Configuring Appliance connections

You are prompted to configure basic host and network settings when you complete the initial configuration. Use the Appliance Configuration menu to modify the configuration as necessary.

Changes to the network configuration do not go into effect until you restart network services. If you connect over a remote SSH connection and change the configuration for the interface with which you are connected, your SSH connection terminates.

Modify the host name and DNS configuration

Host, domain, DNS server, and /etc/hosts settings are configured during the initial setup. If necessary, you can use the Hostname/DNS Configuration menu to make changes.

Contact Tanium Support if you plan to change the Tanium Server host name.Tanium Support needs the new host name to update the Tanium license for you. For more information, see Support for Tanium Appliances.

Modify the host name

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-1 (Appliance Configuration > Hostname/DNS Configuration).

  3. Enter 1 and follow the prompts to change the host name, which must be a fully qualified domain name (FQDN). ClosedView screen

Modify the DNS server

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-1 (Appliance Configuration > Hostname/DNS Configuration).

  3. Enter 2 and follow the prompts to modify the DNS server configuration. ClosedView screen

Modify the hosts file

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-1 (Appliance Configuration > Hostname/DNS Configuration).

  3. Enter 3 and use the manual_hosts menu to update the /etc/hosts file. ClosedView screen

Modify the network interface configuration

Contact Tanium Support before changing the IP address for the interface used by the Tanium Server. The Tanium Server IP address is used in multiple configurations.

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-2-1 (Appliance Configuration > Networking > Network Interfaces).

  3. Enter the line number of the interface that you want to configure to go to the selected Network Interface menu. ClosedView screen
  4. Use the menu to change the IP address, MTU size, or up/down status.

Set up an IPsec tunnel

Use IPsec to ensure end-to-end security between two Tanium Server appliances. An IPsec tunnel is automatically configured when you install an Appliance Array.

  1. Start two SSH terminal sessions so you can copy and paste between them:
    • First Tanium Server appliance
    • Second Tanium Server appliance
  2. Sign in to each of the Tanium Server appliances as a user with the tanadmin role and enter A-2-2 (Appliance Configuration > Networking Configuration > IPSEC).
  3. On the second appliance, copy the IPsec host key to the clipboard:
    1. From the IPSEC menu, enter 1 to view the local IPsec host key. ClosedView screen
    2. Copy the key to the clipboard.
  4. On the first appliance, from the IPSEC menu, enter 3 and follow the prompts to configure this side of the IPsec tunnel. When prompted, paste the IPsec host key for the second appliance. ClosedView screen
  5. On the first appliance, copy the IPsec host key to the clipboard:
    1. From the IPSEC menu, enter 1 to view the local IPsec host key.
    2. Copy the key to the clipboard.
  6. Go to the second appliance and complete the IPsec configuration:
    1. From the IPSEC menu, enter 3 and follow the prompts to configure the IPsec tunnel on the second appliance. When prompted, paste the IPsec host key for the first appliance.
    2. Enter 6 to test the connection from the second appliance. ClosedView screen
  7. Go back to the first appliance and enter 6 to test the connection.

View the IPSEC configuration for an appliance

  1. Sign in to the appliance as a user with the tanadmin role.
  2. Enter A-2-2 (Appliance Configuration > Networking Configuration > IPSEC).

  3. Enter 2 to display the IPSEC configuration. ClosedView screen

Modify the routing configuration

You can add a static route, if necessary.

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-2-3 (Appliance Configuration > Networking > Routing).

  3. Use the menu to manage the routing table.

Configure NIC teaming

This procedure applies only to the physical Tanium Appliance.

Tanium™ Appliance supports active/passive network interface controller (NIC) teaming. Active/passive NIC teaming allows multiple interfaces to be placed in a group to support NIC failover. When you configure the NIC team, you must select interfaces of the same type.

Create NIC team

To create a NIC team, there must be two NICs available for teaming. If you have a physical Tanium Appliance, make sure to enable the tanremote user and configure the iDRAC interface.

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-2-T (Appliance Configuration > Networking > NIC Teaming).

  3. Enter A and follow the prompts to create the NIC team configuration.

When you create a NIC team, the system automatically assigns a MAC address from one of the NICs to the team. The NIC Teaming menu displays the details for each NIC team, including the assigned MAC address.

Manage NIC team

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-2-T (Appliance Configuration > Networking > NIC Teaming).

  3. Enter the line number of the NIC team that you want to manage.
  4. Use the NIC Team menu to change the IP address, delete the NIC team, or view the status. ClosedView screen

Modify the NTP configuration

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A-3 (Appliance Configuration > NTP Configuration).

  3. Enter the line number of the existing NTP server to modify or remove, or enter A to add a new NTP server.
  4. Follow the prompts to add, modify, or remove the NTP server. To add or modify an NTP server, enter the NTP server address and whether the server requires authentication. If the NTP server requires authentication, enter the NTP key ID, NTP key type, and NTP key at the prompts.
  5. Enter yes to save changes and restart the NTP server.

Change from a static IP address to DHCP (virtual Tanium Appliance only)

  1. Sign in to the TanOS console as a user with the tanadmin role.
  2. Enter A (Appliance Configuration).

  3. Enter 7 and follow the prompts to use DHCP.