Prerequisites:
You require two Cat 5/Cat 5e Ethernet cables to connect your fail-open switch to the Sensor.
You require two copper SFP modules to be inserted into two corresponding unused modular sockets on the Sensor.
Tip
For more details about your Sensor and SFP modules, refer to the Trellix Intrusion Prevention System NS-series Sensor Product Guide for the appropriate model.
Control cable that is supplied with the fail-open kit.
Steps:
Connect a Cat 5/Cat 5e Ethernet cable (inside) into the copper SFP in port Gy/a or xA, where y represents the module number (for NS-Series Sensors), and x and a represent port numbers.
Connect the other end of the cable to the port labeled Monitor A on the fail-open switch.
Connect a Cat 5/Cat 5e Ethernet cable (outside) to the corresponding Gy/b or xB peer port. (For example, if you used G0/1 in step 1, plug the cable into port G0/2).
Connect the other end of the cable to the port labeled Monitor B of the fail-open switch.
Connect one end of the control cable to the fail-open switch Control port.
Connect the other end to the Sensor control port Xy, where y is the port number that corresponds to one of the monitoring ports. The table below shows the control ports of compatible NS-Series Sensors and the corresponding port pairs that should be used for connection.
NS-Series Sensor
Control Port
Port (inside)
Port (outside)
NS7x00, NS7x50, NS7500
X1
G0/1
G0/2
NS5x00
X1
G1/1
G1/2
X2
G1/3
G1/4
X3
G1/5
G1/6
X4
G1/7
G1/8
X5
G1/9
G1/10
X6
G1/11
G1/12
Result: With this cable configuration, Sensor monitoring port Gy/a or xA views traffic as originating inside the network, and port Gy/b or xB view traffic as emerging outside the network. This configuration (Gy/a or xA = outside, Gy/b or xB = inside) must match the port configuration specified for this Sensor, and the ports must be configured accordingly.