This section assumes the following for deploying the Virtual Sensor for scenario 1.
The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.
You have the privileges on the ESX server to add and modify vSwitches and port groups.
You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch1.
As an example, this section uses the IPS-VM5000 Virtual Sensor to explain the deployment.
This scenario involves only a Sensor monitoring port deployed in SPAN mode.
This section uses only the vSphere Client for configurations on the ESX.
Steps:
Modify vSwitch0 to create a switch port group in promiscuous mode.
Refer to the section Modify an existing standard vSwitch for a monitoring port. Subsequently, you assign this switch port group to the SPAN port.
Modify vSwitch0 to create a switch port group.
Subsequently, you assign this switch port group to the Sensor response port.
Configure the SPAN port on the Virtual Sensor in the Manager.
Click the Devices tab.
Select the domain from the Domain drop-down list.
In the left pane, click the Devices tab.
Select the device from the Device drop-down list.
Select Setup → Physical Ports.
Double-click on monitoring port 1 and then from the Mode drop-down, select SPAN or Hub.
Click OK.
Click Save in the Monitoring Port Details panel.
Select Deploy Pending Changes and, in the Deploy Pending Changes page, select Configuration & Signature Set for the required Virtual Sensor. Click Update.
Assign the switch port groups you created in steps 1 and 2 to the Sensor SPAN port and the response port respectively.
See the section Specify the switch port groups for monitoring ports.
Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.
Refer to the section Verify the deployment.