Network Engine

Network Engine

The Agent/Appliance's network engine can operate Inline or in Tap Mode. When operating Inline, the live packet stream passes through the network engine. Stateful tables are maintained, Firewall Rules are applied and traffic normalization is carried out so that Intrusion Prevention Rules can be applied to payload content. When operating in Tap Mode, the live packet stream is cloned and diverted from the main stream. In Tap Mode, the live packet stream is not modified; all operations are carried out on the cloned stream.

Events

You can set the maximum size of each individual log file and how many of the most recent files are kept. Event log files will be written to until they reach the maximum allowed size, at which point a new file will be created and written to until it reaches the maximum size and so on. Once the maximum number of files is reached, the oldest will be deleted before a new file is created. Event log entries usually average around 200 bytes in size and so a 4MB log file will hold about 20,000 log entries. How quickly your log files fill up depends on the number of rules in place.

Anti-Evasion Settings

Anti-Evasion settings control the network engine handling of abnormal packets that may be attempting to evade analysis.

Posture: There are three options for the Posture setting. This setting can be inherited from the parent policy:

Advanced Network Engine Settings

Generate an Alert when Agent configuration package exceeds maximum size: Yes or No. The default is Yes.

If you deselect the Default checkbox, you can customize these settings: