
Version 5.2
Sourcefire 3D System Installation Guide
28
Understanding Deployment
Understanding Deployment Options
Chapter 2
•
Using a Multi-Port Managed Device
on page 48 explains how to use a
managed device for multiple networks or for use as a virtual router or virtual
switch in your network deployment.
•
on page 50 explains advanced deployment
scenarios, such as using a VPN or having multiple entry points.
For additional information about deployments, consult the
Best Practices Guide
,
available from the Sourcefire sales department.
Understanding Deployment Options
Your deployment decisions will be based on a variety of factors. Answering these
questions can help you understand the vulnerable areas of your network and
clarify your intrusion detection and prevention needs:
•
Will you be deploying your managed device with passive or inline
interfaces? Does your device support a mix of interfaces, some passive and
others inline? See
on page 28 for more
information.
•
How will you connect the managed devices to the network? Hubs? Taps?
Spanning ports on switches? Virtual switches? See
on page 32 for more information.
•
Do you want to detect every attack on your network, or do you only want to
know about attacks that penetrate your firewall? Do you have specific
assets on your network such as financial, accounting, or personnel records,
production code, or other sensitive, protected information that require
special security policies? See
on page 36 for more
information.
•
Do you provide VPN or modem access for remote workers? Do you have
remote offices that also require an IPS deployment? Do you employ
contractors or other temporary employees? Are they restricted to specific
network segments? Do you integrate your network with the networks of
other organizations such as customers, suppliers, or business partners? See
on page 50 for more information.
Understanding Interfaces
The sections that follow describe how different interfaces affect the capabilities of
the Sourcefire 3D System. In addition to passive and inline interfaces, you can