Shiela012 Lv3Posted 18 Sep 2023 13:28
  
Sangfor NGAF_V8.0.5_Bypass Mode Deployment Guide
1 Applicable Scenario
Bypass Mode: It can protect while not affecting the user network environment and avoid downtime risk caused by NGAF devices. It will connect to the mirror port of the switch to ensure that traffic will go through the switch when the user accesses the server.
2 Configuration Steps
2.1 Configure Interfaces and Logging Option
Navigate to Network > Interface to add or modify the zone and the type of Physical Interface. Set the Network Objects into your desired group of users.
2.2 Configure Logging Option
Navigate to System > Logging Option to activate the Internal Report Center from Traffic audit logs section, as shown below. Kindly click the Apply button to save the configuration from allowing NGAF to audit the user's traffic in their network activities.
2.3 Configure IPS and WAF Policies
Access to Policies and configure IPS and WAF features.
You can check the Realtime Vulnerability Analytics checkbox if you need it for your server.
In Protection, you can activate Intrusion Prevention and Web App Protection.
Navigate to System > General > System > Network, check the Send TCP Reset message in mirror mode to reject checkbox to prevent the packets from entering the network from WAF/IPS.
3 Precautions
AF traffic ranking will show the traffic of the local IP group and non-local IP group.
If there are any other protection functionalities, you have to navigate to System > Network > and select Send TCP Reset message in mirror mode to reject. Else, WAF, IPS, or other functionalities will not be effective.

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders