38
Chapter 5
Defining Sensors and Analyzers
3.
(
Optional
) Select a
Backup
Control interface that is used if the Primary interface is not
available.
4.
(
Sensor Cluster only
) Select the
Primary
Heartbeat Interface for communications between
the nodes of the cluster. This must not be a VLAN interface.
5.
(
Sensor Cluster only, recommended
) Select a second Physical Interface as the
Backup
Heartbeat interface.
6.
Select the
Log/Analyzer communication source IP address
.
•
On Sensors, this is for relaying information about the processed traffic to the Analyzer for
further processing.
•
On Analyzers and Sensor-Analyzers, this is for relaying logs and alerts to the Log Server.
7.
Click
OK
.
Defining Traffic Inspection Interfaces for Sensors
Sensors are the IPS components that inspect traffic. The traffic can either be captured for
inspection through the sensor’s capture interfaces, or it can be inspected as it flows through the
sensor’s inline interfaces. You can define both capture interfaces and inline interfaces for the
same sensor.
A sensor can actively filter only traffic that attempts to pass through its inline interfaces.
However, it can reset traffic picked up through capture interfaces if you set up specific reset
interfaces. The reset interfaces can send TCP resets and ICMP “destination unreachable”
messages when the communications trigger a response. You can use a system communications
interface for sending resets if the resets are routed correctly through that interface and there
are no VLANs on the interface.
When traffic is inspected, it may be important to know the interface through which it arrives to
the sensor. It is also important to be able to distinguish a sensor’s capture interfaces from its
inline interfaces. Logical Interface elements are used for both these purposes. They allow you to
group together interfaces that belong to the same network segment and to identify the type of
the traffic inspection interface (capture interface or inline interface).
Caution – Heartbeat traffic is time-critical. A dedicated network (without other traffic) is
strongly recommended for security and reliability of heartbeat communication.
What’s Next?
If you want to create both capture and inline interfaces on the same sensor, or if you
want to create logical interfaces to distinguish interfaces from each other, proceed to
If you do not want to use an existing system communication interface as the reset
interface, define the new reset interfaces as instructed in
To define capture interfaces, proceed to
To define inline interfaces, proceed to
Содержание stonegate 5.2
Страница 1: ...STONEGATE 5 2 INSTALLATION GUIDE INTRUSION PREVENTION SYSTEM...
Страница 5: ...5 INTRODUCTION In this section Using StoneGate Documentation 7...
Страница 6: ...6...
Страница 12: ...12...
Страница 18: ...18 Chapter 2 Planning the IPS Installation...
Страница 28: ...28 Chapter 4 Configuring NAT Addresses...
Страница 30: ...30...
Страница 50: ...50 Chapter 6 Saving the Initial Configuration...
Страница 59: ...59 INSTALLING SENSORS AND ANALYZERS In this section Installing the Engine on Intel Compatible Platforms 61...
Страница 60: ...60...
Страница 72: ...72 Chapter 8 Installing the Engine on Intel Compatible Platforms...
Страница 73: ...73 UPGRADING In this section Upgrading 75...
Страница 74: ...74...
Страница 88: ...88...
Страница 94: ...94 Appendix A Command Line Tools...