Forcepoint Network Security Platform

The Forcepoint Network Security Platform combines centralized management and firewalls into one platform.

The system includes SMC user interface components, SMC server components, and Security Engines.

Component Description
SMC Client

The SMC Client is the user interface for the SMC. The SMC Client version must match the version of the SMC.

Note: The SMC Client is used to configure the Management Server and Log Server, but the SMC Client itself is not part of the target of evaluation.

You use the SMC Client for all configuration and monitoring tasks. This interface allows the administrator to configure, monitor, and create reports about the whole Forcepoint Network Security Platform with the same tools and within the same user session.

  • You can install the SMC Client locally as an application, or you can login to the SMC Web Access management UI by using a web browser.
  • You can install an unlimited number of SMC Clients.
  • Multiple administrators can log on at the same time to efficiently configure and monitor all Security Engines.
SMC servers

SMC Appliance provides a unified hardware or virtual appliance that includes a dedicated Management Server and Log Server. All upgrades and patches, including operating system updates, come from Forcepoint.

The Management Server stores an audit trail of administrator actions. The Management Server and Log Server can be configured to forward all audit information to an external audit server.

Security Engines

Security Engines inspect network traffic. The Security Engines software includes a purpose built operating system and there is no need for separate OS patches or upgrades. All software on Security Engines is updated during the software upgrade. The Engine policies determine when to use stateful connection tracking, packet filtering, or application-level security.

Certificates are validated as part of the authentication process when they are presented to the Forcepoint Network Security Platform and when they are loaded into the Forcepoint Network Security Platform. The following fields are verified as appropriate:
  • signature
  • validity period
  • extended key usage
  • issuer's name
  • basic constraints (for CA certificates)

At import, the Forcepoint Network Security Platform also verifies that the certificate does not use explicit curve parameters and that the certificate chains to a valid CA certificate.