What you are evaluating
Evaluate the sensor and Center configuration for the actual hardware and software release. Current product material also describes segmentation and remote access; validate the relevant hardware, entitlement and enforcement components separately.
A useful evaluation context
Teams designing OT visibility around supported industrial networking infrastructure.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Sensors inspect industrial traffic and send identified assets, flows and security events to Center.
- Supported passive mirroring and Active Discovery provide different collection paths.
- The sensor guide states TCP and UDP inspection limits and named industrial protocols.
Where it fits in the work
- Check that the proposed switch or router supports the intended sensor release.
- Validate a mirrored lab conversation in Center and compare it with the known equipment inventory.
- Use the observed flow to propose a policy, then test its impact before enforcement.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A plant has Cisco access switches and a non-Cisco legacy cell. Design how each cell supplies observable traffic, using supported embedded or external collection paths.
Evidence to look for
Produce a coverage map with explicit blind spots. Explain why a Center asset map does not establish that every serial or non-IP process is visible.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which sensor deployment supports this site’s existing equipment?
- What traffic falls outside the documented TCP/UDP inspection scope?
- Which current features require additional hardware, modules or external enforcement?