This section assumes the following for deploying the Virtual Sensor for scenario 1.
- The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.
- You have the privileges on the ESX server to add and modify vSwitches and port groups.
- You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch1.
- As an example, this section uses the IPS-VM600 Virtual Sensor to explain the deployment.
- This scenario involves only a Sensor monitoring port deployed in SPAN mode.
- This section uses only the vSphere Client for configurations on the ESX.
Task
-
Modify vSwitch0 to create a switch port group in promiscuous mode.
Refer to the section Modify an existing standard vSwitch for a monitoring port. Subsequently, you assign this switch port group to the SPAN port.
-
Modify vSwitch0 to create a switch port group.
Subsequently, you assign this switch port group to the Sensor response port.
-
Configure the SPAN port on the Virtual Sensor in the Manager.
- Click the Devices tab.
- Select the domain from the Domain drop-down list.
- In the left pane, click the Devices tab.
- Select the device from the Device drop-down list.
- Select Setup → Physical Ports.
- Double-click on monitoring port 1 and then from the Mode drop-down, select SPAN or Hub.
- Click OK.
- Click Save in the Monitoring Port Details panel.
- Select Deploy Pending Changes and, in the Deploy Pending Changes page, select Configuration & Signature Set for the required Virtual Sensor. Click Update.
-
Assign the switch port groups you created in steps 1 and 2 to the Sensor SPAN port and the response port respectively.
See the section Specify the switch port groups for monitoring ports.
-
Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.
Refer to the section Verify the deployment.