1. Trang chủ
  2. » Giáo Dục - Đào Tạo

Multi-Domain Security Management R75 Administration Guide doc

167 780 0

Đang tải... (xem toàn văn)

Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống

THÔNG TIN TÀI LIỆU

Cấu trúc

  • Important Information

  • Multi-Domain Security Management Overview

    • Multi-Domain Security Management Glossary

    • Key Features

    • Basic Architecture

    • The Multi-Domain Server

    • Domain Management Servers

    • Log Servers

      • Multi-Domain Log Server

      • Domain Log Server

    • High Availability

    • Security Policies

      • Global Policies

    • The Management Model

      • Introduction to the Management Model

      • Administrators

      • Management Tools

        • The SmartDomain Manager

        • SmartConsole Client Applications

  • Deployment Planning

    • Multi-Domain Security Management Components Installed at the NOC

    • Using Multiple Multi-Domain Servers

      • High Availability

      • Multi-Domain Server Synchronization

      • Clock Synchronization

    • Protecting Multi-Domain Security Management Networks

    • Logging & Tracking

    • Routing Issues in a Distributed Environment

    • Platform & Performance Issues

    • IP Allocation & Routing

      • Virtual IP Limitations and Multiple Interfaces on a Multi-Domain Server

      • Multiple Interfaces on a Multi-Domain Server

    • Enabling OPSEC

  • Provisioning Multi-Domain Security Management

    • Provisioning Process Overview

    • Setting Up Your Network Topology

    • The Multi-Domain Security Management Trust Model

      • Introduction to the Trust Model

      • Secure Internal Communication (SIC)

      • Trust Between a Domain Management Server and its Domain Network

      • Trust Between a Domain Log Server and its Domain Network

      • Multi-Domain Server Communication with Domain Management Servers

      • Trust Between Multi-Domain Server to Multi-Domain Server

      • Using External Authentication Servers

        • Configuring External Authentication

      • Re-authenticating when using SmartConsole Clients

        • ...When Connecting to a Specific Domain Management Server

        • ...When Connecting to all Domain Management Servers Created on This System in the Future

        • ...When Connecting to this Multi-Domain Server or Multi-Domain Log Server

      • CPMI Protocol

    • Creating a Primary Multi-Domain Server

    • Multiple Multi-Domain Server Deployments

      • Synchronizing Clocks

      • Adding a Secondary Multi-Domain Server or a Multi-Domain Log Server

        • Multi-Domain Log Server Configuration - Additional Step

      • Changing an Existing Multi-Domain Server

      • Deleting a Multi-Domain Server

    • Using SmartDomain Manager

      • Launching the SmartDomain Manager

    • Protecting the Multi-Domain Security Management Environment

      • Standalone Gateway/Security Management

      • Domain Management Server and SmartDomain Manager

      • Security Gateways Protecting a Multi-Domain Server

      • Making Connections Between Different Components of the System

    • Licensing

      • Licensing Overview

      • The Trial Period

      • License Types

        • Multi-Domain Server Licenses

        • Domain Management Server Licenses

        • VSX Licenses

        • Log Server Licenses

        • Gateway Licenses

      • Managing Licenses

        • License Violations

        • Managing Licenses Using SmartUpdate

        • Adding Licenses using the SmartDomain Manager

  • Global Policy Management

    • Security Policies

      • The Need for Global Policies

      • The Global Policy as a Template

      • Global Policies and the Global Rule Base

    • Global SmartDashboard

      • Introduction to Global SmartDashboard

      • Global Services

      • Dynamic Objects and Dynamic Global Objects

      • Applying Global Rules to Gateways by Function

      • Synchronizing the Global Policy Database

    • Creating a Global Policy through Global SmartDashboard

    • Global IPS

      • Introduction to Global IPS

      • IPS in Global SmartDashboard

      • IPS Profiles

        • Managing IPS Profiles

          • Creating a New IPS Profile

          • Editing an IPS Profile

      • Subscribing Domains to IPS Service

      • Managing IPS from a Domain Management Server

        • Assigning IPS Profiles to Gateways

        • Removing Global IPS from a Domain Management Server

      • Managing Global IPS Sensors

    • Assigning Global Policy

      • Assigning Global Policy for the First Time

      • Assigning Global Policies to VPN Communities

      • Re-assigning Global Policies

        • Automatic Gateway Policy Installation

        • Re-assigning Global Policy to one Domain

        • Re-assigning Global Policies to Multiple Domains

        • Considerations For Global Policy Assignment

          • Introduction

          • Assigning Policy for the First Time

          • When You Change a Global Policy

          • Assigning a Different Global Policy

          • Global Object Transfer Method

      • Viewing the Status of Global Policy Assignments

      • Global Policy History File

    • Configuration

      • Assigning or Installing a Global Policy

        • Assign to Many Domains: How To Assign/Install from a Global Policy Object

        • Assign to One Domain: Assign/Install from a Domain Object

      • Reassigning/Installing a Global Policy on Domains

        • To Reassign/Install a Global Policy for a Specific Domain who already has been Assigned a Global Policy

        • To Reassign/Install a Global Policy for Multiple Domains

      • Reinstalling a Domain Policy on Domain Gateways

      • Remove a Global Policy from Multiple Domains

      • Remove a Global Policy from a Single Domain

      • Viewing the Domain Global Policy History File

      • Global Policies Tab

        • Policy Operation Options

      • Global Names Format

  • Domain Management

    • Defining a New Domain

      • Running the Wizard

      • Name the Domain and Enable QoS

      • Domain Properties

      • Assigning a Global Policy

      • Assigning Administrators to the Domain

      • Assign GUI Clients

      • Configuring Domain Management Servers

      • Defining your First Domain Management Servers

    • Configuring Existing Domains

      • Configuring a Domain

        • General Tab

        • Properties Tab

        • Assign Global Policy Tab

        • Administrators Tab

          • Assigning Permissions to Administrators

        • GUI Clients Tab

        • Version & Blade Updates

      • Version and Blade Updates

      • Defining Administrators

        • Adding a New Administrator

        • Change Administrator Permissions

        • Deleting an Administrator

        • Connected Administrators

      • Configuring Domain Management Servers

        • Adding a New Domain Management Server

        • Changing an Existing Domain Management Server

        • Domain Management Server Status

        • Deleting a Domain Management Server

      • Defining GUI Clients

      • Defining Administrator and Domain Groups

        • Configuring Domain Selection Groups

        • Configuring Administrator Selection Groups

      • Version & Blade Updates

        • Overview

        • Installing Version & Blade Updates

        • Activating and Deactivating Version & Blade Updates

        • Update Status

        • High Availability Issues

        • Plug-in Mismatches

      • Using SmartUpdate

      • Adding Domain Security Gateways

      • Starting or Stopping a Domain Management Server or Domain Log Server

  • VPN in Multi-Domain Security Management

    • Overview

      • Authentication Between Gateways

    • VPN Connectivity

    • Global VPN Communities

      • Gateway Global Names

        • Changing the Global Name Template

        • Global or Neighbor VPN Gateway

      • VPN Domains in Global VPN

      • Access Control at the Network Boundary

        • Access Control in Global VPN

      • Joining a Gateway to a Global VPN Community

        • Considerations

    • Configuring Global VPN Communities

      • Enabling a Domain Gateway to Join a Global VPN Community

        • Step 1 - In the SmartDomain Manager

          • Step 2 - In Global SmartDashboard

          • Step 3 - In the SmartDomain Manager

            • To assign to one Domain at a time

            • To assign to many Domains at one time

  • High Availability

    • Overview

    • Multi-Domain Server High Availability

      • Multiple Multi-Domain Server Deployments

      • Multi-Domain Server Status

      • Multi-Domain Server Clock Synchronization

      • The Multi-Domain Server Databases

        • Multi-Domain Security Management System Database

          • ICA Database for Multi-Domain Servers

        • Domain Management Server Databases

      • How Synchronization Works

        • Multi-Domain Server Database Synchronization

        • Multi-Domain Server ICA Database Synchronization

        • Global Policies Database Synchronization

        • Domain Management Server Database Synchronization

        • Full Synchronization Between Multi-Domain Servers

      • Configuring Synchronization

        • Using SmartDomain Manager to Synchronize Multi-Domain Servers

          • Footnote

    • Domain Management Server High Availability

      • Active Versus Standby

      • Adding a Secondary Domain Management Server

      • Domain Management Server Backup Using a Security Management Server

        • Creating a Backup Security Management Server

    • Configuration

      • Adding another Multi-Domain Server

      • Creating a Mirror of an Existing Multi-Domain Server

      • First Multi-Domain Server Synchronization

      • Restarting Multi-Domain Server Synchronization

        • To Synchronize a Single Multi-Domain Server with Another Multi-Domain Server

        • To Synchronize a Group of Multi-Domain Servers

      • Selecting a Different Multi-Domain Server to be the Active Multi-Domain Server

        • To Change the Active Multi-Domain Server

      • Automatic Synchronization for Global Policies Databases

      • Add a Secondary Domain Management Server

      • Mirroring Domain Management Servers with mdscmd

      • Automatic Domain Management Server Synchronization

      • Synchronize ClusterXL Gateways

    • Failure Recovery

      • Recovery with a Functioning Multi-Domain Server

        • Connecting to a Remaining Multi-Domain Server

        • Resetting Domain Management Servers

        • Restoring the High Availability Deployment

      • Recovery from Failure of the Only Multi-Domain Server

        • Recreating the Multi-Domain Security Management Deployment

  • Logging in Multi-Domain Security Management

    • Logging Domain Activity

    • Exporting Logs

      • Log Export to Text

      • Manual Log Export to Oracle Database

      • Automatic Log Export to Oracle Database

        • Log Files

        • Export Profiles

        • Choosing Fields to Export

      • Log Forwarding

      • Cross Domain Logging

    • Logging Configuration

      • Setting Up Logging

      • Working with Domain Log Servers

        • Add a Domain Log Server

        • Starting or Stopping a Domain Log Server

        • Deleting a Domain Log Server

      • Setting up Domain Gateway to Send Logs to the Domain Log Server

      • Synchronizing the Domain Log Server Database with the Domain Management Server Database

      • Configuring a Multi-Domain Server to Enable Log Export

      • Configuring Log Export Profiles

      • Choosing Log Export Fields

      • Log Export Troubleshooting

      • Using SmartReporter

  • Monitoring

    • Overview

    • Monitoring Components in the Multi-Domain Security Management System

      • Exporting the List Pane's Information to an External File

      • Working with the List Pane

        • Filtering

        • Showing and Hiding Selected List Pane Columns

    • Verifying Component Status

      • Viewing Status Details

      • Locating Components with Problems

    • Monitoring Issues for Different Components and Features

      • Multi-Domain Server

      • Global Policies

      • Domain Policies

        • Checking a Domain Management Server Policy

      • Gateway Policies

        • Checking a Gateway's Current Policy

      • High Availability

      • Global VPN Communities

      • Administrators

        • Connected Administrators

      • GUI Clients

    • Using SmartConsole

      • Log Tracking

      • Tracking Logs using SmartView Tracker

      • Real-Time Network Monitoring with SmartView Monitor

        • Monitoring the Status of a Domain Management Server

          • Check Point System Counters

          • Traffic Flow and Virtual Link Monitoring

          • Blocking Suspicious Connections

          • Using Thresholds

      • SmartReporter Reports

  • Architecture and Processes

    • Packages in Multi-Domain Server Installation

    • Multi-Domain Server File System

      • Multi-Domain Server Directories on /opt and /var File Systems

      • Structure of Domain Management Server Directory Trees

      • Check Point Registry

      • Automatic Start of Multi-Domain Server Processes, Files in /etc/rc3.d, /etc/init.d

    • Processes

      • Environment Variables

        • Standard Check Point Environment Variables

        • Parameters/Thresholds for Different Multi-Domain Server functions

          • Logging Cache Size

      • Multi-Domain Server Level Processes

      • Domain Management Server Level Processes

    • Multi-Domain Server Configuration Databases

      • Global Policy Database

      • Multi-Domain Server Database

      • Domain Management Server Database

    • Connectivity Between Different Processes

      • Multi-Domain Server Connection to Domain Management Servers

      • Status Collection

        • Changing the Status Collection Cycle

      • Collection of Changes in Objects

      • Connection Between Multi-Domain Servers

      • Large Scale Management Processes

      • UTM-1 Edge Processes

      • Reporting Server Processes

    • Issues Relating to Different Platforms

      • High Availability Scenarios

      • Migration Between Platforms

  • Commands and Utilities

    • Cross-Domain Management Server Search

      • Overview

      • Searching

      • Copying Search Results

      • Performing a Search in CLI

        • Example

    • P1Shell

      • Overview

      • Starting P1Shell

      • File Constraints for P1Shell Commands

      • Multi-Domain Security Management Shell Commands

        • General Multi-Domain Security Management Commands

        • Native P1Shell Commands

      • Audit Logging

    • Command Line Reference

      • cma_migrate

      • CPperfmon - Solaris only

        • CPperfmon hw - Solaris only

        • CPperfmon procmem - Solaris only

        • CPperfmon monitor - Solaris only

        • CPperfmon mdsconfig - Solaris only

        • CPperfmon summary - Solaris only

        • CPperfmon off - Solaris only

        • CPperfPack

      • cpmiquerybin

      • dbedit

      • export_database

      • mcd bin | scripts | conf

      • mds_backup

      • mds_restore

      • mds_user_expdate

      • mdscmd

        • mdscmd adddomain

        • mdscmd addmanagement

        • mdscmd addlogserver

        • mdscmd deletedomain

        • mdscmd deletemanagement

        • mdscmd deletelogserver

        • mdscmd enableglobaluse

        • mdscmd disableglobaluse

        • mdscmd startmanagement

        • mdscmd stopmanagement

        • mdscmd migratemanagement

        • mdscmd miirrormanagement

      • mdsenv

      • mdsquerydb

      • mdstart

      • mdstat

      • mdstop

      • merge_plug-in_tables

      • migrate_assist

      • migrate_global_policies

  • Index

Nội dung

15 December 2010 Administration Guide Multi-Domain Security Management R75 © 2010 Check Point Software Technologies Ltd. All rights reserved. This product and related documentation are protected by copyright and distributed under licensing restricting their use, copying, distribution, and decompilation. No part of this product or related documentation may be reproduced in any form or by any means without prior written authorization of Check Point. While every precaution has been taken in the preparation of this book, Check Point assumes no responsibility for errors or omissions. This publication and features described herein are subject to change without notice. RESTRICTED RIGHTS LEGEND: Use, duplication, or disclosure by the government is subject to restrictions as set forth in subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS 252.227-7013 and FAR 52.227-19. TRADEMARKS: Refer to the Copyright page (http://www.checkpoint.com/copyright.html) for a list of our trademarks. Refer to the Third Party copyright notices (http://www.checkpoint.com/3rd_party_copyright.html) for a list of relevant copyrights and third-party licenses. Important Information Latest Documentation The latest version of this document is at: http://supportcontent.checkpoint.com/documentation_download?ID=11683 For additional technical information, visit the Check Point Support Center (http://supportcenter.checkpoint.com). Revision History Date Description 8 December 2010 First release of this document Feedback Check Point is engaged in a continuous effort to improve its documentation. Please help us by sending your comments (mailto:cp_techpub_feedback@checkpoint.com?subject=Feedback on Multi-Domain Security Management R75 Administration Guide). Contents Important Information 3 Multi-Domain Security Management Overview 9 Multi-Domain Security Management Glossary 9 Key Features 11 Basic Architecture 11 The Multi-Domain Server 13 Domain Management Servers 14 Log Servers 15 Multi-Domain Log Server 16 Domain Log Server 16 High Availability 16 Security Policies 17 Global Policies 17 The Management Model 17 Introduction to the Management Model 17 Administrators 17 Management Tools 19 Deployment Planning 20 Multi-Domain Security Management Components Installed at the NOC 20 Using Multiple Multi-Domain Servers 20 High Availability 20 Multi-Domain Server Synchronization 21 Clock Synchronization 21 Protecting Multi-Domain Security Management Networks 21 Logging & Tracking 21 Routing Issues in a Distributed Environment 21 Platform & Performance Issues 22 IP Allocation & Routing 22 Virtual IP Limitations and Multiple Interfaces on a Multi-Domain Server 22 Multiple Interfaces on a Multi-Domain Server 22 Enabling OPSEC 22 Provisioning Multi-Domain Security Management 24 Provisioning Process Overview 24 Setting Up Your Network Topology 24 The Multi-Domain Security Management Trust Model 25 Introduction to the Trust Model 25 Secure Internal Communication (SIC) 25 Trust Between a Domain Management Server and its Domain Network 25 Trust Between a Domain Log Server and its Domain Network 25 Multi-Domain Server Communication with Domain Management Servers 26 Trust Between Multi-Domain Server to Multi-Domain Server 26 Using External Authentication Servers 26 Re-authenticating when using SmartConsole Clients 27 CPMI Protocol 28 Creating a Primary Multi-Domain Server 28 Multiple Multi-Domain Server Deployments 28 Synchronizing Clocks 28 Adding a Secondary Multi-Domain Server or a Multi-Domain Log Server 28 Changing an Existing Multi-Domain Server 30 Deleting a Multi-Domain Server 31 Using SmartDomain Manager 31 Launching the SmartDomain Manager 31 Protecting the Multi-Domain Security Management Environment 32 Standalone Gateway/Security Management 32 Domain Management Server and SmartDomain Manager 32 Security Gateways Protecting a Multi-Domain Server 33 Making Connections Between Different Components of the System 34 Licensing 35 Licensing Overview 35 The Trial Period 35 License Types 35 Managing Licenses 36 Global Policy Management 40 Security Policies 40 The Need for Global Policies 40 The Global Policy as a Template 41 Global Policies and the Global Rule Base 41 Global SmartDashboard 42 Introduction to Global SmartDashboard 42 Global Services 42 Dynamic Objects and Dynamic Global Objects 42 Applying Global Rules to Gateways by Function 43 Synchronizing the Global Policy Database 44 Creating a Global Policy through Global SmartDashboard 44 Global IPS 45 Introduction to Global IPS 45 IPS in Global SmartDashboard 46 IPS Profiles 46 Subscribing Domains to IPS Service 47 Managing IPS from a Domain Management Server 48 Managing Global IPS Sensors 49 Assigning Global Policy 49 Assigning Global Policy for the First Time 49 Assigning Global Policies to VPN Communities 49 Re-assigning Global Policies 49 Viewing the Status of Global Policy Assignments 53 Global Policy History File 53 Configuration 53 Assigning or Installing a Global Policy 53 Reassigning/Installing a Global Policy on Domains 54 Reinstalling a Domain Policy on Domain Gateways 55 Remove a Global Policy from Multiple Domains 56 Remove a Global Policy from a Single Domain 56 Viewing the Domain Global Policy History File 56 Global Policies Tab 56 Global Names Format 57 Domain Management 58 Defining a New Domain 58 Running the Wizard 58 Name the Domain and Enable QoS 60 Domain Properties 60 Assigning a Global Policy 60 Assigning Administrators to the Domain 61 Assign GUI Clients 63 Configuring Domain Management Servers 63 Defining your First Domain Management Servers 64 Configuring Existing Domains 65 Configuring a Domain 65 Version and Blade Updates 71 Defining Administrators 72 Configuring Domain Management Servers 75 Defining GUI Clients 77 Defining Administrator and Domain Groups 78 Version & Blade Updates 79 Using SmartUpdate 82 Adding Domain Security Gateways 83 Starting or Stopping a Domain Management Server or Domain Log Server 83 VPN in Multi-Domain Security Management 84 Overview 84 Authentication Between Gateways 84 VPN Connectivity 84 Global VPN Communities 85 Gateway Global Names 85 VPN Domains in Global VPN 86 Access Control at the Network Boundary 86 Joining a Gateway to a Global VPN Community 87 Configuring Global VPN Communities 88 Enabling a Domain Gateway to Join a Global VPN Community 88 High Availability 90 Overview 90 Multi-Domain Server High Availability 90 Multiple Multi-Domain Server Deployments 90 Multi-Domain Server Status 91 Multi-Domain Server Clock Synchronization 92 The Multi-Domain Server Databases 92 How Synchronization Works 93 Configuring Synchronization 95 Domain Management Server High Availability 96 Active Versus Standby 97 Adding a Secondary Domain Management Server 97 Domain Management Server Backup Using a Security Management Server .97 Configuration 100 Adding another Multi-Domain Server 100 Creating a Mirror of an Existing Multi-Domain Server 100 First Multi-Domain Server Synchronization 101 Restarting Multi-Domain Server Synchronization 101 Selecting a Different Multi-Domain Server to be the Active Multi-Domain Server 101 Automatic Synchronization for Global Policies Databases 101 Add a Secondary Domain Management Server 102 Mirroring Domain Management Servers with mdscmd 102 Automatic Domain Management Server Synchronization 102 Synchronize ClusterXL Gateways 102 Failure Recovery 103 Recovery with a Functioning Multi-Domain Server 103 Recovery from Failure of the Only Multi-Domain Server 104 Logging in Multi-Domain Security Management 106 Logging Domain Activity 106 Exporting Logs 107 Log Export to Text 107 Manual Log Export to Oracle Database 108 Automatic Log Export to Oracle Database 108 Log Forwarding 108 Cross Domain Logging 108 Logging Configuration 109 Setting Up Logging 109 Working with Domain Log Servers 109 Setting up Domain Gateway to Send Logs to the Domain Log Server 110 Synchronizing the Domain Log Server Database with the Domain Management Server Database 110 Configuring a Multi-Domain Server to Enable Log Export 110 Configuring Log Export Profiles 110 Choosing Log Export Fields 111 Log Export Troubleshooting 111 Using SmartReporter 112 Monitoring 113 Overview 113 Monitoring Components in the Multi-Domain Security Management System 114 Exporting the List Pane's Information to an External File 114 Working with the List Pane 114 Verifying Component Status 115 Viewing Status Details 116 Locating Components with Problems 117 Monitoring Issues for Different Components and Features 117 Multi-Domain Server 118 Global Policies 118 Domain Policies 119 Gateway Policies 119 High Availability 119 Global VPN Communities 120 Administrators 121 GUI Clients 122 Using SmartConsole 123 Log Tracking 123 Tracking Logs using SmartView Tracker 123 Real-Time Network Monitoring with SmartView Monitor 123 SmartReporter Reports 125 Architecture and Processes 126 Packages in Multi-Domain Server Installation 126 Multi-Domain Server File System 126 Multi-Domain Server Directories on /opt and /var File Systems 126 Structure of Domain Management Server Directory Trees 127 Check Point Registry 128 Automatic Start of Multi-Domain Server Processes, Files in /etc/rc3.d, /etc/init.d 128 Processes 128 Environment Variables 128 Multi-Domain Server Level Processes 129 Domain Management Server Level Processes 129 Multi-Domain Server Configuration Databases 130 Global Policy Database 130 Multi-Domain Server Database 130 Domain Management Server Database 130 Connectivity Between Different Processes 131 Multi-Domain Server Connection to Domain Management Servers 131 Status Collection 131 Collection of Changes in Objects 132 Connection Between Multi-Domain Servers 132 Large Scale Management Processes 132 UTM-1 Edge Processes 132 Reporting Server Processes 132 Issues Relating to Different Platforms 132 High Availability Scenarios 132 Migration Between Platforms 133 Commands and Utilities 134 Cross-Domain Management Server Search 134 Overview 134 Searching 134 Copying Search Results 135 Performing a Search in CLI 135 P1Shell 136 Overview 136 Starting P1Shell 136 File Constraints for P1Shell Commands 137 Multi-Domain Security Management Shell Commands 137 Audit Logging 140 Command Line Reference 140 cma_migrate 140 CPperfmon - Solaris only 141 cpmiquerybin 146 dbedit 146 export_database 148 mcd bin | scripts | conf 149 mds_backup 149 mds_restore 150 mds_user_expdate 150 mdscmd 150 mdsenv 158 mdsquerydb 158 mdstart 159 mdstat 160 mdstop 160 merge_plug-in_tables 160 migrate_assist 161 migrate_global_policies 161 Index 163 Page 9 Chapter 1 Multi-Domain Security Management Overview Multi-Domain Security Management is a centralized management solution for large-scale, distributed environments with many different network Domains. This best-of-breed solution is ideal for enterprises with many subsidiaries, branches, partners and networks. Multi-Domain Security Management is also an ideal solution for managed service providers, cloud computing providers, and data centers. Centralized management gives administrators the flexibility to manage polices for many diverse entities. Security policies should be applicable to the requirements of different departments, business units, branches and partners, balanced with enterprise-wide requirements. In This Chapter Multi-Domain Security Management Glossary 9 Key Features 11 Basic Architecture 11 The Multi-Domain Server 13 Domain Management Servers 14 Log Servers 15 High Availability 16 Security Policies 17 The Management Model 17 Multi-Domain Security Management Glossary This glossary includes product-specific terms used in this guide. Administrator Security administrator with permissions to manage elements of a Multi-Domain Security Management deployment. Global Policy Policies that are assigned to all Domains, or to specified groups of Domains. Global Objects Network objects used in global policy rules. Examples of global objects include hosts, global Domain Management Servers, and global VPN communities. Internal Certificate Authority (ICA) Check Point component that authenticates administrators and users. The ICA also manages certificates for Secure Internal Communication (SIC) between Security Gateways and Multi- Domain Security Management components. Multi-Domain Security Management Check Point centralized management solution for large-scale, distributed environments with many different network Domains. Multi-Domain Security Management Glossary Multi-Domain Security Management Overview Page 10 Domain A network or group of networks belonging to a specified entity, such as a company, business unit or organization. Multi-Domain Server Multi-Domain Security Management server that contains all system information as well as the security policy databases for individual Domains. Domain Management Server Virtual Security Management Server that manages Security Gateways for one Domain. Multi-Domain Log Server Physical log server that hosts the log database for all Domains. Domain Log Server Virtual log server for a specified Domain. Primary Multi-Domain Server The first Multi-Domain Server that you define and log into in a High Availability deployment. Secondary Multi-Domain Server Any subsequent Multi-Domain Server that you define in a High Availability deployment. Active Multi-Domain Server The only Multi-Domain Server in a High Availability deployment from which you can add, change or delete global objects and global policies. By default, this is the primary Multi-Domain Server. You can change the active Multi-Domain Server. Standby Multi-Domain Server All other Multi-Domain Servers in a High Availability deployment, which cannot manage global policies and objects. Standby Multi- Domain Servers are synchronized with the active Multi-Domain Server. Active Domain Management Server In a High Availability deployment, the only Domain Management Server that can manage a specific Domain. Standby Domain Management Server In a High Availability deployment, any Domain Management Server for a specified Domain that is not designated as the active Domain Management Server. [...]... Management permissions Provisioning Multi-Domain Security Management Page 31 Protecting the Multi-Domain Security Management Environment Protecting the Multi-Domain Security Management Environment You should always deploy a Check Point Security Gateway to protect your Multi-Domain Security Management network, including your Multi-Domain Server, Multi-Domain Log Server and management platforms This section... Point Security Gateways to protect your Multi-Domain Security Management network You can manage your Security Gateway using either a Security Management Server (configured as a standalone gateway /Security Management combination) or a Domain Management Server and the SmartDomain Manager Standalone Gateway /Security Management In this scenario the Security Gateway that protects your Multi-Domain Security Management. .. Multi-Domain Security Management Networks The Multi-Domain Security Management network and Network Operation Center (NOC) must be protected by a Security Gateway You can manage this gateway using a Domain Management Server or a Security Management Server This Security Gateway must have a security policy that adequately protects the NOC and allows secure communication between Multi-Domain Security Management. .. install a Security Policy for the gateway Provisioning Multi-Domain Security Management Page 32 Protecting the Multi-Domain Security Management Environment Security Gateways Protecting a Multi-Domain Server A Security Gateway that protects a Multi-Domain Server must have an installed security policy that allows connections between:  The Active and Standby Domain Management Servers and their Domain Security. .. implementing Multi-Domain Security Management This chapter examines different aspects of deployment preparation Included are several issues that you should take into consideration when planning a new Multi-Domain Security Management deployment In This Chapter Multi-Domain Security Management Components Installed at the NOC Using Multiple Multi-Domain Servers Protecting Multi-Domain Security Management. .. Domain Management Server is a virtual Security Management Server that manages security policies and Security Gateways for a specified Domain  The Multi-Domain Server is a physical server that hosts the Domain Management Server databases and Multi-Domain Security Management system databases  The SmartDomain Manager is a management client that administrators use to manage domain security and the Multi-Domain. .. multiple Multi-Domain Servers Domain Management Servers A Domain Management Server is the Multi-Domain Security Management functional equivalent of a Security Management Server Administrators use Domain Management Servers to define, change and install Domain security policies to Domain Security Gateways A Domain can have multiple Domain Management Servers in a high availability deployment One Domain Management. .. 1 Security Gateway 2 Network Operation Center 3 Headquarters Domain Management Server 4A USA Development Domain Management Server 4B Headquarters Domain Management Server 4C UK Development Domain Management Server After you define a Domain Management Server, you define Security Gateways, network objects, and security policies using the basic procedures in the R75 Security Management Administration Guide. .. Logging in Multi-Domain Security Management (on page 106), and High Availability (on page 90) Log Servers This section shows how log servers operate in a Multi-Domain Security Management deployment Multi-Domain Security Management Overview Page 15 High Availability List of Callouts Callout Description A Domain A B Domain B 1 Security Gateway 2 Multi-Domain Server 3 Multi-Domain Log Server 4 Domain Management. .. UK Development Domain 1 Security Gateway 2 Network Operation Center 3 Multi-Domain Server 4A USA Development Domain Management Server 4B Headquarters Domain Management Server 4C UK Development Domain Management Server Multi-Domain Security Management Overview Page 12 The Multi-Domain Server The Multi-Domain Server The Multi-Domain Server is a physical computer that hosts Domain Management Servers, system . (mailto:cp_techpub_feedback@checkpoint.com?subject=Feedback on Multi-Domain Security Management R75 Administration Guide) . Contents Important Information 3 Multi-Domain Security Management Overview 9 Multi-Domain Security Management. can use multiple Multi-Domain Servers. Domain Management Servers A Domain Management Server is the Multi-Domain Security Management functional equivalent of a Security Management Server and security policies using the basic procedures in the R75 Security Management Administration Guide. (http://supportcontent.checkpoint.com/documentation_download?ID=11667) You manage Security

Ngày đăng: 08/08/2014, 06:20

TỪ KHÓA LIÊN QUAN

TÀI LIỆU CÙNG NGƯỜI DÙNG

  • Đang cập nhật ...

TÀI LIỆU LIÊN QUAN