Documente Academic
Documente Profesional
Documente Cultură
40VS
Introduction
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups and
Agenda
What is VSX
A VSX is a Gateway
running several separate
firewalls each protecting
a different network
(customer).
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups10
10
and
Layer 2 Virtual Devices
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups11
11
and
Virtual Devices
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups12
12
and
warp Interfaces
Regular Interfaces
Physical interfaces
Virtual interfaces - VLANS
VSX Gateway introduces a new type of interfaces
warp links interface between component of the
VSX gateway
Eth1 (physical interface)
Wrp
Interface
Eth0.101 Eth0.100
Internet
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups16
16
and
Example: VSX Deployment
VSX
Internet
VS
X
Swit
ch
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups17
17
and
Agenda
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups18
18
and
Clustering
Virtual System Load Sharing
Distributes VS instances
between different VSX
gateways
Sync improvements
New state: Backup
Sync only between
active & standby
(unicast sync)
VS distribution
Performed
automatically or
manually (vsx_util
redistribute_vsls)
SYNC
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups19
19
and
Agenda
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups20
20
and
VSX management
SMART
3-tier management
Console
s
SmartCenter
VSX
Gateways
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups21
21
and
VSX management
Provider-1 focus
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups22
22
and
Agenda
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups23
23
and
VSX - Whats New in R75.40VS
Maintrain
Ver.
Florenc Flint Foxx Flow Fiber Giza
e
a
n ad
re
G
Ecuado El-Salvador
r
VSX Ver.
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups25
25
and
Software Blades
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups26
26
and
Virtualization and segregation
R67 R75.40VS
Resilience Kernel panic effects all An FWK dying effects one VS,
VSs, and takes minutes and takes seconds to recover.
to recover
Segregation All memory shared Separate address spaces for
between VSs and each FWK. Excellent
instances. A bug on one segregation.
VS can cause a memory
corruption on another
VS.
CPU monitoring Resource Control. Not Standard OS tools (top).
per VS. completely accurate
(due to wasted lock
time), and not standard.
RAM monitoring Currently no method. Standard OS tools (ps)
per VS. Will require a lot of
code changes.
RAM limiting per Not possible. Will Can be easily done.
VS require exact
accounting of
consumption per VS.
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups27
27
and
Changing of CP Not possible today on a Can be easily done, per VS.
VSX (R67) architecture
cpd
Trap example cpd cpd
logs
From fwk to fwd
fwd fwd fwd Ioctls ex. policy
install
From cpd to fwk
vpnd vpnd vpnd
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups30
30
and
CoreXL per VS - 2
- Use SmartDashboard
to configure the
number of instances.
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups31
31
and
Jumbo Frames Support
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups32
32
and
SNMP per VS
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups33
33
and
Memory Resource control
overview
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups34
34
and
VSX Memory Resource Control Examples
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups35
35
and
VSX Gateway Conversion
Smart Dashboard
wizard to convert
Gaia Security
Gateways to VSX
Gateways
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups36
36
and
VSX Gateway implicit Conversion
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups37
37
and
Optimal Service Upgrade
OSU provides a
solution for upgrading
a VSX to R75.40VS
without losing
connectivity
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups38
38
and
VSX CLISH commands
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups40
40
and
R75.40 VSX architecture
cpd
Trap example cpd cpd
logs
From fwk to fwd
fwd fwd fwd Ioctls ex. policy
install
From cpd to fwk
vpnd vpnd vpnd
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups42
42
and
User Space FW advantages
Speeding up development
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups44
44
and
User Space FW advantages
Better Security
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups45
45
and
Thank you !
2010 Check Point Software Technologies Ltd. | [Restricted] ONLY for designated groups and