EDON / FIELD NOTES

Intrusion prevention and traffic observation

Intrusion prevention and traffic observation in selected zones.

Intrusion prevention and traffic observation

The DPI tier applies inline prevention in selected zones to flows allowed by policy. Flows are marked so subsequent packets and replies also return to the inspection engine. The advanced tier adds passive observation, authentication events, DNS anomalies, periodic communications and host inventory. The management baseline remains outside inspection.

Encrypted content and analytical limits

Argos does not decrypt TLS. It analyzes available metadata, TLS/QUIC JA4 client fingerprints and application signals; traffic with insufficient signals remains unclassified. When the inline engine is unavailable the queue allows traffic through. Passive observation does not issue blocking verdicts. Coverage depends on selected zones, protocols and loaded signatures.

DPI tier requirements

Traffic analysis requires at least 2 cores, 2 GiB RAM and 20 GB disk; the advanced level requires at least 4 cores, 4 GiB and 40 GB, plus required components. These are activation thresholds, not throughput guarantees. Interface count and speed depend on hardware; verify sizing against expected traffic.

LET’S TALK INFRASTRUCTURE

Control starts with a conversation.

Tell us about your infrastructure. Let’s start with what you actually need.

Talk to an engineer