Support Center > Search Results > SecureKnowledge Details
How to activate inspection on internal traffic on Quantum Spark appliances Technical Level
Solution

By default, LAN traffic is not inspected by deep inspection blades.

To turn on deep inspection:

For Locally Managed appliances: 

  1. In the WebUI, go to DeviceAdvanced Settings.

  2. Search for these Stateful Inspection attributes:

    • Perform deep packet inspection on LAN to LAN traffic

    • Perform deep packet inspection on traffic between LAN and DMZ networks

  3. For each one, double click the attribute name.

  4. In the window that opens, select the checkbox and click Apply.

 

For Centrally Managed appliances:

  1. Connect to the Security Management Server with the GuiDBedit Tool.

  2. Go to Global Properties > properties > firewall_properties and locate a property called dpi_lan_lan or dpi_lan_dmz.

  3. Set the relevant property to true.

  4. Save the changes: go to the File menu and click Save All.

  5. Close the GuiDBedit Tool.

  6. Install the policy on your device.

Note:

The LAN interfaces should be set to separate network and unassigned from the internal switch.
Traffic between two LAN interfaces which are assigned to the switch will not be inspected even when the above settings are applied.

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment