IBM Support

QRadar: How to disable or enable remote tunnel initiation

How To


Summary

The remote tunnel initiation is used with SSH tunnels to allow a remote host to communicate with a local host when the connection is not bidirectional. For example, when a firewall denies communication from an Event Collector to an Event Processor but allows communication from the Event Processor to the Event Collector.

Objective

Disable or enable the remote tunnel initiation feature of QRadar.

Steps

Note: Enabling remote tunnel initiation for a firewall block is a work around and is not a substitute for network admins updating the firewall to allow connection from the Console. These steps are primarily used for when the server is owned by a tenant then the tenant machine creates the connection so they maintain control of the keys.

  1. Log in to the QRadar Console as an administrator.
  2. On the Admin tab, click System and License Management.
  3. Make sure that Display shows Systems.
    Display shows Systems
  4. Click the host to modify.
  5. Click Deployment Actions.
    Deployment actions
  6. Click Edit Host.
    Edit Host Connection
  7. Click the checkbox for Remote Tunnel Initiation to enable this feature. To disable it, uncheck the box.Remote Tunnel Initiation
    Note: The console should not have Encrypt Host Connection enabled unless specifically requested by support because it can prevent the console from communicating with other managed hosts.
  8. Click Save.
  9. Deploy the changes.

    Result
    After the deploy, remote tunnel initiation is enabled. For more information about SSH tunnels, see QRadar: What is a SSH tunnel?

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwtNAAQ","label":"Deployment"}],"ARM Case Number":"","Platform":[{"code":"PF016","label":"Linux"}],"Version":"All Versions"}]

Document Information

Modified date:
31 May 2023

UID

ibm16995695