Symantec 10521148 Implementation Guide - Page 38

Bandwidth licensing options, Passive mode, In-line mode, Interface grouping, Fail-open, Clustering

Page 38 highlights

30 Deploying the 7100 Series Deployment options be appliances or software versions on other platforms. You can integrate the appliance with third party intrusion detection products as well. See the following sections for more information: ■ Bandwidth licensing options ■ Passive mode ■ In-line mode ■ Interface grouping ■ Fail-open ■ Clustering ■ External IDS products Bandwidth licensing options The Symantec Network Security 7100 Series offers extremely flexible bandwidth deployment licensing. You can choose from three bandwidth levels for the 7120, and four levels for a 7160 or 7161. If your network traffic increases beyond your licensed rate, you can add to your license in 50 Mbps increments for the 7120, and in 250 Mbps increments for the 7160 and 7161. For more information about licensing, see "Licensing" on page 91. Passive mode Passive mode is the default method of monitoring traffic on network segments. It provides intrusion detection with logging, alerting, and response capabilities. Passive mode also provides maximum performance. Symantec Network Security 4.0 software provides the same functionality on other platforms as passive mode on the 7100 Series. When configuring monitoring interfaces to monitor network segments: ■ The 7120 can monitor four different network segments with a total bandwidth up to 200 Mbps of network traffic. ■ The 7160 and 7161 models can each monitor up to eight network segments, with a total bandwidth up to 2 Gbps. In passive mode, Network Security detects attacks as they enter the monitored network. You can configure response rules to provide alerts, send TCP resets, execute scripts, or take other actions. See the Symantec Network Security Administration Guide for more information on response rules.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

30
Deploying the 7100 Series
Deployment options
be appliances or software versions on other platforms. You can integrate the
appliance with third party intrusion detection products as well.
See the following sections for more information:
Bandwidth licensing options
Passive mode
In-line mode
Interface grouping
Fail-open
Clustering
External IDS products
Bandwidth licensing options
The Symantec Network Security 7100 Series offers extremely flexible
bandwidth deployment licensing. You can choose from three bandwidth levels
for the 7120, and four levels for a 7160 or 7161. If your network traffic increases
beyond your licensed rate, you can add to your license in 50 Mbps increments
for the 7120, and in 250 Mbps increments for the 7160 and 7161. For more
information about licensing, see
“Licensing”
on page 91.
Passive mode
Passive mode is the default method of monitoring traffic on network segments.
It provides intrusion detection with logging, alerting, and response capabilities.
Passive mode also provides maximum performance. Symantec Network Security
4.0 software provides the same functionality on other platforms as passive mode
on the 7100 Series.
When configuring monitoring interfaces to monitor network segments:
The 7120 can monitor four different network segments with a total
bandwidth up to 200 Mbps of network traffic.
The 7160 and 7161 models can each monitor up to eight network segments,
with a total bandwidth up to 2 Gbps.
In passive mode, Network Security detects attacks as they enter the monitored
network. You can configure response rules to provide alerts, send TCP resets,
execute scripts, or take other actions. See the
Symantec Network Security
Administration Guide
for more information on response rules.