Version 5.2
Sourcefire 3D System Installation Guide
10
Introduction to the Sourcefire 3D System
Sourcefire 3D System Appliances
Chapter 1
Key features of the Defense Center include:
•
device, license, and policy management
•
display of event and contextual information using tables, graphs, and charts
•
health and performance monitoring
•
external notification and alerting
•
real-time threat response using correlation and remediation features
•
reporting
For many physical Defense Centers, a high availability (redundancy) feature can
help you ensure continuity of operations.
Managed Devices
Physical Sourcefire devices are fault-tolerant, purpose-built network appliances
available in a range of throughputs. You can also host virtual devices. Devices
deployed passively help you gain insight into your network traffic. Deployed inline,
you can use Sourcefire devices to affect the flow of traffic based on multiple
criteria. You must manage Sourcefire devices with a Defense Center.
Depending on model and license, managed devices:
•
gather detailed information about your organization’s hosts, operating
systems, applications, users, files, networks, and vulnerabilities
•
block or allow network traffic based on various network-based criteria, as
well as other criteria including applications, users, URLs, IP address
reputations, and the results of intrusion or malware inspections
•
have switching, routing, DHCP, NAT, and VPN capabilities, as well as
configurable bypass interfaces, fast-path rules, and strict TCP enforcement
•
have clustering (redundancy) to help you ensure continuity of operations,
and stacking to combine resources from multiple devices
Understanding Appliance Series, Models, and Capabilities
Version 5.2 of the Sourcefire 3D System is available on two series of physical
appliances, as well as virtual appliances. Many Sourcefire 3D System capabilities
are appliance dependent. For more information, see:
•
•
•
•
Appliances Delivered with Version 5.2
•