SlideShare a Scribd company logo
1 of 48
HP TippingPoint 
Next Generation Firewall 
HP Enterprise Security Internal Technical Pre-Sales Training 
Julian Palmer, NGFW Product Manager, HP TippingPoint 
Russ Meyers, SMS Product Manager, HP TippingPoint 
© Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Agenda 
Introducing HP TippingPoint Next Generation Firewall (NGFW) 
Key attributes, and how HP TippingPoint NGFW achieves them 
Seven steps to get an NGFW on the network 
Shared firewall rules with SMS 
How does NGFW help common problems? 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 2 to change without notice.
Introducing the HP 
TippingPoint Next 
Generation Firewall 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
What is HP NGFW… 
Simple 
Easy-to-Use, 
configure and 
install with 
centralized 
management 
Next Gen IPS Enterprise 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 4 to change without notice. 
Reliable 
Protect the 
network 
availability 
features, IPS, 
and automatic 
protection 
Effective 
Industry 
leading 
security 
intelligence 
with weekly 
DVLabs 
updates 
Integrated 
Policy 
Firewall 
DVLabs 
research 
and feeds 
User and app 
policy
HP NGFW Feature Summary 
Security 
• Enterprise class zonal, stateful firewall 
• Mix and match FW, app, user and IPS policy 
choices 
• Full IPS, DV, RepDV, WebAppDV, Zero Day 
Initiative 
• Apply IPS inspection profile based on app 
• Rate limit, quarantine, trap, pcap, email actions 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 5 to change without notice. 
Certification Plans 
• ICSA Firewall/VPN Enterprise, USGv6 coming 
• FIPS-140-2, EAL, NSS on roadmap 
Management 
• HTTPS local web GUI, SSH, Full CLI, 
inband/outband 
• Role based management, Encrypted Log 
Storage 
• SNMPv2/v3 MIB-2, and TP Enterprise MIBs 
• Integrated FW & IPS management with SMS 
• ArcSight, HP NNMi and NA integration 
Deployment 
• NAT, routed, transparent, segment, one-armed 
• IPv6 ready everywhere 
• Static, RIP/RIPng, OSPFv2/v3, BGPv4, 
multicast 
• Link aggregation, VLAN translation, Rate 
limiting 
• IPSec site-to-site & Client-to-site, GRE/IPSec 
• Active-Passive 2-node Stateful High Availability 
• LDAP, Active Directory, RADIUS authentication
HP NGFW Portfolio 
S1050F S3010F S3020F S8005F S8010F 
FW only 500Mbps 1Gbps 2Gbps 5Gbps 10Gbps 
FW + IPS @512 bytes 250Mbps 500Mbps 1Gbps 2.5Gbps 5Gbps 
New Connections/second 10,000 20,000 20,000 50,000 50,000 
Concurrent Connections 250,000 500,000 1M 10M 20M 
Aggregate VPN Throughput (big 
250 Mbps 500Mbps 1Gbps 1.5Gbps 3Gbps 
pkts) 
VPN Tunnels 2500 5000 7500 7500 7500 
Redundant Power Supply/Fans No Yes Yes Yes Yes 
Removable Solid State Storage 8GB 8GB 8GB 32GB 32GB 
Integrated I/O 8xGbE 8xGbE 
8xSFP 
8xGbE 
8xSFP 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 6 to change without notice. 
8xGbE 
8xSFP 
4x SFP+ 
8xGbE 
8xSFP 
4x SFP+ 
Ordering information: 
ESP 
HPN 
JC850A 
JC882A 
US$4,995 
JC851A 
JC883A 
US$13,995 
JC852A 
JC884A 
US$18,995 
JC853A 
JC885A 
US$49,995 
JC854A 
JC886A 
US$70,995 
HPN care pack info will follow… 
1 Year of DV must be bought w/HW 
Premium (DV+24x7) 
Premium (DV+RepDV+24x7)
Where to Deploy 
• At all network edges 
• Security consolidation 
• Where security needs 
may change 
Virtual machines (VMs) 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 7 to change without notice. 
Campus 
LAN 
Edge 
WLAN 
Core 
Tele-workers, 
partners, and 
customers 
Internet 
Remote 
offices and 
branches 
WAN 
Data 
center 
NGFW 
NGFW 
NGFW 
NGFW 
IPS 
IPS 
NGFW 
NGFW 
Branch Regional 
Hub 
Data 
Center 
S1050F 
S3010F 
S3020F 
S8005F 
S8010F
S1050F Platform 
External User 
Disk 
Console 115200, 8N1 
GbE Data Ports HA MGMTAlert LED 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 8 to change without notice. 
Status 
LED 
Power LED 
On/Off
S3010F , S3020F, S8005F, S8010F Platforms 
SFP GbE Data Ports User Disk H 
MGMT Alert LED 
Ports 
A 
10G 
SFP+ 
(S8000F) 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 9 to change without notice. 
Console 115200, 8N1 
Status 
LED 
Redundant hot swap fans Dual Redundant PSUs 
• Redundan 
t Fan/PSU 
• Hot swap 
fans and 
PSU
LED Meanings 
Alert LED 
Off No power 
Solid 
Yellow 
System booting. After boot 
this indicates a software 
failure. 
Flashing 
Yellow 
A Hardware problem has 
been detected 
Solid 
Green 
Hardware and software are 
running normally 
System LED 
Off No power 
Flashing 
Green 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 10 to change without notice. 
System is booting and traffic is 
not being processed 
Solid Green System is running and healthy 
Solid Yellow System is running but has 
degraded health (software or 
hardware issue) 
Flashing 
Green/Yellow 
A software or BIOS upgrade is 
being performed
HP ESP Field Replacement Parts 
ESP 
SKU 
HPN 
SKU 
ESP Description* 
Ref 
Price 
C1J35 
A 
JC901 
A 
HP TippingPoint 750W AC Power 
Supply 
US$649 
C1J36 
A 
JC903 
A 
HP TippingPoint 32GB CFast 
Card 
US$599 
C1J34 
A 
JC900 
A 
HP TippingPoint 80mm Fan 
Module 
US $190 
DC power option not available 
AC power supply is the same as the NX IPS 
Comments 
Supports NGFW and NX; Replaces 
JC826A 
Supports NGFW and NX; Replaces 
JC828A 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 11 to change without notice. 
* HPN Description is different
Simplicity 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Easy and Powerful Management 
Best of Breed central management with SMS 
• Unified management of IPS and NGFW devices 
• Keep security current with DV active update 
• Advanced reporting & visualization 
• SMS 4.0 adds support for NGFW 
Powerful when you need it 
• Role Based Access Control 
• Forensic reporting 
• ArcSight Logger for universal log management 
• 3rd Party integrations 
Easy to Use On-Box web interface 
• Minimum IE8, Chrome 17, Firefox 10, Safari 5.1 
• Optimized for 1440x900 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 13 to change without notice.
Reporting and Visibility 
Primary reporting tool is SMS 
• Delivers Application Visibility & Utilization, 
Troubleshooting, Security Analysis and 
Capacity Planning 
• Consolidated reporting from all NGFW/IPS boxes 
• High performance, detailed event forensics 
using integrated HP Vertica columnar database 
• Customizable Dashboard for real-time data 
on traffic, apps and network behaviour 
On-box shows summary app, traffic mix 
• Identify app/traffic patterns 
• App visibility is on by default 
Big Data forensics with ArcSight 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 14 to change without notice.
Easy to Deploy in the Network 
Transparent 
• Drop in Deployment 
• Same L2 network on both sides 
• Forwarded traffic based on destination 
MAC 
• Firewall always there… 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 15 to change without notice. 
Routed 
• Different L3 network on each side 
• Traffic is directed via routing table 
• No asymmetric routing 
• No L2FB 
Segment 
• In/out port 
• Bump-in-the-wire 
(no IP address) 
• Reliability through 
L2FB and HA 
modes 
Bridge 
• Multiple ports 
• Bcast domain 
• IP address 
• No L2FB 
Routed 
• One or more IP 
addresses 
One Armed 
• Single port in/out 
• VLAN tagged
Easy to Demo 
Use NGFW to easily demo security & apps: 
1. Attach “in” port of segment to a mirror port 
Leave “out” port unconnected 
2. Configure a segment using these ports 
3. Set the NGFW IPS policy to “IDS Mode” 
4. Create a Firewall Rule to “Permit Any Any” 
5. Override IPS Categories to Permit+Notify 
6. Leave… 
• Return later and look at the reports 
• IPS events, App reports, Traffic Reports 
• Add an SMS for even better reporting 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 16 to change without notice.
Effective Security 
Mitigate Today and Tomorrow’s 
Threats Using Firewall, IPS and 
Application Control 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Security Elements 
Integrated Policy Controlling Who Does What to Whom, When… 
Objects 
• Zones, action sets, 
notification contacts, 
services, address 
groups, schedules 
Firewall 
• Stateful Firewall, with 
NAT/PAT 
• Application Groups, 
selected by category 
• Mix and Match 
Stateful and App 
elements 
• User ID by captive 
portal 
• User authentication 
by AD, LDAP, 
RADIUS 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 18 to change without notice. 
Next Gen IPS 
• 12 categories with 
recommended settings 
• Zero Day, and Best of 
Breed DV security filters 
from DVLabs 
• Reputation to block 
undesirable IPs 
• Automatic DV & RepDV 
update 
• Shared profiles with IPS 
devices
Understanding FW Rules 
Powerful and succinct rules 
• Source/Destination based on Zone 
or IP subnets/ranges 
• Optionally use applications, Users, 
services and schedules 
• Block, Rate limit, Trust, trap, email, pcap 
• Set inspection profile per-rule 
• Position most specific rules at top 
Collapse multiple rules into one 
• Using multiple selectors (like an “or”), 
where the policy/action is the same 
• Negation and Exclude constructs 
Edit Default Block Rule to enable logging 
No implied rules 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 19 to change without notice.
Controlling Applications 
• All web apps look the same to old FW’s 
• True NGFW firewall rules only contain 
apps/categories, not services 
IPS w/ Unknown Profile FW Rule Specific 
Profile 
Match Stateful FW Rule App Detected – 
• NGFW will detect apps regardless of TCP port 
• NGFW keeps looking for a better matching 
FW rule, until app is definitive or not matched 
• IPS can be applied during “app detect phase” 
• NGFW can block encrypted applications, 
but cannot inspect within them 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 20 to change without notice. 
Change Matching FW 
Rule
IPS Profiles Drive Deep Packet Inspection 
Policy 
IPS uses security filters from DVLabs 
• 7,400 filters, 2,650 security researchers 
• No false positives or negatives 
IPS Profiles define a combination of IPS settings 
• Set Profile Deployment Mode to modify 
“Recommended” 
• DV defines “Recommended” for all filters/categories 
• Use Profile settings to override filter settings 
• Create trust relationships or exclude IPs from IPS 
• Simple DDOS protection via SYN proxy rate check 
Use Default Profile or define your own profiles 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 21 to change without notice.
Extended Firewall Rule Configuration in SMS 
Build a global view 
Manage policy across entire 
deployment 
Leverage your existing IPS policy 
• IPS Security Profiles 
• Reputation Filters 
• Shared Settings 
• Named Resources 
The same zone name may be built 
from different ports on different 
NGFW devices, but share same 
policy 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 22 to change without notice. 
Distribute policy changes when 
ready
Reliability: 
Keeping the Network Up 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Segments – TippingPoint Inline Protection 
Only a Layer 2 mode 
Protect against hardware or software failure 
− Layer 2 Fallback (L2FB) and ZPHA bypass 
− HA mode: Permit/Block, due to health or HA config 
− Link Down Synchronization mode helps network 
convergence when one side of the segment fails 
Notes 
− No asymmetric mode 
− A segment can only be a vertical port pair 
− Firewall always runs 
− No TippingPoint virtual ports/segments 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 24 to change without notice.
2-Node High Availability Clusters 
Protect against single failure, minimum downtime 
2-node active/passive cluster, with optional state sync 
• FW, Routing and IPS sessions sync 
SMS is required for configuration sync 
• Operates on a shared MAC 
Nodes are connected by back-to-back HA connection 
• Traffic optionally encrypted 
• Option to allow use of management port for HA traffic if all HA links fail (default:off) 
Nodes must be the same hardware and software version 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 25 to change without notice.
SMS Cluster Configuration 
1. Ensure devices at factory defaults, except 
for management access 
2. Acquire the devices separately into SMS 
3. Click “New Cluster” in Devices view 
4. Identify the cluster name, members, select 
settings for State Sync, HA link etc. 
Cluster will form… 
Use Shared Settings for networking, routing, VPN… 
• Immediate commit, and “copied to Start” 
Use Profiles to create shared FW rules and 
IPS settings, and distribute to the device 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 26 to change without notice.
Cluster Based SW Upgrade 
SMS “rolls out” NGFW Software 
upgrade across the cluster 
• One device kept active at all times 
to keep network up 
• Passive device is upgraded first and 
rebooted 
• Active device is forced passive and 
then upgraded 
• Session state synchronized at all times 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 27 to change without notice.
Examples… 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
Simplicity Example: 
7 Steps to Deploying a New Next Generation 
Firewall… 
Configuration Example 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
7 Steps to Setup a New HP NGFW 
What you will need: 
– Connected Console cable and client 
– Network connections made for LAN and WAN 
– Minimum information: 
• SuperUser account name you want to create 
• Management port IP address 
• Interface IP addresses for LAN and WAN 
For SMS: 
– An installed SMS, with network access to the 
NGFW 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 30 to change without notice.
Step 1: Complete Console Setup 
1. Connect console – 115200, 8N1 
2. Complete OBE prompts: 
• Define security requirements on SuperUser password 
• Define SuperUser account name and password 
3. Log in to CLI 
Please enter a user name for the super-user 
account. 
Spaces are not allowed. 
Name: SuperUser 
Do you wish to accept [SuperUser] <Y,[N]>: y 
Please enter a password for the super-user 
account [SuperUser]: 
Verify password: 
Saving information...Done 
Your super-user account has been created. 
You may continue initial configuration by logging 
into your device. 
After logging in, you will be asked for 
additional information 
ngfw 
login: SuperUser 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 31 to change without notice.
Step 2: Get the NGFW on the network 
1. Log in to CLI on console 
2. Start an CLI edit setting 
3. Define the management port: 
• Set host name (optional) 
• Set IP information 
• Set default route 
4. Define DNS server to perimeter router 
5. Define IP interfaces 
6. Make the changes live 
7. Ensure the changes will apply on next boot 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 32 to change without notice. 
edit 
interface mgmt 
host name demo_unit1 
ipaddress 10.0.0.101/24 
route 0.0.0.0/0 10.0.0.100 
exit 
dns 
name-server 11.0.0.101 
exit 
interface ethernet1 
ipaddress 10.0.0.100/24 
exit 
interface ethernet2 
ipaddress 11.0.0.100/24 
exit 
commit 
save-config 
exit
Step 3: Acquire the Device in SMS 
1. Log in to SMS 
2. Click Devices > New Device 
3. Enter the MGMT IP of the NGFW and the 
SuperUser account name/password from 
the console setup 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 33 to change without notice.
Step 4: Define Security Zones 
1. Click Profiles > Shared Settings 
> Security Zones 
2. Click New… to create a Zone 
3. Enter the name “LAN” 
4. Click Add… to add interfaces 
• Select ethernet1 
5. Repeat to create “WAN” zone 
6. Confirm zone setup 
Note: Can create same zone with 
different interfaces on another 
device 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 34 to change without notice.
Step 5: Create a New FW Profile 
1. Click Profiles > 
Firewall Profiles in menu 
2. Click “New” 
3. Give the profile a name 
4. Select Inspection Profiles 
Default = Default IPS Profile 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 35 to change without notice.
Step 6: Create Firewall Rules 
1. Expand the new Firewall profile 
2. Click “New” to create a rule 
3. Define the rule to permit LAN 
to WAN for any service 
• Action Set = “Permit+Notify” 
• Click + on Sources, select LAN 
• Click + on Destination, select WAN 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 36 to change without notice.
Step 7: Distribute the Firewall Profile 
1. Click the profile name 
and click “Distribute” 
2. Select which NGFWs will receive 
the Firewall Profile 
3. Wait for distribution 
Note: 
• An NGFW only runs one 
Firewall Profile at once 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 37 to change without notice.
Verify 
1. Using a client on the LAN, try to access 
the internet via a browser 
2. Confirm that the web site loads 
3. If it doesn’t work, check for firewall block 
events in SMS… 
or easier, “show fwBlock” on console: 
julian_hpar1{}show log fwBlock tail 
2013-08-06 18:50:51.665 demo_unit1 1 "Blocked by Firewall" Major [Block + Notify] [DEFAULT-BLOCK] ethernet1 ethernet2 
161.71.1.2 47546 64.31.0.235 80 TCP [] pt0 0 0 0 
2013-08-06 18:50:52.665 demo_unit1 1 "Blocked by Firewall" Major [Block + Notify] [DEFAULT-BLOCK] ethernet1 ethernet2 
161.71.1.2 0 212.58.244.66 0 ICMP [] pt0 0 0 0 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 38 to change without notice.
Security Effectiveness 
Example: 
SMS Configuration of Shared Firewall Rules 
Configuration Example 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
SMS Shared Firewall Rules 
Sequence: 
1. Define zones 
2. Create firewall, NAT or captive portal rule 
3. Distribute profile 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 40 to change without notice.
Firewall Profiles: Global Rules 
1. Define zones 
2. Create firewall, NAT or captive portal rule 
3. Distribute profile 
• Shared across deployment 
• Assign interfaces from 1 or more NGFW devices 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 41 to change without notice.
Firewall Profiles: Global Rules 
1. Define zones 
2. Create firewall, NAT or captive portal rule 
3. Distribute profile 
• Source/Destination rule criteria and zone definition determines the devices the rule may be 
installed on 
• Restrict location with ‘install-on’ device setting, provides site specific override capability 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 42 to change without notice.
Firewall Profiles: Global Rules 
1. Define zones 
2. Create firewall, NAT or captive portal rule 
3. Distribute profile 
• Source/Destination rule criteria and zone definition determines the devices the rule may be 
installed on 
• Restrict location with ‘install-on’ device setting, provides site specific override capability 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 43 to change without notice.
Firewall Profiles: Global Rules 
1. Define zones 
2. Create firewall, NAT or captive portal rule 
3. Distribute profile 
• SMS automatically creates snapshot, and displays potential distribution targets 
• Rules distributed (potentially deleted) based on your selection 
• SMS will pull in appropriate published IPS profiles 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 44 to change without notice.
In Closing 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
HP NGFW Helps Save Time & Protect the 
Network Problem How HP TippingPoint NGFW can help… 
I don’t know what applications are being 
Use Visibility and IPS reports to see apps, 
used 
network use and security risks 
I fear something will break if app is blocked Block is one action – perhaps rate limit it 
I need to protect network bandwidth and 
protect business critical apps 
Block or rate limit undesirable or bandwidth 
hogging apps. Use Trust rules to avoid impacting 
critical applications 
How can I control which users can use an 
app? 
User based policy rules 
I don’t have time to test/patch PCs and 
infrastructure 
IPS with Zero Day blocks vulnerabilities, even in 
default settings, putting you in control of patching 
How can I disrupt botnets and drive by 
downloads? 
RepDV stops access to bad web sites & botnet 
activity. 
IPS prevents malware installation through 
blocking the vulnerability 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 46 to change without notice.
Learn More 
Public launch on Sept 16 – www.hp.com/go/ngfw 
• ESP GA Date – 08/30 
• HPN GA Date – 9/30 
Resources – Published on Sales Portal and Partner Central: 
• Whitepaper, data sheet, Infographic, How-To-Sell 
• Training & Customer Deck 
• Up coming webinars: 
• Demo (TBD) 
• Channel Partner Sales training – August 13 
• Channel Partner Technical training – August 15 & 16 
• Tentative training - September 
• Future technical deep dives and live demos 
Questions: NGFW@hp.com 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 47 to change without notice.
Thank You 
© Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.

More Related Content

What's hot

uCPE and VNFs Explained
uCPE and VNFs ExplaineduCPE and VNFs Explained
uCPE and VNFs ExplainedAlan Percy
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Canada
 
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPE
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPEFuture-Proofing SD-WAN: Building on Open and Cost-Effective uCPE
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPEEnea Software AB
 
Building the SD-Branch using uCPE
Building the SD-Branch using uCPEBuilding the SD-Branch using uCPE
Building the SD-Branch using uCPEMichelle Holley
 
IBM System Networking Portfolio Update, June 2014
IBM System Networking Portfolio Update, June 2014IBM System Networking Portfolio Update, June 2014
IBM System Networking Portfolio Update, June 2014Angel Villar Garea
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)Jeff Green
 
CisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsecCisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsecAreaNetworking.it
 
iWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience SolutioniWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience Solutionxband
 
Design, Deployment and Management of Unified WLAN
Design, Deployment and Management of Unified WLANDesign, Deployment and Management of Unified WLAN
Design, Deployment and Management of Unified WLANCisco Canada
 
IWAN Lab Guide
IWAN Lab GuideIWAN Lab Guide
IWAN Lab Guidejww330015
 
SDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergiesSDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergiesHector.Avalos
 
Next Generation Campus Switching: Are You Ready
Next Generation Campus Switching: Are You ReadyNext Generation Campus Switching: Are You Ready
Next Generation Campus Switching: Are You ReadyCisco Canada
 
Assuring Superior VNF Performance at the Network Edge
Assuring Superior VNF Performance at the Network EdgeAssuring Superior VNF Performance at the Network Edge
Assuring Superior VNF Performance at the Network EdgeADVA
 
Aruba 3810 Switch Series Data Sheet
Aruba 3810 Switch Series Data SheetAruba 3810 Switch Series Data Sheet
Aruba 3810 Switch Series Data Sheet美兰 曾
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANsAPNIC
 
Network Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XRNetwork Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XRCisco Canada
 
Is Your Network Ready?
Is Your Network Ready?Is Your Network Ready?
Is Your Network Ready?Brocade
 
Development, test, and characterization of MEC platforms with Teranium and Dr...
Development, test, and characterization of MEC platforms with Teranium and Dr...Development, test, and characterization of MEC platforms with Teranium and Dr...
Development, test, and characterization of MEC platforms with Teranium and Dr...Michelle Holley
 
Meraki Cloud Networking Workshop
Meraki Cloud Networking WorkshopMeraki Cloud Networking Workshop
Meraki Cloud Networking WorkshopCisco Canada
 

What's hot (20)

uCPE and VNFs Explained
uCPE and VNFs ExplaineduCPE and VNFs Explained
uCPE and VNFs Explained
 
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi ExperienceCisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
Cisco Connect Montreal 2017 - Optimizing Your Client's Wi-Fi Experience
 
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPE
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPEFuture-Proofing SD-WAN: Building on Open and Cost-Effective uCPE
Future-Proofing SD-WAN: Building on Open and Cost-Effective uCPE
 
Building the SD-Branch using uCPE
Building the SD-Branch using uCPEBuilding the SD-Branch using uCPE
Building the SD-Branch using uCPE
 
IBM System Networking Portfolio Update, June 2014
IBM System Networking Portfolio Update, June 2014IBM System Networking Portfolio Update, June 2014
IBM System Networking Portfolio Update, June 2014
 
14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)14.) wireless (hyper dense wi fi)
14.) wireless (hyper dense wi fi)
 
CisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsecCisCon 2018 - Overlay Management Protocol e IPsec
CisCon 2018 - Overlay Management Protocol e IPsec
 
iWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience SolutioniWAN - Cisco Application Experience Solution
iWAN - Cisco Application Experience Solution
 
Design, Deployment and Management of Unified WLAN
Design, Deployment and Management of Unified WLANDesign, Deployment and Management of Unified WLAN
Design, Deployment and Management of Unified WLAN
 
IWAN Lab Guide
IWAN Lab GuideIWAN Lab Guide
IWAN Lab Guide
 
SDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergiesSDN Network virtualization, NFV & MPLS synergies
SDN Network virtualization, NFV & MPLS synergies
 
Next Generation Campus Switching: Are You Ready
Next Generation Campus Switching: Are You ReadyNext Generation Campus Switching: Are You Ready
Next Generation Campus Switching: Are You Ready
 
Assuring Superior VNF Performance at the Network Edge
Assuring Superior VNF Performance at the Network EdgeAssuring Superior VNF Performance at the Network Edge
Assuring Superior VNF Performance at the Network Edge
 
Aruba 3810 Switch Series Data Sheet
Aruba 3810 Switch Series Data SheetAruba 3810 Switch Series Data Sheet
Aruba 3810 Switch Series Data Sheet
 
Introduction to Software Defined WANs
Introduction to Software Defined WANsIntroduction to Software Defined WANs
Introduction to Software Defined WANs
 
Network Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XRNetwork Function Virtualization (NFV) using IOS-XR
Network Function Virtualization (NFV) using IOS-XR
 
Shanghai Breakout: Aruba Mobility Access Switch Workshop
Shanghai Breakout: Aruba Mobility Access Switch Workshop Shanghai Breakout: Aruba Mobility Access Switch Workshop
Shanghai Breakout: Aruba Mobility Access Switch Workshop
 
Is Your Network Ready?
Is Your Network Ready?Is Your Network Ready?
Is Your Network Ready?
 
Development, test, and characterization of MEC platforms with Teranium and Dr...
Development, test, and characterization of MEC platforms with Teranium and Dr...Development, test, and characterization of MEC platforms with Teranium and Dr...
Development, test, and characterization of MEC platforms with Teranium and Dr...
 
Meraki Cloud Networking Workshop
Meraki Cloud Networking WorkshopMeraki Cloud Networking Workshop
Meraki Cloud Networking Workshop
 

Similar to Обеспечение сетевой безопасности с помощью многоцелевого адаптируемого межсетевого экрана нового поколения NGFW

Hp helion meetup_networking_sdn
Hp helion meetup_networking_sdnHp helion meetup_networking_sdn
Hp helion meetup_networking_sdnMarton Kiss
 
IPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesIPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesAPNIC
 
Comparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACComparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACThomas Burg
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Cisco Russia
 
Hp - 3martie2011
Hp - 3martie2011Hp - 3martie2011
Hp - 3martie2011Agora Group
 
Forcepoint SD-WAN and NGFW + IPS
Forcepoint SD-WAN and NGFW + IPSForcepoint SD-WAN and NGFW + IPS
Forcepoint SD-WAN and NGFW + IPSLarry Austin
 
Aruba 2930 f switch campus switching
Aruba 2930 f switch   campus switching Aruba 2930 f switch   campus switching
Aruba 2930 f switch campus switching Eketerina Dyakova
 
Introducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment RoutingIntroducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment RoutingCisco Service Provider
 
Mobile enterprise sept 24 v1
Mobile enterprise sept 24 v1Mobile enterprise sept 24 v1
Mobile enterprise sept 24 v1Wilfried Grommen
 
Palo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.pptPalo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.pptPatrickAng14
 
EuroSys zorgevent HP juni 2015
EuroSys zorgevent HP juni 2015EuroSys zorgevent HP juni 2015
EuroSys zorgevent HP juni 2015Marketing Team
 
A new way to connect and protect retail networks with secure enterprise SD-WA...
A new way to connect and protect retail networks with secure enterprise SD-WA...A new way to connect and protect retail networks with secure enterprise SD-WA...
A new way to connect and protect retail networks with secure enterprise SD-WA...National Retail Federation
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 Robb Boyd
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayCisco Canada
 

Similar to Обеспечение сетевой безопасности с помощью многоцелевого адаптируемого межсетевого экрана нового поколения NGFW (20)

Hp helion meetup_networking_sdn
Hp helion meetup_networking_sdnHp helion meetup_networking_sdn
Hp helion meetup_networking_sdn
 
IPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesIPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for Mobiles
 
Migrating to the 7200 controller george anderson marcus christensen
Migrating to the 7200 controller george anderson marcus christensenMigrating to the 7200 controller george anderson marcus christensen
Migrating to the 7200 controller george anderson marcus christensen
 
Comparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RACComparing the TCO of HP NonStop with Oracle RAC
Comparing the TCO of HP NonStop with Oracle RAC
 
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
Решения конвергентного доступа Cisco. Обновление продуктовой линейки коммутат...
 
Hp - 3martie2011
Hp - 3martie2011Hp - 3martie2011
Hp - 3martie2011
 
Forcepoint SD-WAN and NGFW + IPS
Forcepoint SD-WAN and NGFW + IPSForcepoint SD-WAN and NGFW + IPS
Forcepoint SD-WAN and NGFW + IPS
 
Aruba 2930 f switch campus switching
Aruba 2930 f switch   campus switching Aruba 2930 f switch   campus switching
Aruba 2930 f switch campus switching
 
Apresentação HPN
Apresentação HPNApresentação HPN
Apresentação HPN
 
SDN use cases_2014
SDN use cases_2014SDN use cases_2014
SDN use cases_2014
 
SANGFOR NGAF FIREWALL SG TECHNICAL PVT LTD 03002019693
SANGFOR NGAF FIREWALL  SG TECHNICAL PVT LTD 03002019693 SANGFOR NGAF FIREWALL  SG TECHNICAL PVT LTD 03002019693
SANGFOR NGAF FIREWALL SG TECHNICAL PVT LTD 03002019693
 
Introducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment RoutingIntroducing Application Engineered Routing Powered by Segment Routing
Introducing Application Engineered Routing Powered by Segment Routing
 
Mobile enterprise sept 24 v1
Mobile enterprise sept 24 v1Mobile enterprise sept 24 v1
Mobile enterprise sept 24 v1
 
Automation of end-to-end QOS
Automation of end-to-end QOSAutomation of end-to-end QOS
Automation of end-to-end QOS
 
Palo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.pptPalo_Alto_Networks_Cust_June_2009.ppt
Palo_Alto_Networks_Cust_June_2009.ppt
 
HP Moonshot system
HP Moonshot systemHP Moonshot system
HP Moonshot system
 
EuroSys zorgevent HP juni 2015
EuroSys zorgevent HP juni 2015EuroSys zorgevent HP juni 2015
EuroSys zorgevent HP juni 2015
 
A new way to connect and protect retail networks with secure enterprise SD-WA...
A new way to connect and protect retail networks with secure enterprise SD-WA...A new way to connect and protect retail networks with secure enterprise SD-WA...
A new way to connect and protect retail networks with secure enterprise SD-WA...
 
TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000 TechWiseTV Workshop: ASR 9000
TechWiseTV Workshop: ASR 9000
 
DNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus DayDNA Intelligent WAN Campus Day
DNA Intelligent WAN Campus Day
 

More from TechExpert

SMExpert - система автоматизації ITSM-процесів у хмарі
SMExpert - система автоматизації ITSM-процесів у хмаріSMExpert - система автоматизації ITSM-процесів у хмарі
SMExpert - система автоматизації ITSM-процесів у хмаріTechExpert
 
Автоматизация документооборота на базе Microsoft SharePoint
Автоматизация документооборота на базе Microsoft SharePointАвтоматизация документооборота на базе Microsoft SharePoint
Автоматизация документооборота на базе Microsoft SharePointTechExpert
 
HR Expert: корпоративний портал
HR Expert: корпоративний порталHR Expert: корпоративний портал
HR Expert: корпоративний порталTechExpert
 
Рішення для автоматизації діяльності підрозділу інформаційної безпеки
Рішення для автоматизації діяльності підрозділу інформаційної безпекиРішення для автоматизації діяльності підрозділу інформаційної безпеки
Рішення для автоматизації діяльності підрозділу інформаційної безпекиTechExpert
 
TechExpert: Облачные решения и услуги для сферы розничной торговли
TechExpert: Облачные решения и услуги для сферы розничной торговлиTechExpert: Облачные решения и услуги для сферы розничной торговли
TechExpert: Облачные решения и услуги для сферы розничной торговлиTechExpert
 
Бизнес Облако TechExpert
Бизнес Облако TechExpertБизнес Облако TechExpert
Бизнес Облако TechExpertTechExpert
 
Решения по резервному копированию
Решения по резервному копированиюРешения по резервному копированию
Решения по резервному копированиюTechExpert
 
Корпоративный портал на базе Microsoft SharePoint
Корпоративный портал на базе Microsoft SharePointКорпоративный портал на базе Microsoft SharePoint
Корпоративный портал на базе Microsoft SharePointTechExpert
 
Внедрение системы автоматизации учебного процесса и управления школой
Внедрение системы автоматизации учебного процесса и управления школойВнедрение системы автоматизации учебного процесса и управления школой
Внедрение системы автоматизации учебного процесса и управления школойTechExpert
 
SMExpert - система автоматизации ITSM-процессов в облаке
SMExpert - система автоматизации ITSM-процессов в облакеSMExpert - система автоматизации ITSM-процессов в облаке
SMExpert - система автоматизации ITSM-процессов в облакеTechExpert
 
Services and Projects for Business
Services and Projects for BusinessServices and Projects for Business
Services and Projects for BusinessTechExpert
 
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...TechExpert
 
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...TechExpert
 
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)TechExpert
 
TechExpert: Service and Project for Business
TechExpert: Service and Project for BusinessTechExpert: Service and Project for Business
TechExpert: Service and Project for BusinessTechExpert
 
Презентация партнёрской программы Бизнес-облака TechExpert
Презентация партнёрской программы Бизнес-облака TechExpertПрезентация партнёрской программы Бизнес-облака TechExpert
Презентация партнёрской программы Бизнес-облака TechExpertTechExpert
 
ИТ-конструктор или решение под ключ: как объединить эти подходы?
ИТ-конструктор или решение под ключ: как объединить эти подходы?ИТ-конструктор или решение под ключ: как объединить эти подходы?
ИТ-конструктор или решение под ключ: как объединить эти подходы?TechExpert
 
Гибридные Центры Обработки Данных
Гибридные Центры Обработки ДанныхГибридные Центры Обработки Данных
Гибридные Центры Обработки ДанныхTechExpert
 
5. Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning
5.	Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning5.	Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning
5. Готовые инструменты Azure: бизнес-прогнозирования в Machine LearningTechExpert
 

More from TechExpert (20)

SMExpert - система автоматизації ITSM-процесів у хмарі
SMExpert - система автоматизації ITSM-процесів у хмаріSMExpert - система автоматизації ITSM-процесів у хмарі
SMExpert - система автоматизації ITSM-процесів у хмарі
 
Автоматизация документооборота на базе Microsoft SharePoint
Автоматизация документооборота на базе Microsoft SharePointАвтоматизация документооборота на базе Microsoft SharePoint
Автоматизация документооборота на базе Microsoft SharePoint
 
HR Expert: корпоративний портал
HR Expert: корпоративний порталHR Expert: корпоративний портал
HR Expert: корпоративний портал
 
Рішення для автоматизації діяльності підрозділу інформаційної безпеки
Рішення для автоматизації діяльності підрозділу інформаційної безпекиРішення для автоматизації діяльності підрозділу інформаційної безпеки
Рішення для автоматизації діяльності підрозділу інформаційної безпеки
 
TechExpert: Облачные решения и услуги для сферы розничной торговли
TechExpert: Облачные решения и услуги для сферы розничной торговлиTechExpert: Облачные решения и услуги для сферы розничной торговли
TechExpert: Облачные решения и услуги для сферы розничной торговли
 
Бизнес Облако TechExpert
Бизнес Облако TechExpertБизнес Облако TechExpert
Бизнес Облако TechExpert
 
Решения по резервному копированию
Решения по резервному копированиюРешения по резервному копированию
Решения по резервному копированию
 
Корпоративный портал на базе Microsoft SharePoint
Корпоративный портал на базе Microsoft SharePointКорпоративный портал на базе Microsoft SharePoint
Корпоративный портал на базе Microsoft SharePoint
 
Внедрение системы автоматизации учебного процесса и управления школой
Внедрение системы автоматизации учебного процесса и управления школойВнедрение системы автоматизации учебного процесса и управления школой
Внедрение системы автоматизации учебного процесса и управления школой
 
SMExpert - система автоматизации ITSM-процессов в облаке
SMExpert - система автоматизации ITSM-процессов в облакеSMExpert - система автоматизации ITSM-процессов в облаке
SMExpert - система автоматизации ITSM-процессов в облаке
 
Services and Projects for Business
Services and Projects for BusinessServices and Projects for Business
Services and Projects for Business
 
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...
Управление конфигурациями и устройствами в GLPi, интеграция в корпоративную с...
 
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...
Автоматизация процессов сервисного обслуживания с GLPi или Service Desk для «...
 
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)
Управление инцидентами с использованием GLPi (вебинар от 23.06.2016)
 
TechExpert: Service and Project for Business
TechExpert: Service and Project for BusinessTechExpert: Service and Project for Business
TechExpert: Service and Project for Business
 
Презентация партнёрской программы Бизнес-облака TechExpert
Презентация партнёрской программы Бизнес-облака TechExpertПрезентация партнёрской программы Бизнес-облака TechExpert
Презентация партнёрской программы Бизнес-облака TechExpert
 
ИТ-конструктор или решение под ключ: как объединить эти подходы?
ИТ-конструктор или решение под ключ: как объединить эти подходы?ИТ-конструктор или решение под ключ: как объединить эти подходы?
ИТ-конструктор или решение под ключ: как объединить эти подходы?
 
Гибридные Центры Обработки Данных
Гибридные Центры Обработки ДанныхГибридные Центры Обработки Данных
Гибридные Центры Обработки Данных
 
IT education
IT educationIT education
IT education
 
5. Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning
5.	Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning5.	Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning
5. Готовые инструменты Azure: бизнес-прогнозирования в Machine Learning
 

Recently uploaded

Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticscarlostorres15106
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?XfilesPro
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 

Recently uploaded (20)

Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmaticsKotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
Kotlin Multiplatform & Compose Multiplatform - Starter kit for pragmatics
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 

Обеспечение сетевой безопасности с помощью многоцелевого адаптируемого межсетевого экрана нового поколения NGFW

  • 1. HP TippingPoint Next Generation Firewall HP Enterprise Security Internal Technical Pre-Sales Training Julian Palmer, NGFW Product Manager, HP TippingPoint Russ Meyers, SMS Product Manager, HP TippingPoint © Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 2. Agenda Introducing HP TippingPoint Next Generation Firewall (NGFW) Key attributes, and how HP TippingPoint NGFW achieves them Seven steps to get an NGFW on the network Shared firewall rules with SMS How does NGFW help common problems? © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 2 to change without notice.
  • 3. Introducing the HP TippingPoint Next Generation Firewall © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 4. What is HP NGFW… Simple Easy-to-Use, configure and install with centralized management Next Gen IPS Enterprise © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 4 to change without notice. Reliable Protect the network availability features, IPS, and automatic protection Effective Industry leading security intelligence with weekly DVLabs updates Integrated Policy Firewall DVLabs research and feeds User and app policy
  • 5. HP NGFW Feature Summary Security • Enterprise class zonal, stateful firewall • Mix and match FW, app, user and IPS policy choices • Full IPS, DV, RepDV, WebAppDV, Zero Day Initiative • Apply IPS inspection profile based on app • Rate limit, quarantine, trap, pcap, email actions © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 5 to change without notice. Certification Plans • ICSA Firewall/VPN Enterprise, USGv6 coming • FIPS-140-2, EAL, NSS on roadmap Management • HTTPS local web GUI, SSH, Full CLI, inband/outband • Role based management, Encrypted Log Storage • SNMPv2/v3 MIB-2, and TP Enterprise MIBs • Integrated FW & IPS management with SMS • ArcSight, HP NNMi and NA integration Deployment • NAT, routed, transparent, segment, one-armed • IPv6 ready everywhere • Static, RIP/RIPng, OSPFv2/v3, BGPv4, multicast • Link aggregation, VLAN translation, Rate limiting • IPSec site-to-site & Client-to-site, GRE/IPSec • Active-Passive 2-node Stateful High Availability • LDAP, Active Directory, RADIUS authentication
  • 6. HP NGFW Portfolio S1050F S3010F S3020F S8005F S8010F FW only 500Mbps 1Gbps 2Gbps 5Gbps 10Gbps FW + IPS @512 bytes 250Mbps 500Mbps 1Gbps 2.5Gbps 5Gbps New Connections/second 10,000 20,000 20,000 50,000 50,000 Concurrent Connections 250,000 500,000 1M 10M 20M Aggregate VPN Throughput (big 250 Mbps 500Mbps 1Gbps 1.5Gbps 3Gbps pkts) VPN Tunnels 2500 5000 7500 7500 7500 Redundant Power Supply/Fans No Yes Yes Yes Yes Removable Solid State Storage 8GB 8GB 8GB 32GB 32GB Integrated I/O 8xGbE 8xGbE 8xSFP 8xGbE 8xSFP © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 6 to change without notice. 8xGbE 8xSFP 4x SFP+ 8xGbE 8xSFP 4x SFP+ Ordering information: ESP HPN JC850A JC882A US$4,995 JC851A JC883A US$13,995 JC852A JC884A US$18,995 JC853A JC885A US$49,995 JC854A JC886A US$70,995 HPN care pack info will follow… 1 Year of DV must be bought w/HW Premium (DV+24x7) Premium (DV+RepDV+24x7)
  • 7. Where to Deploy • At all network edges • Security consolidation • Where security needs may change Virtual machines (VMs) © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 7 to change without notice. Campus LAN Edge WLAN Core Tele-workers, partners, and customers Internet Remote offices and branches WAN Data center NGFW NGFW NGFW NGFW IPS IPS NGFW NGFW Branch Regional Hub Data Center S1050F S3010F S3020F S8005F S8010F
  • 8. S1050F Platform External User Disk Console 115200, 8N1 GbE Data Ports HA MGMTAlert LED © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 8 to change without notice. Status LED Power LED On/Off
  • 9. S3010F , S3020F, S8005F, S8010F Platforms SFP GbE Data Ports User Disk H MGMT Alert LED Ports A 10G SFP+ (S8000F) © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 9 to change without notice. Console 115200, 8N1 Status LED Redundant hot swap fans Dual Redundant PSUs • Redundan t Fan/PSU • Hot swap fans and PSU
  • 10. LED Meanings Alert LED Off No power Solid Yellow System booting. After boot this indicates a software failure. Flashing Yellow A Hardware problem has been detected Solid Green Hardware and software are running normally System LED Off No power Flashing Green © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 10 to change without notice. System is booting and traffic is not being processed Solid Green System is running and healthy Solid Yellow System is running but has degraded health (software or hardware issue) Flashing Green/Yellow A software or BIOS upgrade is being performed
  • 11. HP ESP Field Replacement Parts ESP SKU HPN SKU ESP Description* Ref Price C1J35 A JC901 A HP TippingPoint 750W AC Power Supply US$649 C1J36 A JC903 A HP TippingPoint 32GB CFast Card US$599 C1J34 A JC900 A HP TippingPoint 80mm Fan Module US $190 DC power option not available AC power supply is the same as the NX IPS Comments Supports NGFW and NX; Replaces JC826A Supports NGFW and NX; Replaces JC828A © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 11 to change without notice. * HPN Description is different
  • 12. Simplicity © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 13. Easy and Powerful Management Best of Breed central management with SMS • Unified management of IPS and NGFW devices • Keep security current with DV active update • Advanced reporting & visualization • SMS 4.0 adds support for NGFW Powerful when you need it • Role Based Access Control • Forensic reporting • ArcSight Logger for universal log management • 3rd Party integrations Easy to Use On-Box web interface • Minimum IE8, Chrome 17, Firefox 10, Safari 5.1 • Optimized for 1440x900 © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 13 to change without notice.
  • 14. Reporting and Visibility Primary reporting tool is SMS • Delivers Application Visibility & Utilization, Troubleshooting, Security Analysis and Capacity Planning • Consolidated reporting from all NGFW/IPS boxes • High performance, detailed event forensics using integrated HP Vertica columnar database • Customizable Dashboard for real-time data on traffic, apps and network behaviour On-box shows summary app, traffic mix • Identify app/traffic patterns • App visibility is on by default Big Data forensics with ArcSight © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 14 to change without notice.
  • 15. Easy to Deploy in the Network Transparent • Drop in Deployment • Same L2 network on both sides • Forwarded traffic based on destination MAC • Firewall always there… © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 15 to change without notice. Routed • Different L3 network on each side • Traffic is directed via routing table • No asymmetric routing • No L2FB Segment • In/out port • Bump-in-the-wire (no IP address) • Reliability through L2FB and HA modes Bridge • Multiple ports • Bcast domain • IP address • No L2FB Routed • One or more IP addresses One Armed • Single port in/out • VLAN tagged
  • 16. Easy to Demo Use NGFW to easily demo security & apps: 1. Attach “in” port of segment to a mirror port Leave “out” port unconnected 2. Configure a segment using these ports 3. Set the NGFW IPS policy to “IDS Mode” 4. Create a Firewall Rule to “Permit Any Any” 5. Override IPS Categories to Permit+Notify 6. Leave… • Return later and look at the reports • IPS events, App reports, Traffic Reports • Add an SMS for even better reporting © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 16 to change without notice.
  • 17. Effective Security Mitigate Today and Tomorrow’s Threats Using Firewall, IPS and Application Control © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 18. Security Elements Integrated Policy Controlling Who Does What to Whom, When… Objects • Zones, action sets, notification contacts, services, address groups, schedules Firewall • Stateful Firewall, with NAT/PAT • Application Groups, selected by category • Mix and Match Stateful and App elements • User ID by captive portal • User authentication by AD, LDAP, RADIUS © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 18 to change without notice. Next Gen IPS • 12 categories with recommended settings • Zero Day, and Best of Breed DV security filters from DVLabs • Reputation to block undesirable IPs • Automatic DV & RepDV update • Shared profiles with IPS devices
  • 19. Understanding FW Rules Powerful and succinct rules • Source/Destination based on Zone or IP subnets/ranges • Optionally use applications, Users, services and schedules • Block, Rate limit, Trust, trap, email, pcap • Set inspection profile per-rule • Position most specific rules at top Collapse multiple rules into one • Using multiple selectors (like an “or”), where the policy/action is the same • Negation and Exclude constructs Edit Default Block Rule to enable logging No implied rules © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 19 to change without notice.
  • 20. Controlling Applications • All web apps look the same to old FW’s • True NGFW firewall rules only contain apps/categories, not services IPS w/ Unknown Profile FW Rule Specific Profile Match Stateful FW Rule App Detected – • NGFW will detect apps regardless of TCP port • NGFW keeps looking for a better matching FW rule, until app is definitive or not matched • IPS can be applied during “app detect phase” • NGFW can block encrypted applications, but cannot inspect within them © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 20 to change without notice. Change Matching FW Rule
  • 21. IPS Profiles Drive Deep Packet Inspection Policy IPS uses security filters from DVLabs • 7,400 filters, 2,650 security researchers • No false positives or negatives IPS Profiles define a combination of IPS settings • Set Profile Deployment Mode to modify “Recommended” • DV defines “Recommended” for all filters/categories • Use Profile settings to override filter settings • Create trust relationships or exclude IPs from IPS • Simple DDOS protection via SYN proxy rate check Use Default Profile or define your own profiles © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 21 to change without notice.
  • 22. Extended Firewall Rule Configuration in SMS Build a global view Manage policy across entire deployment Leverage your existing IPS policy • IPS Security Profiles • Reputation Filters • Shared Settings • Named Resources The same zone name may be built from different ports on different NGFW devices, but share same policy © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 22 to change without notice. Distribute policy changes when ready
  • 23. Reliability: Keeping the Network Up © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 24. Segments – TippingPoint Inline Protection Only a Layer 2 mode Protect against hardware or software failure − Layer 2 Fallback (L2FB) and ZPHA bypass − HA mode: Permit/Block, due to health or HA config − Link Down Synchronization mode helps network convergence when one side of the segment fails Notes − No asymmetric mode − A segment can only be a vertical port pair − Firewall always runs − No TippingPoint virtual ports/segments © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 24 to change without notice.
  • 25. 2-Node High Availability Clusters Protect against single failure, minimum downtime 2-node active/passive cluster, with optional state sync • FW, Routing and IPS sessions sync SMS is required for configuration sync • Operates on a shared MAC Nodes are connected by back-to-back HA connection • Traffic optionally encrypted • Option to allow use of management port for HA traffic if all HA links fail (default:off) Nodes must be the same hardware and software version © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 25 to change without notice.
  • 26. SMS Cluster Configuration 1. Ensure devices at factory defaults, except for management access 2. Acquire the devices separately into SMS 3. Click “New Cluster” in Devices view 4. Identify the cluster name, members, select settings for State Sync, HA link etc. Cluster will form… Use Shared Settings for networking, routing, VPN… • Immediate commit, and “copied to Start” Use Profiles to create shared FW rules and IPS settings, and distribute to the device © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 26 to change without notice.
  • 27. Cluster Based SW Upgrade SMS “rolls out” NGFW Software upgrade across the cluster • One device kept active at all times to keep network up • Passive device is upgraded first and rebooted • Active device is forced passive and then upgraded • Session state synchronized at all times © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 27 to change without notice.
  • 28. Examples… © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 29. Simplicity Example: 7 Steps to Deploying a New Next Generation Firewall… Configuration Example © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 30. 7 Steps to Setup a New HP NGFW What you will need: – Connected Console cable and client – Network connections made for LAN and WAN – Minimum information: • SuperUser account name you want to create • Management port IP address • Interface IP addresses for LAN and WAN For SMS: – An installed SMS, with network access to the NGFW © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 30 to change without notice.
  • 31. Step 1: Complete Console Setup 1. Connect console – 115200, 8N1 2. Complete OBE prompts: • Define security requirements on SuperUser password • Define SuperUser account name and password 3. Log in to CLI Please enter a user name for the super-user account. Spaces are not allowed. Name: SuperUser Do you wish to accept [SuperUser] <Y,[N]>: y Please enter a password for the super-user account [SuperUser]: Verify password: Saving information...Done Your super-user account has been created. You may continue initial configuration by logging into your device. After logging in, you will be asked for additional information ngfw login: SuperUser © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 31 to change without notice.
  • 32. Step 2: Get the NGFW on the network 1. Log in to CLI on console 2. Start an CLI edit setting 3. Define the management port: • Set host name (optional) • Set IP information • Set default route 4. Define DNS server to perimeter router 5. Define IP interfaces 6. Make the changes live 7. Ensure the changes will apply on next boot © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 32 to change without notice. edit interface mgmt host name demo_unit1 ipaddress 10.0.0.101/24 route 0.0.0.0/0 10.0.0.100 exit dns name-server 11.0.0.101 exit interface ethernet1 ipaddress 10.0.0.100/24 exit interface ethernet2 ipaddress 11.0.0.100/24 exit commit save-config exit
  • 33. Step 3: Acquire the Device in SMS 1. Log in to SMS 2. Click Devices > New Device 3. Enter the MGMT IP of the NGFW and the SuperUser account name/password from the console setup © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 33 to change without notice.
  • 34. Step 4: Define Security Zones 1. Click Profiles > Shared Settings > Security Zones 2. Click New… to create a Zone 3. Enter the name “LAN” 4. Click Add… to add interfaces • Select ethernet1 5. Repeat to create “WAN” zone 6. Confirm zone setup Note: Can create same zone with different interfaces on another device © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 34 to change without notice.
  • 35. Step 5: Create a New FW Profile 1. Click Profiles > Firewall Profiles in menu 2. Click “New” 3. Give the profile a name 4. Select Inspection Profiles Default = Default IPS Profile © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 35 to change without notice.
  • 36. Step 6: Create Firewall Rules 1. Expand the new Firewall profile 2. Click “New” to create a rule 3. Define the rule to permit LAN to WAN for any service • Action Set = “Permit+Notify” • Click + on Sources, select LAN • Click + on Destination, select WAN © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 36 to change without notice.
  • 37. Step 7: Distribute the Firewall Profile 1. Click the profile name and click “Distribute” 2. Select which NGFWs will receive the Firewall Profile 3. Wait for distribution Note: • An NGFW only runs one Firewall Profile at once © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 37 to change without notice.
  • 38. Verify 1. Using a client on the LAN, try to access the internet via a browser 2. Confirm that the web site loads 3. If it doesn’t work, check for firewall block events in SMS… or easier, “show fwBlock” on console: julian_hpar1{}show log fwBlock tail 2013-08-06 18:50:51.665 demo_unit1 1 "Blocked by Firewall" Major [Block + Notify] [DEFAULT-BLOCK] ethernet1 ethernet2 161.71.1.2 47546 64.31.0.235 80 TCP [] pt0 0 0 0 2013-08-06 18:50:52.665 demo_unit1 1 "Blocked by Firewall" Major [Block + Notify] [DEFAULT-BLOCK] ethernet1 ethernet2 161.71.1.2 0 212.58.244.66 0 ICMP [] pt0 0 0 0 © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 38 to change without notice.
  • 39. Security Effectiveness Example: SMS Configuration of Shared Firewall Rules Configuration Example © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 40. SMS Shared Firewall Rules Sequence: 1. Define zones 2. Create firewall, NAT or captive portal rule 3. Distribute profile © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 40 to change without notice.
  • 41. Firewall Profiles: Global Rules 1. Define zones 2. Create firewall, NAT or captive portal rule 3. Distribute profile • Shared across deployment • Assign interfaces from 1 or more NGFW devices © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 41 to change without notice.
  • 42. Firewall Profiles: Global Rules 1. Define zones 2. Create firewall, NAT or captive portal rule 3. Distribute profile • Source/Destination rule criteria and zone definition determines the devices the rule may be installed on • Restrict location with ‘install-on’ device setting, provides site specific override capability © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 42 to change without notice.
  • 43. Firewall Profiles: Global Rules 1. Define zones 2. Create firewall, NAT or captive portal rule 3. Distribute profile • Source/Destination rule criteria and zone definition determines the devices the rule may be installed on • Restrict location with ‘install-on’ device setting, provides site specific override capability © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 43 to change without notice.
  • 44. Firewall Profiles: Global Rules 1. Define zones 2. Create firewall, NAT or captive portal rule 3. Distribute profile • SMS automatically creates snapshot, and displays potential distribution targets • Rules distributed (potentially deleted) based on your selection • SMS will pull in appropriate published IPS profiles © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 44 to change without notice.
  • 45. In Closing © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.
  • 46. HP NGFW Helps Save Time & Protect the Network Problem How HP TippingPoint NGFW can help… I don’t know what applications are being Use Visibility and IPS reports to see apps, used network use and security risks I fear something will break if app is blocked Block is one action – perhaps rate limit it I need to protect network bandwidth and protect business critical apps Block or rate limit undesirable or bandwidth hogging apps. Use Trust rules to avoid impacting critical applications How can I control which users can use an app? User based policy rules I don’t have time to test/patch PCs and infrastructure IPS with Zero Day blocks vulnerabilities, even in default settings, putting you in control of patching How can I disrupt botnets and drive by downloads? RepDV stops access to bad web sites & botnet activity. IPS prevents malware installation through blocking the vulnerability © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 46 to change without notice.
  • 47. Learn More Public launch on Sept 16 – www.hp.com/go/ngfw • ESP GA Date – 08/30 • HPN GA Date – 9/30 Resources – Published on Sales Portal and Partner Central: • Whitepaper, data sheet, Infographic, How-To-Sell • Training & Customer Deck • Up coming webinars: • Demo (TBD) • Channel Partner Sales training – August 13 • Channel Partner Technical training – August 15 & 16 • Tentative training - September • Future technical deep dives and live demos Questions: NGFW@hp.com © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject 47 to change without notice.
  • 48. Thank You © Copyright 2013 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.

Editor's Notes

  1. Industry leading security intelligence with weekly DVLabs updates Easy to use, configure and install with centralized management NGFW built on 99.99999% network uptime track record
  2. Easy and Powerful Management Effective Reporting and Traffic Visualization Easy Deployment Easy to Demonstrate
  3. Talk about the ability to drill down and create any of these network objects directly from the rule editor panels Talk about the shared services integrated with non-standard IPS ports User based policy – SMS will use a number of means at it’s disposal to assist with user /group selection; AD query, view existing logs, view previous requests Shares from existing named resources on the SMS
  4. Zones are ‘shared’ objects that are included in SMS distribution Can actually write rules without managing a single device and manage your zone-interface / deployment definition later
  5. Comments on the rule: the “St -> State” field: this shows if the rule is enabled / disabled; or also if a change has been made requiring a distribution for the rule to be added, changed or removed to a device
  6. - SMS distribution will warn you if the device has changes that are not what the SMS is expecting: i.e. you made a change on the local device
  7. Expect to get questions around deal registration, I8 standard process (VBD, NBO, express pricing) (invite liz carter) and promotional conflict.