Deploy SecureConnector in Networks with Overlapping IP Addresses

SecureConnector is a small-footprint executable that runs on the endpoint. It reports endpoint information to the eyeSight and implements actions on the endpoint.

To deploy SecureConnector on an endpoint, Appliances generate an installer package. This package can be downloaded to the endpoint in an interactive session with the end user or distributed in the background to devices by the network administrator.

The installer refers the endpoint to the address and port that the Appliance exposes for SecureConnector communication.

  • In the default/global network, eyeSight devices can redirect SecureConnector communication to the endpoint’s home Appliance. A single installer package can be distributed across the network.
  • In the part of the network that is configured with IP Reuse Domains, Appliances cannot redirect SecureConnector communication. In each overlapping site, SecureConnector must be downloaded from an Appliance in the site. Once installed, SecureConnector can only communicate with this Appliance. This is true even if the IP address of the endpoint is logically part of the default/global network and is excluded from the IP Reuse Domain.

    Configuration options that redirect endpoints between Appliances are not available when overlapping endpoints are managed by SecureConnector. For example, Automatic IP allocation for load sharing and failover cluster definition are not supported.