Configuring a virtual Network Security network using Microsoft Hyper-V Manager

Prev Next

The number of virtual and physical adapters you need for a virtual Network Security appliance depends on the virtual model and the deployment mode. A Network Security appliance deployed in an inline deployment mode uses both ports of each monitoring interface pair. A Network Security appliance deployed in an out-of-band mode uses one port of a monitoring port pair for each connection to the external network.

The default virtual switch for the management network in the Hyper-V server can be connected to the network adapter for the ether1 management interface on the Network Security appliance. Other virtual switches are required for the other network interfaces, as described in Microsoft Hyper-V Requirements.

Note

A Network Security appliance can have up to ten network interfaces—one management interface, one submission interface, and up to eight monitoring interfaces. However, Hyper-V Manager on Windows Server 2016 supports a maximum of eight network adapters.

This section assumes that each network adapter is connected to a separate virtual switch. You can create sub-interfaces of the monitoring ports of a virtual Network Security appliance based on VLAN or CIDR. However, this is beyond the scope of this document.

To configure Network Security networking:
  1. Make sure the required switches exist, as described in Microsoft Hyper-V requirements.

  2. Make sure all network adapters are added and connected to a virtual switch as described in Installing a virtual Network Security appliance using Microsoft Hyper-V Manager.

  3. Configure the deployment mode for the virtual Network Security appliance: