Version 5.2
Sourcefire 3D System Installation Guide
24
Introduction to the Sourcefire 3D System
Security, Internet Access, and Communication Ports
Chapter 1
The following table describes the Internet access requirements of the Sourcefire
3D System.
Open Communication Ports Requirements
The Sourcefire 3D System requires that ports 443 (inbound) and 8305 (inbound
and outbound) remain open for basic intra-appliance communication, as well as to
allow you to access appliances’ web interfaces.
Sourcefire 3D System Internet Access Requirements
F
OR
...
I
NTERNET
ACCESS
IS
REQUIRED
TO
...
H
IGH
A
VAILABILITY
C
ONSIDERATIONS
P
ROXY
?
RSS Feed dashboard
widget
download RSS feed data from
an external source, including
Sourcefire.
Feed data is not synchronized.
Security Intelligence
feeds
download Security Intelligence
feed data from an external
source, including the
Sourcefire Intelligence Feed.
The primary Defense Center
downloads feed data and
shares it with the secondary.
In case of primary failure, you
must switch roles.
URL filtering data
download cloud-based URL
category and reputation data
for access control, and
perform lookups for
uncategorized URLs.
The primary Defense Center
downloads URL filtering data
and shares it with the
secondary. In case of primary
failure, you must switch roles.
malware cloud lookups
(Malware licensed)
perform cloud lookups to
determine if files detected in
network traffic contain
malware.
Paired Defense Centers
perform cloud lookups
independently, although file
policies are synchronized.
FireAMP integration
(FireAMP subscription)
receive endpoint-based
malware events from the
Sourcefire cloud.
Cloud connections are not
synchronized. Configure them
on both Defense Centers.
system, intrusion rule,
GeoDB, and VDB
updates
download or schedule the
download of an intrusion rule,
GeoDB, VDB, or system
update directly to the
appliance.
Rule, GeoDB, and VDB
updates are synchronized;
system updates are not. All
appliances that download
updates must have Internet
access.
obtaining whois
information using the IP
address context menu
obtain whois information.
Any appliance requesting
whois information must have
Internet access.