Using the management server as policy source for filtering-only appliances

Applies to:
  • Forcepoint Web Security, v8.5.x
  • Forcepoint URL Filtering, v8.5.x

It is possible to deploy web protection components so that the central Policy Broker and Policy Server are installed on the management server, and filtering only appliances use that machine as the full policy source.

If you choose this deployment option, it is important to install your components in the following order.
  1. Install Policy Broker and Policy Server on the machine that will become the management server. See Installing web protection components.
  2. Set up the appliance to run in filtering only mode, specifying the Policy Broker machine (the future management server) as the policy source.
  3. Install management components (including the Web or Web and Data modules of the Forcepoint Security Manager) on the Policy Broker machine to create the management server.

    If you have purchased the Web Security DLP module, also install Linking Service on the management server machine.

    See Creating a Forcepoint management server.

    Install reporting and other off-appliance components as necessary. See Installing web protection components.