
Version 5.2
Sourcefire 3D System Installation Guide
201
Restoring a Sourcefire Appliance to Factory Defaults
Obtaining the Restore ISO and Update Files
Chapter 7
Lights-Out Management Using Serial over LAN
The LOM feature allows you to perform a limited set of actions on a Series 3
appliance, using a Serial over LAN (SOL) connection. If you need to restore a
LOM-capable appliance to factory defaults and do not have physical access to
the appliance, you can use LOM to perform the restore process. After you
connect to an appliance using LOM, you issue commands to the restore
utility as if you were using a physical serial connection. For more information,
Setting up Lights-Out Management
Obtaining the Restore ISO and Update Files
Sourcefire provides ISO images for restoring appliances to their original factory
settings. Before you restore an appliance, obtain the correct ISO image from the
Sourcefire Support Site.
The ISO image you should use to restore an appliance depends on when
Sourcefire introduced support for that appliance model. Unless the ISO image
was released with a minor version to accommodate a new appliance model, ISO
images are usually associated with major versions of the system software (for
example, 5.1 or 5.2). To avoid installing an incompatible version of the system,
Sourcefire recommends that you always use the most recent ISO image available
for your appliance.
Most Sourcefire appliances use an external USB or internal flash drive to boot the
appliance so you can run the restore utility. However, DC1000 and DC3000
Defense Centers require a restore ISO CD. If you have a DC1000 or DC3000,
Sourcefire provided you with an ISO image on CD-ROM when you purchased the
appliance. If you want to restore the appliance to a different version, you can
download the appropriate ISO image and create a new restore ISO (not data) CD,
which you can then use to restore the appliance.
Sourcefire also recommends that you always run the latest version of the system
software supported by your appliance. After you restore an appliance to the latest
supported major version, you should update its system software, intrusion rules,
and Vulnerability Database (VDB). For more information, see the release notes for
the update you want to apply, as well as the Updating System Software chapter in
the
Sourcefire 3D System User Guide
.
For your convenience, you can install system software and intrusion rule updates
as part of the restore process on most appliances. For example, you could restore
a device to Version 5.2, and also update the device to Version 5.2.0.1 as part of
that process. Keep in mind that only Defense Centers require rule updates.
Note that because you use a CD to restore DC1000 and DC3000 Defense
Centers, you cannot install updates as part of the restore process on those
appliances. Instead, update the appliances afterward.