Trellix Intrusion Prevention System Sensors, when deployed in-line, route all incoming traffic through a designated port pair. However, at times, a Sensor might need to be turned off for maintenance or its ports can go down because of an outage. In such a scenario, you might want to continue allowing traffic to pass through without interruption. For such requirements, you can consider an external device called a fail-open switch. The fail-open switch can either be an active fail-open switch or a passive fail-open switch.
Note
In this guide, unless explicitly stated, Trellix Intrusion Prevention System Manager is commonly referred to as "Manager" and Trellix Intrusion Prevention System Sensor is commonly referred to as "Sensor".
A passive fail-open switch relies on the Sensor to supply a power signal to the switch through a Control cable. The Control port on the Sensor is connected to a Control port on the fail-open switch by a Control cable. While the Sensor is operating, the switch is “on and routes all traffic directly through the Sensor. When the Sensor fails, the switch automatically shifts to a bypass state; in-line traffic continues to flow through the network link but is no longer routed through the Sensor. After the Sensor resumes normal operation, the switch returns to the "on" state, enabling in-line monitoring again. Certain Trellix IPS Sensors have Control ports. These ports are internally wired to the corresponding monitoring port pair.
The table below shows you the various models of passive fail-open switches.
Fail-open switch | SKU | NS9600 | NS9500 | NS9x00 | NS7600 | NS7500 | NS7x00/NS7x50 |
|---|---|---|---|---|---|---|---|
Passive-Fiber (850 nm) 10G (50 µm) | IAC-PF85050- KT1 | No | No | No | No | Yes (supported on G0 only) | Yes (supported on G0 only) |
Passive-Fiber (850 nm) 10/1G (62.5 µm) | IAC-PF85062- KT1 | No | No | No | No | Yes (supported on G0 only) | Yes (supported on G0 only) |
Passive-Fiber (1310 nm) 10/1G (8.5 µm) | IAC-PF131010- KT1 | No | No | No | No | Yes (supported on G0 only) | Yes (supported on G0 only) |
Passive-Copper 10/100/1000 | IAC-PFOCG- KT2 | No | No | No | No | Yes (1000Mbps supported on G0 only) | Yes (1000Mbps supported on G0 only) |
Fail-open switch | SKU | NS5x00 | NS3600 | NS3500 | NS3x00 |
|---|---|---|---|---|---|
Passive-Fiber (850 nm) 10G (50 µm) | IAC-PF85050- KT1 | Yes (supported on G0 only) | No | No | No |
Passive-Fiber (850 nm) 10/1G (62.5 µm) | IAC-PF85062- KT1 | Yes (10/1G supported on G0, but only 1G supported on G1) | No | No | No |
Passive-Fiber (1310 nm) 10/1G (8.5 µm) | IAC-PF131010- KT1 | Yes (10/1G supported on G0, but only 1G supported on G1) | No | No | No |
Passive-Copper 10/100/1000 | IAC-PFOCG- KT2 | Yes (1000Mbps supported on G0 and G1 only) | No | No | No |
Fiber fail-open switches consist of two types: single mode and multi-mode fibers. The table gives you some details about both types of fiber optic fail-open switches. Such information is important because you must determine the type of fiber optics used in your organization network before you decide which type of fail-open switch to use. It is also important to understand these types because all product documentation for fiber fail-open kits and decals on the fail-open switches display these parameters. The table below shows you the differences between single-mode and multi-mode fiber specifications.
Type | Fiber thickness | Wavelength range |
|---|---|---|
Single mode (Long reach) | 8.5 µm | 1300 nm to 1550 nm |
Multi-mode (Short reach) | 50 µm or 62.5 µm | 850 nm to 1300 nm |
Note
For more details on fail-open kits and Sensor compatibility with various fail-open kit models, refer to the chapter Fail-Open operation in Sensors in the Trellix Intrusion Prevention System Product Guide. Since this Quick Start Guide makes references to information associated with that chapter, keeping an easily accessible copy of it before you begin installing and configuring your fail-open switch will be helpful.