7. NGFW kwa mabizinesi ang'onoang'ono. Magwiridwe ndi malingaliro onse
Nthawi yakwana yoti amalize zolemba za m'badwo watsopano wa SMB Check Point (1500 series). Tikukhulupirira kuti izi zinali zopindulitsa kwa inu komanso kuti mupitiliza kukhala nafe pa blog ya TS Solution. Mutu wankhani yomaliza sunafotokozedwe kwambiri, koma chofunikiranso - kukonza magwiridwe antchito a SMB. M'menemo tidzakambirana zosankha za kasinthidwe ka hardware ndi mapulogalamu a NGFW, kufotokoza malamulo omwe alipo ndi njira zoyankhulirana.
Pakadali pano, palibe magwero ambiri azidziwitso pakukonza magwiridwe antchito a SMB chifukwa cha zoletsa OS yamkati - Gaia 80.20 Yophatikizidwa. M'nkhani yathu tidzagwiritsa ntchito masanjidwe okhala ndi centralized management (Dedicated Management Server) - imakupatsani mwayi wogwiritsa ntchito zida zambiri mukamagwira ntchito ndi NGFW.
Z Hardware
Musanakhudze kamangidwe ka banja la Check Point SMB, mutha kufunsa mnzanu nthawi zonse kuti agwiritse ntchito Chida Chakuyesa Chamagetsi, kusankha yankho loyenera malinga ndi zomwe zafotokozedwa (kupitilira, kuchuluka kwa ogwiritsa ntchito, ndi zina).
Zolemba zofunika mukamalumikizana ndi zida zanu za NGFW
Mayankho a NGFW a banja la SMB alibe kuthekera kokweza zida zamakina (CPU, RAM, HDD); kutengera chitsanzo, pali chithandizo cha makadi a SD, izi zimakulolani kukulitsa mphamvu ya disk, koma osati kwambiri.
Kugwira ntchito kwa maukonde ochezera kumafunika kuwongolera. Gaia 80.20 Embedded ilibe zida zambiri zowunikira, koma mutha kugwiritsa ntchito lamulo lodziwika bwino mu CLI kudzera pa Katswiri.
#inefconfig
Samalani mizere yomwe ili pansi, ikulolani kuti muyese kuchuluka kwa zolakwika pa mawonekedwe. Ndikofunikira kwambiri kuyang'ana magawowa pakukhazikitsa koyamba kwa NGFW yanu, komanso nthawi ndi nthawi mukugwira ntchito.
Kwa Gaia wathunthu pali lamulo:
> chiwonetsero chazithunzi
Ndi chithandizo chake ndizotheka kupeza zambiri zokhudza kutentha kwa hardware. Tsoka ilo, chisankhochi sichikupezeka mu 80.20 Embedded; tiwonetsa misampha yotchuka kwambiri ya SNMP:
Mutu
mafotokozedwe
Chiyankhulo chalumikizidwa
Kuyimitsa mawonekedwe
VLAN yachotsedwa
Kuchotsa Vlans
Kugwiritsa ntchito kwambiri kukumbukira
Kugwiritsa ntchito kwakukulu kwa RAM
Malo otsika a disk
Palibe malo okwanira a HDD
Kugwiritsa ntchito kwakukulu kwa CPU
Kugwiritsa ntchito kwakukulu kwa CPU
High CPU imasokoneza mlingo
Kusokoneza kwakukulu
Mtengo wolumikizira wapamwamba
Kuthamanga kwakukulu kwa maulumikizidwe atsopano
Kulumikizana kwakukulu panthawi imodzi
Mlingo wapamwamba wa magawo ampikisano
High Firewall throughput
High throughput Firewall
Mtengo wapamwamba wovomerezeka wa paketi
Mlingo wapamwamba wolandila paketi
Dziko la membala wa Cluster lasintha
Kusintha chikhalidwe chamagulu
Kulumikizana ndi cholakwika cha seva ya log
Kulumikizidwa kwatayika ndi Log-Server
Kugwiritsa ntchito pachipata chanu kumafuna kuwunika kwa RAM. Kuti Gaia (Linux-like OS) agwire ntchito, izi ndi mkhalidwe wabwinobwinopamene kugwiritsa ntchito RAM kufika pa 70-80% ya ntchito.
Mapangidwe a mayankho a SMB sapereka kugwiritsa ntchito kukumbukira kwa SWAP, mosiyana ndi mitundu yakale ya Check Point. Komabe, mumafayilo amtundu wa Linux adawonedwa , zomwe zikuwonetsa kuthekera kwamalingaliro kosintha mawonekedwe a SWAP.
Mapulogalamu gawo
Panthawi yofalitsa nkhaniyo zaposachedwa Mtundu wa Gaia - 80.20.10. Muyenera kudziwa kuti pali zoletsa mukamagwira ntchito mu CLI: malamulo ena a Linux amathandizidwa mumachitidwe a Katswiri. Kuwunika momwe NGFW ikugwirira ntchito kumafuna kuwunika momwe ma daemoni ndi ntchito zikuyendera, zambiri za izi zitha kupezeka mu nkhani mnzanga. Tiwona malamulo omwe angatheke a SMB.
Kugwira ntchito ndi Gaia OS
Sakatulani ma tempuleti a SecureXL
#fwaccelstat
Onani boot ndi core
# fw ctl multik stat
Onani kuchuluka kwa magawo (malumikizidwe).
# fw ctl pstat
* Onani mawonekedwe amagulu
#cphaprob chiwerengero
Lamulo la Classic Linux TOP
Kudula mitengo
Monga mukudziwira kale, pali njira zitatu zogwirira ntchito ndi zipika za NGFW (kusungira, kukonza): kwanuko, pakati komanso mumtambo. Zosankha ziwiri zomaliza zikutanthawuza kukhalapo kwa bungwe - Management Server.
Njira zowongolera za NGFW zomwe zingatheke
Mafayilo amtengo wapatali kwambiri
Mauthenga pamakina (ali ndi zambiri zochepa kuposa Gaia wathunthu)
* Nthawi zonse zimakhala bwino kusankha pamanja ntchito za HTTPS kapena HTTPS Proxy ndikusiya Iliyonse. Lowani zochitika molingana ndi malamulo a Onani.
IPS
Tsamba la IPS likhoza kulephera kukhazikitsa ndondomeko pa NGFW yanu ngati siginecha yambiri ikugwiritsidwa ntchito. Malinga ndi nkhani kuchokera ku Check Point, kamangidwe kachipangizo ka SMB sikunapangidwe kuti aziyendetsa mbiri yonse yovomerezeka ya IPS.
Tsatanitsani Mbiri Yokhathamiritsa yotchedwa "Optimized SMB" (kapena ina yomwe mwasankha).
Sinthani mbiri yanu, pitani ku IPS β Pre R80.Zikhazikiko gawo ndikuzimitsa Chitetezo cha Seva.
Mwakufuna kwanu, mutha kuletsa ma CVE akale kuposa 2010, zofooka izi sizipezeka kawirikawiri m'maofesi ang'onoang'ono, koma zimakhudza magwiridwe antchito. Kuti mulepheretse zina mwazo, pitani ku MbiriβIPSβKuyambitsanso ZowonjezeraβZitetezo kuti mutseke mndandanda
M'malo mapeto
Monga gawo la mndandanda wa nkhani zokhudzana ndi mbadwo watsopano wa NGFW wa banja la SMB (1500), tinayesetsa kuwonetsa mphamvu zazikulu za yankho ndikuwonetsa kasinthidwe ka zigawo zofunika za chitetezo pogwiritsa ntchito zitsanzo zenizeni. Tidzakhala okondwa kuyankha mafunso aliwonse okhudza mankhwala mu ndemanga. Timakhala nanu, zikomo chifukwa cha chidwi chanu!