Deploying virtual Network Security appliances using Hyper-V Manager in inline mode

Prev Next

In a typical Network Security inline deployment, port pair A is the inline port pair. The pether3 monitoring interface is connected to the subnet that hosts the on-premises enterprise clients (the client subnet) and the pether4 monitoring interface is connected to a subnet that hosts the Network Security appliance (the server subnet).

Example addresses for the subnets and interfaces are shown below.Example addresses for the subnets and interfaces are shown below.

  • Client subnet—10.100.1.64/27

  • Network Security pether3 interface—10.100.1.69

  • Server subnet—10.100.1.96/27

  • Network Security pether4 interface—10.100.1.100

Note

This procedure assumes that the interface pair

The following task is required to configure a virtual Network Security appliance in inline mode. No additional tasks are required in Hyper-V Manager.

  • Use the policymgr layer3-mode enable command in the Network Security CLI to enable Layer 3 forwarding. For detailed information and additional commands, see the "Layer 3 Forwarding Using VRF Instances" information in the Network Security System Administration Guide.