Introduction to the Forcepoint Network Security Platform solution
Before setting up Forcepoint Network Security Platform, it is useful to know what the different components do and what Security Engine roles are available. There are also tasks that you must complete to prepare for installation.
Introduction to Forcepoint Network Security Platform
The Forcepoint Network Security Platform solution consists of Security Engines and the Forcepoint Security Management Center (SMC). The SMC is the management component of the Forcepoint Network Security Platform solution.
Preparing for installation
Before installing Forcepoint Network Security Platform, identify the components of your installation and how they integrate into your environment.
Forcepoint Security Management Center deployment
SMC is the management component of the Security Engine system. SMC must be installed and running before you can deploy the Security Engines.
Installing the SMC
The SMC is the management component of the Forcepoint Network Security Platform solution. The SMC manages and controls the other components in the system. You must install the SMC before you can install Security Engines.
Configuring the SMC
After initial installation is complete, configure the SMC to allow adding the other components for your system.
Forcepoint Security Engine deployment
Forcepoint Security Engine deployment consists of adding and configuring engine elements in the SMC, and configuring the Security Engine software on the engine.
Configuring Forcepoint Security Engines with Layer 3 Interfaces
Configuring engine elements in the SMC prepares the SMC to manage Security Engine with Layer 3 Interfaces.
Configuring Security Engine for the IPS role
Configuring engine elements in the SMC prepares the SMC to manage Security Engine in the IPS role.
Configuring Security Engine for the Layer 2 Engine role
Configuring engine elements in the SMC prepares the SMC to manage Security Enginew with the Layer 2 Engine role.
Configuring Security Engines as Master Engines and Virtual Engines
Configuring engine elements in the SMC prepares the SMC to manage Master Security Engines and Virtual Security Engines.
Configuring routing
After creating the Security Engine elements and defining the interfaces, you can configure the basic routing.
Initial configuration of Security Engine software
After configuring the Security Engines in the SMC Client, apply the initial configuration of the Security Engine and contact the Management Server.
Creating and installing policies
After successfully applying the initial configuration and establishing contact between the Security Engines and the Management Server, the Security Engine is in the initial configuration state. Now you can create and install policies for access control or inspecting traffic.
Maintenance
To maximize the benefit of Security Engine, upgrade the SMC and Security Engine regularly.
Upgrading licenses
You must upgrade licenses if you upgrade the SMC, the SMC Appliance, or the Security Engines to a new major release.
Maintaining the Security Management Center
When there is a new version available, upgrade the SMC before upgrading Security Engines.
SMC Appliance maintenance
The SMC Appliance has a specific patching process that keeps the SMC software, operating system, and appliance firmware up-to-date.
Upgrading Security Engines
When a new version of Forcepoint Network Security Platform introduces features that you want to use, upgrade the Security Engines.
Default communication ports
There are default ports used in connections between SMC components and default ports that SMC components use with external components.
Command line tools
There are command line tools for the SMC and the Security Engines.
Installing SMC Appliance software on a virtualization platform
You can install the SMC Appliance software as a virtual machine on virtualization platforms such as VMware ESX.
Installing Forcepoint Security Engine on a virtualization platform
You can install the Security Engine software as a virtual machine on virtualization platforms such as VMware ESX or KVM.
Installing Forcepoint Security Engine software on third-party hardware
You can install the Security Engine software on third-party hardware that meets the hardware requirements.
Installing the SMC with external certificate management
When you install the SMC, you can use certificates issued by an external CA for internal TLS communication between system components.
Example network (Engine/VPN)
This example gives you a better understanding of how Security Engines with Layer 3 Interfaces fits into a network.
Example network (IPS)
To give you a better understanding of how Security Engine in the IPS role fits into a network, this example outlines a network with IPS engines.
Cluster installation worksheet instructions
For planning the configuration of network interfaces for the engine nodes, use the worksheet.