Skip to content

Commit 9b87675

Browse files
Merge pull request #310056 from DeCohen/WI538550-sensor-monitoring-erspan
Note about Erspan monitoring for Cisco
2 parents b98ae6e + 3da7c88 commit 9b87675

1 file changed

Lines changed: 12 additions & 8 deletions

File tree

articles/defender-for-iot/organizations/how-to-manage-individual-sensors.md

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ Take action by selecting the **Learn more** option under :::image type="icon" so
6363

6464
## Download software for OT sensors
6565

66-
You may need to download software for your OT sensor if you're [installing Defender for IoT software](ot-deploy/install-software-ot-sensor.md) on your own appliances, or [updating software versions](update-ot-software.md).
66+
You might need to download software for your OT sensor if you're [installing Defender for IoT software](ot-deploy/install-software-ot-sensor.md) on your own appliances, or [updating software versions](update-ot-software.md).
6767

6868
In [Defender for IoT](https://portal.azure.com/#view/Microsoft_Azure_IoT_Defender/IoTDefenderDashboard/~/Getting_started) in the Azure portal, use one of the following options:
6969

@@ -193,15 +193,15 @@ When you're done, use the following procedures to validate your certificate file
193193

194194
## Update the OT sensor network configuration
195195

196-
You'd configured your OT sensor network configuring during [installation](ot-deploy/install-software-ot-sensor.md). You may need to make changes as part of OT sensor maintenance, such as to modify network values or setting up a proxy configuration.
196+
After configuring your OT sensor network during [installation](ot-deploy/install-software-ot-sensor.md), you might need to make changes as part of OT sensor maintenance, such as modifying network values or setting up a proxy configuration.
197197

198198
**To update the OT sensor configuration:**
199199

200200
1. Sign into the OT sensor and select **System Settings** > **Basic** > **Sensor network settings**.
201201

202202
1. In the **Sensor network settings** pane, update the following details for your OT sensor as needed:
203203

204-
- **IP address**. Changing the IP address may require users to sign into your OT sensor again.
204+
- **IP address**. Changing the IP address might require users to sign into your OT sensor again.
205205
- **Subnet mask**
206206
- **Default gateway**
207207
- **DNS**. Make sure to use the same hostname that's configured in your organization's DNS server.
@@ -250,6 +250,10 @@ For more information, see [ERSPAN ports](best-practices/traffic-mirroring-method
250250

251251
> [!NOTE]
252252
> This procedure restarts your sensor software to implement any changes made.
253+
>
254+
> Defender for IoT ERSPAN monitoring is tested, certified, and supported **only when the ERSPAN tunnel originates from Cisco devices.**
255+
>
256+
> ERSPAN tunnels from non-Cisco vendors are **not supported** and might fail due to differences in ERSPAN implementations.
253257
254258
**To update your sensor's monitoring interfaces**:
255259

@@ -269,7 +273,7 @@ For more information, see [ERSPAN ports](best-practices/traffic-mirroring-method
269273
|Name |Description |
270274
|---------|---------|
271275
|**Mode** | Select one of the following: <br><br>- **SPAN Traffic (no encapsulation)** to use the default SPAN port mirroring. <br>- **Tunneling** if you're using ERSPAN mirroring. <br><br>For more information, see [Choose a traffic mirroring method for OT sensors](best-practices/traffic-mirroring-methods.md). |
272-
|**Description** | Enter an optional description for the interface. You'll see this later on in the sensor's **System settings > Interface configurations** page, and these descriptions may be helpful in understanding the purpose of each interface. |
276+
|**Description** | Enter an optional description for the interface. You'll see this later on in the sensor's **System settings > Interface configurations** page, and these descriptions might be helpful in understanding the purpose of each interface. |
273277
|**Interface IP** | The ERSPAN IP on the sensor side. <br> - The management interface IP and the ERSPAN interface IP must be configured on separate network subnets. <br> - Configuring both the management and ERSPAN IP addresses on the same subnet might lead to asymmetric routing issues. |
274278
| **Subnet** | The subnet mask of the ERSPAN interface IP. |
275279
|**Name** | Enter a unique name for the virtual ERSPAN interface.|
@@ -286,7 +290,7 @@ For more information, see [ERSPAN ports](best-practices/traffic-mirroring-method
286290

287291
## Synchronize time zones on an OT sensor
288292

289-
You may want to configure your OT sensor with a specific time zone so that all users see the same times regardless of the user's location.
293+
You might want to configure your OT sensor with a specific time zone so that all users see the same times regardless of the user's location.
290294

291295
Time zones are used in [alerts](how-to-view-alerts.md), [trends and statistics widgets](how-to-create-trends-and-statistics-reports.md), [data mining reports](how-to-create-data-mining-queries.md), [risk assessment reports](how-to-create-risk-assessment-reports.md), and [attack vector reports](how-to-create-attack-vector-reports.md).
292296

@@ -337,7 +341,7 @@ Make sure you can reach the SMTP server from the [sensor's management port](./be
337341

338342
## Upload and play PCAP files
339343

340-
When troubleshooting your OT sensor, you may want to examine data recorded by a specific PCAP file. To do so, you can upload a PCAP file to your OT sensor and replay the data recorded.
344+
When troubleshooting your OT sensor, you might want to examine data recorded by a specific PCAP file. To do so, you can upload a PCAP file to your OT sensor and replay the data recorded.
341345

342346
The **Play PCAP** option is enabled by default in the sensor console's settings.
343347

@@ -370,7 +374,7 @@ The **Play PCAP** option is now available in the sensor console's settings, unde
370374

371375
By default, each OT network sensor analyzes ingested data using [built-in analytics engines](architecture.md#defender-for-iot-analytics-engines), and triggers alerts based on both real-time and prerecorded traffic.
372376

373-
While we recommend that you keep all analytics engines on, you may want to turn off specific analytics engines on your OT sensors to limit the type of anomalies and risks monitored by that OT sensor.
377+
While we recommend that you keep all analytics engines on, you might want to turn off specific analytics engines on your OT sensors to limit the type of anomalies and risks monitored by that OT sensor.
374378

375379
> [!IMPORTANT]
376380
> When you disable a policy engine, information that the engine generates won't be available to the sensor. For example, if you disable the Anomaly engine, you won't receive alerts on network anomalies. If you'd created a [forwarding alert rule](how-to-forward-alert-information-to-partners.md), anomalies that the engine learns won't be sent.
@@ -418,7 +422,7 @@ After clearing data on a cloud-connected sensor:
418422
- Some actions on corresponding alerts in the Azure portal are no longer supported, such as downloading PCAP files or learning alerts.
419423

420424
> [!NOTE]
421-
> Network settings such as IP/DNS/GATEWAY will not be changed by clearing system data.
425+
> Network settings such as IP/DNS/GATEWAY won't be changed by clearing system data.
422426
423427
**To clear system data**:
424428

0 commit comments

Comments
 (0)