3-1. Please tell me the specifications of the LED on the Nano's top panel.
There are two LEDs on the top panel of Nano (NSK-NANO-BB0AX) and Nano(V) (NSK-NANO-VB0AX, NSK-NANO-VB4AX).
The "Status 1" LED on the left is green, and the "Status 2" LED on the right is red.
The LEDs indicate the following operations depending on their lighting status.
|
Status1 LED (green) |
Status2 LED (red) |
Operating status |
Startup |
■On |
■On |
System initializing |
■■Blinking |
■off |
Sensor function startup processing |
■■Blinking |
■On |
Fatal Error during the sensor function startup process |
Running |
■On |
■Off |
Operating normally |
Shutdown |
■■■Blinking |
■■■Blinking |
Recognises that the Reset button has been pressed |
■■■Blinking |
■Off |
Shutdown processing |
■Off |
■Off |
Shutdown completed
(The AC adaptor can be safely disconnected) |
Initialize |
■Off |
■■■Blinking |
Recognises that the Reset button has been pressed twice |
■Off |
■■Blinking |
Initialization in progress (automatic reboot after completion) |
Update |
■■blinking |
■On |
Firmware update failed
(only lights on for 60 seconds) |
3-2. Please tell me how to turn off the Nano.
To turn off Nano, operate the Reset button on the main unit or shut it down from the WebUI.
When turning off the power using the Reset button:
- Press and hold the Reset button for more than 5 seconds.
- Release the Reset button after both the Status1 LED (green) and Status2 LED (red) starts blinking.
- The Status1 LED (green) starts blinking and the shutdown process will begin.
- When both the Status1 LED (green) and the Status2 LED (red) are off, shutdown is complete. Finally, disconnect the AC adapter.
When turning off the power from the settings web page:
- Click "Nano Setting/Network Setting" in "Nano Management".
- Click "System Management" on the menu.
- Click the "Shutdown" button in System Shutdown.
3-3. What is safe mode?
Safe mode is the mode that Nano is in after it is started until you log in for the first time. During this time, email notifications and communication blocking actions will not occur. This is a mode to prevent accidents such as when moving Nano in operation to another segment, all terminals connected to the destination segment violate the ATL (Allowed Terminal List) and are blocked.
3-4. Can I operate with safe mode enabled?
If the Nano is restarted due to a power outage, etc. in the operating network, and safe mode is set, no notification will be sent properly even if an unregistered terminal is connected. At the time of initial installation, maintenance, network configuration changes, etc., Safe Mode is turned on and Nano is installed. We assume that Safe Mode will be turned OFF when the segment is finalized, ATL (Allowed Terminal List) settings, etc. are completed, and operations start.
3-5. After starting monitoring, we've adjusted settings and finalized locations and ATL (Allowed Terminal List). We're ready to begin communication blocking and email notifications. Please advise on any other changes needed.
We recommend unchecking "Safe Mode" on the "Action Settings" screen. It is checked in the initial state, and if Nano restarts with it checked, all communication blocking and email notification actions will be disabled and stopped until an administrator accesses the Nano WebUI and logs in.
3-6. Please tell me how to obtain the Nano technical support log.
When a customer requests Nano support, we or our agency support may ask the customer to obtain the Nano technical support log. The method to obtain the Nano technical support log is as follows.
- Click "Nano Setting/Network Setting" in "Nano Management".
- Click "System Management" on the menu.
- Click the "Download" button in "Logs Download".
Please note that depending on the size of the logs stored by Nano, it may take several minutes after clicking the "Download" button for the log download to begin.
3-7. Even if you register an IPv6 address in the ATL (Allowed Terminal List), it may be marked as "unregistered".
By default, Windows OS, etc. may use an IPv6 anonymous (temporary) address that is automatically changed periodically. When operating a ATL with IPv6 addresses, please use it with a fixed IP attached.
3-8. I am in the process of the initial setup, but the setup PC cannot access http://kobannano.local/ via a web browser.
Please try directly connecting the setup PC and Nano using the Ethernet cable included with Nano.
Note: Accessing http://kobannano.local/
uses the mDNS (Multicast DNS) communication protocol, so you may not be able to access it if the setup PC and Nano are connected to different network subnets, or if the setup PC or any network device in use is configured to filter UDP port 5353.
If you are unable to resolve the issue, please contact "Support Desk" (Sales Agent) as listed in the "Support & Upgrade Service Registration Confirmation" document you have.
3-9. Nano's screen becomes English.
When you access the Nano screen from an iPhone/iPad, the display will be in English instead of Japanese.
We plan to improve this in future releases.
3-12. Please tell me how to initialize Nano.
When you initialize the settings, the IP address set on Nano and the NetSkateKoban sensor function setting information will return to their initial state (factory settings).
To initialize the settings, shut down the Nano, then disconnect the AC adapter power cord and Ethernet cable from the Nano to turn the power off.
With the Ethernet cable still disconnected, plug the AC adapter power cord into the Nano and start the Nano startup process.
- Status1 LED (green): Blinking
- Status2 LED (red): Off
To initialize, press the Reset button twice before the startup process is completed and the LED (green) lights up. Keep pressing it the second time and do not release it. After a while, LEDs will look like this.
- Status1 LED (green): Off
- Status2 LED (red): Blinks for 2 beats and 1 pause
If you release the Reset button in this state, the initialization process will start. LEDs during the initialization process look like this.
- Status1 LED (green): Off
- Status2 LED (red): Blinking
* If the LED (green) lights up before you release the Reset button, startup is complete and the initialization process will not be performed.
3-14. I changed the Blocking, Mail and Auto Registration settings in the action settings, but they don't seem to be reflected.
Changes to Blocking, Mail and Auto Registration settings will only take effect on terminals that are detected "after" the changes are made.
To redetect terminals that were already detected when you changed the settings, please do one of the following.
- Disable Safe Mode and reboot Nano.
- Disconnect the terminal from the network and reconnect the terminal after the "Terminal Connection Timeout" has elapsed and the terminal information has disappeared from the Detected terminals list.
3-15. I have checked the web help and FAQ, but I still can't resolve the issue related to Nano.
If you are unable to resolve the issue related to Nano, please contact "Support Desk" (Sales Agent) as listed in the "Support & Upgrade Service Registration Confirmation" document you have.
3-16. Please tell me where to direct product inquiries?
For any questions regarding the product, please contact "Support Desk" (Sales Agent) as listed in the "Support & Upgrade Service Registration Confirmation" document you have.
3-17. How can I change the email address registered with NetSkate Service Center?
We apologize for the inconvenience, but please contact "Support Desk" (Sales Agent) as listed in the "Support & Upgrade Service Registration Confirmation" document you have.
3-18. Which communication port should I use when managing Nano using Nano Manager?
For Nano Manager versions 1.5.0 or higher and Nano versions 3.0.0 or higher, Nano Manager communicates with all managed Nanos using the following destination communication port.
- 80/TCP (default, can be changed in Nano's "Network Settings" → "HTTP Port")
For other combinations, Nano Manager communicates with all managed Nanos using the following destination communication ports.
- 80/TCP (default, can be changed in Nano's "Network Settings" → "HTTP Port")
- 9907/TCP
3-19. If multiple networks are operated on the same broadcast domain (using secondary IP, etc.), is it possible to monitor and block communication with a single Nano?
Yes, it is possible without any problem. However, please note the following points:
- The maximum number of devices that can be detected simultaneously is 2048, so please do not exceed this limit.
- Please manually change the "Active Detection" settings according to your network address range.
3-20. We are operating multiple IP networks on a single network segment, but some terminals are not being detected.
You can expect to see improvement by reviewing the "Active Detection" settings.
Please configure the "Terminal Search Range" in the "Active Detection" settings to include the IP host address range for each of your IP networks. Then click "Save" to save the settings and restart the Nano.
3-21. If multiple IP networks are being operated on a single network segment, can Nano specify the range of target addresses to be detected?
No, Nano cannot specify a range of target addresses and exclude others from detection.
In such a network segment, all terminals within the network will be detected.
3-22. Does Nano support TLS 1.2 connections to mail servers?
The following products support TLS 1.2 connections to mail servers.
- NSK-NANO-BB0AX
- NSK-NANO-VB0AX
- NSK-NANO-VB4AX
- NK4-NANO-WB0AX (version 2.6.3 or higher)
The following products are not supported.
- NK4-NANO-WB0AX (version 2.6.1 and below)
3-23. I am using multiple routers for redundancy. Please tell me how to register the router terminal information with ATL (Allowed Terminal List).
Please register all MAC addresses and IP addresses assigned to the router.
Protocols such as VRRP (Virtual Router Redundancy Protocol) use virtual MAC addresses and virtual IP addresses, so please make sure to register those as well.
3-24. I checked "Blocking" under "Auto Action" on the "Action Settings" screen and restarted Nano. After that, even if I connect an unregistered terminal, it doesn't seem to block.
- Your Nano may be running in "Safe Mode".
- "Safe Mode" is a mode of operation in which no Blocking or Mail actions are performed after the Nano reboots and until an administrator logs in to the Nano WebUI for the first time. This is a function that is turned on at the time of shipment, to reduce accidents such as unintentional blocking when the Nano is accidentally connected to a different network than usual.
- To disable "Safe Mode", turn off the "Safe Mode" checkbox on the "Action Settings" screen, "Save", and then restart Nano.
3-25. I have installed Nano on my company's internal LAN. If I connect a mobile device or laptop from a network outside the company to the company's internal LAN via VPN, can Nano monitor it?
Devices connected via Layer 3 VPN cannot be monitored.
When making a VPN connection to the company LAN from outside the company using a mobile device or laptop, a Layer 3 VPN is generally used.
In this case, the MAC address of the connected device is not used for communication on the company LAN, so it cannot be monitored by Nano.
3-26. If I use Mobile Hotspot to share my internet connection on a Windows PC that is connected to a network that Nano is monitoring, can Nano monitor other devices that are connected to it?
No, it can not monitor.
3-27. Is it possible to remotely manage Nano installed on another network?
Yes, it is possible if you prepare a network connection such as LAN or VPN to enable communication to the IP address set on Nano. In that case, please also make sure that an appropriate "default router" is set for Nano.
3-28. What kind of security event (content) occurs in FortiGate when the action when linking with FortiGate is executed?
The items that can be linked with ForitiGate using Nano's "SNMP trap linkage settings" and "Syslog linkage settings" are as follows. Only one of these combinations can be configured and used on a single Nano. (Example: Syslog - fgTrapAvVirus)
For information on the FortiGate functions and settings, please refer to the FortiOS Handbook, the documentation that comes with the FortiGate product.
- SNMP trap
-
- fgTrapIpsSignature
- fgTrapIpsAnomaly
- Syslog
-
- fgTrapIpsSignature
- fgTrapIpsAnomaly
- fgTrapAvVirus
- fgWebFilter
- fgDNSFilter
3-29. The MAC address (same) of L2/L3 switch equipment is detected irregularly in multiple VLANs.
It seems that you are connecting a device that is designed to communicate using a single MAC address for all connected VLANs. In this case, there is nothing particularly abnormal. However, when registering such a device to the ATL (Allowed Terminal List) based on its MAC address, please register by specifying all VLANs that may communicate, or "All". It is possible to avoid actions such as detection and blocking in unexpected VLANs.
3-32. Is it normal for the same IP address to be detected with multiple MAC addresses?
The following situations may be considered:
If multiple terminals have the same IP address:
Please configure each terminal with a unique and appropriate IP address.
If there is a L3 switch or router with the Proxy ARP function enabled within the network:
If the Proxy ARP function is not needed, please disable it.
3-33. Please tell me the support period for Nano.
The support period for NetSkateKoban Nano/Nano(V) is 5 years from the date of implementation.
3-34. How do I display a network map using Nano Manager?
Network Map function is available from the following version onwards.
- NetSkateKoban Nano Manager version 1.6.0
- NetSkateKoban Nano version 3.1.0
The settings are as follows:
- Setting up Nano Manager:
- Configuration file: NanoManager.conf located in the "config" folder under the folder where Nano Manager is installed.
- Enabling Network Map function: Please set the ENABLE_L2MAP option to true (The default value is false).
- Setting up Nano (Nano Action Settings screen):
- Enable "Do Device Type Discovery".
- If the SNMP community name of the intelligent switch is other than "public", add the community name to "SNMP Community" separated by a comma.
For details, please refer to "5.15.1 Configuration Steps" in the Nano Manager User Manual.
3-35. How can I determine on the terminal side whether a terminal is being blocked by Nano?
Check the ARP table information (arp -a) and if the MAC addresses of many entries have been replaced with the addresses used for blocking (Cyber Solutions vendor code: 00:1a:b2:xx:xx:xx
), the terminal may be being blocked.
arp -a
Internet Address Physical address Type
192.168.0.1 00-1a-b2-2a-11-ed dynamic
192.168.0.100 00-1a-b2-2a-11-ed dynamic
192.168.0.129 00-1a-b2-2a-11-ed dynamic
3-36. How can I check whether a terminal is being blocked by Nano from another terminal on the same segment?
To the terminal suspected of being blocked (e.g. 172.16.0.178), ping it from another terminal on the same segment. Then, check the ARP table information (arp -a) of the other terminal, and if the MAC address in the IP address entry of the terminal suspected of being blocked have been replaced by the addresses used for blocking (Cyber Solutions vendor code: 00:1a:b2:xx:xx:xx
), the terminal with that IP address may be being blocked.
arp -a
Internet Address Physical address Type
172.16.0.178 00-1a-b2-2a-11-ed Dynamic
3-37. Please tell me where I can find information about version updates?
We regularly provide version update information under "Latest Information" on the top page of our website, so please take a look there.
3-38. Please tell me where I can download the firmware required for upgrading?
You can download the firmware from NetSkate Service Center.
NetSkate Service Center also provides access to release notes, documentation, and other related materials.
For login instructions and important notes, please refer to the top page of NetSkate Service Center.