• No results found

2012 Best Practice Seminar. Presented by David Rawle

N/A
N/A
Protected

Academic year: 2021

Share "2012 Best Practice Seminar. Presented by David Rawle"

Copied!
60
0
0

Loading.... (view fulltext now)

Full text

(1)

2012 Best Practice

Seminar

(2)
(3)

Housekeeping

Mobiles on Silent please

Toilets are…

(4)

Agenda

Introduction

What's new

R75.45

R75.40VS

E80.40 with integrated management

Best Practices

(5)

Introduction

Who am I?

David Rawle

Technical Director of Bytes Security Partnerships

15 years working within the industry

Who are we?

6th biggest Check Point reseller in the UK

(6)

Introduction

We will remain an autonomous part of Bytes

We are currently focused on growing SPARC

Fundamental to keep the current Direct to

Engineer model

Will be consulting with customers and seeking

(7)
(8)

R75.45

New Gaia features:

– Ability to configure 6in4 tunnels.

– Backup and restore, including scheduled backups.

– Policy Based Routing

– Support for PPPoE interfaces. See sk79880.

– Ability to configure SNMP traps for RAID issues.

– TACACS+ authentication.

– e1000 driver updated to version 7.6.15.

– Monitor mode on 10GbE ports, with automatic "one legged" bridge creation.

– 2012 appliances automatic license fetch during the First Time Wizard.

– ISP Redundancy. See sk25129.

Automatic Software Updates

– Get updates for licensed Check Point products directly through the Operating System.

– Download and install R75.45 more easily and quickly.

– For R75.45 installation using Automatic Software Updates for Gaia, refer to sk81680

Aggregation of logs of the IPS Non Compliant HTTP and Non Compliant DNS protections.

Log Server performance improvements enables writing logs in a more efficient way. This solved

capacity issues in specific scenarios

Anti-Malware report Expose the severity and category of the malwares found in the overview and

additional pages to allow better high level understanding of Anti-Bot and Anti-Virus Blade findings.

(9)

R75.45

Very few customers have upgraded to it

Provides specific fixes

(10)
(11)

R75.40VS

Otherwise know as main-train R7X VSX

Simple Virtual System configuration

(12)

Demo

(13)
(14)
(15)

New in E80.40

What's new?

(16)
(17)

E80.40 with integrated Management

N etwor k P ol icy

Alongside

with Network

Security

management

R75.40

En d p oi n t P ol icy

Endpoint

Security

Management

E80.40

SMART-1

Security Management

(18)

E80.40

Additional features in Endpoint Security E80.40

Manage

150,000 seats

of FDE & ME

Custom image

in full disk

Encryption

Scan

Multiple

AD trees

Web-remote

help to remediate

passwords

Manage

80,000 seats

full E80 suite

Getting –Started

Wizard

Set alerts & notifications

including email alerts

Configure &

preview user

messages

(19)
(20)
(21)

Introducing

Document Security

(22)

Select authorised users & classification

to protect your document

(23)
(24)

Secure

access from

smartphones

Secure

access from

PC & Mac

Business

Container

VPN App

Web Portal

for Business

Applications

VPN Client

(25)

What is Check

Point Mobile

Business Application?

Protect Business Data

Bring Your Own Device

Part of the Mobile Access

(26)
(27)
(28)
(29)

Best Practices – Recover Laptops

How to recover a broken FDE Laptop

Demo

(30)

Best Practices – FDE Boot Protection

SSD’s don’t all require full encryption

But you cant just configure pre-boot

protection

(31)

Best Practices - Syslogging

(32)

Best Practices – Check Point VE

Check Point Virtual Edition

What is it useful for?

How about DLP

Check Point VE

DLP

Linked to SmartCentre

(33)

Best Practices – Check Point VE

Available for the following Hypervisors

ESX v4.0

ESX v4.1

ESXi v4.0

ESXi v4.1

ESXi v5.0

ESXi v5.1

Available in the following license breaks

8 Core

16 Core

(34)
(35)

Best Practices - Backups

We talk about this every year…

SPLAT

“backup –n --ftp

ipaddress username password

“backup –n --scp

ipaddress username password

Use “crontab –e” to edit the cron job and schedule

Gaia

To save a backup locally:

add backup local

To save a backup on a remote server using ftp:

add backup ftp ip VALUE username VALUE password plain

To save a backup on a remote server using tftp:

add backup tftp ip VALUE

To save a backup on a remote server using scp:

(36)

Best Practices - Backups

Gaia – Restores

To restore a backup from a locally held file:

set backup restore local <TAB>

To restore a backup from a remote server using ftp:

set backup restore ftp ip VALUE username VALUE password

plain

To restore a backup from a remote server using tftp:

set backup restore tftp ip VALUE file VALUE

To restore a backup from a remote server using scp:

set backup restore scp ip VALUE username VALUE password

plain

(37)

Best Practices - Backups

Gaia – Scheduled Backups

To add a scheduled backup locally:

– add backup-scheduled name VALUE local

To add a scheduled backup on a remote server using ftp:

– add backup-scheduled name VALUE ftp ip VALUE username VALUE password plain

To add a scheduled backup on a remote server using scp:

• add backup-scheduled name VALUE scp ip VALUE username VALUE password plain

To add a scheduled backup on a remote server using tftp:

• add backup-scheduled name VALUE tftp ip VALUE

To configure a daily backup schedule:

• set backup-scheduled name VALUE recurrence daily time VALUE

To configure a monthly backup schedule:

• set backup-scheduled name VALUE recurrence monthly month VALUE days VALUE time VALUE

To configure a weekly backup schedule:

• set backup-scheduled name VALUE recurrence weekly days VALUE time VALUE

To show the details of the scheduled backup:

• show backup-scheduled VALUE

To delete a scheduled backup:

(38)

Best Practices - Backups

Speaking of Backups

VMWare

(39)

Best Practices – Gaia Commands

Expert Mode activation

“set expert-password plain”

When not in expert mode…

Type command then press <TAB>

(40)

Best Practices – Gaia Commands

Some other commands available

show interface <TAB>

set interface <TAB>

add user <TAB>

save config

show commands

show commands feature <TAB>

show configuration

expert

(41)

Best Practices – Gaia Commands

One nice “Cisco” type touch

“show configuration”

Copy the output into Notepad

(42)

Best Practices – table.def

Gets flagged as part of the upgrade process

If you modify this file it will be over written at

upgrade

Why would you?

See sk31832 for traffic hiding behind Virtual IP

NTP typically fails from secondary

DNS typically fails from secondary

If NTP and DNS fails the clock will not be right on

your secondary box which means it won’t failover

cleanly

(43)

Best Practices – What to Log (or not)

Large amounts of logging kill performance

DO LOG

Web Protocols

VPN Traffic (except that below)

DO NOT LOG

Microsoft/NetBIOS Traffic

DNS (except external lookups for browsing)

(44)

Best Practices – What to Log (or not)

(45)

Best Practices – Tidy up after yourself

We have customers spending large amounts

of money on firewall audits

Sometimes compliance means they

have

to be

done

If you just disable a rule when you don’t need

it anymore and delete objects when you don’t

need them your lives will be much easier

(46)

Best Practices – Tidy up after yourself

What are Check Point doing to help

(47)

Best Practices – Tidy up after yourself

What are other people doing to help

(48)

Best Practices – Monitor Performance

Don’t just monitor CPU

Check Point has a whole SNMP stack built in

Use it monitor other metrics

(49)
(50)

Best Practices – VPN Cert Renewal

(51)
(52)

A year ago we said…

“Check Point and IPv6

(53)

IPv6

Gaia Supports IPv6

About to EA IPv6 Support in ALL Blades

IPv6 Support for Management

(54)

R75.45

New Gaia features:

– Ability to configure 6in4 tunnels.

– Backup and restore, including scheduled backups.

– Policy Based Routing

– Support for PPPoE interfaces. See sk79880.

– Ability to configure SNMP traps for RAID issues.

– TACACS+ authentication.

– e1000 driver updated to version 7.6.15.

– Monitor mode on 10GbE ports, with automatic "one legged" bridge creation.

– 2012 appliances automatic license fetch during the First Time Wizard.

– ISP Redundancy. See sk25129.

Automatic Software Updates

– Get updates for licensed Check Point products directly through the Operating System.

– Download and install R75.45 more easily and quickly.

– For R75.45 installation using Automatic Software Updates for Gaia, refer to sk81680

Aggregation of logs of the IPS Non Compliant HTTP and Non Compliant DNS protections.

Log Server performance improvements enables writing logs in a more efficient way. This solved

capacity issues in specific scenarios

Anti-Malware report Expose the severity and category of the malwares found in the overview and

additional pages to allow better high level understanding of Anti-Bot and Anti-Virus Blade findings.

(55)

R75.45

New Gaia features:

– Ability to configure 6in4 tunnels.

– Backup and restore, including scheduled backups.

– Policy Based Routing

– Support for PPPoE interfaces. See sk79880.

– Ability to configure SNMP traps for RAID issues.

– TACACS+ authentication.

– e1000 driver updated to version 7.6.15.

– Monitor mode on 10GbE ports, with automatic "one legged" bridge creation.

– 2012 appliances automatic license fetch during the First Time Wizard.

– ISP Redundancy. See sk25129.

Automatic Software Updates

– Get updates for licensed Check Point products directly through the Operating System.

– Download and install R75.45 more easily and quickly.

– For R75.45 installation using Automatic Software Updates for Gaia, refer to sk81680

Aggregation of logs of the IPS Non Compliant HTTP and Non Compliant DNS protections.

Log Server performance improvements enables writing logs in a more efficient way. This solved

capacity issues in specific scenarios

Anti-Malware report Expose the severity and category of the malwares found in the overview and

additional pages to allow better high level understanding of Anti-Bot and Anti-Virus Blade findings

.

(56)
(57)

IPv6 Addresses

An IPv6 address has 8 "hextets" rather than 4

octets

“:”

not

“.”

2001:05c0:9168:0000:0000:0000:0000:0001/1

28

Leading zeros may be dropped

one time, and one time only, you may drop

contiguous zeros completely

(58)

IPv6 Subnets

All done in /XX notation

2001:05c0:9168:0000:0000:0000:0000:0001/128

2001:05c0:9168:5234::/64

2001:05c0:9168::/48

Machine IP’s typically use the last 4 "hextets“

Tunnelbroker.net will give you a /64 or /48 subnet

One /48 contains 65k /64 subnets

2001:05c0:9168::/48

Contains

(59)

IPv6 auto assigned addresses

NOT Random

IP = 2001:470:1f09:128a:2

25

:

22

ff:fe

61

:

47fe

MAC = 00:

25

:

22

:

61

:

47

:

fe

What about the FE80 Address?

(60)

IPv6

With 6in4 tunnels here and full support

for all blades immanent now is the right

time to start planning your IPv6 tests

and roll-outs

References

Related documents

Theater aan het Spui Glazen Zaal Kasteel Duivenvoorde Paleiskerk Paleiskerk Paleiskerk 20.00 hours 20.00 hours 20.30 hours 20.00 hours 20.00 hours 20.00 hours 21.00 hours

In light of the limited long-term data on mor- tality after bariatric surgery and the recent in- crease in bariatric surgery in the United States, 15-17 we undertook a retrospective

Peter Peregrine, professor of anthropology, received the Award for Excellence in Scholarship, which honors a faculty member who has demonstrated sustained scholarly excellence for

A 5, 10 100 RP + cation-exchange + ion-exclusion Neutral and weak basic compounds AB 5, 10 100 RP + cation-exchange + anion-exchange Neutral, acidic and basic compounds B2 5, 10 100

ET-TIC-BUS is the application for the CDB-6 PLUS, CDB-5 PLUS and CDB-4 PLUS on board multifunctional units to make them become the heart of the on board system, if not the only

If the blast wave encoun- ters a change in the CBM profile during the deceleration phase, with density decreasing faster than ρ ∝ R −3 beyond some radius, the conversion of

Due to severe poverty and food insecurity in the Gaza strip Ummah Welfare Trust have started a programme to support 270 vulnerable families.

Instructions There are 3 situations that will be explore by the player which are email scam, phone scam and SMS scam. Each situation will undergo 2 levels. Level 1: Player