Windows: Configuring an Inspection Engine
Configure or modify an inspection engine in the S-TAP Control pane.
Before you begin
About this task
Do not configure an S-TAP inspection engine to monitor network traffic that is also monitored directly by a Guardium system that is hosting the S-TAP, or by another S-TAP reporting to the same Guardium system. That would cause the Guardium system to receive duplicate information: it would not be able to reconstruct sessions, and it would ignore that traffic.
You can also add inspection engines directly in the guard_tap.ini file, see Editing the protocol 7 and protocol 8 S-TAP configuration parameters.
You can define up to 50 inspection engines per S-TAP.
Procedure
- Navigate to .
-
In the row of the S-TAP, click
.
The S-TAP Configuration window opens. -
Scroll to the bottom of the inspection engines, and click
next to Add Inspection Engine....
- Select the protocol and enter the port range. The window refreshes with the relevant parameters, some with their default values.
- Configure all required parameters, and click Add. If you are missing parameters, the system informs you what is missing.