You can use the following information to verify if you have deployed the Virtual Sensor correctly and if it is inspecting traffic.
Task
- Make sure the Sensor management port and the Manager server and can reach each other.
- On the Sensor CLI, use the status and show commands to see whether the trust is established, the channels are up, and the Sensor is in good health.
- On the Manager Dashboard, check the System Faults monitor to verify if the Sensor is active.
- In the Manager, select Devices → <Admin Domain Name> → Devices → <Device name> → Setup → Physical Ports and check if the monitoring ports are up.
- Verify if the client and server are reachable to one another.
- Send a sample attack from the client to the server, for example, execute root.exe, and check if an alert is raised in the Attack Log with the correct details.
- After you deploy a Virtual Sensor, the process of configuring and managing it is similar to that of a physical Sensor. Therefore, refer to the relevant sections in the Trellix Virtual Intrusion Prevention System Product Guide for more details.