Most NBA sensors can be deployed in passive mode only, using
the same connection methods (e.g., network tap, switch
spanning port) as network-based IDPSs. Passive sensors that are
performing direct network monitoring should be placed so that
they can monitor key network locations, such as the divisions
between networks, and key network segments, such as DMZ
subnets. Inline sensors are typically intended for network
perimeter use, so they would be deployed in close proximity to
the perimeter firewalls, often in front to limit incoming attacks
that could overwhelm the firewalls.