Version 5.2
Sourcefire 3D System Installation Guide
41
Understanding Deployment
Deployment Options
Chapter 2
Hybrid Interface on a Managed Device
In this example, computer A and computer B are on the same network and
communicate using a Layer 2 virtual switch configured on the managed device
(indicated by the blue and green lines). A virtual router configured on the
managed device provides Layer 3 access to the firewall. A hybrid interface
combines the Layer 2 and Layer 3 capabilities of the virtual switch and virtual
router to allow traffic to pass from each computer through the hybrid interface to
the firewall (indicated by the red and orange lines).
For more information, see Setting Up Hybrid Interfaces in the
Sourcefire 3D
System User Guide
.
Deploying a Gateway VPN
L
ICENSE
:
VPN
S
UPPORTED
D
EVICES
:
Series 3
You can create a
gateway virtual private network
(gateway VPN) connection to
establish a secure tunnel between a local gateway and a remote gateway. The
secure tunnel between the gateways protects communication between them.
You configure the Sourcefire 3D System to build secure VPN tunnels from the
virtual routers of Sourcefire managed devices to remote devices or other
third-party VPN endpoints using the Internet Protocol Security (IPSec) protocol
suite. After the VPN connection is established, the hosts behind the local
gateway can connect to the hosts behind the remote gateway through the secure
VPN tunnel. The VPN endpoints authenticate each other with either the Internet
Key Exchange (IKE) version 1 or version 2 protocol to create a security association
for the tunnel. The system runs in either IPSec authentication header (AH) mode
or the IPSec encapsulating security payload (ESP) mode. Both AH and ESP
provide authentication, and ESP also provides encryption.