Symantec 10521148 Implementation Guide - Page 39

In-line mode, Blocking and alerting

Page 39 highlights

Deploying the 7100 Series 31 Deployment options Note: Passive mode does not provide the ability to block malicious traffic from reaching its destination. The attack is detected on its way to the target. Blocking is only available using in-line mode. See "In-line mode" on page 31 and "About protection policies" on page 116. In-line mode In-line mode is a powerful mode of deployment that is available only on the Symantec Network Security 7100 Series. This section provides the following information: ■ Blocking and alerting ■ In-line pairs ■ Deployment using in-line mode ■ Comparing in-line mode to passive mode Blocking and alerting You can configure in-line mode on your appliance to operate in either of two modes: ■ Alerting: Sends configurable alerts using email, pagers, SNMP, and console pop-ups. Provides configurable responses such as sending TCP resets, executing scripts or programs, traffic recording, and more. ■ Blocking: Prevents malicious traffic from entering your network. Also provides the same configurable alerts and responses offered in alerting mode. Both operating modes provide logging of suspicious or malicious events, including the display of events and incidents on the Network Security console. In-line alerting mode provides the same capabilities as passive mode provides (see "Passive mode" on page 30). The advantage of in-line alerting mode over passive mode is that you can quickly switch from alerting to blocking mode in the Network Security console. In-line blocking mode is an important tool for securing your network, because it allows you to stop attacks at the point of detection. Blocking mode on the 7100 Series utilizes Symantec Network Security's powerful analysis software to identify both zero-day attacks and those with known signatures. You can find more information about Network Security's analysis and detection capabilities in the Symantec Network Security Administration Guide.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

31
Deploying the 7100 Series
Deployment options
Note:
Passive mode does not provide the ability to block malicious traffic from
reaching its destination. The attack is detected on its way to the target. Blocking
is only available using in-line mode. See
“In-line mode”
on page 31 and
“About
protection policies”
on page 116.
In-line mode
In-line mode is a powerful mode of deployment that is available only on the
Symantec Network Security 7100 Series.
This section provides the following information:
Blocking and alerting
In-line pairs
Deployment using in-line mode
Comparing in-line mode to passive mode
Blocking and alerting
You can configure in-line mode on your appliance to operate in either of two
modes:
Alerting: Sends configurable alerts using email, pagers, SNMP, and console
pop-ups. Provides configurable responses such as sending TCP resets,
executing scripts or programs, traffic recording, and more.
Blocking: Prevents malicious traffic from entering your network. Also
provides the same configurable alerts and responses offered in alerting
mode.
Both operating modes provide logging of suspicious or malicious events,
including the display of events and incidents on the Network Security console.
In-line alerting mode provides the same capabilities as passive mode provides
(see
“Passive mode”
on page 30). The advantage of in-line alerting mode over
passive mode is that you can quickly switch from alerting to blocking mode in
the Network Security console.
In-line blocking mode is an important tool for securing your network, because it
allows you to stop attacks at the point of detection. Blocking mode on the 7100
Series utilizes Symantec Network Security’s powerful analysis software to
identify both zero-day attacks and those with known signatures. You can find
more information about Network Security’s analysis and detection capabilities
in the
Symantec Network Security Administration Guide
.