowCollector, then you also need to deploy FlowSensor, as the latter allows collecting Netflow using SPAN\/RSPAN technologies.<\/p>\n<p>As a lab setup, as I mentioned earlier, your actual network can serve since StealthWatch only requires a copy, or more precisely, a distilled copy of the traffic. In the illustration below, my network is presented, where I will configure a Netflow Exporter on the security gateway, and as a result, I will be sending Netflow to the collector.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/b82e6d6e7b229ebfa3e31b5a47292f25.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nTo access the future VMs, on your firewall, if you have one, you should allow the following ports:<\/p>\n<p><b> TCP 22 l TCP 25 l TCP 389 l TCP 443 l TCP 2393 l TCP 5222 l UDP 53 l UDP 123 l UDP 161 l UDP 162 l UDP 389 l UDP 514 l UDP 2055 l UDP 6343 <\/b><\/p>\n<p>Some of these are well-known services, while some are reserved for Cisco services.<br \/>\nIn my case, I simply deployed StealthWatch in the same network as Check Point, and no rules had to be configured.<\/p>\n<h3>2. Installing FlowCollector using VMware vSphere<\/h3>\n<p>\n2.1. Click Browse and select the OVF file. After confirming resource availability, go to the menu View, Inventory \u2192 Networking (Ctrl+Shift+N).<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/4533c23d8b9b65163f9f426d25ce3215.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.2. In the Networking tab, select New Distributed port group in the virtual switch settings.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/26bec9aa59a409f6fd58aef93f685d26.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.3. Assign a name, let's call it StealthWatchPortGroup, the other settings can be made as shown in the screenshot, and click Next.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/1b5f9225675eefb37a8be070cb12dbe0.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/c24f649de31b1d55cf9ac97d6321a8c1.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.4. Complete the creation of the Port Group by clicking Finish.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/4dcd93fc9054f908b3ce69d10538e260.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.5. For the created Port Group, edit the settings by right-clicking on the port group and selecting Edit Settings. In the Security tab, be sure to enable 'promiscuous mode', Promiscuous Mode \u2192 Accept \u2192 OK.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/b7792f5e3c2dad347db252588ae7447e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.6. As an example, we will import the OVF FlowCollector, the download link for which was sent by a Cisco engineer after the GVE request. Right-click on the host where you plan to deploy the VM and choose Deploy OVF Template. Regarding the allocated space, it will run with 50 GB, but for production conditions, it is recommended to allocate around 200 GB.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/000e3a98673b2577f33c0e5fc2913704.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.7. Select the folder where the OVF file is located.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/855a4dfcb92bb41912d059bfedd3e98a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.8. Click 'Next'.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/adc372dd2e4df3b75724f6146771e800.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.9. Specify the name and the server where we are deploying this.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/abdb25ced5addf714adf07898541b0b6.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.10. As a result, we get the following screen and click 'Finish'.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/eef848e4998de5bab0e0dc3845466134.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.11. Repeat the same steps to deploy the StealthWatch Management Console.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/33010b6a604071f68300fb31b951ea71.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n2.12. Now, specify the necessary networks in the interfaces so that the FlowCollector can see both SMC and the devices from which NetFlow will be exported. <\/p>\n<h3>3. Initializing StealthWatch Management Console<\/h3>\n<p>\n3.1. Once you access the console of the installed SMCVE machine, you will see a place to enter the username and password, which by default is <b>sysadmin\/lab1cope<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/898a885324fd1a5542a94fb40e1f79f8.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n3.2. Go to the Management section, set the IP address and other network parameters, then confirm the changes. The device will reboot.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/5f7d56d1f108afa873aa370f87a55d0b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/76a90cf85e51c9aea91d8b738d0de775.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/a9af327e6449932d0f88f05f31f5601e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n3.3. Navigate to the web interface (using HTTPS at the address assigned to SMC) and initialize the console; the default username\/password is <b>admin\/lab411cope<\/b>. <\/p>\n<p>P.S.: Sometimes it won't open in Google Chrome, but Explorer will always work.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/a0eb07f52f4080c4fba42df214283dc7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n3.4. Be sure to change the passwords, set the DNS, NTP servers, domain, and other settings. The settings are intuitive. <\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/d3de68f5f828022df4ef493c8ee91fac.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n3.5. After clicking the 'Apply' button, the device will reboot again. After 5-7 minutes, you can reconnect to this address; StealthWatch management will be done via the web interface.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/f22752b76ddb46d7262fd3b3999fac2b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>4. Configuring FlowCollector<\/h3>\n<p>\n4.1. The process for the collector is the same. First, in the CLI, specify the IP address, mask, domain, then the FC will reboot. After that, you can connect to the web interface at the specified address and conduct the same basic setup. Due to the similarity of settings, detailed screenshots are omitted. <b>Credentials<\/b> for access <b>the same<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/9753ff123a18d6fc7c26a41be71515f0.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n4.2. In the penultimate step, it is necessary to specify the SMC IP address; in this case, the console will be able to see the device, and you will have to confirm this setting by entering the credentials.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/0c8504533a1f70475fed8e061bc9f584.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n4.3. Choose the domain for StealthWatch, which was set earlier, and the port <b>2055 <\/b>\u2013 standard NetFlow, if you are working with sFlow, the port <b>6343<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/6ac15c0eaf9097a2d66bbc54769055a7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>5. NetFlow Exporter Configuration<\/h3>\n<p>\n5.1. For configuring the NetFlow exporter, I highly recommend referring to this <noindex><a rel=\"nofollow\" href=\"http:\/\/configurenetflow.info\">resource <\/a><\/noindex>, here are the main guides for configuring the Netflow exporter for many devices: Cisco, Check Point, Fortinet. <\/p>\n<p>5.2. In our case, I repeat, we are exporting Netflow from the Check Point gateway. The configuration of the Netflow exporter is done in a similarly named tab in the web interface (Gaia Portal). To do this, you need to click 'Add', specify the Netflow version, and the required port. <\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/d3544d986d85aea336081d3fc207c553.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>6. Analyzing StealthWatch's operation<\/h3>\n<p>\n6.1. By going to the SMC web interface, on the first page Dashboards &gt; Network Security, you can see that the traffic has started!<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/8e7d65efd8b212096f447dd2828f68f1.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n6.2. Some settings, such as grouping hosts, monitoring individual interfaces, their load, managing collectors, and others can only be found in the StealthWatch Java application. Naturally, Cisco is gradually transferring all functionality to the browser version, and soon we will part with this desktop client.<\/p>\n<p>To install the application, you first need to install <noindex><a rel=\"nofollow\" href=\"https:\/\/www.oracle.com\/technetwork\/java\/javase\/downloads\/jre8-downloads-2133155.html\">JRE <\/a><\/noindex>(I installed version 8, although it is said to support up to 10) from the official Oracle website.<\/p>\n<p>In the top right corner of the web management console, to download you need to click the 'Desktop Client' button.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/6345b6eb1606d219bbaf65f73b196446.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nYou manually save and install the client; Java will most likely complain about it, and you may need to add the host to the Java exceptions.<\/p>\n<p>As a result, you have a fairly user-friendly client that easily shows the load of exporters, interfaces, attacks, and their flows.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/d5742de9c3d3792c308f34f2a6c87839.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/ca3c8d53a56d6c0e8fac12eb4c263096.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/56ba3458be8c6f50929a1008d30f4412.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h3>7. StealthWatch Central Management<\/h3>\n<p>\n7.1. In the Central Management tab are all devices that are part of the deployed StealthWatch, such as: FlowCollector, FlowSensor, UDP-Director, and Endpoint Concentrator. Here you can manage network settings and services of devices, licenses, and manually turn off devices.<\/p>\n<p>You can access it by clicking on the 'gear' in the top right corner and selecting Central Management. <\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/86c411fef0ec8eb0f1941cd4aa2b8c41.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/1ff2e89817e47ac38fc141f9fe82674a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n7.2. By going to Edit Appliance Configuration for the FlowCollector, you will see SSH settings, NTP, and other network settings related to the appliance. To access it, select Actions \u2192 Edit Appliance Configuration for the required device.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/1b1d27c3238f47a9fe4e0190ddf4e8a0.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/78be8a43bbbefee502fbbf1e398c6f5e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/15a8b2d77ffba34be2d5ae876a20cf61.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n7.3. License management can also be found in the Central Management &gt; Manage Licenses tab. Trial licenses in the case of GVE requests are given for <b>90 days.<\/b>.<\/p>\n<p><img decoding=\"async\" alt=\"StealthWatch: deployment and configuration. Part 2\" src=\"\/wp-content\/uploads\/2019\/07\/56b02e7921a94b51b8d2a9a9dea40a16.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe product is ready for use! In the next part, we will look at how StealthWatch can detect attacks and generate reports.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/461831\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0417\u0434\u0440\u0430\u0432\u0441\u0442\u0432\u0443\u0439\u0442\u0435, \u043a\u043e\u043b\u043b\u0435\u0433\u0438! \u041e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0432\u0448\u0438\u0441\u044c \u0441 \u043c\u0438\u043d\u0438\u043c\u0430\u043b\u044c\u043d\u044b\u043c\u0438 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u0434\u043b\u044f \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f StealthWatch \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0447\u0430\u0441\u0442\u0438, \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043d\u0430\u0447\u0430\u0442\u044c \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u0435 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u0430. 1. \u0421\u043f\u043e\u0441\u043e\u0431\u044b \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u044f StealthWatch \u0421\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u0435\u0442 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u00ab\u043f\u043e\u0442\u0440\u043e\u0433\u0430\u0442\u044c\u00bb StealthWatch: dcloud \u2013 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0439 \u0441\u0435\u0440\u0432\u0438\u0441 \u043b\u0430\u0431\u043e\u0440\u0430\u0442\u043e\u0440\u043d\u044b\u0445 \u0440\u0430\u0431\u043e\u0442; Cloud Based: Stealthwatch Cloud Free Trial \u2013 \u0437\u0434\u0435\u0441\u044c Netflow \u0441 \u0432\u0430\u0448\u0435\u0433\u043e \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430 \u043f\u043e\u0441\u044b\u043f\u0435\u0442\u0441\u044f \u0432 \u043e\u0431\u043b\u0430\u043a\u043e \u0438 \u0431\u0443\u0434\u0435\u0442 \u0442\u0430\u043c \u0430\u043d\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u041f\u041e StealthWatch; On-premise POV [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":27463,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-36669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0417\u0434\u0440\u0430\u0432\u0441\u0442\u0432\u0443\u0439\u0442\u0435, \u043a\u043e\u043b\u043b\u0435\u0433\u0438!\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-razvertyvanie-i-nastrojka-chast-2\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47StealthWatch: \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u0435 \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430. \u0427\u0430\u0441\u0442\u044c 2 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0417\u0434\u0440\u0430\u0432\u0441\u0442\u0432\u0443\u0439\u0442\u0435, \u043a\u043e\u043b\u043b\u0435\u0433\u0438!\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-razvertyvanie-i-nastrojka-chast-2\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:13:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:13:01+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47StealthWatch: deployment and configuration. Part 2 | ProHoster","description":"Hello, colleagues!","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-razvertyvanie-i-nastrojka-chast-2","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47StealthWatch: \u0440\u0430\u0437\u0432\u0435\u0440\u0442\u044b\u0432\u0430\u043d\u0438\u0435 \u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0430. \u0427\u0430\u0441\u0442\u044c 2 | ProHoster","og:description":"\u0417\u0434\u0440\u0430\u0432\u0441\u0442\u0432\u0443\u0439\u0442\u0435, \u043a\u043e\u043b\u043b\u0435\u0433\u0438!","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/stealthwatch-razvertyvanie-i-nastrojka-chast-2","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:13:01+00:00","article:modified_time":"2019-10-31T19:13:01+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36669","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 04:21:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 17:18:11","updated":"2026-01-22 04:21:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=36669"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36669\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/27463"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=36669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=36669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=36669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}