This section assumes the following for deploying the Virtual Sensor for scenario 3.
The ESX server meets the requirements as discussed in Requirements for deploying the Virtual Sensor.
You have the privileges on the ESX server to add and modify vSwitches and port groups.
You have installed the Virtual Sensor and established trust with the Manager successfully. As an example in this scenario, the management port is connected to vSwitch2.
As an example, this section uses the IPS-VM5000 Virtual Sensor to explain the deployment.
This scenario involves only a Sensor monitoring port pair deployed in inline fail-closed mode.
This section uses only the vSphere Client for configurations on the ESX.
Steps:
Create a standard vSwitch for connecting Sensor monitoring port 2 with the external network through vmnic0. For this scenario, consider it is vSwitch1.
Refer to the section Create a standard vSwitch for a monitoring port.
Make sure this vSwitch has a physical adapter and that this is connected to the corresponding external switch.
Modify vSwitch0 to connect monitoring port 1 and the virtual servers.
For this scenario, you need not change the switch port group for the virtual servers. Create a new switch port group for monitoring port 1. Refer to the section Modify an existing standard vSwitch for a monitoring port.
Assign the corresponding switch port group (promiscuous mode) to the monitoring ports.
See the section Specify the switch port groups for monitoring ports.
The switch port group that you created in step 1 (vSwitch1) must be assigned to monitoring port 2.
The switch port group that you created in step 2 (vSwitch0) must be assigned to monitoring port 1.
Verify if you have deployed the Virtual Sensor correctly and whether it is inspecting traffic.
Refer to the section Verify the deployment.