6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Imibuliso kuye wonke umntu oqhubeka efunda uthotho malunga nesizukulwana esitsha se-NGFW Jonga indawo yosapho lwe-SMB (uthotho lwe-1500). IN Iziqendu ezi-5 sijonge isisombululo se-SMP (i-portal yolawulo ye-SMB gateways). Namhlanje ndingathanda ukuthetha nge-Smart-1 Cloud portal, ibeka ngokwayo njengesisombululo esisekelwe kwi-SaaS Check Point, isebenza njengeSeva yoLawulo kwifu, ngoko kuya kufaneleka kuyo nayiphi na i-NGFW yokuHlola iNqanaba. Kwabo bathe basijoyina, mandikukhumbuze ngezihloko ebekuxoxiwe ngazo ngaphambili: ukuqaliswa kunye noqwalaselo , umbutho wothumelo lwetrafikhi engenazingcingo (WiFi kunye neLTE) , VPN.

Masiqaqambise ezona mpawu ziphambili zeSmart-1 Cloud:

  1. Isisombululo esisodwa esisembindini sokulawula yonke isiseko sakho se-Check Point (amasango abonakalayo kunye nawomzimba kumanqanaba ahlukeneyo).
  2. Iseti eqhelekileyo yemigaqo-nkqubo yazo zonke iiBlades ikuvumela ukuba wenze lula iinkqubo zolawulo (ukudala/ukuhlelwa kwemithetho yemisebenzi eyahlukeneyo).
  3. Inkxaso yendlela yeprofayili xa usebenza kunye nezicwangciso zesango. Uxanduva lokuhlukana kwamalungelo okufikelela xa usebenza kwi-portal, apho abalawuli benethiwekhi, iingcali zophicotho-zincwadi, njl njl.
  4. Ukubeka iliso kwesongelo, esibonelela ngeelogs kunye nokujongwa kwesiganeko kwindawo enye.
  5. Inkxaso yokusebenzisana nge-API. Umsebenzisi unokuphumeza iinkqubo ezizenzekelayo, ukwenza lula imisebenzi yesiqhelo yemihla ngemihla.
  6. Ukufikelela kwiwebhu. Isusa izithintelo malunga nenkxaso yee-OS ezizimeleyo kwaye iyaqondakala.

Kwabo sele beqhelene nezisombululo ze-Check Point, amandla angundoqo anikezelweyo awahlukanga kunokuba neSeva yoLawulo oluzinikeleyo kwindawo kwiziseko zakho. Ziya kuba zilungile, kodwa kwimeko ye-Smart-1 Cloud, ukugcinwa komncedisi wolawulo kunikezelwa ziingcali ze-Check Point. Ibandakanya: ukwenza ii-backups, ukubeka esweni indawo yasimahla kwimidiya, ukulungisa iimpazamo, ukufaka iinguqulelo zesoftware zamva nje. Inkqubo yokufuduka (ukudluliselwa) izicwangciso nazo zenziwe lula.

Ukunikezelwa kwemvume

Ngaphambi kokuba uqhelane nokusebenza kwesisombululo solawulo lwamafu, masifunde imiba yelayisensi evela kwigosa. Ishiti yedatha.

Ukulawula isango elinye:

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Ubhaliso luxhomekeke kwiiblawudi zolawulo ezikhethiweyo; kukho imikhombandlela emi-3 iyonke:

  1. Ulawulo. I-50 GB yokugcina, i-1 GB yonke imihla kwiilogi.
  2. Ulawulo + SmartEvent. I-100 GB yokugcina, i-3 GB yemihla ngemihla yemihla ngemihla, ukuveliswa kwengxelo.
  3. Ulawulo + Ukuthotyelwa + SmartEvent. Ukugcinwa kwe-100 GB, ii-3 GB zemihla ngemihla, ii-logs zemihla ngemihla, ukuveliswa kwengxelo, iingcebiso zezicwangciso ezisekelwe kwizenzo zokhuseleko lolwazi ngokubanzi.

*Ukhetho luxhomekeke kwizinto ezininzi: uhlobo lwelogi, inani labasebenzisi, umthamo wetrafikhi.

Kukho kwakhona umrhumo wokulawula i-5 gateways. Asiyi kuhlala kule nto ngokweenkcukacha - ungasoloko ufumana ulwazi kuyo Ishiti yedatha.

Ukuphehlelelwa kwe-Smart-1 Cloud

Nabani na unokuzama isisombululo; ukwenza oku, kufuneka ubhalise kwi-Infinity Portal-inkonzo yelifu evela kwi-Check Point, apho unokufumana ukufikelela kwesilingo kwezi ndawo zilandelayo:

  • uKhuseleko lwamafu (CloudGuard SaaS, CloudGuard Native);
  • Ukhuseleko lweNethiwekhi (i-CloudGuard Connect, i-Smart-1 Cloud, i-Infinity SOC);
  • Ukhuseleko lwendawo yokugqibela (I-Sandblast Agent Management Platform, i-SandBlast Agent Cloud Management, Sandblast Mobile).

Siza kungena kwinkqubo kunye nawe (ubhaliso luyafuneka kubasebenzisi abatsha) kwaye uye kwisisombululo se-Smart-1 Cloud:

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Uya kuxelelwa ngokufutshane malunga neenzuzo zesi sisombululo (Ulawulo lweziseko zophuhliso, akukho kufakelo olufunekayo, uhlaziyo ngokuzenzekelayo).

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Emva kokugcwalisa amasimi, kuya kufuneka ulinde de iakhawunti yakho ilungele ukungena kwi-portal:

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Ukuba umsebenzi uphumelele, uya kufumana ulwazi lokubhalisa nge-imeyile (echazwe xa ungena kwi-Infinity Portal), kwaye uya kuthunyelwa kwakhona kwiphepha lasekhaya le-Smart-1 Cloud.

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Ii-portal tabs ezikhoyo:

  1. Qalisa iSmartConsole. Ukusebenzisa usetyenziso olufakelweyo kwiPC yakho, okanye sebenzisa ujongano lwewebhu.
  2. Ungqamaniso kunye nento yesango.
  3. Ukusebenza ngezigodo.
  4. Useto.

Ungqamaniso kunye nesango

Masiqale ngongqamaniso lweSango loKhuseleko; ukwenza oku, kufuneka uyidibanise njengento. Yiya kwisithuba "Connect Gateway"

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Kufuneka ungenise igama lesango elilodwa, unokongeza inkcazo kwinto. Emva koko cinezela "Bhalisa".

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Into yesango iya kuvela eyakufuna ukudityaniswa nomncedisi wolawulo ngokuphumeza imiyalelo yeCLI yesango:

  1. Qinisekisa ukuba i-JHF yamva nje (Jumbo Hotfix) ifakwe kwisango.
  2. Seta ithokheni yoqhagamshelwano: cwangcisa i-maas yesango lokhuseleko kwi-auth-token
  3. Jonga ubume betonela yongqamaniso:
    Isimo se-MaS: Sivuliwe
    I-MaS Tunnel State: Phezulu
    Igama lommandla we-MaS:
    Service-Identifier.maas.checkpoint.com
    Isango le-IP loNxibelelwano lwe-MaS: 100.64.0.1

Nje ukuba iinkonzo ze-Mass Tunnel zinyusiwe, kufuneka uqhubeke nokuseka uqhagamshelo lwe-SIC phakathi kwesango kunye ne-Smart-1 Cloud kwi-Smartconsole. Ukuba umsebenzi uphumelele, i-topology yesango iya kufumaneka, masiqhoboshele umzekelo:

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Ngaloo ndlela, xa usebenzisa i-Smart-1 Cloud, isango lixhunyiwe kwinethiwekhi "yegrey" 10.64.0.1.

Makhe ndongeze ukuba kwisakhiwo sethu isango ngokwalo lifikelela kwi-Intanethi usebenzisa i-NAT, ngoko ke, akukho dilesi ye-IP yoluntu kwi-interface yayo, nangona kunjalo, sinokuyilawula ngaphandle. Le yenye into enomdla ye-Smart-1 Cloud, enkosi apho i-subnet yolawulo eyahlukileyo yenziwe kunye nephuli yayo yeedilesi ze-IP.

isiphelo

Nje ukuba wongeze ngempumelelo isango lolawulo nge-Smart-1 Cloud, unokufikelela ngokupheleleyo, njengakwi-Smart Console. Kubeko lwethu, saphehlelela inguqulelo yewebhu; enyanisweni, ngumatshini ophakanyisiweyo onenyani onomthengi osebenzayo wolawulo.

6. I-NGFW yamashishini amancinci. I-Smart-1 Cloud

Unokuhlala ufunda ngakumbi malunga nesakhono seSmart Console kunye neCheck Point uyilo kumbhali wethu kunjalo.

Yiyo yonke loo nto namhlanje, silindele inqaku lokugqibela loluhlu, apho siya kuchukumisa amandla okulungisa ukusebenza kosapho lwe-SMB 1500 kunye ne-Gaia 80.20 Embedded.

Ukukhetha okukhulu kwemathiriyeli kwi-Check Point evela kwi-TS Solution. Hla umamele (yocingo, Facebook, VK, TS Solution Blog, Yandex.Zen)

umthombo: www.habr.com

Thenga ukusingathwa okuthembekileyo kwiindawo ezinokhuseleko lweDDoS, iiseva zeVPS VDS 🔥 Thenga ukusingathwa kwewebhusayithi okuthembekileyo ngokhuseleko lwe-DDoS, iiseva zeVPS VDS | ProHoster