Professional Documents
Culture Documents
NetworKraft Consultancy
Why Checkpoint?
• Specialized Vendor
– Only Firewall Creators
• More Granularity
– Connection based Granularity
• More Open
– Multiple hardware platforms
– Multiple OS platforms for Management Server
Why Checkpoint?
• Simpler GUI
– More User friendly GUI (My view)
– Easy to troubleshoot
• Stand-alone Deployment
– Secure Platform + Management Server Enforcement Unit
– Client Software on Client Machine
• Distributed Deployment
– Secure Platform Enforcement Module
– Management Server Another Hardware
– Client Software on Client Machine
Deployment
Distributed Deployment:
Security
Security Security
Gateway
Mgmt Smartview
(Physical
Server Tracker
Hardware)
Stand-Alone Deployment:
Security
Gateway Security
(Physical
Hardware) + Smartview
Security Mgmt Tracker
Server
Traffic Control Methods
• Packet Filtering
– Specific Rules for Allowing/Denying Traffic
– Explicit Deny at the end of the policy
• Stateful Filtering
– Maintaining state table
– Makes environment more secured
– Stale out old entries to protect FW from running out of memory space
• Application Aware Filtering
– More granular
– Datagram inspection
Secure Platform
• IPSO: FreeBSD
– Ipsilon company 1997 NOKIA acquired 2009 Check Point acquired NOKIA
Security Appliances
• GAIA: FreeBSD
– Same command line as in IPSO
– Beginning of Virtualization (Virtual System eXtension)
– More concurrent connections (210 million)
Real World of Check Point
Tire X
NETWORK- DC
(Ferrari)
YOUR
Metal
X
Internet
Design- iDMZ and xDMZ
Internal Network
Internet
idmz xdmz
Why Distributed Deployment
• Anti-spoofing
• Anti-bot
• Identity Awareness
Lab Topology
.2
.20
.7
.3
.30
192.168.10.4 Internet
.5 192.168.1.1
.40
GAiA
• Interface configuration
• Routing
– Static
– Dynamic (RIP,OSPF)
• System Management
– Proxy Server
– Core dump
– System Logging
GAiA Continued…
• High Availability
-VRRP (Virtual Router Redundancy Protocol)
• User Management
• Back-up/Restore
• Upgrade and licensing
Checkpoint SmartConsole
Checking HCL
Check Point Installation
- Partition Configuration
- View/Change
- OK
Check Point Installation
- Reboot
Check Point Configuration
- Entering Gaia
Best Practices