Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HUNT_LEE
Participant

Can CheckPoint be Secure Web Gateway

i have some web servers that i want to protect (the web servers is to provide public websites to users from the Internet).

Can Checkpoint be used as a Web Security Gateway? Can it protect inbound traffic from Internet with Layer 7 capabilities (with analytics)?

We would need to capability to block attacks on our web servers and be able to have visibility.

Cheers,

Hunt 

0 Kudos
8 Replies
PhoneBoy
Admin
Admin

Yes, many customers do exactly this with the NGTX package.
To see encrypted traffic, you can so enable SSL Inspection so the gateway can see unencrypted traffic.
0 Kudos
HUNT_LEE
Participant

Hi PhoneBoy,
I have searched online and many said enabling IPS will requires lots of tuning and manpower.
Would you know any places where i can find some examples on how this can be done?
Cheers,
Hunt
0 Kudos
Wolfgang
Authority
Authority

Hunt_Lee,

to enable the IPS protections for your webserver......

Enable the webserver option on your webservers host-object

webserver.png

 

 

 

 

 

 

 

 

configure the operating system and services running on these host

webserver1.png

and finally you have to enable the IPS protections following your needs

webserver2.png

 

 

 

 

 

 

 

 

 

IPS blade thas to be enabled and a profile has to be assigned via a TP rule to your webservers.

Wolfgang

 

 

 

 

 

 

 

 

0 Kudos
HUNT_LEE
Participant

Hi Wolfgang,

The TP Rule, you are referring to the ones i attached? (Rule 4)

Am I correct in assuming that I will need to create a usual 

Source:  Any (public internet)

Destination:  New_Web_Server

Services:  HTTPS

 

By using these TP, would it create much of a performance hit on the checkpoint cluster? 

Cheers,

Hunt

0 Kudos
Wolfgang
Authority
Authority

Hunt,

yes, you can use the shown rule.

You need a TP rule which is catching your webserver, you can use a granular rule like you attached or you can use a TP rule with protection scope on any or your DMZ networks.

If IPS is already on the performance impact is marginal.

Wolfgang

0 Kudos
HUNT_LEE
Participant

Thanks Wolfgang
0 Kudos
PhoneBoy
Admin
Admin

0 Kudos
Chris_Atkinson
Employee Employee
Employee

For reference, please see: Next-Gen-Threat-Prevention-WAF-OWASP-Top-10-Comparison.pdf 

CCSM R77/R80/ELITE

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events