- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello Experts, can you please share some links/thoughts on sizing firewall for large on-prem enterprise datacenter.
The initial idea was to assign one of the existing perimeter checkpoint interfaces to a monitor mode and plug the datacenter VLANs using SPAN. Then we discovered that "These features and deployments are not supported in Monitor Mode: Passing production traffic through a Security Gateway, on which you configured Monitor Mode interface(s)." (as per Special Scenarios for Security Gateways > Deploying a Security Gateway in Monitor Mode ) Therefore we will not be allowed to use a perimeter firewall for discovery. It is always an option to build a temp box or lease the firewall from a channel partner if we want to pursue the Monitor Mode option.
We are not sure if we can trust NetFlow, because the collector is temperamental, besides there is no clarity if we would like to microsegment existing VLANs (and NetFlow only showing VLAN to VLAN flows).
What is the most recent with microsegmentation or OS-level firewalling agents for legacy on-prem datacenters? I was following the nano-firewall story but the most recent review (Overview of Infinity Next ) gives an impression that all focus on Cloud. CloudGuard provides support for all modern on-premises hypervisors. What about physical servers, or Microsoft Hyper-V? I realise that the best is to migrate to the modern hypervisor. But is there any stop-gap solution besides deploying a traditional physical default gateway firewall? Thanks!
Hi Serhej,
it would be best to engage the local office, so one of our SEs could help you.
@Matthew_Griffit, can you ask someone to assist, please?
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY