- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-08-2014 04:30 AM
I received a PA-200 device for review and testing. I like to set it up besides my current firewall and see what it can filter.
Via SPAN Monitor on a Cisco switch I copy all traffic on the UNTRUST side to the PA-200. Now I get a lot of tcp-reject-non-syn drops.
What is the correct way to configure the PA-200 to listen to all traffic on the UNTRUST line?
04-08-2014 06:18 AM
Normally you mirror the port from the "external" working interface to wherever the PAN is plugged into, and configure the PAN to be in a "TAP" interface mode.
Is the PAN in "TAP" mode for its interface?
Per the Admin guide, it states the following:
Tap Mode Deployments
A network tap is a device that provides a way to access data flowing across a computer network. Tap
mode deployment allows you to passively monitor traffic flows across a network by way of a switch
SPAN or mirror port.
The SPAN or mirror port permits the copying of traffic from other ports on the switch. By dedicating an
interface on the firewall as a tap mode interface and connecting it with a switch SPAN port, the switch
SPAN port provides the firewall with the mirrored traffic. This provides application visibility within the
network without being in the flow of network traffic.
Note: When deployed in tap mode, the firewall is not able to take action, such as
blocking traffic or applying QoS traffic control.
04-08-2014 06:22 AM
Thanks jdelio.
That seems what I am looking for. The admin guide is not telling much, but using tap mode deployment I could find an how to on configuring this.
Cheers,
Menno.
04-08-2014 06:45 AM
Please mark this as "Correct" or "Helpful" as this will help everyone in the community. 😃 Glad I could help.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!