
Version 5.2
Sourcefire 3D System Installation Guide
32
Understanding Deployment
Connecting Devices to Your Network
Chapter 2
To use routed interfaces in a Layer 3 deployment, you must configure virtual
routers and assign routed interfaces to them. A virtual router is a group of routed
interfaces that route Layer 3 traffic.
You can configure your device as a virtual router and use the remaining interfaces
to connect to network segments you want to monitor. You can also enable strict
TCP enforcement for maximum TCP security. To use a virtual router on your
device, create physical routed interfaces on your device and then follow the
instructions for Setting Up Virtual Routers in the
Sourcefire 3D System User
Guide
.
Hybrid Interfaces
L
ICENSE
:
Control
S
UPPORTED
D
EVICES
:
Series 3
You can configure logical hybrid interfaces on managed devices that allow the
Sourcefire 3D System to bridge traffic between virtual routers and virtual
switches. If IP traffic received on interfaces in a virtual switch is addressed to the
MAC address of an associated hybrid logical interface, the system handles it as
Layer 3 traffic and either routes or responds to the traffic depending on the
destination IP address. If the system receives any other traffic, it handles it as
Layer 2 traffic and switches it appropriately.
To create a hybrid interface, you first configure a virtual switch and virtual router,
then add the virtual switch and virtual router to the hybrid interface. A hybrid
interface that is not associated with both a virtual switch and a virtual router is not
available for routing, and does not generate or respond to traffic.
You can configure hybrid interfaces with network address translation (NAT) to
pass traffic between networks. For more information, see
If you want to use hybrid interfaces on your device, define a hybrid interface on
the device and then follow the instructions for Setting Up Hybrid Interfaces in the
Sourcefire 3D System User Guide
.
Connecting Devices to Your Network
You can connect your managed devices to your network in several ways.
Configure a hub or network tap using either passive or inline interfaces, or a span
port using passive interfaces. The following sections describe supported
connection methods and cabling considerations:
•
•
•
•
Cabling Inline Deployments on Copper Interfaces
•