Deployment Options

On-Premise

  • Network TAP (best practice): Passive, fail-safe full-duplex mirroring. Use optical/copper TAPs (Ixia, Keysight, or Gigamon) on critical links. Sensor receives traffic on a single or across multiple capture interfaces.
  • Switch SPAN Port (last resort): Configure port mirroring (Cisco monitor session, Arista mirror session, Juniper port-mirror). Use ERSPAN for remote sources.
  • Sensors operate in passive IDS mode by default.

Cloud Deployments

  • AWS: VPC Traffic Mirroring (filter by ENI, subnet, or VPC) targeting the Sensor’s ENI.
  • Azure: Virtual Network TAP or Network Watcher packet capture routed to Sensor VM.
  • GCP: Packet Mirroring policies targeting instance groups or specific VMs.
  • Sensors run as VMs in the same VPC/VNet. Manager can be deployed in the same cloud or on-premise (hybrid).
  • Supports multi-region and multi-account setups via transit gateways or peering.
VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches