Network processes

Many network processes can run on the appliances while in an evaluated configuration.

For more information, see the Default communication ports appendix in the Forcepoint Network Security Platform Product Guide.

Table 1. Processes for SMC Appliance
Process Listening Ports/Protocol Contact- ing Hardware Privilege User Linux Capabilities TLS Description
/usr/local/forcepoint/smc/jre/bin/java DNS Server 53/UDP, 53/TCP Manage- ment Server, Log Server Ring 3 sgadmin 0 No DNS queries.
/usr/local/forcepoint/smc/jre/bin/java Log Server

5514/TCP,

5514/UDP

Monitored third-party compon- ents, SMC Appliance Ring 3 sgadmin 0 No Syslog reception from third-party components and SMC Appliance.
/usr/local/forcepoint/smc/jre/bin/java Log Server 3020/TCP Security Engines Ring 3 sgadmin 0 Server Log and alert messages; monitoring of blacklists, connections, status, and statistics from Security Engine Engines.
/usr/local/forcepoint/smc/jre/bin/java Log Server 8914- 8918/TCP SMC Client Ring 3 sgadmin 0 Server Log browsing.
/usr/local/forcepoint/smc/jre/bin/java Manage- ment Server 3021/TCP Log Server, Security Engines Ring 3 sgadmin 0 Server System comm- unications certificate request/renewal.
/usr/local/forcepoint/smc/jre/bin/java Manage- ment Server 8902- 8903, 8905, 8907, 8913/TCP SMC Client, Log Server Ring 3 sgadmin 0 Server Monitoring and control connections.
/usr/local/forcepoint/smc/jre/bin/java Manage- ment Server 8906/TCP Security Engines Ring 3 sgadmin 0 Server Monitoring and control connections.
/usr/local/forcepoint/smc/jre/bin/java Manage- ment Server 3023/TCP Log Server, Security Engines Ring 3 sgadmin 0 Server Status monitoring.
/usr/local/forcepoint/smc/jre/bin/java Manage- ment Server 8085/TCP SMC Web Access clients Ring 3 sgadmin 0 No Communication for using SMC Web Access.
/usr/sbin/snmpd SMC Appliance 161/UDP Third-party compon- ents Ring 3 snmp 0xffffffffffffffff=all No Requesting health and other information about the SMC Appliance.
/usr/local/forcepoint/smc/jre/bin/java Syslog server 6514/TCP Manage- ment Server, Log Server Ring 3 sgadmin 0 Client Audit and log data forwarding to syslog servers.
/usr/sbin/snmpd Third-party compon- ents 162/UDP SMC Appliance Ring 3 snmp 0xffffffffffffffff=all No Sending SNMP status probing to external devices.
/usr/local/forcepoint/smc/jre/bin/java Update servers 443/TCP Manage- ment Server Ring 3 sgadmin 0 Client Update packages, Security Engine Engine upgrades, and licenses.
/usr/bin/python Update servers 443/TCP SMC Appliance Ring 3 root 0xffffffffffffffff=all Client Receiving appliance patches and updates.
Table 2. Processes for Security Engines
Process Listening Ports/Protocol Contact- ing Hardware Privilege User Linux Capabilities TLS Description
/usr/sbin/slapd_proxy Firewall 636/TCP Manage- ment Server Ring 3 sgadmin 0x0000003fffffffff Server Internal user database replication.
/usr/sbin/authd Firewall 2543/TCP Any Ring 3 root 0x0000003fffffffff No User authentication (Telnet) for Access rules. Denied by default.
/usr/sbin/upgrd Firewall 4950/TCP Manage- ment Server Ring 3 root 0x0000003fffffffff Server Remote upgrade.
/usr/sbin/mgmtd Firewall 4987/TCP Manage- ment Server Ring 3 root 0x0000003fffffffff Server Manage- ment Server commands and policy upload.
/usr/sbin/blocklistd Firewall 15000/TCP Manage- ment Server Ring 3 root 0x0000003fffffffff Server Block list entries.
/usr/sbin/smonitd Firewall 161/UDP SNMP server Ring 3 smonitd 0x0000003fffffffff No SNMP monitoring.
/usr/sbin/sendlogd Log Server 3020/TCP Engine Ring 3 root 0x0000003fffffffff Client Log and alert messages; monitoring of blacklists, connections, status, and statistics.
/usr/lib/stonegate/bin/contact Manage- ment Server 3021/TCP Engine Ring 3 root 0x0000003fffffffff Client System comm- unications certificate request/ renewal (initial contact).
/usr/sbin/sendlogd Manage- ment Server 3023/TCP Engine Ring 3 root 0x0000003fffffffff Client Monitoring (status) connection.
/usr/sbin/smonitd SNMP server 162/UDP Engine Ring 3 smonitd 0x0000003fffffffff No SNMP traps from the Security Engine Engine.
/usr/sbin/dnsmasq Firewall 53/TCP, 53/UDP Any Ring 3 nobody 0x0000003fffffffff No DNS relay