Skip to content

Commit a532c3d

Browse files
Merge pull request #236090 from Shereen-Bhar/patch-41
Deploy with unidirectional gateways/data diodes
2 parents cff4770 + c3e7e34 commit a532c3d

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

articles/defender-for-iot/organizations/traffic-mirroring/configure-mirror-span.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,16 @@ switchport mode trunk
7474

7575
[!INCLUDE [validate-traffic-mirroring](../includes/validate-traffic-mirroring.md)]
7676

77+
## Deploy with unidirectional gateways/data diodes
78+
79+
You might deploy Defender for IoT with unidirectional gateways, also known as data diodes. Data diodes provide a secure way to monitor networks as they only allow data to flow in one direction. This means data can be monitored without compromising the security of the network, as data cannot be sent back in the opposite direction. Examples of data diode solutions are [Waterfall](https://waterfall-security.com/data-diode-solutions/), [Owl Cyber Defense](https://owlcyberdefense.com/products/data-diode-products/), or [Hirschmann](https://hirschmann.com/en/Hirschmann_Produkte/Hirschmann-News/Rail_Data_Diode/index.phtml).
80+
81+
If unidirectional gateways are needed, we recommend deploying your data diodes on the SPAN traffic going to the sensor monitoring port. For example, use a data diode to monitor traffic from a sensitive system, such as an industrial control system, while keeping the system completely isolated from the monitoring system.
82+
83+
Place your OT sensors outside the electronic perimeter and have them receive traffic from the diode. In this scenario, you’ll be able to manage your Defender for IoT sensors from the cloud, keeping them automatically updated with the latest threat intelligence packages.
84+
85+
<!--add in the diagram?-->
86+
7787
## Next steps
7888

7989
> [!div class="step-by-step"]

0 commit comments

Comments
 (0)