Configuring Mirror Mode

Mirror Mode monitors newly connected sessions through Mirroring port and blocks connection by transmitting TCP RST or ICMP Destination Unreachable packet.

Mirror mode requires at least two NICs. One NIC assigns an IP to manage the sensor and the other as an unnumbered NIC for Packet Monitoring.

For more information. See Policy Enforcement Methods

Global Mirror

The Global Mirror sensor monitors all Nodes.

  1. Go to System in the top panel
  2. Go to System > Sensors in the left System Management panel
  3. Select the desired sensor’s IP Address for Mirror
  4. Click Sensor tab
  5. Click the interface desired to use in mirror mode. eth1 There is no IP assigned to this interface
  6. Select Mirror in Sensor Mode
  7. Select Global in Mirror Operating Scope
  8. For Sensor Operating Mode, change to Enforcement
  9. Click Update

Note

If you use Global Mirror only, the agent must be installed on the endpoint because it is not registered as a node.

Local Mirror

You can use it with Host mode sensor to gather more information. Available in the same equipment as Host mode sensor.

  1. Go to System in the top panel
  2. Go to System > Sensors in the left System Management panel
  3. Select the desired sensor’s IP Address for Mirror
  4. Click Sensor tab
  5. Click the interface desired to use in mirror mode. eth1 There is no IP assigned to this interface
  6. Select Mirror in Sensor Mode
  7. Select Local in Mirror Operating Scope
  8. For Sensor Operating Mode, change to Enforcement
  9. Click Update

Note

Local Mirror can additionally use Traffic Monitoring.

  1. Find Traffic Monitoring section
  2. Collection Interval 0 is disable, minimum 10 seconds, maximum 1 day
  3. Time for Average minimum 10 seconds, maximum 1 day, Initial value is 5 minutes
  4. Minimum Update Value KB/s unit, the minimum value to update the traffic information, Initial value is 30 KB/s
  5. Update Fluctuation % unit, the minimum fluctuation percentage rate, Initial value is 30 %
  6. Destination based Status Collection Select On or Off, collect the traffic information based on the destination