McAfee DTP-165C-DPVG Installation Guide - Page 16

Select an integration mode for McAfee DLP Monitor, SPAN port configuration

Page 16 highlights

2 Setting up the hardware Select an integration mode for McAfee DLP Monitor Select an integration mode for McAfee DLP Monitor McAfee DLP Monitor must be physically integrated into the network so it can capture traffic. There are two integration modes: use of a mirror (SPAN) port on a LAN switch, or placement of a network tap between the network and the appliance. SPAN port configuration A SPAN (Switched Port Analyzer) port configuration enables monitoring by transparently copying traffic from source ports to the destination port to which McAfee DLP Monitor is connected. If two capture ports are used, two traffic sources (for example, different subnets) must be used. Certain switch models permit the use of a "remote SPAN", or "RSPAN" capability, which allows ports from multiple switches to be mirrored to the port to which McAfee DLP Monitor is connected. If you want to mirror multiple ports on multiple switches to your DLP appliance, contact the switch vendor for details on configuring RSPAN. Figure 2-4 Span port configuration 1 Capture ports 2 WAN router traffic mirrored to McAfee DLP Monitor port 3 LAN 4 LAN switch 5 WAN This method requires a change on the LAN switch, but no downtime is required because network traffic is not disrupted. With this configuration, some packets might be dropped under heavy loads. As a result, the number of packets seen by McAfee DLP Monitor might not match the number seen by the ports being monitored. Integrate the appliance using a SPAN port Task 1 Connect McAfee DLP Monitor to a network switch using a console cable or network connection (such as Telnet or SSH). Note the port used to connect the appliance to the LAN switch, and the port used by the WAN router. 2 Apply the appropriate SPAN port configuration. 16 McAfee Data Loss Prevention 9.2.0 Installation Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76

Select an integration mode for McAfee DLP Monitor
McAfee DLP Monitor must be physically integrated into the network so it can capture traffic. There are
two integration modes: use of a mirror (SPAN) port on a LAN switch, or placement of a network tap
between the network and the appliance.
SPAN port configuration
A SPAN (Switched Port Analyzer) port configuration enables monitoring by transparently copying traffic
from source ports to the destination port to which McAfee DLP Monitor is connected.
If two capture ports are used, two traffic sources (for example, different subnets) must be used.
Certain switch models permit the use of a “remote SPAN”, or “RSPAN” capability, which allows ports
from multiple switches to be mirrored to the port to which McAfee DLP Monitor is connected. If you
want to mirror multiple ports on multiple switches to your DLP appliance, contact the switch vendor for
details on configuring RSPAN.
Figure 2-4
Span port configuration
1
Capture ports
2
WAN router traffic mirrored to McAfee DLP Monitor port
3
LAN
4
LAN switch
5
WAN
This method requires a change on the LAN switch, but no downtime is required because network
traffic is not disrupted.
With this configuration, some packets might be dropped under heavy loads. As a result, the number of
packets seen by McAfee DLP Monitor might not match the number seen by the ports being monitored.
Integrate the appliance using a SPAN port
Task
1
Connect McAfee DLP Monitor to a network switch using a console cable or network connection
(such as Telnet or SSH).
Note the port used to connect the appliance to the LAN switch, and the port used by the WAN router.
2
Apply the appropriate SPAN port configuration.
2
Setting up the hardware
Select an integration mode for McAfee DLP Monitor
16
McAfee Data Loss Prevention 9.2.0
Installation Guide