This section discusses the generic requirements and notes that you need to consider with respect to active fail-open kits:
The currently supported active fail-open kits are not plug and play devices. Initial configuration/setup is required before you begin.
The following default options are fixed in Trellix active fail-open kits and cannot be changed:
LFD is set to On
Bypass Detection is set to Off
Note
Even if you change the configuration for these options using the NetOptics Web Manager or System Manager, the settings of these options on the Trellix active fail-open kit hardware cannot be changed.
The management port on the active fail-open bypass kits cannot be configured.
The parameters for the monitoring port must be set to Auto-Negotiate based on the speed, that is, 10/100/1000 Mbps. Trellix recommends that you set the Speed to 100 Mbps full Duplex with Auto-Negotiate enabled to improve performance.
Unlike passive fail-open kits, an active fail-open kit moves into the bypass mode only when it does not receive the heart beat signals within its programmed interval. When the Sensor monitoring port is manually disabled or the cable is pulled out, for example, the Manager displays the port status as AUK (Active Unknown) under Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Physical Ports page.
If you are planning to use the 10/100/1000 copper active fail-open kit with SNMP monitoring, note that Trellix IPS currently supports only SNMP v1 on active fail-open kits.
You can configure only a single SNMP Manager. The option to configure a secondary SNMP Manager is currently not available.
The active fail-open kits do not provide any CLI option to view the serial and model numbers of the kits.
If your network architecture is such that it requires you to remotely manage the active fail-open kits in your deployment, you can consider one of the following options:
Use a terminal server to connect to the system console and then connect using a remote login (interoperability issues might be seen while using UPLOGIX Terminal Server)
Pre-configure the kit with the required settings before shipping.