Introduction
This article provides a detailed outline for deploying our Shuttle in either the port mirrored or inline configuration, complete with sensor-specific images.
For more high-level content about our physical network sensors, see Physical Network Sensors: Overview and Specs.
The Shuttle series devices (110, 410, and 510) are virtually identical, but the internal components of each device allow for scalability that suits the needs of your organization in terms of storage, network speeds, and user counts. Your device specifications would have been determined while scoping the solution with your Sales Engineer. If you received a Shuttle, the installation instructions in this document apply to all Shuttle series sensors.
This article covers the following topics:
Notes for Shuttle Deployments
- If your organization has restrictive firewall policies, you may need to make exceptions in your firewall that allows for outbound connections to Field Effect’s specific domains and ports. Our Customer Success team will reach out to you if this is required. To learn more, visit Firewall Exceptions for Network Sensors and Endpoint Agents.
- Every sensor ships with a USB YubiKey; a security device that provides a physical form of multi-factor authentication (MFA). The device will not power on unless the YubiKey is plugged into a USB port.
- If standard DHCPs are provided, you can connect the sensor directly to the internal network device via the green management port green.
- If you can’t provide a DHCP lease, a static IP can be assigned, and the steps are included in the appendix of this article.
- The sensor must be installed at the pre-Network Access Translation (pre-NAT) level for full visibility into all network traffic.
- When installing the sensor physically, ensure to place it in the proper orientation as shown in this guide. If it's positioned in a way that restricts airflow, it may create performance and/or hardware issues.
Procedure: Port Mirrored Configuration
The port mirrored configuration was formerly referred to as the passive configuration. But, since both sensors can be "passive", we have updated the terminology from "passive" to "port mirrored".
When using the port mirrored configuration, internet traffic from your network's primary switch is mirrored and sent to the sensor for analysis. The illustration below shows the sensor deployed with a port mirrored configuration, which requires the following connections:
- Yellow: a 1Gbps inbound connection that sends traffic from the mirrored port to the sensor.
- Green: an outbound VPN connection used to connect to Field Effect’s data center(s).

Making the Yellow Connection
If applicable: repeat this process as many times as necessary by configuring SPAN ports on any remaining switches/firewalls and connecting them to yellow ports.
On the device you wish to use for port mirroring (firewall or switch), configure a Switched Port Analyzer (SPAN) port and mirror all traffic to it. Plug the provided yellow cable into this newly configured SPAN port.

Plug the other end of the yellow cable into the yellow port on your sensor.

Making the Green Connection with a DHCP Lease (preferred)
If you can’t provide a DHCP lease: After completing this guide and powering on the sensor, connect a monitor and keyboard to the sensor and contact support@fieldeffect.com for your login credentials for the sensor. After logging in, you’ll be presented with a console where you can configure a static IP.
If you can provide a DHCP lease, plug one end of the green cable into any network port on your core switch with internet access.

Then connect the other end of the green cable into the green port on your sensor.

From your router's management interface, create a DHCP Reservation. This allows you to assign a specific IP address to a device - based on its MAC address. Reserving an IP for the sensor will boost reliability and connectivity. The process of reserving an IP will vary based your environment, but the benefits include:
- If the sensor reboots, it will quickly reestablish a connection with Field Effect.
- You can leverage firewall rules to maintain a more reliable connection.
- It helps ensure that syslogs are being sent correctly.
To find the MAC address for the green connection (aka interface) on your sensor, navigate to your Status Page and reserve the MAC address for the green interface.

Powering the Sensor
Now that the sensor is properly connected, you can power it on. Ensure the power cable is plugged in, and once powered on, it will receive an IP address and connect to our data center. The IP address should be reserved on your DHCP server.

Every physical sensor is shipped with a unique YubiKey, which is provides a physical form of multi-factor authentication (MFA). The sensor will not power on unless the YubiKey is plugged into a USB port. Ensure that the YubiKey is properly connected before powering on your sensor.
To confirm connectivity, browse to the status page or connect to the console.
Procedure: Inline Configuration
When using the inline configuration, the sensor sits in between your network's primary switch and the firewall. All network traffic is directly passed from the switch, through the sensor, and then out through the firewall.
The illustration below shows the connections required for an inline configuration:
- Yellow: a 1Gbps inbound connection that sends traffic from the mirrored port to the sensor.
- Blue: an 1Gbps outbound connection from the sensor to the internal network device.
- Green: an outbound VPN connection used to connect to Field Effect’s data center(s).

Making the Yellow Connection
Begin by unplugging both ends of the network cable that connects the LAN port on your firewall and the WAN port on your core switch. This will disable your Internet connection. Plug the provided yellow cable into the LAN port you just unplugged on your firewall.

Plug the other end of the yellow cable into the yellow port on your sensor.

Making the Blue Connection
If applicable: using the additional blue and yellow cables, repeat this process to connect any additional links you wish to monitor.Begin by plugging the blue cable into the blue port on your sensor.

Plug the other end of the blue cable into the WAN port you disconnected on your core switch. This will restore your Internet connection. To confirm an internet connection has been reestablished, navigate to a website using a computer connected to this core switch.

Making the Green Connection with a DHCP Lease (preferred)
If you can’t provide a DHCP lease: After completing this guide and powering on the sensor, connect a monitor and keyboard to the sensor and contact support@fieldeffect.com for your login credentials for the sensor. After logging in to the sensor, you’ll be presented with a console where you can configure a static IP.
Once network connectivity is restored, plug one end of the green cable into any network port on any switch with internet access.

Then connect the other end of the green cable into the green port on your sensor.

Powering the Sensor
Now that the sensor is properly connected, you can power it on. Ensure the power cable is plugged in, and once powered on, it will receive an IP address and connect to our data center. The IP address should be reserved on your DHCP server.

To confirm connectivity, browse to the status page or connect to the console.
Every physical sensor is shipped with a unique YubiKey that provides a physical form of multi-factor authentication (MFA). It will not power on unless the YubiKey is plugged into a USB port. While they are inserted prior to shipping, ensure that the YubiKey is properly connected before powering on your sensor.
Positioning the Sensor
Now that the device is connected and powered on, ensure to place it in the proper orientation. If it's positioned in a way that restricts airflow, it may create performance and/or hardware issues. In the image below, the top two orientations are approved as they allow for proper airflow.

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article

