.

Showing posts with label firewall basic. checkpoint Gaia. Show all posts
Showing posts with label firewall basic. checkpoint Gaia. Show all posts

Saturday, April 18, 2015

Checkpoint Firewall VSX Overview:


VSX (Virtual System Extension) is a security and VPN solution for large-scale environments based on the proven security of Check Point Security Gateway. VSX provides comprehensive protection for multiple networks or VLANs within complex infrastructures. It securely connects them to shared resources such as the Internet and/or a DMZ, and allows them to safely interact with each other. VSX is supported by IPS™ Services, which provide up-to-date preemptive security.

A VSX Gateway contains a complete set of virtual devices that function as physical network components, such as Security Gateway, routers, switches, interfaces, and even network cables. Centrally managed, and incorporating key network resources internally, VSX lets businesses deploy comprehensive firewall and VPN functionality, while reducing hardware investment and improving efficiency.

VSX:
Virtual System Extension - Check Point virtual networking solution, hosted on a single computer or cluster containing virtual abstractions of Check Point Security Gateways and other network devices. These virtual devices provide the same functionality as their physical counterparts.

VSX Gateway:
Physical server that hosts VSX virtual networks, including all virtual devices that provide the functionality of physical network devices.

Management Server:
The Security Management Server or a Multi-Domain Security Management used by administrators to manage the VSX virtual network and its security policies.

Virtual Switch:
A virtual device that provides the functionality of a physical switch in a VSX deployment.

Virtual Router:
A virtual device that provides the functionality of a physical router in a VSX deployment.

Warp Link (wrp):
A virtual interface that is created automatically in a VSX topology.

Tuesday, December 23, 2014

Juniper SRX Packet Flow in detail (part 2)

Juniper SRX Packet Flow in detail (part 2)

SECURITY SERVICES PACKET WALK


About Services ALG Module:
An Application Layer Gateway (ALG) is a software component that is designed to manage specific protocols such as Session Initiation Protocol (SIP) or FTP on Juniper Networks devices running Junos OS. In Juniper SRX this is where all the services are being matched.
It has multiple module to process the services based on there service request.

1) AppID (Packet): The APPID (application identification) Module is a Junos OS feature that identifies applications as constituents of application groups in TCP/UDP/ICMP traffic.

2) IDP: This Module is use for Intrusion Detect Prevention.

3) SSL Proxy: This Module is use for SSL Inspection (ssl encrypted packet) 

4) ALG: The ALG module is responsible for Application-Layer aware packet processing.

5) UTM: With UTM module, you can implement a comprehensive set of security features that include antispam, antivirus, Web filtering, and content filtering protection.

6) AppFW: This Module is use for identifying and inspecting applications.

7) UserFW: UserFW module is foe identifying the users, basically it's identity awareness.