Network processes
Many network processes can run on the appliances while in an evaluated configuration.
For more information, see the Default communication ports appendix in the Forcepoint Network Security Platform Product Guide.
| Process | Listening | Ports/Protocol | Contact- ing | Hardware Privilege | User | Linux Capabilities | TLS | Description |
|---|---|---|---|---|---|---|---|---|
| /usr/local/forcepoint/smc/jre/bin/java | DNS Server | 53/UDP, 53/TCP | Manage- ment Server, Log Server | Ring 3 | sgadmin | 0 | No | DNS queries. |
| /usr/local/forcepoint/smc/jre/bin/java | Log Server |
5514/TCP, 5514/UDP |
Monitored third-party compon- ents, SMC Appliance | Ring 3 | sgadmin | 0 | No | Syslog reception from third-party components and SMC Appliance. |
| /usr/local/forcepoint/smc/jre/bin/java | Log Server | 3020/TCP | Security Engines | Ring 3 | sgadmin | 0 | Server | Log and alert messages; monitoring of blacklists, connections, status, and statistics from Security Engine Engines. |
| /usr/local/forcepoint/smc/jre/bin/java | Log Server | 8914- 8918/TCP | SMC Client | Ring 3 | sgadmin | 0 | Server | Log browsing. |
| /usr/local/forcepoint/smc/jre/bin/java | Manage- ment Server | 3021/TCP | Log Server, Security Engines | Ring 3 | sgadmin | 0 | Server | System comm- unications certificate request/renewal. |
| /usr/local/forcepoint/smc/jre/bin/java | Manage- ment Server | 8902- 8903, 8905, 8907, 8913/TCP | SMC Client, Log Server | Ring 3 | sgadmin | 0 | Server | Monitoring and control connections. |
| /usr/local/forcepoint/smc/jre/bin/java | Manage- ment Server | 8906/TCP | Security Engines | Ring 3 | sgadmin | 0 | Server | Monitoring and control connections. |
| /usr/local/forcepoint/smc/jre/bin/java | Manage- ment Server | 3023/TCP | Log Server, Security Engines | Ring 3 | sgadmin | 0 | Server | Status monitoring. |
| /usr/local/forcepoint/smc/jre/bin/java | Manage- ment Server | 8085/TCP | SMC Web Access clients | Ring 3 | sgadmin | 0 | No | Communication for using SMC Web Access. |
| /usr/sbin/snmpd | SMC Appliance | 161/UDP | Third-party compon- ents | Ring 3 | snmp | 0xffffffffffffffff=all | No | Requesting health and other information about the SMC Appliance. |
| /usr/local/forcepoint/smc/jre/bin/java | Syslog server | 6514/TCP | Manage- ment Server, Log Server | Ring 3 | sgadmin | 0 | Client | Audit and log data forwarding to syslog servers. |
| /usr/sbin/snmpd | Third-party compon- ents | 162/UDP | SMC Appliance | Ring 3 | snmp | 0xffffffffffffffff=all | No | Sending SNMP status probing to external devices. |
| /usr/local/forcepoint/smc/jre/bin/java | Update servers | 443/TCP | Manage- ment Server | Ring 3 | sgadmin | 0 | Client | Update packages, Security Engine Engine upgrades, and licenses. |
| /usr/bin/python | Update servers | 443/TCP | SMC Appliance | Ring 3 | root | 0xffffffffffffffff=all | Client | Receiving appliance patches and updates. |
| Process | Listening | Ports/Protocol | Contact- ing | Hardware Privilege | User | Linux Capabilities | TLS | Description |
|---|---|---|---|---|---|---|---|---|
| /usr/sbin/slapd_proxy | Firewall | 636/TCP | Manage- ment Server | Ring 3 | sgadmin | 0x0000003fffffffff | Server | Internal user database replication. |
| /usr/sbin/authd | Firewall | 2543/TCP | Any | Ring 3 | root | 0x0000003fffffffff | No | User authentication (Telnet) for Access rules. Denied by default. |
| /usr/sbin/upgrd | Firewall | 4950/TCP | Manage- ment Server | Ring 3 | root | 0x0000003fffffffff | Server | Remote upgrade. |
| /usr/sbin/mgmtd | Firewall | 4987/TCP | Manage- ment Server | Ring 3 | root | 0x0000003fffffffff | Server | Manage- ment Server commands and policy upload. |
| /usr/sbin/blocklistd | Firewall | 15000/TCP | Manage- ment Server | Ring 3 | root | 0x0000003fffffffff | Server | Block list entries. |
| /usr/sbin/smonitd | Firewall | 161/UDP | SNMP server | Ring 3 | smonitd | 0x0000003fffffffff | No | SNMP monitoring. |
| /usr/sbin/sendlogd | Log Server | 3020/TCP | Engine | Ring 3 | root | 0x0000003fffffffff | Client | Log and alert messages; monitoring of blacklists, connections, status, and statistics. |
| /usr/lib/stonegate/bin/contact | Manage- ment Server | 3021/TCP | Engine | Ring 3 | root | 0x0000003fffffffff | Client | System comm- unications certificate request/ renewal (initial contact). |
| /usr/sbin/sendlogd | Manage- ment Server | 3023/TCP | Engine | Ring 3 | root | 0x0000003fffffffff | Client | Monitoring (status) connection. |
| /usr/sbin/smonitd | SNMP server | 162/UDP | Engine | Ring 3 | smonitd | 0x0000003fffffffff | No | SNMP traps from the Security Engine Engine. |
| /usr/sbin/dnsmasq | Firewall | 53/TCP, 53/UDP | Any | Ring 3 | nobody | 0x0000003fffffffff | No | DNS relay |