      Just going through the ESM Installation Guide (v9.3.0), and wondering what the purpose of some of the ports are, as the network interface configuration steps (p22) for the ERC refer to Mgt1 only, and make no reference to the others at all.


      From what I can see from fig2-2 (p14) and fig 2-10 (p18), we have:


      PortNameUse (non HA)Use (HA)
      1IPMI<not used>Connected directly to peer 1250 port 4 (IPMI NIC)
      2Mgmt 2Data source feed?Data source feed. Local and Shared IP configured.
      3Mgmt 1management interface - main comms (ESM, DNS, NTP, Call Home, SNMP, SSH for command line)management interface - main comms as per non-HA. Local and Shared IP configured.
      4IPMI NIC<not used>Connected directly to peer 1250 port 1 (IPMI)
      5HB<not used>Hearbeat port - connected directly to peer port 5 (HB)
      6Mgmt 3<not used><not used>
      7Mgmt 4<not used><not used>


      Note that figure 2-10 looks to be mis-labelled as it has two 'Mgmt2' ports...  I assume fig2-10 is meant to read '6 Mgmt3, 7 Mgmt4'?


      Few questions:

      - As Mgmt 2 isnt identified as being related to data sources in fig2-2, is the above table correct?  Do you need to use Mgmt1 for both general management and data source feeds in a non-HA setup?

      - As steps to configure Mgmt1 only are included in the installation guide, is Mgmt2 only configurable via ESM when the ERC is a keyed device, or can Mgmt2 also be configured locally on the appliance?

      - Are Mgmt3 and Mgmt4 disabled / reserved for future use?  Connected to some iLO type functionality? McAfee SB10049 refers to vulns related to BMC/RMM3?

      - Can the data source feed (mgmt2) NICs be on the same VLAN as the management (mgmt1) NICs?  Not something I would neccessarily design, but just asking!


          Similar questions around X6/3450/similar appliances here


            To assist anybody who is wondering about similar questions, I have had recent discussions with McAfee and:


            - Mgmt 1 is used for all inbound and outbound communications with the other SIEM components, as well as GUI/console access.  Mgmt 2 can be reconfigured to accept connections to the GUI if needed.

                 - After the above response, clarification was received to advise: You can use both Mgmt 1 and Mgmt 2 for communicating with devices (only Mgmt 1 is used out of the box).  Main issue is routing, as static routes will need to be configured (not confirmed, but I believe this would need to be via the CLI as root - and there is no [current] guarantee that those static routes would remain if updates/upgrades carried out.  Need to confirm if this is formally supported)

            - Mgmt 3 and Mgmt 4 are not currently used, and any future use for them has not yet been defined




            - As of 9.3.2, a NIC bonding feature has been added, allowing the same IP to be added to Mgmt 1 and Mgmt 2 if they are connected to two separate switches, allowing for switch redundancy.  Need to confirm if this can be used for link aggregation (related, but different)

              So you could use the Mgmt 2 port to plug in an IP KVM? Or would you use 3 or 4 for that?

                As I cannot edit my post from May 12, please be advised that the information in that reply pertains to the ESM/ETM, and not the ERC (the ERC obviously does not have a GUI!).


                In response to above,

                For a KVM, I believe that as of release 9.4, RMM3 / IPMI functionality will be available on all appliances (not sure of which port will be used however) - I think that the hardware already exists in the appliances, just hasnt been enabled for this purpose pre-9.4.  For pre9.4, an IP KVM will be connected to the appliances as any KVM would be - the IP connection is made to the IP KVM, and the KVM is connected to the monitor and keyboard connectors on the appliance.


