Recommendation: security requirements for network deployment
Install the dynamic attributes connector on a protected internal network. Although the dynamic attributes connector is configured to have only the necessary services and ports available, you must make sure that attacks cannot reach it.
If the dynamic attributes connector and the Security Cloud Control reside on the same network, you can connect the Security Cloud Control to the same protected internal network as the dynamic attributes connector.
Take steps to ensure that communications between appliances cannot be interrupted, blocked, or tampered with. Regardless of how you deploy your appliances, inter-system communication is encrypted. However, you must still protect against distributed denial of service (DDoS) or adversary-in-the-middle attacks.