Version 5.2
Sourcefire 3D System Installation Guide
199
Restoring a Sourcefire Appliance to Factory Defaults
Understanding the Restore Process
Chapter 7
Configuration and Event Backup Guidelines
Before you begin the restore process, Sourcefire recommends that you delete or
move any backup files that reside on your appliance, then back up current event
and configuration data to an external location.
Restoring your appliance to factory defaults results in the loss of almost
all
configuration and event data on the appliance. Although the restore utility can
retain the appliance’s license, network, console, and Lights-Out Management
(LOM) settings, you must perform all other setup tasks after the restore process
completes.
Traffic Flow During the Restore Process
To avoid disruptions in traffic flow on your network, Sourcefire recommends
restoring your appliances during a maintenance window or at a time when the
interruption will have the least impact on your deployment.
Restoring a managed device that is deployed inline resets the device to a
non-bypass (fail closed) configuration, disrupting traffic on your network. Traffic is
blocked until you configure bypass-enabled inline sets on the device.
For more information about editing your device configuration to configure bypass,
see the Managing Devices chapter of the
Sourcefire 3D System User Guide
.
Understanding the Restore Process
A Sourcefire
appliance
is either a traffic-sensing managed
device
or a managing
Defense Center
: There are several
models
of each appliance type; these models
are further grouped into
series
and
family
. For more information, see
Understanding Appliance Series, Models, and Capabilities
The precise steps you take to restore an appliance depend on the appliance’s
model and whether you have physical access to the appliance, but the general
process is the same.
IMPORTANT!
Only reimage your appliances during a maintenance window.
Reimaging resets appliances in bypass mode to a non-bypass configuration and
disrupts traffic on your network until you reconfigure bypass mode. For more
information, see
Traffic Flow During the Restore Process
To restore a Sourcefire appliance:
A
CCESS
:
Admin
1.
Determine the model of the appliance (device or Defense Center) you want to
restore.
2.
Obtain the correct restore ISO image from the Support Site.