7. NGFW para pequeñas empresas. Tuning y recomendaciones generales

SMB Check Point (1500 c). , , TS Solution. , - SMB. NGFW, .

NGFW :

  1. CheckPoint 1500 Security Gateway

  2. : WiFi LTE

  3. VPN

  4. SMP

  5. Smart-1 Cloud

SMB - Gaia 80.20 Embedded. ( Management Server ) - NGFW.

Check Point SMB, , Appliance Sizing Tool, ( , .).

NGFW
  1. NGFW SMB (CPU, RAM, HDD), SD-, , .

  2. . Gaia 80.20 Embedded , CLI Expert 

    # ifconfig

    , . NGFW, .

  3. Gaia :

    > show diag

    .  , 80.20 Embedded , SNMP-traps:

     

    Interface disconnected

    VLAN removed

    Vlan

    High memory utilization

    RAM

    Low disk space

    HDD

    High CPU utilization

    CPU

    High CPU interrupts rate

    High connection rate

    High concurrent connections

    High Firewall throughput

    Firewall

    High accepted packet rate

    Cluster member state changed

    Connection with log server error

    Log-Server

  4. RAM. Gaia (Linux OC) , RAM 70-80% .

    SMB- SWAP-, Check Point. , Linux <vm.swapsiness>, SWAP.

Gaia - 80.20.10. , CLI:   Expert Linu . NGFW , . SMB.

Gaia OS
  1. SecureXL

    # fwaccel stat

  2. # fw ctl multik stat

  3. ().

    # fw ctl pstat

  4. *

    # cphaprob stat

  5. Linux- TOP

, NGFW (, ) : , . - Management Server.

NGFW

  1. ( , Gaia)

    # tail -f /var/log/messages2

  2. C ( )

    # tail -f /var/log/log/sfwd.elg

  3. .

    # dmesg

NGFW heck Point, , .

Application Control / URL Filtering
  • ANY, ANY (Source, Destination).

  • URL- : (^|..)checkpoint.com

  • (UserCheck).

  • , “SecureXL”. accelerated / medium path. ( Hits ).

HTTPS-Inspection

, 70-80% HTTPS-, , . , HTTPS-Inspection IPS, Antivirus, Antibot.

80.40 HTTPS- Legacy Dashboard, :

  • Bypass (Destination).

  • Bypass URL-.

  • Bypass IP c (Source).

  • Inspect ,

  • Bypass .

* HTTPS HTTPS Proxy, Any. Inspect.

IPS

IPS NGFW , . Check Point, SMB IPS.

, :

  1. Optimized “Optimized SMB” ( ).

  2. , IPS → Pre R80.Settings Server Protections.

  3. CVE 2010, , . , Profile→ IPS→ Additional Activation → Protections to deactivate list

NGFW SMB (1500) , . . , !

Check Point TS Solution.  — (TelegramFacebookVKTS Solution Blog.).




All Articles