Microsoft Defender for IoT
Identity protection

Set up traffic mirroring - Defender for IoT

In brief

The documentation now expands L2 as Layer 2, clarifies the Wireshark validation wording, and updates the link text for validating traffic mirroring.

What Defender admins need to know

Administrators get clearer guidance for confirming protocol visibility and sensor placement during setup.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Set up traffic mirroring

Validate the sensor location

After deciding on a potential location for the sensor, validate the presence of L2Layer 2 (L2) and operational technology (OT) protocols. It's recommended to use tools like Wireshark to verify these protocols at the potential sensor location. For example:

:::image type="content" source="media/guide/deployment-guide-analyzer.png" alt-text="Screenshot of the wireshark program used to confirm and validate OT sensor set up and network protocols communicating with the newly deployed OT sensor.":::

Wireshark displays the list of protocols identified by the sensor and the amount of data being monitored, thereby validating the location of your sensor. If protocols don't appear or don't detect any data,no data is detected, this result indicates that the sensor is incorrectly placed or set up in the network. For example:

:::image type="content" source="media/guide/deployment-guide-protocols.png" alt-text="Screenshot of the wireshark program protocol output used to confirm and validate OT sensor set up and network protocols communicating with the newly deployed OT sensor.":::

Validating the presence of L2 and OT protocols at the potential sensor location is crucial to ensure effective monitoring of your OT networks. For more information,steps to validate traffic mirroring, see Validate traffic mirroring.

Deploy your sensor