38 Deploying the 7100 Series
Deployment options
Online and bypass modes
The bypass units can operate in two modes:
■
Online mode: Network traffic passes from the bypass unit to the 7100 Series
for analysis, then goes back to the bypass unit and out through the other
network interface. Also called online state.
■
Bypass mode: Network traffic entering the bypass unit passes directly from
one side of the network to the other. Also called bypass state.
After connecting the bypass unit to the 7100 Series and powering on, all port
groups are initially in bypass mode. In bypass mode, network traffic does not
pass through the appliance for event detection. To change the port group to
online mode, you must start a sensor on the in-line pair that is connected to that
port group. Event detection can only occur when the bypass unit is in online
mode.
See
“Starting a sensor on an appliance interface”
on page 115.
While the appliance is running, the bypass unit stays in online mode. If the
appliance has a hardware or software failure, fail-open is activated when the
bypass unit senses the failure via the USB connection and switches to bypass
mode.
Link parameters on bypass unit interfaces
The interface link parameters, including speed and duplex mode, should be
auto-negotiated between Net A and App A, and Net B and App B. You should not
force the link speed or duplex mode to a specific setting on network devices that
connect to Net A or Net B. Forcing the link parameters to a certain value may
The even-numbered
interface on the
appliance
App A
Connects to the interface in the in-line pair that is
associated with one side of the network. App A
always connects to the even-numbered interface
(for example, re1000g0 or eth2).
The odd-numbered
interface on the
appliance
App B
Connects to the interface in the in-line pair that is
associated with the other side of the network. App
B always connects to the odd-numbered interface
(for example, re1000g1 or eth3).
The other side of the
network
Net B
Connects to the other side of the network.
Table 3-3
Connections needed for deploying bypass unit
Connection
Bypass port Description
Summary of Contents for 10521148 - Network Security 7161
Page 1: ...Symantec Network Security 7100 Series Implementation Guide...
Page 8: ...8...
Page 16: ...8 Contents...
Page 24: ...16 Introduction Verifying the materials...
Page 52: ...44 Deploying the 7100 Series Symantec LiveUpdate accessibility...
Page 174: ...166 Maintaining and administering the 7100 Series Using the serial console...
Page 190: ...182 Re imaging and unconfiguring About migration...
Page 198: ...190 Specifications and safety Product certifications...
Page 214: ...12 Index...