Key Concepts
- Falcon Sensor: A security agent installed on endpoints to monitor and protect them.
- Big IP: A network device, often a load balancer or application delivery controller, manufactured by F5 Networks.
- Customer ID: A unique identifier required for the Falcon sensor installer.
- Bash Prompt: A command-line interface used in Unix-like operating systems.
- Tag: A label used to identify and categorize specific devices or sensors.
- Falcon Console: The web-based interface for managing Falcon sensors and policies.
- Host Groups: A feature in the Falcon console to organize and manage groups of hosts.
- Assignment Rule: A rule used to automatically assign hosts to specific host groups based on defined criteria (e.g., tags).
- Prevention Policy: A set of security configurations applied to sensors to dictate their behavior and protection levels.
- Content Update Policy (Sensor Update Policy): A policy that controls how and when the Falcon sensor agent is updated.
- Early Access Program (EAP): A program for testing new features or products before their general release.
Falcon Sensor Installation on Big IP
This video details the process of installing the Falcon sensor on a Big IP device. The installation involves several key steps, from obtaining necessary credentials to configuring the sensor's behavior within the Falcon console.
1. Pre-installation Steps
- Obtain Customer ID: The first step is to navigate to the "D sensor downloads" section to retrieve the customer ID. This ID is crucial for the installer to authenticate and register the sensor with the Falcon platform.
- File Transfer: The installer files need to be copied from the local machine to the Big IP device.
2. Running the Installer
- Access Bash Prompt: The installation is executed from the bash prompt on the Big IP device.
- Locate Installer Scripts: Within the transferred files, there are scripts for installation and uninstallation. The video highlights the presence of an
installerscript and anuninstallscript. - Execute Installer:
- Navigate to the directory containing the scripts using the
cdcommand. - Run the
installerscript. - The installer requires the
customer ID(CD) as an argument. - A
tagmust also be provided as an argument. This tag is used for later identification and configuration of the sensor in the Falcon console. The example tag used is "F5 big IPVE".
- Navigate to the directory containing the scripts using the
3. Falcon Console Configuration
Once the sensor is installed on the Big IP device, configuration is managed through the Falcon console.
-
Host Management and Detection:
- After installation, the Big IP host should be detected in the Falcon console under "Host Management."
- Initially, the host might not be part of any specific host group and will inherit default settings.
-
Creating a Host Group:
- A new host group is created to specifically manage Big IP devices.
- Naming: The host group is named "big IPVE" in this example.
- Assignment Rule: An assignment rule is created to automatically add Big IP devices to this group.
- Filter: The rule uses a filter based on the tag applied during installation. In this case, the filter is set to match the "F5 big IPVE" tag.
- Application: The rule is applied, and the host group is updated to include this assignment logic.
-
Assigning a Prevention Policy:
- A prevention policy defines the security settings and behaviors of the Falcon sensor.
- Policy Naming: A policy named "big IP EAP" is created.
- Policy Source: The video mentions that these settings are derived from a KB article and that users should refer to current documentation, especially as this feature might be part of an Early Access Program (EAP). Users are advised to check comments for the latest settings.
- Saving and Enabling: The policy is saved and then enabled.
- Assigning Policy to Group: The "big IP EAP" prevention policy is then assigned to the "big IPVE" host group.
-
Configuring Sensor Update Policy:
- The "Content Update Policy" (also referred to as "Sensor Update Policy") is configured to control agent updates.
- Purpose: During the EAP phase, it's important to ensure manual updates of the sensor agent.
- Policy Naming: A policy named "no updates for big IP" is created.
- Default Setting: The default setting for this policy is to not perform any automatic updates, which aligns with the requirement for manual updates during EAP.
- Assignment: This update policy is assigned to the "big IPVE" host group and then enabled.
4. Verification
- Host View Update: After completing the configuration, returning to the host view in the Falcon console will show that the Big IP host has now been assigned to the "big IPVE" host group.
Conclusion
The installation and configuration process for the Falcon sensor on Big IP devices involves obtaining credentials, running an installer script with specific arguments (customer ID and tag), and then leveraging the Falcon console to create host groups, assignment rules, prevention policies, and sensor update policies. These configurations ensure that the sensor is correctly identified, managed, and secured according to specific requirements, particularly during early access phases.
AI summaries can miss context or contain errors. Check important details against the original video.





