Check Point Gaia R80.40. Π§Ρ‚ΠΎ Π±ΡƒΠ΄Π΅Ρ‚ Π½ΠΎΠ²ΠΎΠ³ΠΎ?

Check Point Gaia R80.40. Π§Ρ‚ΠΎ Π±ΡƒΠ΄Π΅Ρ‚ Π½ΠΎΠ²ΠΎΠ³ΠΎ?

ΠŸΡ€ΠΈΠ±Π»ΠΈΠΆΠ°Π΅Ρ‚ΡΡ ΠΎΡ‡Π΅Ρ€Π΅Π΄Π½ΠΎΠΉ Ρ€Π΅Π»ΠΈΠ· ΠΎΠΏΠ΅Ρ€Π°Ρ†ΠΈΠΎΠ½Π½ΠΎΠΉ систСмы Gaia R80.40. НСсколько нСдСль Π½Π°Π·Π°Π΄ стартовала ΠΏΡ€ΠΎΠ³Ρ€Π°ΠΌΠΌΠ° Early Access, ΠΏΠΎ ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠΉ ΠΌΠΎΠΆΠ½ΠΎ ΠΏΠΎΠ»ΡƒΡ‡ΠΈΡ‚ΡŒ доступ для тСстирования дистрибутива. ΠœΡ‹, ΠΊΠ°ΠΊ ΠΎΠ±Ρ‹Ρ‡Π½ΠΎ ΠΏΡƒΠ±Π»ΠΈΠΊΡƒΠ΅ΠΌ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡŽ ΠΎ Ρ‚ΠΎΠΌ, Ρ‡Ρ‚ΠΎ Π±ΡƒΠ΄Π΅Ρ‚ Π½ΠΎΠ²ΠΎΠ³ΠΎ, Π° Ρ‚Π°ΠΊΠΆΠ΅ Π²Ρ‹Π΄Π΅Π»ΠΈΠΌ ΠΌΠΎΠΌΠ΅Π½Ρ‚Ρ‹, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ Π½Π°ΠΈΠ±ΠΎΠ»Π΅Π΅ интСрСсны с нашСй Ρ‚ΠΎΡ‡ΠΊΠΈ зрСния. ЗабСгая Π²ΠΏΠ΅Ρ€Π΅Π΄, ΠΌΠΎΠ³Ρƒ ΡΠΊΠ°Π·Π°Ρ‚ΡŒ, Ρ‡Ρ‚ΠΎ Π½ΠΎΠ²ΡˆΠ΅ΡΡ‚Π²Π° Π΄Π΅ΠΉΡΡ‚Π²ΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎ Π·Π½Π°Ρ‡ΠΈΠΌΡ‹Π΅. ΠŸΠΎΡΡ‚ΠΎΠΌΡƒ стоит Π³ΠΎΡ‚ΠΎΠ²ΠΈΡ‚ΡŒΡΡ ΠΊ скорой ΠΏΡ€ΠΎΡ†Π΅Π΄ΡƒΡ€Π΅ обновлСния. Π Π°Π½Π΅Π΅ ΠΌΡ‹ ΡƒΠΆΠ΅ ΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π»ΠΈ ΡΡ‚Π°Ρ‚ΡŒΡŽ ΠΎ Ρ‚ΠΎΠΌ, ΠΊΠ°ΠΊ это Π΄Π΅Π»Π°Ρ‚ΡŒ (Π·Π° Π΄ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎΠΉ ΠΈΠ½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΠ΅ΠΉ ΠΌΠΎΠΆΠ½ΠΎ ΠΎΠ±Ρ€Π°Ρ‚ΠΈΡ‚ΡŒΡΡ сюда). ΠŸΠ΅Ρ€Π΅ΠΉΠ΄Π΅ΠΌ ΠΊ Ρ‚Π΅ΠΌΠ΅…

What’s New

Рассмотрим здСсь ΠΎΡ„ΠΈΡ†ΠΈΠ°Π»ΡŒΠ½ΠΎ заявлСнныС Π½ΠΎΠ²ΡˆΠ΅ΡΡ‚Π²Π°. Π˜Π½Ρ„ΠΎΡ€ΠΌΠ°Ρ†ΠΈΡ взята с сайта Check Mates (ΠΎΡ„ΠΈΡ†ΠΈΠ°Π»ΡŒΠ½ΠΎΠ΅ сообщСство Check Point). Π‘ вашСго позволСния, я Π½Π΅ Π±ΡƒΠ΄Ρƒ ΠΏΠ΅Ρ€Π΅Π²ΠΎΠ΄ΠΈΡ‚ΡŒ этот тСкст, Π±Π»Π°Π³ΠΎ аудитория Ρ…Π°Π±Ρ€Π° это позволяСт. ВмСсто этого я ΠΎΡΡ‚Π°Π²Π»ΡŽ свои ΠΊΠΎΠΌΠΌΠ΅Π½Ρ‚Π°Ρ€ΠΈΠΈ Π² ΡΠ»Π΅Π΄ΡƒΡŽΡ‰Π΅ΠΉ Π³Π»Π°Π²Π΅.

1. IoT Security. НовыС Ρ„ΡƒΠ½ΠΊΡ†ΠΈΠΈ, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ ΠΊΠ°ΡΠ°ΡŽΡ‚ΡΡ ΠΈΠ½Ρ‚Π΅Ρ€Π½Π΅Ρ‚Π° Π²Π΅Ρ‰Π΅ΠΉ

  • Collect IoT devices and traffic attributes from certified IoT discovery engines (currently supports Medigate, CyberMDX, Cynerio, Claroty, Indegy, SAM and Armis).
  • Configure a new IoT dedicated Policy Layer in policy management.
  • Configure and manage security rules that are based on the IoT devices’ attributes.

2. TLS InspectionHTTP/2:

  • HTTP/2 is an update to the HTTP protocol. The update provides improvements to speed, efficiency and security and results with a better user experience.
  • Check Point’s Security Gateway now support HTTP/2 and benefits better speed and efficiency while getting full security, with all Threat Prevention and Access Control blades, as well as new protections for the HTTP/2 protocol.
  • Support is for both clear and SSL encrypted traffic and is fully integrated with HTTPS/TLS
  • Inspection capabilities.

TLS Inspection Layer. ΠΠΎΠ²ΡˆΠ΅ΡΡ‚Π²Π° ΠΎΡ‚Π½ΠΎΡΠΈΡ‚Π΅Π»ΡŒΠ½ΠΎ HTTPS инспСкции:

  • A new Policy Layer in SmartConsole dedicated to TLS Inspection.
  • Different TLS Inspection layers can be used in different policy packages.
  • Sharing of a TLS Inspection layer across multiple policy packages.
  • API for TLS operations.

3. Threat Prevention

  • Overall efficiency enhancement for Threat Prevention processes and updates.
  • Automatic updates to Threat Extraction Engine.
  • Dynamic, Domain and Updatable Objects can now be used in Threat Prevention and TLS Inspection policies. Updatable objects are network objects that represent an external service or a known dynamic list of IP addresses, for example β€” Office365 / Google / Azure / AWS IP addresses and Geo objects.
  • Anti-Virus now uses SHA-1 and SHA-256 threat indications to block files based on their hashes. Import the new indicators from the SmartConsole Threat Indicators view or the Custom Intelligence Feed CLI.
  • Anti-Virus and SandBlast Threat Emulation now support inspection of e-mail traffic over the POP3 protocol, as well as improved inspection of e-mail traffic over the IMAP protocol.
  • Anti-Virus and SandBlast Threat Emulation now use the newly introduced SSH inspection feature to inspect files transferred over the SCP and SFTP protocols.
  • Anti-Virus and SandBlast Threat Emulation now provide an improved support for SMBv3 inspection (3.0, 3.0.2, 3.1.1), which includes inspection of multi-channel connections. Check Point is now the only vendor to support inspection of a file transfer through multiple channels (a feature that is on-by-default in all Windows environments). This allows customers to stay secure while working with this performance enhancing feature.

4. Identity Awareness

  • Support for Captive Portal integration with SAML 2.0 and third party Identity Providers.
  • Support for Identity Broker for scalable and granular sharing of identity information between PDPs, as well as cross-domain sharing.
  • Enhancements to Terminal Servers Agent for better scaling and compatibility.

5. IPsec VPN

  • Configure different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities. This provides:
  • Improved privacy β€” Internal networks are not disclosed in IKE protocol negotiations.
  • Improved security and granularity β€” Specify which networks are accessible in a specified VPN community.
  • Improved interoperability β€” Simplified route-based VPN definitions (recommended when you work with an empty VPN encryption domain).
  • Create and seamlessly work with a Large Scale VPN (LSV) environment with the help of LSV profiles.

6. URL Filtering

  • Improved scalability and resilience.
  • Extended troubleshooting capabilities.

7. NAT

  • Enhanced NAT port allocation mechanism β€” on Security Gateways with 6 or more CoreXL Firewall instances, all instances use the same pool of NAT ports, which optimizes the port utilization and reuse.
  • NAT port utilization monitoring in CPView and with SNMP.

8. Voice over IP (VoIP)Multiple CoreXL Firewall instances handle the SIP protocol to enhance performance.

9. Remote Access VPNUse machine certificate to distinguish between corporate and non-corporate assets and to set a policy enforcing the use of corporate assets only. Enforcement can be pre-logon (device authentication only) or post-logon (device and user authentication).

10. Mobile Access Portal AgentEnhanced Endpoint Security on Demand within the Mobile Access Portal Agent to support all major web browsers. For more information, see sk113410.

11. CoreXL and Multi-Queue

  • Support for automatic allocation of CoreXL SNDs and Firewall instances that does not require a Security Gateway reboot.
  • Improved out of the box experience β€” Security Gateway automatically changes the number of CoreXL SNDs and Firewall instances and the Multi-Queue configuration based on the current traffic load.

12. Clustering

  • Support for Cluster Control Protocol in Unicast mode that eliminates the need for CCP

Broadcast or Multicast modes:

  • Cluster Control Protocol encryption is now enabled by default.
  • New ClusterXL mode -Active/Active, which supports Cluster Members in different geographic locations that are located on different subnets and have different IP addresses.
  • Support for ClusterXL Cluster Members that run different software versions.
  • Eliminated the need for MAC Magic configuration when several clusters are connected to the same subnet.

13. VSX

  • Support for VSX upgrade with CPUSE in Gaia Portal.
  • Support for Active Up mode in VSLS.
  • Support for CPView statistical reports for each Virtual System

14. Zero TouchA simple Plug & Play setup process for installing an appliance β€” eliminating the need for technical expertise and having to connect to the appliance for initial configuration.

15. Gaia REST APIGaia REST API provides a new way to read and send information to servers that run Gaia Operating System. See sk143612.

16. Advanced Routing

  • Enhancements to OSPF and BGP allow to reset and restart OSPF neighboring for each CoreXL Firewall instance without the need to restart the routed daemon.
  • Enhancing route refresh for improved handling of BGP routing inconsistencies.

17. New kernel capabilities

  • Upgraded Linux kernel
  • New partitioning system (gpt):
  • Supports more than 2TB physical/logical drives
  • Faster file system (xfs)
  • Supporting larger system storage (up to 48TB tested)
  • I/O related performance improvements
  • Multi-Queue:
  • Full Gaia Clish support for Multi-Queue commands
  • Automatic Β«on by defaultΒ» configuration
  • SMB v2/3 mount support in Mobile Access blade
  • Added NFSv4 (client) support (NFS v4.2 is the default NFS version used)
  • Support of new system tools for debugging, monitoring and configuring the system

18. CloudGuard Controller

  • Performance enhancements for connections to external Data Centers.
  • Integration with VMware NSX-T.
  • Support for additional API commands to create and edit Data Center Server objects.

19. Multi-Domain Server

  • Back up and restore an individual Domain Management Server on a Multi-Domain Server.
  • Migrate a Domain Management Server on one Multi-Domain Server to a different Multi-Domain Security Management.
  • Migrate a Security Management Server to become a Domain Management Server on a Multi-Domain Server.
  • Migrate a Domain Management Server to become a Security Management Server.
  • Revert a Domain on a Multi-Domain Server, or a Security Management Server to a previous revision for further editing.

20. SmartTasks and API

  • New Management API authentication method that uses an auto-generated API Key.
  • New Management API commands to create cluster objects.
  • Central Deployment of Jumbo Hotfix Accumulator and Hotfixes from SmartConsole or with an API allows to install or upgrade multiple Security Gateways and Clusters in parallel.
  • SmartTasks β€” Configure automatic scripts or HTTPS requests triggered by administrator tasks, such as publishing a session or installing a policy.

21. DeploymentCentral Deployment of Jumbo Hotfix Accumulator and Hotfixes from SmartConsole or with an API allows to install or upgrade multiple Security Gateways and Clusters in parallel.

22. SmartEventShare SmartView views and reports with other administrators.

23. Log ExporterExport logs filtered according to field values.

24. Endpoint Security

  • Support for BitLocker encryption for Full Disk Encryption.
  • Support for external Certificate Authority certificates for Endpoint Security client
  • authentication and communication with the Endpoint Security Management Server.
  • Support for dynamic size of Endpoint Security Client packages based on the selected
  • features for deployment.
  • Policy can now control level of notifications to end users.
  • Support for Persistent VDI environment in Endpoint Policy Management.

Π§Ρ‚ΠΎ большС всСго ΠΏΠΎΠ½Ρ€Π°Π²ΠΈΠ»ΠΎΡΡŒ Π½Π°ΠΌ (Π½Π° основС Π·Π°Π΄Π°Ρ‡ ΠΊΠ»ΠΈΠ΅Π½Ρ‚ΠΎΠ²)

Как Π²ΠΈΠ΄ΠΈΡ‚Π΅, ΠΎΡ‡Π΅Π½ΡŒ ΠΌΠ½ΠΎΠ³ΠΎ Π½ΠΎΠ²ΡˆΠ΅ΡΡ‚Π². Но для нас, ΠΊΠ°ΠΊ для систСмного ΠΈΠ½Ρ‚Π΅Π³Ρ€Π°Ρ‚ΠΎΡ€Π°, Π΅ΡΡ‚ΡŒ нСсколько вСсьма интСрСсных ΠΌΠΎΠΌΠ΅Π½Ρ‚ΠΎΠ² (ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ Ρ‚Π°ΠΊΠΆΠ΅ интСрСсны нашим ΠΊΠ»ΠΈΠ΅Π½Ρ‚Π°ΠΌ). Наш Π’ΠΎΠΏ-10:

  1. НаконСц появилась полноцСнная ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΠ° IoT устройств. Π£ΠΆΠ΅ довольно Ρ‚Ρ€ΡƒΠ΄Π½ΠΎ Π²ΡΡ‚Ρ€Π΅Ρ‚ΠΈΡ‚ΡŒ компанию, Ρƒ ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠΉ Π½Π΅ Π±Ρ‹Π»ΠΎ Π±Ρ‹ Ρ‚Π°ΠΊΠΈΡ… дСвайсов.
  2. TLS инспСкция Ρ‚Π΅ΠΏΠ΅Ρ€ΡŒ вынСсСна Π² ΠΎΡ‚Π΄Π΅Π»ΡŒΠ½Ρ‹ΠΉ слой (Layer). Π­Ρ‚ΠΎ Π³ΠΎΡ€Π°Π·Π΄ΠΎ ΡƒΠ΄ΠΎΠ±Π½Π΅Π΅, Ρ‡Π΅ΠΌ сСйчас (Π² 80.30). Π‘ΠΎΠ»ΡŒΡˆΠ΅ Π½Π΅ Π½ΡƒΠΆΠ½ΠΎ Π·Π°ΠΏΡƒΡΠΊΠ°Ρ‚ΡŒ старый Legasy Dashboard. Плюс, Ρ‚Π΅ΠΏΠ΅Ρ€ΡŒ Π² ΠΏΠΎΠ»ΠΈΡ‚ΠΈΠΊΠ΅ HTTPS инспСкции ΠΌΠΎΠΆΠ½ΠΎ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚ΡŒ Updatable ΠΎΠ±ΡŠΠ΅ΠΊΡ‚Ρ‹, Ρ‚Π°ΠΊΠΈΠ΅ ΠΊΠ°ΠΊ сСрвисы Office365, Google, Azure, AWS ΠΈ Ρ‚.Π΄. Π­Ρ‚ΠΎ ΠΎΡ‡Π΅Π½ΡŒ ΡƒΠ΄ΠΎΠ±Π½ΠΎ, ΠΊΠΎΠ³Π΄Π° Π½ΡƒΠΆΠ½ΠΎ Π½Π°ΡΡ‚Ρ€ΠΎΠΈΡ‚ΡŒ ΠΈΡΠΊΠ»ΡŽΡ‡Π΅Π½ΠΈΡ. Однако, всС Π΅Ρ‰Π΅ Π½Π΅Ρ‚ ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΠΈ tls 1.3. Π’ΠΈΠ΄ΠΈΠΌΠΎ «догонят» ΡΠ»Π΅Π΄ΡƒΡŽΡ‰ΠΈΠΌ хотфиксом.
  3. Π—Π½Π°Ρ‡ΠΈΡ‚Π΅Π»ΡŒΠ½Ρ‹Π΅ измСнСния для Anti-Virus ΠΈ SandBlast. Π’Π΅ΠΏΠ΅Ρ€ΡŒ ΠΌΠΎΠΆΠ½ΠΎ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΡΡ‚ΡŒ Ρ‚Π°ΠΊΠΈΠ΅ ΠΏΡ€ΠΎΡ‚ΠΎΠΊΠΎΠ»Ρ‹ ΠΊΠ°ΠΊ SCP, SFTP ΠΈ SMBv3 (кстати, Π΄Π°Π½Π½Ρ‹ΠΉ ΠΌΡƒΠ»ΡŒΡ‚ΠΈΠΊΠ°Π½Π°Π»ΡŒΠ½Ρ‹ΠΉ ΠΏΡ€ΠΎΡ‚ΠΎΠΊΠΎΠ» большС Π½ΠΈΠΊΡ‚ΠΎ ΠΏΡ€ΠΎΠ²Π΅Ρ€ΡΡ‚ΡŒ Π½Π΅ ΡƒΠΌΠ΅Π΅Ρ‚).
  4. ΠžΡ‡Π΅Π½ΡŒ ΠΌΠ½ΠΎΠ³ΠΎ ΡƒΠ»ΡƒΡ‡ΡˆΠ΅Π½ΠΈΠΉ, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹Π΅ ΠΊΠ°ΡΠ°ΡŽΡ‚ΡΡ Site-to-Site VPN. Π’Π΅ΠΏΠ΅Ρ€ΡŒ ΠΌΠΎΠΆΠ½ΠΎ Π½Π°ΡΡ‚Ρ€Π°ΠΈΠ²Π°Ρ‚ΡŒ нСсколько VPN Π΄ΠΎΠΌΠ΅Π½ΠΎΠ² Π½Π° шлюзС, ΠΊΠΎΡ‚ΠΎΡ€Ρ‹ΠΉ состоит Π² Π½Π΅ΡΠΊΠΎΠ»ΡŒΠΊΠΈΡ… VPN community. Π­Ρ‚ΠΎ ΠΎΡ‡Π΅Π½ΡŒ ΡƒΠ΄ΠΎΠ±Π½ΠΎ ΠΈ Π½Π°ΠΌΠ½ΠΎΠ³ΠΎ бСзопаснСй. ΠšΡ€ΠΎΠΌΠ΅ Ρ‚ΠΎΠ³ΠΎ, Check Point Π½Π°ΠΊΠΎΠ½Π΅Ρ† вспомнил ΠΏΡ€ΠΎ Route Based VPN ΠΈ Π½Π΅ΠΌΠ½ΠΎΠ³ΠΎ ΡƒΠ»ΡƒΡ‡ΡˆΠΈΠ» Π΅Π³ΠΎ ΡΡ‚Π°Π±ΠΈΠ»ΡŒΠ½ΠΎΡΡ‚ΡŒ/ΡΠΎΠ²ΠΌΠ΅ΡΡ‚ΠΈΠΌΠΎΡΡ‚ΡŒ.
  5. Появилась ΠΎΡ‡Π΅Π½ΡŒ вострСбованная функция для ΡƒΠ΄Π°Π»Π΅Π½Π½Ρ‹Ρ… ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ. Π’Π΅ΠΏΠ΅Ρ€ΡŒ ΠΌΠΎΠΆΠ½ΠΎ Π°ΡƒΡ‚Π΅Π½Ρ‚ΠΈΡ„ΠΈΡ†ΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ Π½Π΅ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ ΡŽΠ·Π΅Ρ€Π°, Π½ΠΎ ΠΈ дСвайс, с ΠΊΠΎΡ‚ΠΎΡ€ΠΎΠ³ΠΎ ΠΎΠ½ ΠΏΠΎΠ΄ΠΊΠ»ΡŽΡ‡Π°Π΅Ρ‚ΡΡ. НапримСр, ΠΌΡ‹ Ρ…ΠΎΡ‚ΠΈΠΌ Ρ€Π°Π·Ρ€Π΅ΡˆΠΈΡ‚ΡŒ ΠΏΠΎΠ΄ΠΊΠ»ΡŽΡ‡Π΅Π½ΠΈΠ΅ ΠΏΠΎ VPN Ρ‚ΠΎΠ»ΡŒΠΊΠΎ с ΠΊΠΎΡ€ΠΏΠΎΡ€Π°Ρ‚ΠΈΠ²Π½Ρ‹Ρ… устройств. ДСлаСтся это ΠΊΠΎΠ½Π΅Ρ‡Π½ΠΎ с ΠΏΠΎΠΌΠΎΡ‰ΡŒΡŽ сСртификатов. Π’Π°ΠΊΠΆΠ΅ стало Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ автоматичСски ΠΌΠΎΠ½Ρ‚ΠΈΡ€ΠΎΠ²Π°Ρ‚ΡŒ (SMB v2/3) Ρ„Π°ΠΉΠ»ΠΎΠ²Ρ‹Π΅ ΡˆΠ°Ρ€Ρ‹ для ΡƒΠ΄Π°Π»Π΅Π½Π½Ρ‹Ρ… ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ с VPN ΠΊΠ»ΠΈΠ΅Π½Ρ‚ΠΎΠΌ.
  6. ΠžΡ‡Π΅Π½ΡŒ ΠΌΠ½ΠΎΠ³ΠΎ ΠΈΠ·ΠΌΠ΅Π½Π΅Π½ΠΈΠΉ Π² Ρ€Π°Π±ΠΎΡ‚Π΅ кластСра. Но ΠΏΠΎΠΆΠ°Π»ΡƒΠΉ ΠΎΠ΄Π½Π° ΠΈΠ· самых интСрСсных β€” Π²ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎΡΡ‚ΡŒ Ρ€Π°Π±ΠΎΡ‚Ρ‹ кластСра, Π³Π΄Π΅ ΡˆΠ»ΡŽΠ·Ρ‹ ΠΈΠΌΠ΅ΡŽΡ‚ Ρ€Π°Π·Π½Ρ‹Π΅ вСрсии Gaia. Π­Ρ‚ΠΎ ΡƒΠ΄ΠΎΠ±Π½ΠΎ, ΠΏΡ€ΠΈ ΠΏΠ»Π°Π½ΠΈΡ€ΡƒΠ΅ΠΌΠΎΠΌ ΠΎΠ±Π½ΠΎΠ²Π»Π΅Π½ΠΈΠΈ.
  7. Π£Π»ΡƒΡ‡ΡˆΠ΅Π½Ρ‹ возмоТности Zero Touch. ПолСзная ΡˆΡ‚ΡƒΠΊΠ° для Ρ‚Π΅Ρ…, ΠΊΡ‚ΠΎ часто устанавливаСт «малСнькиС» ΡˆΠ»ΡŽΠ·Ρ‹ (Π½Π°ΠΏΡ€ΠΈΠΌΠ΅Ρ€ для Π±Π°Π½ΠΊΠΎΠΌΠ°Ρ‚ΠΎΠ²).
  8. Для Π»ΠΎΠ³ΠΎΠ² Ρ‚Π΅ΠΏΠ΅Ρ€ΡŒ поддСрТиваСтся Ρ…Ρ€Π°Π½ΠΈΠ»ΠΈΡ‰Π΅ Π΄ΠΎ 48Π’B.
  9. МоТно Β«ΡˆΠ°Ρ€ΠΈΡ‚ΡŒΒ» свои Π΄Π°ΡˆΠ±ΠΎΡ€Π΄Ρ‹ SmartEvent с Π΄Ρ€ΡƒΠ³ΠΈΠΌΠΈ администраторами.
  10. Log Exporter Ρ‚Π΅ΠΏΠ΅Ρ€ΡŒ позволяСт Π΄Π΅Π»Π°Ρ‚ΡŒ ΠΏΡ€Π΅Π΄Ρ„ΠΈΠ»ΡŒΡ‚Ρ€Π°Ρ†ΠΈΡŽ отправляСмых сообщСний, ΠΏΠΎ Π½ΡƒΠΆΠ½Ρ‹ΠΌ полям. Π’.Π΅. Π½Π° ваши SIEM систСмы Π±ΡƒΠ΄ΡƒΡ‚ ΠΏΡ€ΠΎΡ…ΠΎΠ΄ΠΈΡ‚ΡŒ Ρ‚ΠΎΠ»ΡŒΠΊΠΎ Π½ΡƒΠΆΠ½Ρ‹Π΅ Π»ΠΎΠ³ΠΈ ΠΈ события

ОбновлСниС

Π’ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ ΠΌΠ½ΠΎΠ³ΠΈΠ΅ ΡƒΠΆΠ΅ ΠΏΠΎΠ΄ΡƒΠΌΡ‹Π²Π°ΡŽΡ‚ Π½Π° счСт обновлСния. НС стоит ΡΠΏΠ΅ΡˆΠΈΡ‚ΡŒ. Для Π½Π°Ρ‡Π°Π»Π° вСрсия 80.40 Π΄ΠΎΠ»ΠΆΠ½Π° ΠΏΠ΅Ρ€Π΅ΠΉΡ‚ΠΈ Π² General Availability. Но ΠΈ послС этого Π½Π΅ стоит сразу ΠΎΠ±Π½ΠΎΠ²Π»ΡΡ‚ΡŒΡΡ. Π›ΡƒΡ‡ΡˆΠ΅ ΠΏΠΎΠ΄ΠΎΠΆΠ΄Π°Ρ‚ΡŒ хотя Π±Ρ‹ ΠΏΠ΅Ρ€Π²ΠΎΠ³ΠΎ хотфикса.
Π’ΠΎΠ·ΠΌΠΎΠΆΠ½ΠΎ ΠΌΠ½ΠΎΠ³ΠΈΠ΅ «сидят» ΠΈ Π½Π° Π±ΠΎΠ»Π΅Π΅ старых вСрсиях. ΠœΠΎΠ³Ρƒ ΡΠΊΠ°Π·Π°Ρ‚ΡŒ, Ρ‡Ρ‚ΠΎ ΠΊΠ°ΠΊ ΠΌΠΈΠ½ΠΈΠΌΡƒΠΌ ΡƒΠΆΠ΅ ΠΌΠΎΠΆΠ½ΠΎ (ΠΈ Π΄Π°ΠΆΠ΅ Π½ΡƒΠΆΠ½ΠΎ) ΠΎΠ±Π½ΠΎΠ²Π»ΡΡ‚ΡŒΡΡ Π΄ΠΎ 80.30. Π­Ρ‚ΠΎ ΡƒΠΆΠ΅ ΡΡ‚Π°Π±ΠΈΠ»ΡŒΠ½Π°Ρ ΠΈ провСрСнная систСма!

Π’Ρ‹ Ρ‚Π°ΠΊΠΆΠ΅ ΠΌΠΎΠΆΠ΅Ρ‚Π΅ ΠΏΠΎΠ΄ΠΏΠΈΡΠ°Ρ‚ΡŒΡΡ Π½Π° наши ΠΏΠ°Π±Π»ΠΈΠΊΠΈ (Telegram, Facebook, VK, TS Solution Blog), Π³Π΄Π΅ ΠΌΠΎΠΆΠ½ΠΎ ΡΠ»Π΅Π΄ΠΈΡ‚ΡŒ Π·Π° появлСниСм Π½ΠΎΠ²Ρ‹Ρ… ΠΌΠ°Ρ‚Π΅Ρ€ΠΈΠ°Π»ΠΎΠ² ΠΏΠΎ Check Point ΠΈ Π΄Ρ€ΡƒΠ³ΠΈΠΌ security ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Π°ΠΌ.

Волько зарСгистрированныС ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»ΠΈ ΠΌΠΎΠ³ΡƒΡ‚ ΡƒΡ‡Π°ΡΡ‚Π²ΠΎΠ²Π°Ρ‚ΡŒ Π² опросС. Π’ΠΎΠΉΠ΄ΠΈΡ‚Π΅, поТалуйста.

ΠšΠ°ΠΊΡƒΡŽ Π²Π΅Ρ€ΡΠΈΡŽ Gaia Π²Ρ‹ ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΠ΅Ρ‚Π΅?

  • R77.10
  • R77.30
  • R80.10
  • R80.20
  • R80.30
  • Other

ΠŸΡ€ΠΎΠ³ΠΎΠ»ΠΎΡΠΎΠ²Π°Π»ΠΈ 13 ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ. Π’ΠΎΠ·Π΄Π΅Ρ€ΠΆΠ°Π»ΠΈΡΡŒ 6 ΠΏΠΎΠ»ΡŒΠ·ΠΎΠ²Π°Ρ‚Π΅Π»Π΅ΠΉ.

Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: habr.com