QUICK START GUIDE 7000 SERIES DEVICES

Similar documents
QUICK START GUIDE 7000 SERIES DEVICES. 3D7010/7020/7030 (Chassis: CHRY-1U-AC) 3D7115/7125, AMP7150 (Chassis: GERY-1U-4C8S-AC)

Installing the IPS 4345 and IPS 4360

Junos WebApp Secure 5.0 Hardware Guide

Installing the ASA 5550

Installing the Cisco ADE 2130 and 2140 Series Appliance Hardware Options

Installation Job Aid for VSP 4450GTX-HT- PWR+

Installing and Upgrading Internal Modules and FRUs

GigaStor Upgradeable 2U. User Guide

Installation Job Aid for VSP 4850GTS

Installation Note for the Cisco ME 3800X and ME 3600X Switch Power Supply and Fan Modules

Product Overview. Cisco ME 6524 Ethernet Switch (ME-C6524GS-8S) CHAPTER

Installing and Managing the Switch

Switch Installation. Preparing. Safety Warnings CHAPTER

Quick Start. This document describes how to install the Juniper Networks PTX5000 Packet Transport

Installing the Cisco Unified Videoconferencing 3545 MCU

apple Service Source Xserve RAID 17 March Apple Computer, Inc. All rights reserved.

McAfee Network Security Platform

apple Service Source Xserve RAID Xserve RAID and Xserve RAID (SFP) Updated: 25 May Apple Computer, Inc. All rights reserved.

Installation Job Aid for Ethernet Routing Switch 3600 Series

Installing the IPS 4260

Dell MD1280 Storage Enclosure Getting Started Guide

Installing IDS Introducing IDS-4215 CHAPTER

Installation and Maintenance

Dell Storage Center. Getting Started Guide. SCv2000 and SCv2020 Storage System. Regulatory Model: E09J, E10J Regulatory Type: E09J001, E10J001

Switch Installation. Preparing for Installation. Safety Warnings

H3C SecPath M9000-S NSQM2MPUD0 main processing unit

Dell Networking S4810 Open Networking (ON) Getting Started Guide

Maintaining E-Series Routers

SGI InfiniteStorage 120

Technical Specifications

Installing IDS 4215 CHAPTER. This chapter describes IDS 4215 and how to install it. It also describes the accessories and how to install them.

Dell EMC Storage MD1280 Enclosure Owner's Manual

Next Generation Firewall

Dell SC7020 and SC7020F Storage Systems Owner s Manual

Next Generation Firewall

Security Acceleration Module

E-Series Site Preparation Guide

Citrix CloudBridge CB User Manual

Installation Manual. Mounting Instructions Mechanical Mounting. Luminato. Teleste Corporation

Installing the Cisco SFS 3504 Server Switch

Dell SCv3000 and SCv3020 Storage System Owner s Manual

Maintaining the ERX System

Replacing the RAID Battery Backup Unit Assembly on Series 3 FireSIGHT 3500 Defense Centers, Version 5.x

Installation Job Aid for Avaya Virtual Services Platform 8400

Cascade Sensor Installation Guide. Version 8.2 March 2009

G3-APEX-ENT-32T. Apex technical specifications. Parts list

Dell PowerVault MD3060e Storage Enclosure Owner's Manual

Installing the Cisco MDS 9020 Fabric Switch

Dell SC5020 and SC5020F Storage Systems Getting Started Guide

Catalyst 2360 Switch Getting Started Guide

Dell SCv3000 and SCv3020 Storage System Getting Started Guide

CVH Slot Media Converter Chassis Quick Installation Guide

ExtremeSwitching 210 and 220 Series Switches: Hardware Installation Guide

Lightspeed Advanced Reporting Bottle Rocket Hardware Installation Guide

Manual Version: V1.00. Video Decoder Quick Guide

NGFW Security Management Center Appliance. for Forcepoint Next Generation Firewall Hardware Guide. Revision B

Installing a Network Module

Introducing the Cisco 1121 Secure Access Control System Hardware

Allworx 24x Service and Troubleshooting Guide

Symantec S500 Network Interface Card Options and Installation

Symantec S500 Network Interface Card Options and Installation

Installing and Replacing Hardware Options

HPE Port and 48-Port Switches Quick Setup Guide

Dell SC7020 Storage Controller Getting Started Guide

Installation Job Aid for Ethernet Routing Switch 5900 Series

Dell SCv300 and SCv320 Expansion Enclosure Owner's Manual

SINGLEstream Link Aggregation Tap (SS-100)

Stonesoft Next Generation Firewall. Hardware Guide Models 5201, 5205, Revision C

Replacing the Power Supply

Omnitron Systems Technology, Inc. 1. iconverter. 19-Module Managed Power Chassis User s Manual

Hardware Reference Guide For Thin Clients

Introducing the Cisco NAM 2220 Appliance

Savant Host Controller: SVR-4100

Table of Contents Quick Install Guide page Introduction Safety Rack System Precautions ESD Precautions...

SCv360 Expansion Enclosure

Installing a Network Module

Savant Host: SVR-4500S

LifeSize ClearSea Installation Guide August 2012

G3-GS-4P-16T. Parts list G3-GS-4P-16T technical specifications. The G3-GS-4P-16T is best suited for small data centers or at your network edge.

LVN5200A-R2, rev. 1, Hardware Installation Guide

NAS System. User s Manual. Revision 1.0

Maintaining the Avaya S8800 Server for Avaya Aura SIP Enablement Services

1 Getting Started Installing & Configuring

Next Generation Firewall

Quick Start Guide. C-100 Series Switches

Installation Job Aid for Avaya Virtual Services Platform 7200 Series

Stonesoft Next Generation Firewall. Hardware Guide Models 3201, 3202, 3205, 3206, 3207, 3301, Revision F

Filtered SINGLEstream Link Aggregation Tap. User s Guide. FSS-1000 Series (BT, SX, LX) FSS-2000 Series (BT, SX, LX, BT/SX, BT/LX)

G5 PDU Installation Guide

Installing IDS-4235 and IDS-4250

MS400870M. User's Guide. Ver.: Port GBE SFP Switch 19 1U 24x10/100/1000T Combo 10/1000X SFP

Install your TPS 440T and 2200T security devices

Installation and Operation Back-UPS BR1000G-IN / BR1500G-IN

Install the Cisco DNA Center Appliance

Tiger Serve1 Assembly Guide

PoE Powered Gigabit Ethernet Media Converters 1000BASE-T TO 1000BASE-SX/LX. KGC-352 Series. Installation Guide

Dell Vostro 1310/1510/1710/2510 Setup and Features Information

PS3108C. 8-Port Web Smart GbE PoE+ Switch QUICK INSTALLATION GUIDE

Fidelis Network Sensor Appliances QUICK START GUIDE

How to Set Up Your SRX300 Services Gateway

Transcription:

QUICK START GUIDE 7000 SERIES DEVICES Thank you for choosing Sourcefire! Before installing this device, download and follow the instructions in the Sourcefire Support Welcome Kit (https://support.sourcefire.com) to get started with Sourcefire Support, and to set up your Customer Center account. Included items: one of the following Sourcefire 7000 Series models: Sourcefire Sourcefire Sourcefire Each model group (,, and ) has identical chassis. To confirm which model you have, see your packing list. two power cords ( only: one power cord) two straight-through Cat 5e Ethernet cables rack-mounting kit Required items: flathead and Phillips screwdrivers for the rack-mounting kit only: chassis tray, available separately only: small form-factor pluggable (SFP) transceivers, available separately (optional) (Chassis: CHRY-1U-AC) FRONT BACK A (A) LCD panel (B) Front panel (E) USB ports (F) Grounding stud (G) System ID LED G C B D (C) Sensing interfaces (D) Management interface E H I (H) VGA port (I) Serial port (J) Power supply connector F J (Chassis: GERY-1U-8-C-AC / GERY-1U-8-FM-AC) (Chassis: GERY-1U-4C8S-AC) FRONT Fiber interfaces FRONT Copper interfaces A B C A B C D (A) LCD panel (B) Front panel (C) Sensing interfaces (D) Small form-factor pluggable sockets SMALL FORM-FACTOR PLUGGABLE TRANSCEIVERS A B C (C) Sensing interfaces (A) LCD panel (B) Front panel The supports only Sourcefire SFP tranceivers: SFP-F-1-SX SFP-F-1-LX SFP-C-1 Rear with Contacts Front with Bale Fiber SFP Copper SFP Samples SFPs BACK D E F BACK E F G G H I J K H I J K L (D) Reserved (E) Grounding studs (G) Management interface (H) USB ports (F) Power supply LEDs (I) VGA port (J) Serial port (K) Redundant power supplies (E) Reserved (F) Grounding studs (G) Power supply LEDs (H) Management interface (I) USB ports (J) VGA port (K) Serial port (L) Redundant power supplies 2014 Cisco and/or its affiliates. All rights reserved. Page 1 of 8

DEPLOYMENT and CABLING Deploying the Appliance Your device is typically deployed inside a firewall, where it is connected to your trusted management network and the various network segments you want to monitor. In a simple deployment scenario, you connect the management interface on your device to your trusted management network using an Ethernet cable, then connect the sensing interfaces to the network segments you want to monitor using the appropriate cables (copper or fiber) in either a passive or inline cabling configuration. The trusted management network (a restricted network protected from unauthorized access) may have a single secure connection to the Internet for security updates and similar functions, but is separate from the rest of your network and is not accessible to hosts used in daily business operations. You can connect sensing interfaces to different network segments dedicated to particular components of your business that have distinct security requirements to target policies based on the needs for specific segments. These segments can include the DMZ (outward-facing servers, such as mail, ftp, and web hosts), your internal network (hosts used in daily operation and similar applications), and the core (hosts reserved for critical business assets), and can also include segments dedicated to remote locations, mobile access, or other functions. How you cable your sensing interfaces determines your configuration options. If you use passive cabling, you can configure passive sensing interfaces. If you use inline cabling, you can create passive, inline, inline with fail-open, virtual switch, virtual router, or hybrid sensing interfaces on your device. For more information on deployment options and interface configurations and how they affect product features, see the Sourcefire 3D System User Guide and the Sourcefire 3D System Installation Guide. Cabling the Device You can cable your device to configure passive or inline interfaces, depending on your deployment needs. Use passive cabling if you want to: monitor traffic collect information about hosts, operating systems, applications, users, files, networks, and vulnerabilities Use inline cabling if you want to use the same features as a passive deployment, plus: configure a virtual switch, virtual router, or hybrid interface perform network address translation (NAT) use policies to block traffic based on access control features such as application control, user control, security intelligence, URL dispositions, file control, malware detection, or intrusion prevention Use the appropriate cables (as indicated by your interface) and cabling diagram for the interface you want to configure, then use the web interface on the Defense Center to configure the interfaces. See Connecting the Sensing s on page 4. Page 2 of 8

SENSING INTERFACES Understanding the Sensing s The is a 1U device one-half the width of the rack tray with eight copper sensing interfaces, each with bypass capability. You can use these interfaces to passively monitor up to eight separate network segments. You can also use paired interfaces in an inline configuration on up to four network segments. EIGHT-PORT 1000BASE-T COPPER The is a 1U device with eight copper or eight fiber sensing interfaces, each with bypass capability. EIGHT-PORT 1000BASE-SX FIBER You can use these interfaces to passively monitor up to eight separate network segments. You can also use paired interfaces in an inline configuration on up to four network segments. The is a 1U device with four copper sensing interfaces with bypass capability and eight small form-factor pluggable (SFP) sockets without bypass capability. You can use the four copper interfaces to passively monitor up to four separate network segments. You can also use paired interfaces in an inline configuration on up to two network segments. You can insert up to eight SFP transceivers (any combination of copper, fiber, or both) and use their interfaces to monitor up to eight separate network segments. You can also use any combination of transceivers on sequentially paired interfaces (interfaces 5 and 6, 7 and 8, 9 and 10, or 11 and 12) in an inline deployment. Note that SFP interfaces do not have bypass capabilities. SAMPLE SFP TRANSCEIVERS Rear with contacts Fiber SFP Front with bale Copper SFP Inserting or Removing a Small Form-Factor Pluggable (SFP) Transceiver The contains eight SFP sockets in a tab toward center configuration. Cable the interface on the transceiver after the transceiver is inserted into the chassis. Use appropriate electrostatic discharge (ESD) procedures when inserting or removing the transceiver. Avoid touching the contacts, and keep the contacts and interfaces free of dust and dirt. To insert an SFP transceiver into the chassis SFP socket: 1. Taking care not to touch the contacts in the rear, use your fingers to grasp the sides of the bale and slide the rear of the transceiver into a socket on the chassis. Note that sockets on the upper row face up and sockets on the lower row face down. 2. Gently push the bale toward the transceiver to engage the locking mechanism, securing the transceiver in place. CAUTION! Do not force an SFP transceiver into a socket as this can jam the transceiver and can cause permanent damage to the transceiver, the chassis, or both. Use only Sourcefire SFP tranceivers. Non-Sourcefire transceivers may jam in the socket and can cause permanent damage to the transceiver, the chassis, or both. To remove an SFP transceiver: 1. Disconnect all cables from the transceiver you want to remove from the device. 2. Using your fingers, gently pull the bale of the transceiver away from the chassis to disengage the locking mechanism. For transceivers in the upper row, pull down. For transceivers in the lower row, lift up. 3. Gently slide the transceiver directly out of the socket, taking care not to touch the contacts at the back of the transceiver. If the transceiver does not slide out easily, push the transceiver back into the socket and try again, using the bale as a handle. Page 3 of 8

INSTALLATION Installing the Hardware The device is delivered with mounting brackets for 19-inch racks. To install the hardware into the rack: 1. 2. 3. 4. 5. only: mount the device in the chassis tray using the instructions included in the chassis tray kit. Mount the device or chassis tray in your rack using the instructions included with the mounting kit. Connect the power cord to the receptacle on the power supply at the rear of the device. The has one power supply per device; all others have two power supplies per device. Connect the other end of the power cord to an electrical outlet carrying suitable power. See power supply documentation in the Sourcefire 3D System Installation Guide for specifications. Turn on the device using the power button on the front panel. Connecting the Sensing s This section describes the physical connection of the sensing interfaces. After you cable the interfaces, use the web interface on the Defense Center that manages the device to configure the device s sensing interfaces as passive, inline, inline with fail-open, switched, routed, or hybrid. Use only the interfaces on the front of the device as sensing interfaces. See the Sourcefire 3D System Installation Guide for detailed information on planning your deployment. After you have selected a deployment model, cable the sensing interfaces as needed for your configuration. Passive Cabling For each network segment you want to monitor passively, connect the appropriate cables (either copper or fiber) to one sensing interface. Use this cabling when you want to configure passive interfaces. Inline Cabling For each network segment you want to monitor inline, connect the appropriate cables (either copper or fiber sequentially to pairs of sensing interfaces. Use this cabling when you want to configure inline, inline with fail-open, switched, routed, or hybrid interfaces. Passive Inline Inline with Fail-Open Configuration If you want to take advantage of the device s configurable fail-open capability, you must cable two sequential vertical interfaces (interfaces 1 and 2, 3 and 4, 5 and 6, or 7 and 8) to a network segment. After you cable the interfaces, use the web interface on the Defense Center that manages the device to configure the interface as inline with fail-open. See Setting Up an IPS Device in the Sourcefire 3D System User Guide. Page 4 of 8

CONFIGURATION Passive Copper s Fiber s Inline Copper s Fiber s Inline with Fail-Open Configuration If you want to take advantage of the device s configurable fail-open capability, you must cable two sequential interfaces (interfaces 1 and 2, 3 and 4, 5 and 6, or 7 and 8) to a network segment. After you cable the interfaces, use the web interface on the Defense Center that manages the device to configure the interface as inline with fail-open. See Setting Up an IPS Device in the Sourcefire 3D System User Guide. Passive Copper s SFP s Inline Copper s SFP s Inline with Fail-Open Configuration You can configure SFP interfaces inline, but SFP interfaces do not have inline fail-open capability. If you want to take advantage of the device s configurable fail-open capability, you must cable two sequential copper interfaces (interfaces 1 and 2, or 3 and 4) to a network segment. After you cable the interfaces, use the web interface on the Defense Center that manages the device to configure the interface as inline with fail-open. See Setting Up an IPS Device in the Sourcefire 3D System User Guide. Page 5 of 8

CONFIGURATION Configuring the Management This section descibes the process of using a monitor and keyboard to connect your management interface to a secure internal network, and to set up the IP address and network settings for the management interface for the device. You can also use a host on the management interface, the LCD Panel, or the command line to enter the network configuration and register the device to a Defense Center. See the Sourcefire 3D System Installation Guide for more information. The procedure prompts you for the following information about the management interface and your network environment: the IP address you want to give to the management interface the netmask for the management interface s IP address the default gateway for the management interface To use a monitor and keyboard to confi gure the management interface: 1. Using the supplied Ethernet cable, connect the management interface on the rear of the device to a protected management network. You can use the ID button on the front of the device to light an LED in the rear to help locate the chassis in the rack. 2. Connect a monitor and keyboard to the USB ports on the device. 3. Log in as admin. The system requests a password. 4. Enter Sourcefire as the password. Note that the password is case sensitive. 5. Type expert and press Enter. 6. Type sudo su - and press Enter. If needed, reenter Sourcefire as the admin account password to approve the command and display the root prompt. 7. Run the following script: /usr/local/sf/bin/configure-network The following prompt appears (appended with the current value): Do you wish to configure IPv4? (y or n) 8. Type y and press Enter to configure the appliance with an IPv4 address. The following prompt (appended with the current value) appears: Management IP address? 9. Enter the IP address you want to assign to the management interface or press Enter to accept the current value. For example: 10.2.2.20 The following prompt (appended with the current value) appears: Management netmask? 10. Enter the netmask for the interface s IP address or press Enter to accept the current value. For example: 255.255.0.0 The following prompt appears: Management default gateway? 11. Enter the IP address of the gateway for this IP address. For example: 10.2.1.1 The following prompt appears: Are these settings correct: (y or n)? 12. You have two options: If the settings are correct, type y and press Enter to continue. If the settings are incorrect, type n and press Enter. You are prompted to enter the information again. 13. After you enter the correct network settings for the management interface, type exit and press Enter to log out of root. 14. Type logout and press Enter to log out of the appliance, then disconnect the monitor and keyboard. Continue with Performing the Initial Setup. Performing the Initial Setup Complete the initial setup through the web interface. To access the web interface through the management interface, browse to the IP address you configured in the previous procedure. See the Sourcefire 3D System Installation Guide for information on setting up the devices. Page 6 of 8

LEDS Front Panel LEDs A B C LED Reset button System status Hard drive activity System ID Power button and LED Allows you to reboot the appliance without disconnecting it from the power supply. Indicates the system status: A green light indicates the system is powered up and operating normally, or powered down and attached to AC power. An amber light indicates a system fault. A green light indicates there is management network activity. No light indicates there is no management network activity. Indicates the hard drive status: A blinking green light indicates the fixed disk drive is active. If the light is off, there is no drive activity or the system is powered off. When pressed, the ID button displays a blue light, and a blue light is visible at the rear of the chassis. Indicates whether the appliance has power: A green light indicates that the appliance has power and the system is on. No light indicates the system is shut down or does not have power. and LED D NIC1 and NIC2 activity E and A B C D Hard Disk Drive Status EF G A Reset button B System status LED C Hard disk activity LED D System ID button E Power button and LED H Indicates whether there is any network activity: A green light indicates there is network activity. No light indicates there is no network activity. A USB 2.0 connector B Reset button C NIC2 activity LED D System status LED E NIC1 activity LED F Hard drive activity LED G ID button H Power button and LED Indicated the hard disk drive status: A green light indicates the fixed disk drive is active. An amber light indicates a fixed disk drive fault. No light indicates there is no drive activity, or the system is powered off. Sensing LEDs Copper / LEDs Both LEDs off amber green blinking green Fiber / LEDs (top) (bottom) LED (all) Off EIGHT-PORT 1000 BASE-T COPPER INTERFACES EIGHT-PORT 1000BASE-T COPPER FOUR-PORT 1000 BASE-T COPPER INTERFACES with EIGHT-PORT SMALL FORM-FACTOR PLUGGABLE SOCKETS Steady green The interface does not have link. The speed of the traffic on the interface is 10Mb or 100Mb. The speed of the traffic on the interface is 1Gb. The interface has link and is passing traffic. For an inline interface, the light is on when the interface has activity. If dark, there is no activity. For a passive interface, the light is non-functional For an inline or passive interface: the light is on when the interface has link. If dark, there is no link. EIGHT-PORT 1000BASE-SX FIBER The interface pair is not in bypass mode or has no power. The interface pair is ready to enter bypass mode. LEDS System Status Reset button System ID Indicates the system status: No light indicates the system is operating normally, or is powered off. A red light indicates a system error. Allows you to reboot the appliance without disconnecting it from the power supply. Helps identify a system installed in a high-density rack with other similar systems: A blue light indicates the ID button is pressed and a blue light is on at the rear of the appliance. No light indicates the ID button is not pressed. Steady amber Blinking amber SFP / LEDs SFPs only The interface pair has been placed in bypass mode and is not inspecting traffic. The interface pair is in bypass mode; that is, it has failed open. 5 7 9 11 Power button and LED Indicates whether the appliance has power: A green light indicates that the appliance has power and the system is on. A blinking green light indicates that the appliance has power and is shut down. If the light is off, the system does not have power. Management LEDs (all) 6 8 10 12 Left (activity) Right (link) Indicates activity on the port: A blinking light indicates activity. No light indicates there is no link. Indicates whether the link is up: A light indicates the link is up. No light indicates there is no link. Top (activity) Bottom (link) For an inline interface, the light is on when the interface has activity. If dark, there is no activity. For a passive interface, the light is non-functional. For an inline or passive interface, the light is on when the interface has link. If dark, there is no link. Page 7 of 8

! 7000 SERIES SPECIFICATIONS, REGULATORY, and SECURITY Hardware Specifications Physical and Environmental Parameters Parameter Form factor 1U, half-rack width 1U Dimensions (D x W x H) Weight (max installed) Copper 1000BASE-T Single chassis: 12.49 x 7.89 x 1.66 (31.74 cm x 20.04 cm x 4.21 cm) 2-Chassis Tray: 25.05 x 17.24 x 1.73 (63.62 cm x 43.8 cm x 4.44 cm) Chassis: 7 pounds (3.17 kg) Single chassis and power supply in tray: 17.7 pounds (8.03 kg) Double chassis and power supplies in single tray: 24.7 pounds (11.2 kg) Gigabit copper ethernet fail-open interfaces in a paired configuration Cable and distance: Cat5E at 50m 21.6 x 19.0 x 1.73 inches (54.9 x 48.3 x 4.4 cm) 29.0 pounds (13.2kg) Gigabit copper ethernet fail-open interfaces in a paired configuration Cable and distance: Cat5E at 50m Fiber 1000BASE-SX Not applicable Fiber bypass with LC connectors Cable and distance: SX is multimode fiber (850nm) at 550m (standard) Not applicable Copper 1000BASE-T SFP Not applicable Not applicable Gigabit copper ethernet non-bypass interfaces in a paired configuration Cable and distance: Cat5E at 50m Fiber 1000BASE-SX SFP Not applicable Not applicable Fiber non-bypass with LC connectors Cable and distance: SX is multimode fiber (850nm) at 550m (standard) 200m (656 ft) for 62.5μm/125μm fiber 500m (1640 ft) for 50μm/125μm fiber Fiber 1000BASE-LX SFP Not applicable Not applicable Fiber non-bypass with LC connectors Cable and distance: LX is single mode fiber (1310nm) at 10km for 9μm/125μm fiber (standard) Power supply 200W AC power supply Voltage: 100VAC to 240VAC nominal (90VAC to 264VAC maximum) Current: 2A maximum over the full range Frequency range: 50/60 Hz nominal (47Hz to 63Hz maximum) 450W dual redundant (1+1) AC power supplies Voltage: 100VAC to 240VAC nominal (85VAC to 264VAC maximum) Current: 3A maximum for 90VAC to 132VAC, per supply 1.5A maximum for 187VAC to 264VAC, per supply Frequency range: 47Hz to 63Hz Operating temperature 0 C to 40 C (32 F to 104 F) 5 C to 40 C (41 F to 104 F) Non-operating temperature -20 C to 70 C (-4 F to 158 F) -20 C to 70 C (-4 F to 158 F) Operating humidity Non-operating humidity 5% to 95%, noncondensing Operation beyond these limits is not guaranteed and not recommended. 0% to 95%, non-condensing Store the unit below 95% non-condensing relative humidity. Acclimate below maximum operating humidity at least 48 hours prior to placing the unit in service. 5% to 85%, non-condensing Operation beyond these limits is not guaranteed and not recommended. 5% to 90%, non-condensing with a maximum wet bulb of 28 C (82 F) at temperatures from 25 C to 35 C (77 F to 95 F) Store the unit below 95% non-condensing relative humidity. Acclimate below maximum operating humidity at least 48 hours prior to placing the unit in service. Altitude 0 ft (sea level) to 5905 ft (0 to 1800m) 0 ft (sea level) to 5905 ft (0 to 1800m) Cooling requirements 682 BTU/hour You must provide sufficient cooling to maintain the appliance within its required operating temperature range. Failure to do this may cause a malfunction or damage to the appliance. 900 BTU/hour You must provide sufficient cooling to maintain the appliance within its required operating temperature range. Failure to do this may cause a malfunction or damage to the appliance. Acoustic noise 53 dba when idle. 62 dba at full processor load. 64 dba at full processor load, normal fan operation Meets GR-63-CORE 4.6 Acoustic Noise Operating shock No errors with half a sine wave shock of 5G (with 11 msec. duration) Complies with Bellecore GR-63-CORE standards Airflow Regulatory Conformance 20 ft 3 (0.57m 3 ) per minute Airflow through the appliance enters at the front and exits at the rear, with no side ventilation. 140 ft 3 (3.9m 3 ) per minute Airflow through the appliance enters at the front and exits at the rear with no side ventilation. This Sourcefire appliance conforms to multiple national and international standards. For a full list of regulatory compliance, see the Sourcefire 3D System Installation Guide. Security Considerations Before you install your appliance, Sourcefire recommends that you consider the following: Locate your appliance in a lockable rack within a secure location that prevents access by unauthorized personnel. Allow only trained and qualified personnel to install, replace, administer, or service the appliance. Always connect the management interface to a secure internal management network that is protected from unauthorized access. WARNING! This Sourcefire appliance should be installed and maintained by qualified personnel only. Keep in mind the following safety information to avoid system damage or personal injury: Remove all factory packaging before using the appliance. Provide adequate ventilation to prevent overheating. Do not cover or block vents, or otherwise enclose the appliance. The appliance must be properly grounded when connecting power to the power outlet. At all times, keep the chassis area free from dust. Lifting the chassis for rack installation may require two people, as the unit is heavy. To avoid electrical shock, do not open or remove the chassis covers or metal parts without proper instruction. 9770 Patuxent Woods Drive Columbia, MD 21046 USA 800.917.4134 +1.410.423.1901 support@sourcefire.com 2014 Cisco and/or its affiliates. All rights reserved. Page 8 of 8