Symantec 10521148 Implementation Guide - Page 42

Asymmetric traffic pattern, Router, Outflow of, sessions, Servers, Multi, layered, switch

Page 42 highlights

34 Deploying the 7100 Series Deployment options Figure 3-3 Asymmetric traffic pattern Router Router Inflow of sessions Multilayered switch Outflow of sessions Inflow of sessions Outflow of sessions Multilayered switch Servers Servers You can configure up to four monitoring interfaces into one interface group. Symantec Network Security starts a single sensor for the group, with the result that all network traffic seen on any interface within the group is analyzed in the group context, as if the traffic were being seen on a single interface. Any policy you create for an interface group applies to all interfaces in the group. Interfaces that are part of a group cannot be configured individually. An interface group can only include passive mode interfaces. Interface grouping of in-line pairs is not supported. You can only create an interface group using interfaces from the same node. Interfaces groups spanning multiple nodes in a cluster are not supported.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

34
Deploying the 7100 Series
Deployment options
Figure 3-3
Asymmetric traffic pattern
You can configure up to four monitoring interfaces into one interface group.
Symantec Network Security starts a single sensor for the group, with the result
that all network traffic seen on any interface within the group is analyzed in the
group context, as if the traffic were being seen on a single interface. Any policy
you create for an interface group applies to all interfaces in the group.
Interfaces that are part of a group cannot be configured individually.
An interface group can only include passive mode interfaces. Interface grouping
of in-line pairs is not supported.
You can only create an interface group using interfaces from the same node.
Interfaces groups spanning multiple nodes in a cluster are not supported.
Router
Router
Outflow of
sessions
Inflow of
sessions
Inflow of
sessions
Outflow of
sessions
Servers
Servers
Multi-
layered
switch
Multi-
layered
switch