Placing The Flowsensor Inside Your Firewall - Lancope StealthWatch System Hardware Installation Manual

Table of Contents

Advertisement

20
The following illustration shows an example of this configuration using an Ethernet
electrical TAP. The management port must be connected to the switch or hub of the
monitored network. This setup is similar to the setup that monitors traffic to and from
your network.
Note:
If your firewall is performing network address translation (NAT), you can observe
only the addresses that are on the firewall.

Placing the FlowSensor Inside Your Firewall

To monitor traffic between internal networks and a firewall, the FlowSensor must be
able to access all traffic between the firewall and the internal networks. You can
accomplish this by configuring a mirror port that mirrors the connection to the firewall
on the main switch. Make sure that the FlowSensor Monitor Port 1 is connected to the
mirror port, as shown in the following illustration:
Pre-Configuration Considerations

Advertisement

Table of Contents
loading

Table of Contents