- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Can CheckPoint be Secure Web Gateway
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can CheckPoint be Secure Web Gateway
i have some web servers that i want to protect (the web servers is to provide public websites to users from the Internet).
Can Checkpoint be used as a Web Security Gateway? Can it protect inbound traffic from Internet with Layer 7 capabilities (with analytics)?
We would need to capability to block attacks on our web servers and be able to have visibility.
Cheers,
Hunt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To see encrypted traffic, you can so enable SSL Inspection so the gateway can see unencrypted traffic.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have searched online and many said enabling IPS will requires lots of tuning and manpower.
Would you know any places where i can find some examples on how this can be done?
Cheers,
Hunt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hunt_Lee,
to enable the IPS protections for your webserver......
Enable the webserver option on your webservers host-object
configure the operating system and services running on these host
and finally you have to enable the IPS protections following your needs
IPS blade thas to be enabled and a profile has to be assigned via a TP rule to your webservers.
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Wolfgang,
The TP Rule, you are referring to the ones i attached? (Rule 4)
Am I correct in assuming that I will need to create a usual
Source: Any (public internet)
Destination: New_Web_Server
Services: HTTPS
By using these TP, would it create much of a performance hit on the checkpoint cluster?
Cheers,
Hunt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hunt,
yes, you can use the shown rule.
You need a TP rule which is catching your webserver, you can use a granular rule like you attached or you can use a TP rule with protection scope on any or your DMZ networks.
If IPS is already on the performance impact is marginal.
Wolfgang
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's discussed here: https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/Moving-from-Detect-to-Prevent-TechT...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For reference, please see: Next-Gen-Threat-Prevention-WAF-OWASP-Top-10-Comparison.pdf
