121
Zenarmor (Sensei) / Re: I need some advice for a first installation of Zenarmor
« on: February 10, 2024, 08:55:36 pm »
Hi,
1- It is in our roadmap. Please keep in touch for the announcement.
2- You can not protect the same interface with Suricata in (IPS mode) and Zenarmor. You can protect your WAN interface on Zenarmor.
3- The default policy matches the session which if it is not match any custom policy. So you need to set each policy rules individually. The default policy settings will be applied only the sessions that matches it.
4- Home license has the default + 2 custom policies.
5- It is enough to protect only the parent interface. Zenarmor will cover VLANs inside it. If you protect both the parent and child interface together, the traffic will be inspected 2 times.
6- Zenarmor always checks the network packages if there is more detail or new information for the devices until you activate stop device updates in device detail.
7- It should be better to wait a bit more. Zenarmor catches the information from network packages and match them with its device identification database. If it is not be corrected for a while, please share Zenarmor logs with the team via Have feedback option in UI. It could be a false positive classification.
1- It is in our roadmap. Please keep in touch for the announcement.
2- You can not protect the same interface with Suricata in (IPS mode) and Zenarmor. You can protect your WAN interface on Zenarmor.
3- The default policy matches the session which if it is not match any custom policy. So you need to set each policy rules individually. The default policy settings will be applied only the sessions that matches it.
4- Home license has the default + 2 custom policies.
5- It is enough to protect only the parent interface. Zenarmor will cover VLANs inside it. If you protect both the parent and child interface together, the traffic will be inspected 2 times.
6- Zenarmor always checks the network packages if there is more detail or new information for the devices until you activate stop device updates in device detail.
7- It should be better to wait a bit more. Zenarmor catches the information from network packages and match them with its device identification database. If it is not be corrected for a while, please share Zenarmor logs with the team via Have feedback option in UI. It could be a false positive classification.

