Network Considerations

The OT Security appliance (both physical and virtual) must reach these network interfaces:

Management and Active Query Interface

  • An interface configured with an IP address that allows network reachability to manage and configure the appliance.

  • Allows the appliance to reach assets on the network for active querying (recommended, but optional).

Monitoring Interface

  • Passively monitors and collects traffic for analysis.

  • Must be connected to a Mirroring, Switch Port Analyzer (SPAN), or Remote Switch Port Analyzer (RSPAN) destination interface of a switch.

  • (Optional) Uses sensors and Encapsulated Remote SPAN (ERSPAN) configuration to monitor traffic that cannot mirror directly into the appliance interface.