32
Chapter 5
Defining Sensors and Analyzers
Getting Started with Defining Sensors and Analyzers
The Sensor and Analyzer elements are a tool for configuring nearly all aspects of your physical
IPS components.
An important part of the Sensor and Analyzer elements are the interface definitions. There are
two main categories of Sensor and Analyzer interfaces:
•
Interfaces for system communications. They are used when the Sensor or the Analyzer is the
source or the final destination of the communications (for example, in control
communications between the Sensor or Analyzer and the Management Server). You must
define at least one interface that is dedicated to system communications for each Sensor
and Analyzer element.
•
Interfaces for inspecting traffic. You must define one or more traffic inspection interfaces for
each Sensor element.
The interfaces have their own numbering in the Management Center called Interface ID.
The
numbering is independent of the operating system interface numbering on the engines.
However, if you do the engine’s initial configuring using the automatic USB memory stick
configuration method, the Interface IDs in the Management Center are mapped to match the
physical interface numbering in the operating system (eth0 is mapped to Interface ID 0 and so
on). If you do the initial configuration manually, you can freely choose how the Interface IDs in
the Management Center are mapped to the physical interfaces.
Creating Engine Elements
There are two main installation types. The Sensor and the Analyzer can be installed as a
combined Sensor-Analyzer on the same machine, or as separate Sensor and Analyzer engines
on separate machines. A combined Sensor-Analyzer is both a Sensor and an Analyzer, and has
the properties of both element types in the configuration tools.
This section covers the basic configuration of a Sensor and Analyzer elements. For complete
instructions on configuring Sensor and Analyzer properties, see the
Online Help
of the
Management Client or the
Administrator’s Guide
PDF.
To create an engine element
1.
Click the Configuration icon in the toolbar and select
IPS
. The IPS Configuration view opens.
1
Summary of Contents for stonegate 5.2
Page 1: ...STONEGATE 5 2 INSTALLATION GUIDE INTRUSION PREVENTION SYSTEM...
Page 5: ...5 INTRODUCTION In this section Using StoneGate Documentation 7...
Page 6: ...6...
Page 12: ...12...
Page 18: ...18 Chapter 2 Planning the IPS Installation...
Page 28: ...28 Chapter 4 Configuring NAT Addresses...
Page 30: ...30...
Page 50: ...50 Chapter 6 Saving the Initial Configuration...
Page 60: ...60...
Page 72: ...72 Chapter 8 Installing the Engine on Intel Compatible Platforms...
Page 73: ...73 UPGRADING In this section Upgrading 75...
Page 74: ...74...
Page 88: ...88...