Symantec 10521148 Implementation Guide - Page 43

Fail-open, About the In-line Bypass unit

Page 43 highlights

Fail-open Deploying the 7100 Series 35 Deployment options Fail-open refers to a configuration that allows network traffic to continue even if the Symantec Network Security 7100 Series appliance has a hardware or software failure that affects one or more of its in-line interface pairs. For in-line interface pairs on the appliance, fail-open is an option that requires the purchase and installation of another device called the Symantec Network Security In-line Bypass unit. See the following sections for more information: ■ About the In-line Bypass unit ■ The 2 In-line Bypass unit ■ The 4 In-line Bypass unit ■ Port groups and the management port on the bypass unit ■ Online and bypass modes ■ Link parameters on bypass unit interfaces ■ Front panel LEDs on the bypass unit ■ Rear panel LEDs on the bypass unit About the In-line Bypass unit Since in-line mode by definition places the appliance into the network path, a hardware or software failure affecting the interface pair will interrupt network traffic, or fail closed. To avoid this you can install the In-line Bypass unit. The bypass unit monitors the 7100 Series status, and if it senses a failure, the bypass unit provides direct network connectivity. There are two bypass unit models, called the 2 In-line Bypass unit and the 4 In-line Bypass unit. The two models are designed to accommodate 7100 Series appliances with either four or eight copper monitoring interface ports. The following table summarizes the features of the bypass unit models: Table 3-2 Bypass unit features Feature 2 In-line Bypass unit 4 In-line Bypass unit Supported appliance model 7120 Supported number of in-line interface 2 pairs (equals number of port groups on bypass unit) 10/100/1000 Base-TX (MDIX) interfaces 2 7160 4 4

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214

35
Deploying the 7100 Series
Deployment options
Fail-open
Fail-open refers to a configuration that allows network traffic to continue even
if the Symantec Network Security 7100 Series appliance has a hardware or
software failure that affects one or more of its in-line interface pairs. For in-line
interface pairs on the appliance, fail-open is an option that requires the
purchase and installation of another device called the Symantec Network
Security In-line Bypass unit.
See the following sections for more information:
About the In-line Bypass unit
The 2 In-line Bypass unit
The 4 In-line Bypass unit
Port groups and the management port on the bypass unit
Online and bypass modes
Link parameters on bypass unit interfaces
Front panel LEDs on the bypass unit
Rear panel LEDs on the bypass unit
About the In-line Bypass unit
Since in-line mode by definition places the appliance into the network path, a
hardware or software failure affecting the interface pair will interrupt network
traffic, or fail closed. To avoid this you can install the In-line Bypass unit. The
bypass unit monitors the 7100 Series status, and if it senses a failure, the bypass
unit provides direct network connectivity.
There are two bypass unit models, called the 2 In-line Bypass unit and the 4
In-line Bypass unit. The two models are designed to accommodate 7100 Series
appliances with either four or eight copper monitoring interface ports. The
following table summarizes the features of the bypass unit models:
Table 3-2
Bypass unit features
Feature
2 In-line Bypass
unit
4 In-line Bypass
unit
Supported appliance model
7120
7160
Supported number of in-line interface
pairs (equals number of port groups on
bypass unit)
2
4
10/100/1000 Base-TX (MDIX) interfaces
2
4