Prerequisites:
You require two LC-LC cables to connect your fail-open switch to the Sensor.
If you are connecting a 1-Gigabit fail-open switch, you require two fiber SFP modules to be inserted into two corresponding unused module sockets on the Sensor.
If you are connecting a 10-Gigabit fail-open switch, you require two fiber SFP+ modules to be inserted into two corresponding unused module sockets on the Sensor.
Tip
For more details about your Sensor or SFP/SFP+ modules, refer to the Trellix Intrusion Prevention System NS-series Sensor Product Guide for the appropriate model.
Control cable that is supplied with the fail-open kit.
Steps:
Connect an LC-LC cable into the LC receptacle of port Gy/a or xA, where y represents the module number (for NS-Series Sensors), and x and a are the port numbers.
Connect the other end of the LC cable to the LC receptacle labeled Monitor A of the fail-open switch.
Connect an LC-LC cable to the corresponding Gy/b or xB peer port. (For example, if you used G1/1 in step 1, plug the cable into port G1/2).
Connect the other end of this cable to the port labeled Monitor B of the fail-open switch.
Connect one end of the control cable to the fail-open switch Control port.
Note
The control port you connect to on the Sensor must correspond to the port pair you use. For example, if you used port pair G0/1-G0/2 on the Sensor, make sure you use Control port X1.
Result: With this cable configuration, Sensor Monitoring port Gy/a or xA views traffic as originating inside the network, and port Gy/b or xB views traffic as originating outside the network. This configuration (Gy/a or xA = outside, Gy/b or xB = inside) must match the port configuration specified for this Sensor, and the ports must be configured accordingly.