4. NGFW for Small Business. VPN

4. NGFW for Small Business. VPN

We continue our series of articles on NGFW for small businesses, reminding you that we are looking at the new 1500 series model range. In this part 1 cycle, I mentioned one of the most useful options when purchasing an SMB device — the provision of gateways with built-in Mobile Access licenses (from 100 to 200 users depending on the model). In this article, we will discuss setting up VPN for the 1500 series gateways that come with pre-installed Gaia 80.20 Embedded. Here’s a brief outline:

  1. VPN capabilities for SMB.
  2. Setting up Remote Access for a small office.
  3. Available clients for connection.

1. VPN capabilities for SMB

To prepare today’s material, the official administrator guide for version R80.20.05 (current at the time of the article) was used. Accordingly, in the VPN section for Gaia 80.20 Embedded, the following is supported:

  1. Site-To-Site. Creating VPN tunnels between your offices, where users can work as if in a single 'local' network.

    4. NGFW for Small Business. VPN

  2. Remote Access. Remote connection to your office resources using user devices (PCs, mobile phones, etc.). Additionally, there is an SSL Network Extender, which allows publishing individual applications and running them via a Java Applet when connected through SSL. Note: Do not confuse with Mobile Access Portal (support for this is not available on Gaia Embedded).

    4. NGFW for Small Business. VPN

Additional I highly recommend the author's course from TS Solution — Check Point Remote Access VPN it reveals Check Point technologies in terms of VPN, addresses licensing issues, and contains detailed instructions for setup.

2. Remote Access for a small office

We will begin organizing remote connectivity to your office:

  1. For users to build a VPN tunnel with the gateway, you need to have a public IP address. If you have already completed the initial setup (2 articles from the cycle), typically the External Link is already active. You can find this information by going to the Gaia Portal: Device → Network → Internet

    4. NGFW for Small Business. VPN

    In the case that your company uses a dynamic public IP address, you can set up Dynamic DNS. Go to Device → DDNS & Device Access

    4. NGFW for Small Business. VPN

    Currently, support exists from two providers: DynDns and no-ip.com. To activate the option, you need to enter your credentials (username, password).

  2. Next, we will create a user account, which will be useful for testing the settings: VPN → Remote Access → Remote Access Users

    4. NGFW for Small Business. VPN

    In the group (using the example: remoteaccess), we will create a user by following the instructions in the screenshot. The account setup is standard; we set a username and password, and additionally enable the Remote Access permissions option.

    4. NGFW for Small Business. VPN

    If you have successfully applied the settings, two objects should appear: a local user and a local user group.

    4. NGFW for Small Business. VPN

  3. The next step is to go to VPN → Remote Access → Blade Control. Make sure that your blade is enabled and traffic from remote users is allowed.

    4. NGFW for Small Business. VPN

  4. *The above provided the minimum set of steps to configure Remote Access. But before we test the connection, let's explore additional settings by going to the tab VPN → Remote Access → Advanced.

    4. NGFW for Small Business. VPN

    Based on the current settings, we can see that remote users will receive an IP address from the network 172.16.11.0/24 upon connection, thanks to the Office Mode option. This is sufficient for using 200 concurrent licenses (as specified for the 1590 NGFW Check Point).

    Option ‘Route Internet traffic from connected clients through this gateway’ is optional and is responsible for routing all traffic from the remote user through the gateway (including connections to the Internet). This allows inspecting the user's traffic and protects their workstation from various threats and malware.

  5. *Working with access policies for Remote Access.

    After we configured Remote Access, an automatic access rule was created at the Firewall level, which can be viewed by going to the tab: Access Policy → Firewall → Policy.

    4. NGFW for Small Business. VPN

    In this case, remote users who belong to the previously created group will be able to access all internal resources of the company; note that the rule is located in the general section ‘Incoming, Internal and VPN traffic’. To allow VPN users’ traffic to access the Internet, a separate rule will need to be created in the general section of ‘Outgoing access to the Internet’.”.

  6. Finally, we need to ensure that the user can successfully create a VPN tunnel to our NGFW gateway and access the internal resources of the company. For this, it is necessary to install the VPN client on the testing host, and it is provided link for download. After installation, the standard procedure for adding a new site must be followed (the public IP address of your gateway is specified). For convenience, the process is presented in a GIF format.

    4. NGFW for Small Business. VPN

    Once the connection is established, let's check the received IP address on the host machine using the command in CMD: ipconfig

    4. NGFW for Small Business. VPN

    We confirmed that the virtual network adapter received an IP address from the Office Mode of our NGFW, and packets are sent successfully. To wrap up, we can navigate to the Gaia Portal: VPN → Remote Access → Connected Remote Users

    4. NGFW for Small Business. VPN

    The user 'ntuser' appears as connected; let's check the event logging by going to Logs & Monitoring → Security Logs

    4. NGFW for Small Business. VPN

    Connection logging is in progress, with the source being the IP address: 172.16.10.1 — this is the address our user obtained through Office Mode.

    3. Supported Clients for Remote Access

    After reviewing the remote connection setup procedure to your office using the NGFW Check Point SMB family, I would like to discuss the support for clients on various devices:

    The variety of supported operating systems and devices allows you to fully utilize your license included with the NGFW. To set up a specific device, there is a convenient option "How to connect"

    4. NGFW for Small Business. VPN

    It automatically generates steps according to your settings, enabling administrators to install new clients without any issues.

    Output: In summary, this article examined the VPN capabilities of the NGFW Check Point SMB family. Next, we described the steps for setting up Remote Access in the case of remote user connections to the office, and afterward, we explored monitoring tools. Finally, we discussed available clients and connection options for Remote Access. Thus, your branch office can ensure the continuity and security of employee operations using VPN technologies, despite various external threats and challenges.

    A large collection of materials on Check Point from TS Solution. Stay tuned for updates (Telegram, Facebook, VK, TS Solution Blog, Yandex.Zen).

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster