Questions and answers
We collected what network administrators and heads of information security ask most often. If your question is not here, ask us directly.
Connection and installation
Does the network have to be stopped during installation?
No. The appliance connects to a switch mirror port and takes no part in data transmission. The only operation on live equipment is enabling port mirroring, which is done without breaking connectivity.
What if our switch is unmanaged and has no mirroring?
Port mirroring exists on practically all managed equipment. If an unmanaged switch sits at the required point, we design the scheme separately: the observation point usually moves up to the network core.
How long does the rollout take?
Physically it is two patch cords and a power supply. The software boots in up to five minutes after voltage is applied. Configuring time, network, scanning tasks and notifications fits into a single visit.
Do agents have to be installed on employee computers?
No. The appliance analyses a copy of the network traffic and probes the network from the outside. An account on a device is only needed for the file integrity module, if you decide to place server configurations under control.
Can the appliance be mounted in a rack?
Yes, the device sits on any stable horizontal surface, including a rack shelf. Room requirements are ordinary: dry, heated, temperature from +10 to +35 degrees.
Does one appliance cover several offices?
The appliance sees the traffic of the switch it is attached to. For several sites you place one device per site and consolidate events into a shared collection system over syslog or as JSON.
Operation and security
Does the appliance block attacks or only show them?
It shows, classifies and passes them on. Blocking stays with the firewall and the administrator. This is a deliberate decision: an out of band connection can never become a point of failure and never affects network operation.
What happens if the appliance goes down?
The network keeps running as if the device had never been there. Only event collection stops, and there will be no data for the outage period.
Where does our data go?
Nowhere. The appliance works inside your own perimeter, and traffic and logs are stored on the device itself. Data leaves only where you configure the export yourself: your event collector, your mailbox, your Telegram chat.
Does the appliance decrypt traffic?
No. It analyses headers, connection behaviour, service protocols and indicators visible without decryption. Many indicators of compromise, including calls to command and control servers and network scanning, are detected exactly this way.
How many false positives are there?
It depends on the network. In traffic monitoring some rules produce noise without value in a specific infrastructure, so any system rule can be switched off or rewritten for you. The honeypot has practically no false positives by design: a legitimate employee has no reason to touch it.
Who is going to work with all this every day?
Daily work amounts to reading notifications. You choose which event types of every module go to email and Telegram, and teams usually keep only the critical ones. Once a day the duty officer opens the Analysis module, where events from every module sit on one screen.
Integration and compatibility
We already run a SIEM. Will the appliance work with it?
Yes. Events are exported over syslog or as JSON to a given address and port, 514 by default. Operation with Wazuh is documented, and for MaxPatrol SIEM the collection is configured on the SIEM side over HTTP in JSON format.
What if we have no SIEM of our own?
Then the Analysis module fills that role: events from every module over the last 24 hours on one screen with unread counters. Plus direct delivery to email and Telegram for the event types you select.
Which network equipment does it work with?
Any equipment that can mirror a port. The appliance does not manage your equipment and requires no compatibility from it: it receives a traffic copy over ordinary Ethernet.
Which operating systems does integrity monitoring support?
Windows and Linux. Connection over SSH, WinRM, SMB or FTP. WinRM has to be enabled on the remote device beforehand, and SMB requires raising the concurrent session limit.
Can a report be exported for management or an auditor?
Yes. A filtered log exports to HTML, JSON or XLSX with aggregation by a chosen field. Raw traffic for a specific event downloads as a PCAP file.
Licensing, support, maintenance
How much does it cost?
The price is calculated for a specific configuration: the appliance edition, the number of devices and the rollout scope. That is why there are no prices on the site. Send a request describing your infrastructure and we will prepare an offer.
How does licensing work?
The licence has a term. Its state, number, owner and dates are visible in the interface both overall and per module. When the term expires the licence is renewed with an activation key entered in the web interface.
How are updates installed?
From the web interface. The management menu has an update check, download and installation. The appliance functionality is unavailable during the update, so it is usually scheduled outside working hours.
What maintenance is required?
A technical inspection at least once every six months: visually check the chassis for damage, remove dust with a dry soft cloth, inspect the power supply and the cable. There are no consumables.
Can we see the system before buying?
Yes. We show a working interface on a live demo unit: event logs, network map, vulnerability scanner, honeypot console. We answer questions from your network administrator.
Who develops the platform?
The appliance is built on the Innotech Network Monitor platform developed by Innotech Solutions, a resident of the High Technologies Park. The device carries the EAC and TR BY conformity marks.
We will prepare a quote for your network
Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.
- We reply within one business day
- We design the connection scheme for your topology
- We show the interface on a live demo unit
