Symantec 10521148 Implementation Guide - Page 123

Configuring detection and response, About detection and response, Starting a sensor on an appliance

Page 123 highlights

9 Chapter Configuring detection and response This chapter includes the following topics: ■ About detection and response ■ Starting a sensor on an appliance interface ■ Creating and applying protection policies ■ About response rules About detection and response The fundamental purpose of Symantec Network Security is to detect malicious traffic and respond in a way that helps protect your network. Network Security sensor processes monitor traffic and detect suspicious events on each monitoring interface, in-line pair, or interface group. The detected events are handled according to policies that you apply. You can also create and apply response rules for specific event types and source or destination addresses. Response rules provide a means of automating actions for Network Security to take when it detects the configured events. Starting a sensor on an appliance interface You must start a sensor on an interface, interface group, or in-line pair before Symantec Network Security will detect traffic or attacks. Sensors function on a per interface basis. It is possible for sensors to be running on some appliance interfaces, and not running on others. To start a sensor, you must apply a protection policy to the interface.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

Chapter
9
Configuring detection and
response
This chapter includes the following topics:
About detection and response
Starting a sensor on an appliance interface
Creating and applying protection policies
About response rules
About detection and response
The fundamental purpose of Symantec Network Security is to detect malicious
traffic and respond in a way that helps protect your network. Network Security
sensor processes monitor traffic and detect suspicious events on each
monitoring interface, in-line pair, or interface group. The detected events are
handled according to policies that you apply.
You can also create and apply response rules for specific event types and source
or destination addresses. Response rules provide a means of automating actions
for Network Security to take when it detects the configured events.
Starting a sensor on an appliance interface
You must start a sensor on an interface, interface group, or in-line pair before
Symantec Network Security will detect traffic or attacks. Sensors function on a
per interface basis. It is possible for sensors to be running on some appliance
interfaces, and not running on others.
To start a sensor, you must apply a protection policy to the interface.