38
Chapter 5
Defining Sensors and Analyzers
3.
(
Optional
) Select a
Backup
Control interface that is used if the Primary interface is not
available.
4.
(
Sensor Cluster only
) Select the
Primary
Heartbeat Interface for communications between
the nodes of the cluster. This must not be a VLAN interface.
5.
(
Sensor Cluster only, recommended
) Select a second Physical Interface as the
Backup
Heartbeat interface.
6.
Select the
Log/Analyzer communication source IP address
.
•
On Sensors, this is for relaying information about the processed traffic to the Analyzer for
further processing.
•
On Analyzers and Sensor-Analyzers, this is for relaying logs and alerts to the Log Server.
7.
Click
OK
.
Defining Traffic Inspection Interfaces for Sensors
Sensors are the IPS components that inspect traffic. The traffic can either be captured for
inspection through the sensor’s capture interfaces, or it can be inspected as it flows through the
sensor’s inline interfaces. You can define both capture interfaces and inline interfaces for the
same sensor.
A sensor can actively filter only traffic that attempts to pass through its inline interfaces.
However, it can reset traffic picked up through capture interfaces if you set up specific reset
interfaces. The reset interfaces can send TCP resets and ICMP “destination unreachable”
messages when the communications trigger a response. You can use a system communications
interface for sending resets if the resets are routed correctly through that interface and there
are no VLANs on the interface.
When traffic is inspected, it may be important to know the interface through which it arrives to
the sensor. It is also important to be able to distinguish a sensor’s capture interfaces from its
inline interfaces. Logical Interface elements are used for both these purposes. They allow you to
group together interfaces that belong to the same network segment and to identify the type of
the traffic inspection interface (capture interface or inline interface).
Caution – Heartbeat traffic is time-critical. A dedicated network (without other traffic) is
strongly recommended for security and reliability of heartbeat communication.
What’s Next?
If you want to create both capture and inline interfaces on the same sensor, or if you
want to create logical interfaces to distinguish interfaces from each other, proceed to
If you do not want to use an existing system communication interface as the reset
interface, define the new reset interfaces as instructed in
To define capture interfaces, proceed to
To define inline interfaces, proceed to
Summary of Contents for stonegate 5.2
Page 1: ...STONEGATE 5 2 INSTALLATION GUIDE INTRUSION PREVENTION SYSTEM...
Page 5: ...5 INTRODUCTION In this section Using StoneGate Documentation 7...
Page 6: ...6...
Page 12: ...12...
Page 18: ...18 Chapter 2 Planning the IPS Installation...
Page 28: ...28 Chapter 4 Configuring NAT Addresses...
Page 30: ...30...
Page 50: ...50 Chapter 6 Saving the Initial Configuration...
Page 60: ...60...
Page 72: ...72 Chapter 8 Installing the Engine on Intel Compatible Platforms...
Page 73: ...73 UPGRADING In this section Upgrading 75...
Page 74: ...74...
Page 88: ...88...