EasyManua.ls Logo

Trellix NS Series - Ns9 X00 Sensors; About Sensors; Functions of an NS-Series Sensor

Default Icon
309 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
•
•
•
•
•
•
NS9x00 Sensors
:
About Sensors
Sensors are high-performance, scalable, and exible content processing appliances built for the accurate detection and
prevention of:
Network intrusions
Network misuse
Distributed Denial-of-Service (DDoS) attacks
Sensors are specically designed to handle trac at wire speed, eciently inspect and detect intrusions with a high degree of
accuracy, and exible enough to adapt to the security needs of any enterprise environment. When deployed at key network
access points, the Sensor provides real-time trac monitoring to detect malicious activity and respond to such activity based on
the responses congured by the administrator.
After you deploy a Sensor successfully, you congure and manage it using the Manager. The process of conguring a Sensor
and establishing communication with the Manager is described in subsequent chapters of this guide. For the details about the
Manager, see the Manager Administration section in Trellix Intrusion Prevention System Product Guide.
:
Functions of an NS-series Sensor
The NS-series Sensors are a third-generation hardware platform for Sensors designed for high bandwidth links to oer Next
Generation IPS (NGIPS) capability and provide high aggregate throughput across various Sensor models. The following models
are supported.
NS9300 - The NS9300 Sensor consists of a Primary Sensor and a Secondary Sensor. Each of these is a 2RU unit, providing
an aggregate throughput of 40 Gbps.
NS9200 - The NS9200 Sensor is a 2RU unit providing an aggregate throughput of 20 Gbps.
NS9100 - The NS9100 Sensor is a 2RU unit providing an aggregate throughput of 10 Gbps.
The primary function of a Sensor is to analyze trac on selected network segments and to respond when an attack is detected.
The Sensor examines the header and data portion of every network packet, looking for patterns and behavior in the network
trac that indicate malicious activity. The Sensor examines packets according to user-congured policies, or rule sets, which
determine what attacks to watch for, and how to respond with countermeasures if an attack is detected.
If an attack is detected, a Sensor responds according to its congured policy. Sensor can perform many types of attack
responses, including generating alerts and packet logs, resetting TCP connections, "scrubbing" malicious packets, and even
blocking attack packets entirely before they reach the intended target.
:
Trellix Intrusion Prevention System NS-series Sensor Product Guide
| NS9x00 Sensors2
84

Table of Contents