Introduction to the Forcepoint Network Security Platform solution Before setting up Forcepoint Network Security Platform, it is useful to know what the different components do and what Security Engine roles are available. There are also tasks that you must complete to prepare for installation.
Introduction to Forcepoint Network Security PlatformThe Forcepoint Network Security Platform solution consists of Security Engines and the Forcepoint Security Management Center (SMC). The SMC is the management component of the Forcepoint Network Security Platform solution.
Preparing for installationBefore installing Forcepoint Network Security Platform, identify the components of your installation and how they integrate into your environment.
Forcepoint Security Management Center deploymentSMC is the management component of the Security Engine system. SMC must be installed and running before you can deploy the Security Engines.
Installing the SMC The SMC is the management component of the Forcepoint Network Security Platform solution. The SMC manages and controls the other components in the system. You must install the SMC before you can install Security Engines.
Configuring the SMC After initial installation is complete, configure the SMC to allow adding the other components for your system.
Forcepoint Security Engine deploymentForcepoint Security Engine deployment consists of adding and configuring engine elements in the SMC, and configuring the Security Engine software on the engine.
Configuring Forcepoint Security Engines with Layer 3 Interfaces Configuring engine elements in the SMC prepares the SMC to manage Security Engine with Layer 3 Interfaces.
Configuring Security Engine for the IPS role Configuring engine elements in the SMC prepares the SMC to manage Security Engine in the IPS role.
Configuring Security Engine for the Layer 2 Engine role Configuring engine elements in the SMC prepares the SMC to manage Security Enginew with the Layer 2 Engine role.
Configuring Security Engines as Master Engines and Virtual Engines Configuring engine elements in the SMC prepares the SMC to manage Master Security Engines and Virtual Security Engines.
Configuring routing After creating the Security Engine elements and defining the interfaces, you can configure the basic routing.
Initial configuration of Security Engine software After configuring the Security Engines in the SMC Client, apply the initial configuration of the Security Engine and contact the Management Server.
Creating and installing policies After successfully applying the initial configuration and establishing contact between the Security Engines and the Management Server, the Security Engine is in the initial configuration state. Now you can create and install policies for access control or inspecting traffic.
Maintenance To maximize the benefit of Security Engine, upgrade the SMC and Security Engine regularly.
Upgrading licensesYou must upgrade licenses if you upgrade the SMC, the SMC Appliance, or the Security Engines to a new major release.
Maintaining the Security Management Center When there is a new version available, upgrade the SMC before upgrading Security Engines.
SMC Appliance maintenanceThe SMC Appliance has a specific patching process that keeps the SMC software, operating system, and appliance firmware up-to-date.
Upgrading Security EnginesWhen a new version of Forcepoint Network Security Platform introduces features that you want to use, upgrade the Security Engines.
Default communication ports There are default ports used in connections between SMC components and default ports that SMC components use with external components.
Command line tools There are command line tools for the SMC and the Security Engines.
Installing SMC Appliance software on a virtualization platform You can install the SMC Appliance software as a virtual machine on virtualization platforms such as VMware ESX.
Installing Forcepoint Security Engine on a virtualization platform You can install the Security Engine software as a virtual machine on virtualization platforms such as VMware ESX or KVM.
Installing Forcepoint Security Engine software on third-party hardware You can install the Security Engine software on third-party hardware that meets the hardware requirements.
Installing the SMC with external certificate management When you install the SMC, you can use certificates issued by an external CA for internal TLS communication between system components.
Example network (Engine/VPN) This example gives you a better understanding of how Security Engines with Layer 3 Interfaces fits into a network.
Example network (IPS) To give you a better understanding of how Security Engine in the IPS role fits into a network, this example outlines a network with IPS engines.
Cluster installation worksheet instructions For planning the configuration of network interfaces for the engine nodes, use the worksheet.