Traffic that uses different paths for the request and response is termed as asymmetric traffic. There are chances of having asymmetric traffic within a network, when networks increase in size.
If there are chances of asymmetric traffic in your network, consider the following options:
Install IPS Sensors at a location where the traffic is symmetric.
Place an IPS Sensor each on the request and the response path of the asymmetric traffic and create a HA pair to sync up the traffic flow between the two Sensors.
When the distance between the two IPS Sensors is such that a HA pair cannot be created, consider enabling Stateless Inspection.
Note
Sensors in a HA pair scan the traffic independently, but they also share the information with each other during the scanning process. In this way, if a flow happens to be asymmetrically routed across both Sensors, each Sensor will end up with full flow.
.png)
The diagram above explains about HTTP traffic flow in an asymmetric network between User A and the University Admin server. The outgoing connection flow from User A is through Switch 1, Switch 2, Sensor 1, Router 1, Internet Service Provider 1, to the Internet connection. The return path for the packet however, is through Internet Service Provider 2, Router 2, and so on. If traffic flows by the Sensor in an asymmetric manner as described above, all packets of a TCP flow are not visible to a single Sensor. In such a scenario, if Stateless Inspection is enabled, the Sensor will inspect packets without having the valid state for the TCP connection.
Caution
When you enable Stateless Inspection, there are chances of false positives, false negatives, and lower detection accuracy compared to when the Sensor sees all traffic. This is because, when a single communication flow is divided across paths, each interface will receive and analyze part of the conversation. Trellix recommends that you use Stateless Inspection only when network configuration does not allow the Sensor to be placed in locations where it could see all traffic.