Once communication between the Sensors has been confirmed, the failover configuration should be tested.
The way in which the configuration is best validated will vary from setup to setup, but these tests should be similar to the ones performed after the Sensors were physically installed on the network.
The key differences this time include the following:
In the specific case in which the network at hand has two active paths that route asymmetrically, the intrusion tests that previously failed should now be successful because both Sensors are analyzing all packets from all flows.
Existing session state should not be lost when a Sensor goes offline.
The most precise way to confirm that the session remained intact after the "failure" is to capture and analyze packets. A more rudimentary test is to open a browser and start a large download while one Sensor is taken offline. If the state is successfully kept, there will be no fatal interruption in the download process.
If the state is lost, confirm that the Sensors are indeed communicating with each other.
If the Sensors are not communicating, try the following steps in the order shown:
Cold start both Sensors.
Reconnect the cables between them. Check if the Media Type is selected as Copper when using copper SFP.
Recreate the HA pair.
If GBICs are used, confirm that Trellix supplied them.
Caution
Non-Trellix GBICs are known to create problems. If the GBICs used are not from Trellix pricelist, temporarily swap them out for those that are before spending more time on troubleshooting.
If they are communicating:
Capture packets simultaneously on both redundant paths. This will provide a full picture of the data flow, and more insight into the problem.