
Version 5.2
Sourcefire 3D System Installation Guide
23
Introduction to the Sourcefire 3D System
Security, Internet Access, and Communication Ports
Chapter 1
Security, Internet Access, and Communication Ports
To safeguard the Defense Center, you must install the Defense Center on a
protected internal network. Although the Defense Center is configured to have
only the necessary services and ports available, you must make sure that attacks
cannot reach it from outside the firewall.
If the Defense Center and the managed device reside on the same network, you
can connect the management interface on the device to the same protected
internal network as the Defense Center. This allows you to securely control the
device from the Defense Center and aggregate the event data generated on the
managed device’s network segment. By using the Defense Center’s filtering
capabilities, you can analyze and correlate data from attacks across your network
to evaluate how well your security policies are being implemented.
Note, however, that Sourcefire appliances are configured to directly connect to
the Internet. Specific features of the Sourcefire 3D System require this direct
connection, and others support use of a proxy server. Additionally, the system
requires that certain ports remain open for basic intra-appliance communication,
as well as to allow you to access appliances’ web interfaces. By default, several
other ports are open to allow the system to take advantage of additional features
and functionality.
For more information, see:
•
•
Open Communication Ports Requirements
Internet Access Requirements
By default, Sourcefire appliances are configured to directly connect to the
Internet. Specific features of the Sourcefire 3D System require this direct
connection, while others support use of a proxy server; see the Configuring s
chapter in the
Sourcefire 3D System User Guide
.
TIP!
You can manually upload system software, intrusion rule, GeoDB, and VDB
updates to appliances.
To ensure continuity of operations, both Defense Centers in a high availability pair
must have Internet access. For specific features, the primary Defense Center
contacts the Internet, then shares information with the secondary during the
synchronization process. Therefore, if the primary fails, you should promote the
secondary to primary as described in the Managing Devices chapter in the
Sourcefire 3D System User Guide
.