•
•
•
•
•
•
NS9x00 Sensors
:
About Sensors
Sensors are high-performance, scalable, and exible content processing appliances built for the accurate detection and
prevention of:
Network intrusions
Network misuse
Distributed Denial-of-Service (DDoS) attacks
Sensors are specically designed to handle trac at wire speed, eciently inspect and detect intrusions with a high degree of
accuracy, and exible enough to adapt to the security needs of any enterprise environment. When deployed at key network
access points, the Sensor provides real-time trac monitoring to detect malicious activity and respond to such activity based on
the responses congured by the administrator.
After you deploy a Sensor successfully, you congure and manage it using the Manager. The process of conguring a Sensor
and establishing communication with the Manager is described in subsequent chapters of this guide. For the details about the
Manager, see the Manager Administration section in Trellix Intrusion Prevention System Product Guide.
:
Functions of an NS-series Sensor
The NS-series Sensors are a third-generation hardware platform for Sensors designed for high bandwidth links to oer Next
Generation IPS (NGIPS) capability and provide high aggregate throughput across various Sensor models. The following models
are supported.
NS9300 - The NS9300 Sensor consists of a Primary Sensor and a Secondary Sensor. Each of these is a 2RU unit, providing
an aggregate throughput of 40 Gbps.
NS9200 - The NS9200 Sensor is a 2RU unit providing an aggregate throughput of 20 Gbps.
NS9100 - The NS9100 Sensor is a 2RU unit providing an aggregate throughput of 10 Gbps.
The primary function of a Sensor is to analyze trac on selected network segments and to respond when an attack is detected.
The Sensor examines the header and data portion of every network packet, looking for patterns and behavior in the network
trac that indicate malicious activity. The Sensor examines packets according to user-congured policies, or rule sets, which
determine what attacks to watch for, and how to respond with countermeasures if an attack is detected.
If an attack is detected, a Sensor responds according to its congured policy. Sensor can perform many types of attack
responses, including generating alerts and packet logs, resetting TCP connections, "scrubbing" malicious packets, and even
blocking attack packets entirely before they reach the intended target.
:
Trellix Intrusion Prevention System NS-series Sensor Product Guide
| NS9x00 Sensors2
84