A Intelligent Virtual Execution - Server appliance is ready to be a compute node as soon as it is added to an IVX cluster. The cluster interface that the compute node uses to communicate with the brokers and other compute nodes is defined in the configuration wizard during the initial configuration of the Intelligent Virtual Execution - Server appliance. The submission interface that the broker uses to communicate with sensors and hybrid appliances is also defined in the configuration wizard. You must manually designate a compute node as a broker. A broker can perform analysis as well as managing the queue.
The detection-related configuration settings on all compute nodes must match, because any compute node in a cluster can process submissions from any sensor or hybrid appliance. One broker must be designated as the master configuration. The Central Management appliance that manages the IVX cluster synchronizes relevant configuration settings on other compute nodes (including brokers) with the master configuration.
An Network Security sensor or an Network Security hybrid appliance applies its policies and filters to the traffic it receives on its monitoring ports, and extracts suspicious or malicious files and URLs that need to be inspected by the IVX cluster. An Email Security - Server sensor or hybrid appliance applies its policies and filters to the emails it receives on its network interfaces, and extracts suspicious or malicious files or URLs that need to be inspected by the IVX cluster. An Network Security sensor or hybrid appliance applies its policies and filters to the scans it runs on network shares, and extracts suspicious or malicious files that need to be inspected by the IVX cluster. The sensor or hybrid appliance then sends a submission to its dedicated broker.
The broker receives the submissions from the sensor or hybrid appliance and places them in the queue. Each compute node is connected to all brokers in its cluster. When a compute node has processing capacity, it pulls submissions from a broker and performs the analysis. The compute node sends the verdict and malware artifacts to the sensor or hybrid appliance through the broker. The sensor or hybrid appliance generates alerts and takes action based on its deployment and operational mode and policies.