Friday, June 22, 2012

DDOS Protector - details are public now

Check Point has finally published details about newest DDOS Protector appliances I was mentioning earlier.



There are 7 different models available.

As Check Point describes, DDoS Protector is capable of stopping today's advanced DDoS attacks including:

  • Vulnerability-based attacks that exploit server application weaknesses including Web, Mail, DNS, FTP, SIP, SQL server vulnerabilities
  • Non-vulnerability-based attacks that misuse server resources, such as
    • Application DoS – HTTP , SIP, and other flood attacks
    • Authentication defeat - brute force attacks
    • Information theft – application scanning
  • DoS/DDoS flood attacks that misuse network bandwidth resources
  • Rapid response and real-time update of custom filters to protect against emerging attacks
  Press Release and Data Sheet for the appliances are available on the product page.

Monday, June 18, 2012

ClusterXL: Sync on VLAN interfaces

We all know Sync network in cluster configuration should be isolated from the rest of production networks, or, as Check Point calls it in the documentation, "secured". Reason for that is that sync interfaces have no security policy enforced and can be used to penetrate your FW cluster.

Nevertheless sometimes you have to do Sync over VLAN interface instead of a physical NIC.

If you do so, you might bare in mind sk34574. As described there, ClusterXL requires to use the lowerst VLAN tag for Sync interface.

For example, if you are using eth.1.10, eth1.20 and eth.30, you can only configure eth1.10 for cluster synchronization.

In case you did it wrong, cphaprob -a if will report you the following:
 
Warning: Sync will not function since there aren't any sync(secured) interfaces 


 In this case it is not enough to re-configure VLANs and re-push policy. If you picked the wrong interface first, you will have to re-initialize ClusterXL on your physical machines. To do that, go to cponfig and remove clustering, then start it again from there. Reboots are required.

Thursday, June 14, 2012

Check Point to launch DDOS Protector

Check Point is having partner's session as we speak where it introduces DDOS Protector - HW based product, not available in SW form.

Press release is to be sent out soon.

Wednesday, June 13, 2012

Official upgrade matrix for Check Point products

As you may know, navigating between the major and minor versions of Check Point is not easy. Many of us, myself included, are using these maps, courtesy of Patrick Waters.

Although Patrick's maps are great, they are not official and a bit out dated, considering the author partied with check Point on 2011.

If you are looking for an official upgrade matrix, there is a better resource in the UserCenter. Please mind it is available for download to registered users only.

Good luck with your upgrades.

Tuesday, May 15, 2012

Next Generation security features - are you using them?

Next Generation firewalls - this term is buzzing for some time now. In Check Point world it is presented by the following features:

DLP
Application Control
Identity Awareness
Anti-Bot

What features from the list are used in your security systems? What about your customers? Thanks for sharing

Thursday, May 10, 2012

GAiA: ClusterXL magic mac settings - same as before

GAiA is Linux RH based, and it has system 2.6.18 kernel.  And Check Point ClusterXL is still the same as before.

If you are upgrading to GAiA or installing in fresh in a cluster configuration, you may need to take care of so-called "magic mac" settings.

To remind you briefly, "magic mac" is an artificial MAC address used in CCP, Cluster Control Protocol, responsible for probing, messaging and sync communications in ClusterXL. Once you have more than one cluster in the same network, you have to change magic mac settings starting from the second cluster and up.

Some details about the change is mentioned in SK66527.

GAiA or SPLAT, it makes no difference. If you are using ClusterXL and not VRRP, follow the mentioned solution.

For those who do not have the access, here is a quick HOWTO:

First, make sure your magic mac are default. To check that, run fw ctl get int fwha_mac_magic and fw ctl get int fwha_mac_forward_magic commands, as in the example bellow:

# fw ctl get int fwha_mac_magic
fwha_mac_magic = 254
# fw ctl get int fwha_mac_forward_magic
fwha_mac_forward_magic = 253

The default settings are, as shown 254 and 253.

On the second cluster you will have to do the following:

On each of the Cluster Modules
1. cd $FWDIR/boot/modules
2. create the fwkern.conf file by: # vi fwkern.conf
3. Add the required parameters and values as given below:
fwha_mac_magic=250
fwha_mac_forward_magic=251


Mind the numbers marked bold should be unique on each cluster you are making changes and non equal to default.
4. Save the fwkern.conf
5. Verify the fwker.conf is correctly configured by: # more fwkern.conf
6. Reboot the Module
7. Verify the new mac magic setups correctly configured by:
# fw ctl get int fwha_mac_magic
# fw ctl get int fwha_mac_forward_magic
8. Verify the Cluster Module status by:
# cphaprob stat

 And just a reminder, if you are using VRRP instead of ClusterXL, you do not have to do any of the above.

Tuesday, May 8, 2012

GAiA: sysconfig disabled, migration tools are still there

If Google is correct, some of you are looking for details about GAiA in this blog.

In particular, about sysconfig. On SPLAT it is "one script for all" tool, that allows  you configuring most of OS and Check Point parameters. But is you are trying to get it on GAiA, here is what you get:

This command is not active

This is made by design, as GAiA provides you IPSO-like experience. Although sysconfig binary is still present, it seems to be completely disabled. CLI is configured to use CLISH instead.

If you are new to CLISH, I advise you to start reading "GAiA Administration manual", chapter 3 or" IPSO 6.2 CLI reference guide" for the matter.

Concerning more advanced tools, like migrate export/import scrypts, there are not too many changes. You find them in the usual place, $FWDIR/bin/updrade_tools, with unchanged syntax.