Thursday, October 13, 2011

Network Agent

Network Agent monitors all Internet requests and sends them to Websense Filtering Service. Network Agent also sends block messages to users attempting to access filtered content


Network agent acts as a packet sniffer – using promiscuous mode to capture and
analyse packets.

Must be deployed where it can see all internal Internet traffic


Network Agent can typically monitor 50 Mbits of traffic per second, or about
800 requests per second. The number of users that Network Agent can monitor

Up to 4 Network Agents can be deployed per Filtering Service


In Integrated mode – its function is to cover non-HTTP protocols and tunnelled
protocols


Change a port mode to spanning, mirroring, or monitoring mode).
Websense strongly recommends using a switch that supports bidirectional spanning.
This allows Network Agent to use a single network card (NIC) to both monitor traffic
and send block pages.

Network Agent Functionality:
1. Network agent is deployed with a connection to the core switch providing full
visibility of all network traffic originating from the corporate LAN
2. Network Agent captures protocol (and web traffic in standalone mode) and
determines policy disposition by contacting the filtering service
3. If the communication is not permitted, Network Agent uses a TCP reset
(RST) to terminate the session.



No comments:

Post a Comment