- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Why do Hackers Love IoT Devices so Much?
Join our TechTalk on Aug 17, at 5PM CET | 11AM EST
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hi,
I want to run R80.30 in my home lab and get all R80 features. Management will run on another remote server.
What are you using? I am thinking on running Gaia on a NUC or other small PC and run vmware, or should I get an 1430 firewall?
Any recommentations?
R80.30 doesn't run on SMB appliances yet, like the 1430 box you mentioned (sk97766). I'm using 3200 appliances at home. These are very silent and powerful enough for home testing and lab. Depending on what you really want to do (you wrote: ALL R80 features) you might want to consider even more powerful appliances (enterprise grade).
Thanks Danny,
3200 would be nice but its too pricey for my home lab...
This data sheet for 1400-series show R80.10, but is it only for the management?
https://www.checkpoint.com/downloads/products/1400-security-gateway-datasheet.pdf
The 3100 is the lowest appliance capable of running a full Gaia deployment with all features. 1400s and lower use embedded Gaia which does not quite have the full feature set. At one point there was some kind of special "test lab" or "non-production" pricing, perhaps @_Val_ or @PhoneBoy could chime in on this one?
However it is much easier to just use VMWare Workstation or VirtualBox on an old piece of hardware.
Minor quibble. The 3100 is the lowest current appliance. The 2200 should also be able to run full GAiA.
The 3100 and 3200 use Intel Avoton (Atom C2000-series) chips. That family has a bug known as AVR54, which affects the Low Pin Count (LPC) bus. This bus is used to connect the processor to the system firmware. Eventually, it degrades to the point the system will no longer boot. Intel fixed this issue in the C0 stepping of the Avoton chips. I don't yet know if the 3100 and 3200 use C0 stepping chips.
Of course, throwing a hypervisor on a NUC and running firewall and SmartCenter VMs is my preferred option. I'm currently really enjoying SmartOS. NUC models are listed in the form #i#___, where the first # is the processor generation and the second # is the processor family within the generation. For example, the NUC6i3 has an i3-6100U processor. The three _ characters are letters indicating other capabilities of the device, such as whether it has a 2.5" drive bay or not.
The 6i model NUCs all work with 64 GB of RAM if you can find 32 GB SO-DIMMs. That's enough RAM to run a pretty sizable lab.
Then the best option seems to be a PC/Server with ESX.
If the 1400 doesn't have full Gaia it's too limited. Already have a 700 serie. Got it earlier with the partner discount. Think it was 60-70% off price list.
When using a NUC or similar with one physical network interface. Do you add a secondary USB-ethernet or does it work Ok with a trunk port and setup vlans?
My "home lab" is in fact not at home. I run it on a ESXi server colocated so I can scratch it if I need to. Check out https://www.soyoustart.com/us/ as they have a few options that your homelab will never have.
I now have 16 public IP addresses to tinker with.
Which server are you currently using Hugo? I'm considering the dedicated infra server v2.
I prefer GNS3. I like that its all linux based, gives access to just about anything you want in the bios and uses qcow2 images by default. Down side is it require a fat client. I've heard of other people using eve-ng which is pure html based.
BTW i'm not using the GNS3 VM. I'm running gns3server on ubuntu and gns3 client on windows/linux.
Oh.. btw.. GNS3 also supports multiple uses in a single project meaning we can have multiple people working on the same network drawing configuring stuff. pretty cool.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY