It all begins with estimating the requirements of your organization’s network. If it is paramount to allow uninterrupted traffic flow to the network, a fail-open deployment will work best. However, if security cannot be compromised at any instant, you must choose a fail-closed configuration. Both deployments come with inherent advantages and disadvantages. While a fail-closed setup ensures that all traffic entering the network is monitored, it results in network outages which may not be favorable if you host business-critical servers in the network. On the other hand, a fail-open setup ensures that traffic is never interrupted but can result in malicious traffic entering the network during a Sensor outage. So, this is the first choice that you, as a security analyst, need to make.
Broadly, these are the benefits of choosing a fail-open network architecture.
It reduces network downtime to seconds during any Sensor reboot or Sensor failure.
It protects your network during link failure on the Sensor.
It bypasses the Sensor when troubleshooting network issues. This will help you identify or eliminate the Sensor as the cause of network issues.
Fail-closed configuration
To configure your network for fail-closed operation, you will simply need to make sure that a port pair on the Sensor is set to inline fail-closed configuration.
Fail-open configuration
Should you decide to go the fail-open route, you have two options:
Internal fail-open: Fail-Open is built into some of the Sensor ports
Note
When a port pair is configured for internal fail-open, the downtime between link failure on the Sensor and bypass can be a maximum of 3 seconds.
External fail-open: Fail-Open is carried out using external hardware
If you use a Sensor that supports internal fail-open, you simply need to configure the appropriate port pair for inline fail-open.
If you use a Sensor that supports external fail-open, you will need to make sure you have the additional hardware necessary for an inline fail-open deployment. Trellix IPS provides a range of fail-open kits to accommodate diverse requirements. You must purchase a fail-open kit that best suits your requirements and one that is compatible with your existing network infrastructure. The primary component in a fail-open kit is the fail-open switch, which can be active or passive.
An active fail-open switch sends a signal to the Sensor at regular intervals and awaits a response. A response indicates that the Sensor is operating normally. This signal is called a “heartbeat” signal. If the switch does not receive a response for a set number of signals, it removes the Sensor from the path of traffic and routes all traffic through its own ports, thereby ensuring continuous traffic flow.
A passive fail-open switch relies on the Sensor to send an electrical signal to determine if the Sensor is operating normally. If the switch does not receive a signal in a specified period, it removes the Sensor from the path of network traffic and bypasses the Sensor, routing traffic through its own ports.
Note
A heartbeat signal is a data packet that is sent by the Sensor or by the fail-open switch (depending on whether it is passive or active). Regardless of whether it is passive or active, a signal is sent at regular intervals and is used by the fail-open switch to determine the operational state of the Sensor. The interval between each signal varies with the type of fail-open switch you are using.