2.2.3. Management overview of `Management` and `Tunnel` interfaces

Important

Concept of role is introduced in the release 2.5.4.0.

These interfaces perform the following roles:

  • Role 1: called `tunnel`, is the secure communication between the probe and GCenter through an IPSEC tunnel in order to:

    • Escalate information such as files, alerts,metadata, and so on, derived from analyzing the monitored flows

    • Report information on the health of the probe to the GCenter

    • Control the probe - analysis rules, signatures, etc

  • Role 2 : called `management`, is the remote administration through the SSH protocol with access :

    • To the probe's command line interface (CLI)

    • To the graphical set / configuration menu


2.2.3.1. CLI commands

Managing the network interfaces is done using the CLI commands listed in the Summary of orders by theme and level table.


2.2.3.2. View or configure

To view or configure the network interfaces, refer to Procedure to manage the network parameters of `Tunnel` and `Management` interfaces.


2.2.3.2.1. Single interface configuration.

In single-interface configuration, role 1 and role 2 is assigned to one network interface.
To toggle from dual-interface to single-interface configuration, refer to Procedure to switch the single-interface configuration.

2.2.3.2.2. Dual-interface configuration

The `Management` and `Tunnel` roles are allocated over two network interfaces.

Important

This dual-interface configuration is mandatory if using the MPL mode on the GCenter.

The aim of this situation is to ensure that the management flow and the interconnection flow between the GCap and GCenter are separated from each other.

Note

Since version 2.5.4.0, you can assign role to the network of your choice.
We recommend the use of embedded gigabit interfaces.

To toggle from single-interface to dual-interface configuration, refer to Procedure to switch to the configuration dual-interface.