Installation guide

Contents
Preface ........................................................................................................... v
Introducing McAfee Network Security Platform............................................................................. v
About the Guide ............................................................................................................................ v
Conventions used in this guide ..................................................................................................... v
Related documentation .................................................................................................................vi
Contacting Technical Support ......................................................................................................vii
Chapter 1 Background.................................................................................. 1
Chapter 2 Network Security Platform Failover Architecture .................... 2
Chapter 3 Sensor Failover Implementation................................................ 3
Chapter 4 Understanding the current network topology.......................... 4
Two paths - Active/Passive ........................................................................................................... 4
Two paths - Active/Active.............................................................................................................. 4
A single path.................................................................................................................................. 5
Chapter 5 Determining optimal Sensor location........................................ 6
Redundant Sensors on a single path ............................................................................................ 8
Preventing duplicate alerts.......................................................................................................... 10
Summary..................................................................................................................................... 10
Chapter 6 Configuring the ports on each Sensor.................................... 11
Potential pitfall............................................................................................................................. 12
A note on fail open functionality for GE ports.............................................................................. 12
A caution about active-passive failover....................................................................................... 13
Chapter 7 How dongles work..................................................................... 14
Chapter 8 Physically installing the Sensors ............................................ 18
Reality check - Asymmetric routing............................................................................................. 21
Chapter 9 Defining the Network Security Platform Failover Pair........... 22
Chapter 10 Cabling the heartbeat connection ......................................... 25
Initial hints ................................................................................................................................... 25
GBIC cabling ............................................................................................................................... 26
Important notes ....................................................................................................................27
Cabling guidelines and examples................................................................................................ 27
I-1200 and I-1400 examples ................................................................................................27
I-2700 examples...................................................................................................................27
I-4000 example ....................................................................................................................28
I-3000 and I-4010 examples ................................................................................................28
TX GBICs .................................................................................................................................... 28
Cabling failover through a network device .................................................................................. 29
Chapter 11 Verifying the failover configuration....................................... 30
iii