Symantec 10521146 Administration Guide - Page 62

Deploying a single 7100 Series appliance node, About interface grouping, About in-line mode

Page 62 highlights

62 Getting started Deploying single nodes Managing a single node is simpler than managing a cluster. For example, you can partition your network to make each security administrator responsible for only one segment, without the need to communicate with other segments or with other software or appliance nodes. In this scenario, the nodes have no method of communication with each other. Using a single Network Security console, you can log in to any single node in your network, and view it individually. With single-node deployment, you cannot view all nodes simultaneously from the Network Security console. Also, failover groups do not function for single nodes. Deploying a single 7100 Series appliance node You can deploy a Symantec Network Security 7100 Series node just as you would a Network Security software node. It can operate independently or as part of a cluster. A 7100 Series appliance also has several extra deployment options. You can configure it for interface grouping, in-line mode, and fail-open, in addition to passive monitoring mode. You can also deploy the appliance using a combination of these modes in a way that best suits your network. About interface grouping Interface grouping provides a solution when your network employs asymmetric routing. Asymmetric routing occurs when traffic arrives on one interface and departs on another. Because the request and reply sides of the client/server traffic are on different interfaces, a standard monitoring interface cannot see the full conversation to analyze it properly. With the Symantec Network Security 7100 Series, you can place up to four interfaces into a single group. One sensor is started for the interface group, allowing Symantec Network Security to analyze the different traffic flows as if they were combined on one interface. This is a very effective deployment mode for a network with asymmetric routing. About in-line mode In-line mode is another mode of deployment available only with the Symantec Network Security 7100 Series appliance. In-line mode uses an interface pair to place the appliance directly into the network path. Both interfaces connect to the monitored network segment, effectively separating it into two sides. Incoming packets are fully analyzed before being allowed to continue into the other side of the network. Because of the nature of the connection, it is necessary to interrupt network traffic briefly while you connect the cables to the appliance interfaces.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

62
Getting started
Deploying single nodes
Managing a single node is simpler than managing a cluster. For example, you
can partition your network to make each security administrator responsible for
only one segment, without the need to communicate with other segments or
with other software or appliance nodes. In this scenario, the nodes have no
method of communication with each other. Using a single Network Security
console, you can log in to any single node in your network, and view it
individually. With single-node deployment, you cannot view all nodes
simultaneously from the Network Security console. Also, failover groups do not
function for single nodes.
Deploying a single 7100 Series appliance node
You can deploy a Symantec Network Security 7100 Series node just as you would
a Network Security software node. It can operate independently or as part of a
cluster. A 7100 Series appliance also has several extra deployment options. You
can configure it for interface grouping, in-line mode, and fail-open, in addition
to passive monitoring mode. You can also deploy the appliance using a
combination of these modes in a way that best suits your network.
About interface grouping
Interface grouping provides a solution when your network employs asymmetric
routing. Asymmetric routing occurs when traffic arrives on one interface and
departs on another. Because the request and reply sides of the client/server
traffic are on different interfaces, a standard monitoring interface cannot see
the full conversation to analyze it properly. With the Symantec Network
Security 7100 Series, you can place up to four interfaces into a single group. One
sensor is started for the interface group, allowing Symantec Network Security to
analyze the different traffic flows as if they were combined on one interface.
This is a very effective deployment mode for a network with asymmetric
routing.
About in-line mode
In-line mode is another mode of deployment available only with the Symantec
Network Security 7100 Series appliance. In-line mode uses an interface pair to
place the appliance directly into the network path. Both interfaces connect to
the monitored network segment, effectively separating it into two sides.
Incoming packets are fully analyzed before being allowed to continue into the
other side of the network. Because of the nature of the connection, it is
necessary to interrupt network traffic briefly while you connect the cables to the
appliance interfaces.