Sensor Placement

Prev Next

The following figure illustrates some of the areas in your network where you may want to place a Cloud Collector or Comm Broker, collectively referred to as network sensors. Trellix will provide you with the fully-qualified domain names (FQDN) of the dedicated receivers that your network sensors will use to send data to the Helix VPC.

Net_Topology.jpg

Cloud Collector Installation

Each Trellix Cloud Collector requires two network interfaces.

Note

For more diagrams that show connected interfaces, see Network Requirements.

The first interface, referred to as the monitor interface, collects data about your network traffic, and does not require a dedicated IP address. The monitor interface is connected to a network TAP (preferred) or SPAN port (for example, on the trusted side of an egress firewall) so it can monitor all incoming and outgoing network traffic.

The second interface, referred to as the management interface, connects to your internal network and is responsible for sending data to the Communications Broker Receiver in the Helix VPC, as well as allowing Trellix to remotely manage the server. The management interface connects to your internal network. You will configure this interface with an IP address for the subnet to which it is connected. Both static and dynamic IP addresses are supported.

Communications Broker Sender Installation

The Trellix Comm Broker requires a management interface only, as it does not actively monitor network traffic. It accepts logs from current log sources.

Traffic Management

To manage large streams of data both to the Comm Broker Sender or Cloud Collector (also called network sensors), and between the Comm Broker Sender or Cloud Collector and the Comm Broker Receiver, Helix supports multiple options.

Multiple Comm Brokers and Cloud Collectors

You can deploy multiple Comm Brokers or Cloud Collectors in your network. A single Comm Broker Receiver (in the Helix VPC) can receive traffic from multiple Cloud Collectors or Comm Brokers in your network. Each Cloud Collector and Comm Broker Sender operates independently.

Installing these network sensors closer to the data source conserves bandwidth. If your environment includes data centers that are regional, you can deploy one or more network sensors within each data center.

Load Balancers

Comm Brokers can be deployed behind load balancers for redundancy and load sharing. Load balancers can also be used to detect when systems are unavailable.

Domain Name Servers (DNS)

A DNS round robin can be used to provide redundancy. Some systems may not be capable of sending syslog to a DNS, however, and are limited to an IP destination only. You can also use low TTL DNS to help automatically fail over devices that use FQDN destinations for syslog.