Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
Advisor

TP - Best Practices

Hello, Mates.

In VSX environments, the recommendation regarding enabling Threat Prevention Blades on all the VS's you have, is always going to depend on how ‘robust’ your main VSX box is?

Does enabling Threat Prevention “force” you to also enable HTTPS Inspection on your VS's or is this always optional?

Thanks for your recommendations.

0 Kudos
10 Replies
the_rock
Legend
Legend

Hey bro,

I always tell people to follow this mentality "When in doubt, always leave default settings". If then, you notice any issues, you can tailor it as needed.

Andy

0 Kudos
Lesley
Authority Authority
Authority

You only enable IPS on VS0 for updates not to protect VS0. VS0 is for mgmt purpose 

Should I enable IPS Software Blade on the VSX Gateway?

You must enable and configure the IPS Software Blade in these objects:

  1. VSX Gateway or VSX Cluster (because VS0 handles contract validation for all Virtual Systems).

  2. Applicable Virtual Systems.

 

To enable Anti-Bot, Anti-Virus, or IPS on Virtual Systems

Important:

Make sure the routing, DNS, and proxy settings for the VSX GatewayClosed or VSX ClusterClosed Members (VS0) are configured correctly.

You must enable and configure the Software Blades in these objects:

VSX Gateway or VSX Cluster (because VS0 handles contract validation for all Virtual Systems).

Applicable Virtual Systems.

Make sure the VSX Gateway or VSX Cluster and the applicable Virtual Systems can connect to the Internet.

Virtual Systems get updates through the VSX Gateway or VSX Cluster (VS0).

If the VSX Gateway or VSX Cluster fails to connect, each Virtual SystemClosed uses its proxy settings to get the updates from the Internet.

 

 

Regarding HTTPS inspection. Now you can run IPS without but you don't get the full inspection. The firewall cannot inspect traffic that is encrypted. Most traffic now is encrypted so it is quite important. 

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Matlu
Advisor

To enable IPS/AB/AV blades, there are 2 ways?

Because I know people who enable these blades ‘Instance by Instance’ (VS x VS), but according to your explanation, I understand that I can enable the blades from the box as such (VS0) and this should ‘Replicate’ on all my VS's?

Is that the logic?

0 Kudos
Lesley
Authority Authority
Authority

If you want to use IPS on a VS you always enable it on VS0 and any other VS that you want to run IPS.

For example

VS0: IPS

VS1:No ips because internal fw

VS2: IPS enabled

You can attach a IPS profile on each VS, also VS0

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Matlu
Advisor

Does the IPS recommendation also apply to other blades, such as AB and AV?

 

Or AV/AB can be enabled on the VS's one needs, without the need to enable it also on VS0?

0 Kudos
PhoneBoy
Admin
Admin

Yes, AB/AV should only be enabled on VSes where it is required.
Traffic is checked via ThreatCloud, so the VS needs Internet access.

Matlu
Advisor

In general terms, does Threat Prevention make sense to be used in FW or VS's that have Internet access?

Because these blades, enabling them in FW that do not have Internet access, would not make sense, right?

0 Kudos
the_rock
Legend
Legend

Personally bro, at least in my logical opinion, it makes total sense to use those blades on VS with Internet access and NOT use them on ones that dont have it. Its literally same method for regular quantum fws and truth be told, pretty much applies to any fw vendor out there.

Andy

0 Kudos
Lesley
Authority Authority
Authority

Yes also needed on VS0

Anti-Bot and Anti-Virus

Click Here to Show This Section
-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Chris_Atkinson
Employee Employee
Employee

HTTPS is not mandatory for TP but what the blades can see is limited to clear traffic without it same as any gateway.

IPS and TEX are the two blades I believe must be enabled also on VSO if to be used on other VS.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events