Contents
-
Introducing Tachyon Platform
-
Quick Start
-
Implementing Tachyon Platform
-
Using consumer applications
-
Using Settings
-
Using Inventory
-
Troubleshooting
-
Extending Tachyon
-
Training
-
Tachyon v5.2 - Install and Configure - Lab Guide
-
Tachyon v5.2 - AppClarity Training
-
Tachyon v5.2 - Application Migration Training
-
Tachyon v5.2 - Using - Using Experience - Lab Guide
-
Tachyon v5.2 - Using - Using Explorer - Lab Guide
-
Ex 1 - Tachyon v5.2 - Using - Using Explorer - The Tachyon Exchange
-
Ex 2 - Tachyon v5.2 - Using - Using Explorer - Run Verification Instructions
-
Ex 3 - Tachyon v5.2 - Using - Using Explorer - Assign Locations
-
Ex 4 - Tachyon v5.2 - Using - Using Explorer - Device Criticality
-
Ex 5 - Tachyon v5.2 - Using - Using Explorer - Assign Tags
-
Ex 6 - Tachyon v5.2 - Using - Using Explorer - Quarantine a Device
-
Ex 7 - Tachyon v5.2 - Using - Using Explorer - The Device View
-
Ex 1 - Tachyon v5.2 - Using - Using Explorer - The Tachyon Exchange
-
Tachyon v5.2 - Using - Using Guaranteed State - Lab Guide
-
Tachyon v5.2 - Using - Using Inventory - Lab Guide
-
Tachyon v5.2 - Using - Using Patch Success - Lab Guide
-
Tachyon v5.2 - Using - Using TIMS - Lab Guide
-
Tachyon Advanced v5.2 Lab Guide
-
Tachyon v5.2 - Using - Application Programming Interface Lab Guide
-
Tachyon - Nomad as Content Provider Lab Guide
-
Tachyon v5.2 - Install and Configure - Lab Guide
-
Reference
Working with Quarantine
In the event of a security breach, Tachyon can quarantine devices. This will cut off the device from all network traffic except for the Tachyon Switch. This can contain an outbreak while the device is remediated. In this exercise, we will target a specific system and quarantine it. We with then remove it from quarantine.
Checking Quarantine State
- Logged into 1ETRNW102 as 1ETRN\Tachyon_AdminPP
- Open Google Chrome and Navigate to the Explorer Application
- From the Home screen click All Instructions
- Expand Quarantine
- Click Are my devices quarantined?
- Click Ask this question
- This is a simple query to see if the devices are actually quarantined. As you can see none of our devices are in quarantine
Quarantine a Device
In this task we are going to quarantine 1ETRNW72
- Navigate to Explorer application – Home screen
- In the I want to know field type in Quarantine
- Click on Quarantine Selected Devices. Click Edit on parameters
- Click coverage
- Expand Device. Choose = in the first field and type in 1ETRNW72.1ETRN.local in the second field
- Click Set
- Click Perform this Action
- Type in your Password
- Open LiveMail and enter your authentication code
- Open LiveMail and Launch the Notification Page or refresh Chrome and navigate to Notifications
- Approve the Request
Checking the Quarantined Device
- In the Explorer application check the results from the instruction
- Notice there is now 1 device quarantined
- Click on Quarantined in Status and see the device name
- Launch a Command Prompt and type in ping 1etrnw72. Your request will time out without a response
- Launch a command prompt and ping 1ETRNDC
- Ping 1ETRNCM
- Ping Tachyon (our alias for 1ETRNAP)
- Launch a new browser window and navigate to Google.com
- Notice that our device cannot get to other devices or the internet
Removing a Device from Quarantine
Now we will issue the instruction that will remove the device from quarantine. The device can only communicate with the Tachyon Switch at this time.
- Still logged in as 1ETRN\Tachyon_Admin1
- Open Google Chrome – the Explorer Application should still be open
- Navigate to Home and in the I want to know field type in Quaran and Select Releases Selected devices from Quarantine
- Click Edit on the Parameters
- Expand Coverage – Expand Device
- In the contains field select =
- In the next field type in 1ETRNW72.1ETRN.Local click Set
- Type in the entire FQDN or the instruction will fail
- Click Perform this action
- Type in Passw0rd and click Confirm and Send
- Open LiveMail and copy the authentication code for Instruction X
- Paste the code into the Authentication Code box. Click Submit
- Still logged in as 1ETRN\Tachyon_AdminG
- Open Chrome and refresh the page
- In the Explorer Application navigate to Notifications
- Approve Instruction X from above
- In the Explorer Application – Navigate to Instructions – History
- Select our Releases selected devices from quarantine
- Wait for this one to complete
- Move back to Instructions – History. Select Are my devices quarantined?
- Rerun this instruction
- Wait for it to complete and see that all 7 devices are now NotQuarantined
- Open a command prompt and Ping 1ETRNW72. Device should respond
- Ping any of the other devices in the lab
- Browse to the Internet
- The device should be able to get to the internet
Lab Summary
In this lab, We learned how to use Quarantine to help us remediate security issues and prevent further spread.
Next Page
Ex 7 - Tachyon v5.2 - Using - Using Explorer - The Device View