SonicOSX 7 System

Configuring IPS Sniffer Mode

To configure IPS Sniffer Mode

  1. Navigate to NETWORK | System > Interfaces.
  2. Click on the Edit icon for the X2 interface. The Edit Interface dialog displays.
  3. Set the Mode / IP Assignment to Layer 2 Bridged Mode. The options change.
  4. Set the Bridged To: interface to X0.
  5. Select Only sniff traffic on the bridge-pair.
  6. Click OK to save and activate the change. The dialog closes, and the NETWORK | System > Interfaces page redisplays.
  7. Click the Edit icon for the X1 WAN interface. The Edit Interface dialog displays.
  8. Assign the X1 WAN interface a unique IP address for the internal LAN segment of your network — this might sound wrong, but this is actually the interface from which you manage the appliance, and it is also the interface from which the security appliance sends its SNMP traps as well as the interface from which it gets security services signature updates.
  9. Click OK.
  10. For traffic to pass successfully, you must also modify the firewall rules to allow traffic from the
    • LAN to WAN
    • WAN to the LAN
  1. Connect the:
    • Span/mirror switch port to X0 on the security appliance, not to X2 (in fact, X2 is not plugged in at all)
    • X1 to the internal network

Use care when programming ports spanned/mirrored to X0.

Informational videos with interface configuration examples are available online. For example, see How to configure the SonicWall WAN / X1 Interface with PPPoE Connection. This and other videos are available at: https://support.SonicWall.com/videos-product-select.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden