50
SonicWall
SuperMassive
9800
Getting
Started
Guide
Secure
Mode
affords
the
same
level
of
visibility
and
enforcement
as
conventional
NAT
or
Layer
2
Bridged
Mode
deployments,
but
without
any
L3/L4
transformations,
and
with
no
alterations
of
ARP
or
routing
behavior.
Secure
Mode
provides
a
Next
Generation
Firewall
deployment
requiring
no
logical
and
only
minimal
physical
changes
to
existing
network
designs.
Inspect
Mode
Inspect
Mode
allows
packets
to
pass
through
the
firewall’s
switch
fabric,
but
they
are
also
mirrored
to
the
multi
‐
core
Reassembly
‐
Free
Deep
Packet
Inspection
(RF
DPI)
engine
for
the
purposes
of
passive
inspection,
classification,
and
flow
reporting.
This
reveals
the
firewall’s
Application
Intelligence
and
threat
detection
capabilities
without
any
actual
intermediate
processing.
Bypass
Mode
Bypass
Mode
allows
for
the
quick
and
non
‐
interruptive
introduction
of
firewall
hardware
into
a
network.
Upon
selecting
a
point
of
insertion
into
a
network
(such
as
between
a
core
switch
and
a
perimeter
firewall,
in
front
of
a
server
farm,
or
at
a
transition
point
between
data
classification
domains),
the
firewall
is
inserted
into
the
physical
data
path,
requiring
a
very
short
maintenance
window.
One
or
more
pairs
of
switch
ports
on
the
firewall
are
used
to
forward
all
packets
across
network
segments
at
full
line
rates,
rather
than
passing
the
packets
to
the
multi
‐
core
inspection
and
enforcement
path.
Bypass
mode
allows
the
administrator
to
physically
introduce
the
firewall
into
the
network
with
a
minimum
of
downtime
and
risk,
and
to
obtain
a
level
of
comfort
with
the
newly
inserted
component
of
the
networking
and
security
infrastructure.
The
following
table
summarizes
the
key
functional
differences
between
modes
of
interface
configuration.
NOTE:
Tap
Mode
is
an
alternative
to
using
Wire
Mode.
This
mode
provides
the
same
visibility
as
Inspect
Mode,
but
differs
in
that
it
ingests
a
mirrored
packet
stream
through
a
single
switch
port
on
the
firewall.
Tap
Mode
is
designed
for
use
in
environments
employing
network
taps,
smart
taps,
port
mirrors,
or
SPAN
ports
to
deliver
packets
to
external
devices
for
inspection
or
collection.
Tap
Mode
can
operate
on
multiple
concurrent
port
instances,
supporting
discrete
streams
from
multiple
taps.
Summary of Contents for SuperMassive 9800
Page 1: ...SonicWall SuperMassive 9800 Getting Started Guide Regulatory Model Number 2RK04 0AD...
Page 36: ...36 SonicWall SuperMassive 9800 Getting Started Guide...
Page 58: ...58 SonicWall SuperMassive 9800 Getting Started Guide...
Page 64: ...64 SonicWall SuperMassive 9800 Getting Started Guide...
Page 72: ...72 SonicWall SuperMassive 9800 Getting Started Guide...
Page 75: ...SonicWall SuperMassive 9800 Getting Started Guide 75...
Page 76: ...SuperMassive 9800 Getting Started Guide Updated July 2017 232 003430 50 Rev A...