2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Siqhubeka nothotho lwamanqaku okusebenza noluhlu olutsha lwemodeli ye-SMB yokujonga i-CheckPoint, masikukhumbuze ukuba ku Inxalenye yokuqala sichaze iimpawu kunye nobuchule beemodeli ezintsha, iindlela zolawulo kunye nolawulo. Namhlanje siza kujonga imeko yokuhanjiswa kwemodeli yakudala kuthotho: I-CheckPoint 1590 NGFW. Nasi isishwankathelo sale nxalenye:

  1. Ukukhupha izixhobo (inkcazo yamacandelo, uqhagamshelwano olubonakalayo kunye nothungelwano).
  2. Ukuqaliswa kwesixhobo sokuqala.
  3. Ukusekwa kokuqala.
  4. Uvavanyo lomsebenzi.

Izixhobo zokukhulula

Ukwazi izixhobo kuqala ngokususa izixhobo kwibhokisi, ukuqhaqha amacandelo kunye nokufaka iinxalenye; cofa kwi-spoiler, apho inkqubo inikezelwa ngokufutshane.

Ukuhanjiswa kweNGFW 1590
2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ngokufutshane malunga namacandelo:

  • NGFW 1590;
  • iadaptha yamandla;
  • Ii-Antenna ze-Wifi ezi-2 (2.4 Hz kunye ne-5 Hz);
  • Ii-eriyali ezi-2 ze-LTE;
  • Iincwadana ezinamaxwebhu (isikhokelo esifutshane soqhagamshelwano lokuqala, isivumelwano selayisenisi, njl.njl.)

Ngokuphathelele izibuko zenethiwekhi kunye nojongano, kukho zonke izakhono zangoku zokuhanjiswa kwetrafikhi kunye nokunxibelelana, izibuko elahlukileyo lendawo ye-DMZ, i-USB 3.0 yongqamaniso nePC.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Inguqulo ye-1590 ifumene idizayini ehlaziyiweyo, iinketho zanamhlanje zonxibelelwano olungenacingo kunye nokwandiswa kwememori: i-2 slots yokusebenza kunye ne-Micro / Nano SIM kwimodi ye-LTE. (siceba ukubhala ngolu khetho ngokweenkcukacha kwelinye lamanqaku ethu alandelayo kuluhlu olunikezelwe kuqhagamshelwano olungenazingcingo); slot ikhadi le-SD.

Unokufunda ngakumbi malunga nezakhono ze-1590 NGFW kunye nezinye iimodeli ezintsha kwi Iziqendu ezi-1 ukusuka kuthotho lwamanqaku malunga nezisombululo ze-CheckPoint SMB. Siza kuqhubeka nokuqaliswa kokuqala kwesixhobo.

Ukuqaliswa kokuqala

Abafundi bethu abaqhelekileyo kufuneka baqaphele ukuba umgca we-SMB we-1500 Series usebenzisa i-80.20 Embedded OS entsha, ebandakanya i-interface ehlaziyiweyo kunye nezakhono eziphuculweyo.

Ukuqala ukuqalisa isixhobo kufuneka:

  1. Nika amandla kwisango.
  2. Qhagamshela intambo yenethiwekhi ukusuka kwiPC yakho ukuya kwi-LAN -1 kwisango.
  3. Ngokuzithandela, unokubonelela ngokukhawuleza isixhobo ngokufikelela kwi-Intanethi ngokuqhagamshela ujongano kwizibuko le-WAN.
  4. Yiya kwi-Gaia Embedded portal: https://192.168.1.1:4434/

Ukuba ulandele amanyathelo achaziweyo ngaphambili, emva kokuya kwiphepha le-portal ye-Gaia, kuya kufuneka uqinisekise ukuvula iphepha ngesatifikethi esingathembekanga, emva koko iwizadi yezicwangciso ze-portal iya kuqalisa:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Uya kubuliswa liphepha elibonisa imodeli yesixhobo sakho, kufuneka uye kwicandelo elilandelayo:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Siya kucelwa ukuba senze i-akhawunti yokugunyazwa, kunokwenzeka ukuba ucacise iimfuno eziphezulu zephasiwedi kumlawuli, kwaye sibonisa ilizwe apho siya kusebenzisa isango.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ifestile elandelayo ichaphazela umhla kunye noseto lwexesha; ungayiseta ngesandla okanye usebenzise iseva yeNTP yenkampani.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Isinyathelo esilandelayo sibandakanya ukuseta igama lesixhobo kunye nokucacisa isizinda senkampani ukwenzela ukuba iinkonzo zesango zisebenze ngokuchanekileyo kwi-Intanethi.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Inyathelo elilandelayo lichaphazela ukhetho lolawulo lwe-NGFW, apha kufuneka kuqatshelwe:

  1. Ulawulo lweNdawo. Olu lukhetho olukhoyo lokulawula isango ekuhlaleni usebenzisa iGaia Portal iphepha lewebhu.
  2. Ulawulo oluphakathi. Olu hlobo lolawulo lubandakanya ungqamaniso kunye neseva yoLawulo lwe-CheckPoint ezinikeleyo, ungqamaniso kunye nelifu le-Smart1-Cloud okanye nge-SMP (inkonzo yolawulo ye-SMB).

Kweli nqaku, siza kugxila kwindlela yoLawulo lweNdawo; ungacacisa indlela eyimfuneko. Ukuziqhelanisa nenkqubo yongqamaniso kunye neSeva yoLawulo oluzinikeleyo, sicebisa unxibelelwano ukusuka kwi-CheckPoint Getting Started training series elungiselelwe yi-TS Solution.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Okulandelayo, iwindow iya kuboniswa ichaza indlela yokusebenza yojongano kwisango:

  • Imowudi yokutshintsha ithetha ubukho be-subnet ukusuka kujongano olunye ukuya kwi-subnet yolunye ujongano.
  • Ikhubaza imo yoTshintsho ngokufanelekileyo ivala imowudi yoTshintsho; izibuko lendlela nganye yetrafikhi njengeqhekeza lothungelwano elahlukileyo.

Kwakhona kucetywayo ukuba kucaciswe iqela leedilesi ze-DHCP eziya kusetyenziswa xa kudityaniswa nojongano lwasekhaya lwesango.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Inyathelo elilandelayo kukulungisa indlela yokungena kwimowudi engenazingcingo; siceba ukuxoxa ngalo mba ngokubanzi kwinqaku elinye kuthotho, ngoko ke sakuhlehlisa uqwalaselo lwezicwangciso. Unokwenza indawo entsha yokufikelela engenazingcingo, usete igama lokugqitha ukuze uqhagamshele kuyo kwaye umisele indlela yokusebenza yetshaneli engenazingcingo (2.4 Hz okanye 5 Hz).

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Inyathelo elilandelayo liya kuba kukulungisa ukufikelela kwisango labalawuli benkampani. Ngokungagqibekanga, amalungelo ofikelelo avumelekile ukuba umdibaniso uvela:

  1. I-subnet yenkampani yangaphakathi
  2. Inethiwekhi engenazingcingo ethembekileyo
  3. Itonela yeVPN

Inketho yokudibanisa kwisango nge-Intanethi ikhutshaziwe ngokungagqibekanga, oku kuthwala imingcipheko enkulu kwaye kufuneka kuthethelelwe ukubandakanywa, ngaphandle koko kucetyiswa ukuba uyishiye njengomzekelo wethu.Kukwakhona ukucacisa ukuba yeyiphi idilesi ye-IP eya kuvunyelwa. ukudibanisa kwisango.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ifestile elandelayo iphathelene nokusebenza kweelayisensi; ekuqalisweni kwesixhobo, uya kunikwa ixesha lovavanyo lweentsuku ezingama-30. Kukho iindlela ezimbini ezikhoyo zokuvula:

  1. Ukuba kukho uqhagamshelo lwe-Intanethi, iphepha-mvume livulwa ngokuzenzekelayo.
  2. Ukuba usebenzisa ilayisenisi ngaphandle kweintanethi, kufuneka wenze oku kulandelayo: Khuphela ilayisenisi kwiZiko loMsebenzisi, bhalisa isixhobo sakho kwindawo ekhethekileyo. i-portal. Okulandelayo, kuzo zombini iimeko, kuya kufuneka ungenise ilayisenisi ekhutshelweyo ngesandla.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Okokugqibela, iwindow yokugqibela kwiwizadi yesethingi ikukhuthaza ukuba ukhethe iiblades ekufuneka zivulwe; qaphela ukuba iblade ye-QOS ivulwa kuphela emva kokuqaliswa kokuqala. Kuya kufuneka ugqibezele ngefestile yokugqiba eshwankathela izicwangciso zakho.

Ukusekwa kokuqala

Okokuqala, sicebisa ukuba kujongwe ubume bamaphepha-mvume; uqwalaselo olongezelelweyo luya kuxhomekeka koku. Yiya kwindawo ethi β€œEKHAYA” β†’ β€œIlayisensi” thebhu:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ukuba iilayisenisi ziyasebenza, sincoma ukuhlaziya ngokukhawuleza kwi-firmware yangoku; ukwenza oku, yiya kwi-"DEVICE" β†’ "Imisebenzi yeNkqubo" ithebhu:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Uhlaziyo lweSistim lubekwe kwindawo yoPhuculo lweFirmware. Kwimeko yethu, i-firmware yangoku kunye nenguqulo yakamuva ifakwe.

Emva koko, ndicebisa ukuba ndithethe ngokufutshane malunga nezakhono kunye nezicwangciso zeeblades zesistim. Ngokwengqiqo, zinokwahlulwa zibe kuFirewall (Firewall, Control Application, URL Filtering) kunye noThintelo lweTreat (IPS, Antivirus, Anti-Bot, Threat Emulation) imigaqo-nkqubo yenqanaba.

Masiyeni kuMgaqo-nkqubo woFikelelo β†’ Ulawulo lwe-Blade tab:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ngokungagqibekanga, imo ye-STANDARD isetyenzisiweyo, ivumela i-traffic ephumayo kwi-Intanethi, i-traffic ngaphakathi kwenethiwekhi yendawo, kodwa kwangaxeshanye ivimba i-traffic engenayo kwi-Intanethi.

Ngokumalunga ne-APPLICATIONS & URL FILTERING blades, ngokungagqibekanga zisetelwe ukubhloka iziza ezinezinga eliphezulu lengozi, izicelo zokutshintshiselana ibhloko (i-Torrent, i-File Storage, njl.). Ungaphinda uthintele iindidi zeesayithi ngesandla.

Makhe sijonge ukhetho lwetrafikhi yabasebenzisi "Ukunciphisa usetyenziso lwe-bandwidth esetyenziswayo" kunye nokukwazi ukunciphisa isantya setrafikhi ephumayo/engenayo yamaqela ezicelo.

Okulandelayo, vula icandelwana loMgaqo-nkqubo; ngokungagqibekanga, imithetho yenziwa ngokuzenzekelayo ngokweseto ezichazwe ngaphambili.

Ukwahlulahlula kwe-NAT ngokungagqibekanga kusebenza kwi-Global Fihla Nat Automatic, o.k.t. zonke iinginginya zangaphakathi ziya kuba nokufikelela kwi-Intanethi ngedilesi ye-IP yoluntu. Kuyenzeka ukuba usete ngesandla imithetho ye-NAT yokupapasha usetyenziso okanye iinkonzo zakho zewebhu.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Okulandelayo, icandelo elichaphazela uQinisekiso loMsebenzisi kwinethiwekhi linika iinketho ezimbini: Imibuzo yoLawulo oluSebenzayo (ukudibanisa neAD yakho), uQinisekiso oluSekwe kwiSikhangeli (umsebenzisi ufaka iziqinisekiso zesizinda kwi-portal).

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Kuyafaneleka ukukhankanya ukuhlolwa kwe-SSL ngokwahlukileyo; isabelo se-HTTPS epheleleyo yetrafikhi kwiNethiwekhi yeGlobal sikhula ngenkuthalo. Makhe sijonge ukuba zeziphi iimpawu ezibonelela nge-CheckPoint kwizisombululo ze-SMB Ukwenza oku, yiya kuHlolo lwe-SSL β†’ icandelo loMgaqo-nkqubo:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Kuseto unokuhlola itrafikhi ye-HTTPS; kuya kufuneka ungenise isatifikethi kwaye usifake kwiziko lesatifikethi elithembekileyo koomatshini bomsebenzisi wokugqibela.

Sithatha imo ye-BYPASS yeendidi ezichazwe kwangaphambili njengokhetho olufanelekileyo; oku konga kakhulu ixesha xa uvumela uhlolo.

Emva kokumisela imithetho kwinqanaba le-Firewall / Isicelo, kufuneka uqhubekele ekulungiseni imigaqo-nkqubo yokhuseleko (uThintelo loTsongo), ukwenza oku, yiya kwicandelo elifanelekileyo:

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Kwiphepha elivuliweyo sibona ii-blades ezinikwe amandla, utyikityo kunye neemeko zohlaziyo lwedatha. Siphinde sicelwe ukuba sikhethe iphrofayili yokukhusela i-perimeter yenethiwekhi, kunye nezicwangciso ezihambelanayo ziboniswa.

Icandelo elahlukileyo "Ukhuseleko lwe-IPS" likuvumela ukuba uqwalasele isenzo sotyikityo oluthile lokhuseleko.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Kungekudala sabhala kwiblogi yethu malunga nokuba sesichengeni kwehlabathi yeWindows Server-SigRed. Makhe sijonge ubukho bayo kwi-Gaia Embekelwe i-80.20 ngokufaka umbuzo "CVE-2020-1350"

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Irekhodi lichongiwe kolu tyikityo apho enye yezenzo inokusetyenziswa. (ngokungagqibekanga uThintelo lwenqanaba lengozi Lubalulekile). Ngokufanelekileyo, ukuba nesisombululo se-SMB, awuyi kushiywa ngaphandle malunga nohlaziyo kunye nenkxaso; esi sisisombululo esipheleleyo se-NGFW kwiiofisi zesebe eziya kuthi ga kwi-200 yabantu abavela kwi-CheckPoint.

Uvavanyo lomsebenzi

Ukuqukumbela inqaku, ndingathanda ukuqaphela ukufumaneka kwezixhobo zokusombulula iingxaki emva kokuqaliswa kokuqala kunye nokucwangciswa kwesisombululo se-SMB. Ungaya kwindawo ethi β€œIKHAYA” β†’ β€œIzixhobo” icandelo. Ukhetho olunokwenzeka:

  • izibonelelo zenkqubo yokubeka iliso;
  • itafile yomzila;
  • ukujonga ukufumaneka kweenkonzo zelifu ze-CheckPoint;
  • ukuveliswa kweCPinfo;

Imiyalelo yothungelwano eyakhelwe-ngaphakathi iyafumaneka: Ping, Traceroute, Traffic Capture.

2. I-NGFW yamashishini amancinci. Unboxing kunye nokuSeta

Ngaloo ndlela, namhlanje sihlolisise kwaye safunda uxhulumaniso lokuqala kunye noqwalaselo lwe-NGFW 1590, uya kwenza izenzo ezifanayo kulo lonke uchungechunge lwe-1500 SMB Checkpoint. Iinketho ezikhoyo zisibonise ukuhluka okuphezulu kwezicwangciso, inkxaso yeendlela zanamhlanje zokukhusela i-traffic kwi-perimeter yenethiwekhi.

Namhlanje, izisombululo ze-CheckPoint zokukhusela iiofisi ezincinci kunye namasebe (ukuya kubantu be-200) zinezixhobo ezininzi kunye nokusebenzisa iteknoloji yakutshanje (ulawulo lwamafu, inkxaso yeSIM khadi, ukwandiswa kwememori usebenzisa amakhadi e-SD, njl.). Qhubeka uhlale unolwazi kwaye ufunde amanqaku avela kwi-TS Solution, siceba ukukhutshwa okungakumbi malunga ne-NGFW CheckPoint yosapho lwe-SMB, siyakubona!

Ukukhetha okukhulu kwemathiriyeli kwi-Check Point evela kwi-TS Solution. Hla umamele (yocingo, Facebook, VK, TS Solution Blog, Yandex.Zen).

umthombo: www.habr.com

Yongeza izimvo