Place a network sensor and see what it sees
A passive sensor sees only what a switch copies to it. Synapse derives that sight from the mirror port, so where a sensor looks — and where it does not — is a fact about the design rather than a line in a countermeasure register.
Every OT security programme deploys passive monitoring, and every architecture review asks the same two questions of it: which segments does the sensor actually see, and which does it not. Those are answered by one thing, the mirror (SPAN) port that feeds it, and that is a decision made on the drawing. This recipe makes it one.
Monitoring is a placement decision
A sensor filters nothing and originates no process traffic. It sees the copies a switch sends to its mirror port, which means it sees the VLANs the mirrored ports carry and nothing else. Put it on the wrong switch and it watches an empty wire while the plant floor goes unobserved. So Synapse models the sensor as an asset of its own, the mirror as a port kind of its own, and derives everything in between.
01Start from the sensor Voltara ships with
Open the studio. In the Operations & Engineering band, select Station Sensor. The right panel opens on its properties with a Monitoring section: the engine, whether its management path is out of band, and Fed from, which names the L2 Managed Switch and its port 8.
Now select the L2 Managed Switch. In its Port schedule, port 8 reads Mirror with the sensor as its device and all as its sources: every other port on the switch is copied to it.
02Read what it sees
Back on the sensor, the Seesblock is derived and read-only. For the shipped mirror it lists VLANs 130, 140, 150 and 200: the Automation segment, the IEC 61850 station bus, the field protection segment and the out-of-band management VLAN, because the switch’s trunks carry them. Below that, the zones those segments are home to, each a link that lights the zone on the canvas, and a count of the conduits and assets in sight.
03Find what it does not
Open View▸Monitoring coverage if it is not already on. Every zone now carries a chip: seen where a sensor sees one of its segments,unseen where none does and the zone is at SL-T 2 or above. The OT DMZ is unseen, and so is the crossing from it into Supervisory Control.
The Check tab says the same in findings: Zone outside every sensor’s sight for the DMZ, graded by its SL-T, and IT/OT boundary outside every sensor’s sight for the conduit. Both cite SR 6.2. Neither existed before a sensor was placed: a design that has not drawn one gets a single observation that it is silent on monitoring, and nothing else.
04Narrow the mirror and watch sight shrink
On the L2 switch, expand port 8. Under Mirrors, click every portoff and pick only P2, the RET630 relay. The sensor’s Sees block collapses to VLAN 150 and the field zone; the Automation and station-bus zones turn unseen and two new findings appear. Under Only these VLANs, pick 130 to restrict a wide mirror to one segment.
Set the port back to Spare and the sensor reads Network sensor sees nothing, with the reason: it names a feed that is no longer a mirror. The sensor’s own feed list followed the port, so the drawing and the sensor never disagree about what feeds it.
05Where it lands: ledger, coverage, report
Open Countermeasures. The sensor is a derived row on the detection axis, Designed, protecting the zones it sees, answering SR 6.2 and naming the ATT&CK for ICS techniques a passive sensor can see on the wire. It earns no likelihood credit: a sensor stops nothing, and the risk register is identical with and without it.
In Requirements & reports, SR 6.2 coverage now has two halves: the boundary devices reporting on themselves through logs, and a sensor seeing the wire. Logs alone are the partial floor. The PDF gains a Monitoring coveragesection: one row per sensor, and the zones outside every sensor’s sight.
What the range proves, and does not yet
The cyber range already runs Zeek and Suricata on a mirror of the root switch for every live run, and the Twin Lab reports their detections. It does not yet place the sensor where the design says, mirror only the VLANs the design says, or attribute a detection to a named sensor. Until it does, the ledger row never reads Verified, the Twin Lab calls its sensor the range default, and the report says in words that nothing here is verified by a run. That delivery is the next one.
Recap
- A sensor is an asset, a mirror is a port kind: and what the sensor sees is derived from the switch, never typed in.
- Silence until placed: a design with no sensor gets one observation; a design with one is held to what it does not see.
- Detection credit only: the ledger row protects what it sees and answers SR 6.2; the risk register does not move.
To turn the design into audit evidence, continue with Generate audit-ready evidence.
Try it on the reference
Voltara opens with a Station Sensor already fed from the L2 switch. Move the mirror and watch the findings follow.
Open the studio