F5 BIG-IP

IBM® QRadar® Risk Manager 는 F5 BIG-IP 어댑터를 지원합니다.

F5 BIG-IP 어댑터로 다음 기능을 사용할 수 있습니다.
  • 인접 항목 데이터 지원
  • 동적 NAT
  • 정적 NAT
  • SNMP 감지
  • 정적 라우팅

LTM(Local Traffic Manager)을 실행하는 F5 BIG-IP 로드 밸런서 어플라이언스는 지원됩니다.

다음 표에는 F5 BIG-IP 어댑터에 대한 통합 요구사항이 설명되어 있습니다.

표 1. F5 BIG-IP 어댑터에 대한 통합 요구사항
통합 요구사항 설명

버전

10.1 - 13.1

SNMP 감지

1.3.6.1.4.1.3375.2 를 포함하는 sysOid 의 F5 BIG-IP와 일치합니다.

필요한 신임 정보 매개변수

QRadar에 신임 정보를 추가하려면 관리자로 로그인하고 위험 탭에서 구성 모니터 를 사용하십시오.

username

비밀번호

지원되는 연결 프로토콜

QRadar에서 프로토콜을 추가하려면 관리자로 로그인하고 위험 탭에서 구성 모니터 를 사용하십시오.

SSH

버전 10 (Bigpipe) 백업 명령
참고: 버전 10에서 어댑터는 Bigpipe 명령을 전송합니다. 버전 11이상에서 어댑터는 tmsh 명령을 전송합니다.

bigpipe global

bigpipe system hostname

bigpipe platform

uptime

bigpipe version show

cat /config/bigip.license

bigpipe db packetfilter

bigpipe db packetfilter.defaultaction

bigpipe packet filter list

bigpipe nat list all

bigpipe vlan show all

bigpipe vlangroup list all

bigpipe vlangroup

ip addr list

bigpipe interface show all

bigpipe interface all media speed

bigpipe trunk all interfaces

route -n

bigpipe route all list all

bigpipe mgmt show all

bigpipe mgmt route show all

bigpipe pool

bigpipe self

bigpipe virtual list all

bigpipe snat list all

bigpipe snatpool list all

b db snat.anyipprotocol

버전 11이상 (tmsh) 백업 명령
참고: 버전 10에서 어댑터는 Bigpipe 명령을 전송합니다. 버전 11이상에서 어댑터는 tmsh 명령을 전송합니다.

list sys global-settings hostname

list sys management-ip

show sys memory

show sys hardware

show sys version

list sys db packetfilter

list sys db packetfilter.defaultaction

list sys db snat.anyipprotocol

list net interface all-properties

list net trunk

list net packet-filter

list net vlan all-properties

show net vlan

list net vlan-group all all-properties

show net vlan-group

list ltm virtual

list ltm nat

list ltm snatpool

list ltm snat

list net route

list ltm pool

list net self

list net ipsec

list net tunnels