【正文】
Wxwdv SUNWxwdvx SUNWxwmod SUNWxwmox。CheckPoint Firewall/VPN1軟件自身為一個(gè)安全的防火墻系統(tǒng),只需安裝相應(yīng)的hotfix即可修補(bǔ)防火墻的安全漏洞。2出現(xiàn)策略加載對(duì)象選擇窗口,將需要加載該策略的防火墻后面的Security框勾選上(Enable),點(diǎn)擊OK開(kāi)始加載策略。根據(jù)業(yè)務(wù)需求詳細(xì)制定各條策略。1定義各策略時(shí)可直接將對(duì)象從左邊窗口中拖入策略行中。1根據(jù)需要定義網(wǎng)段的NAT。 1如果該主機(jī)需要做NAT,則點(diǎn)擊左邊的NAT,Checkpoint NG支持兩種形式的NAT,一種為Hide模式,即Manytoone,按端口進(jìn)行映射,將內(nèi)部IP映射到防火墻的外部網(wǎng)口上,多用于內(nèi)部上網(wǎng),不需要外部訪問(wèn)的環(huán)境。 在防火墻對(duì)象的Tepology中雙擊外部網(wǎng)卡,在Topology標(biāo)簽項(xiàng)中定義外部網(wǎng)卡,選擇External (leads out to the),在下面的AntiSpoofing中,建議用戶(hù)勾掉(Disable)Perform AntiSpoofing based on interface選項(xiàng),即不對(duì)外部網(wǎng)卡做AntiSpoofing。 雙擊每塊網(wǎng)卡,并點(diǎn)出彈出窗口中的Topology標(biāo)簽項(xiàng),定義網(wǎng)卡的AntiSpoofing,對(duì)于防火墻連接內(nèi)部的網(wǎng)卡,選擇Internal (Leads to the local),IP Addresses behind this中選擇 Network defined by the interface IP and Net Mask。FloodGate1是用于帶寬管理的軟件,在此處不需要。點(diǎn)擊Approve按鈕后,將出現(xiàn)下列界面,這即是Checkpoint NG的Policy Editor的主界面。Managerment中填入Managerment的IP地址,即為防火墻的IP地址。點(diǎn)擊Next繼續(xù)。l Reporting Tool用來(lái)分析防火墻生成的Log,生成各種類(lèi)型報(bào)表和圖表。l SecureClient Packaging Tool用于VPN用戶(hù),將VPN客戶(hù)端所需的軟件包和策略封成一個(gè)數(shù)據(jù)包,發(fā)送給移動(dòng)VPN用戶(hù)。出現(xiàn)安裝路徑選擇窗口,默認(rèn)路徑為C:\Program Files\Checkpoint\Managernt Clients。出現(xiàn)Server端組件選擇窗口,由于VPN1amp。如果沒(méi)有自動(dòng)出現(xiàn)下列界面,光盤(pán)將會(huì)自動(dòng)運(yùn)行。Enter39。隨意敲任意,直到出現(xiàn)Thank you)Configuring Certificate Authority...====================================The system uses an internal Certificate Authorityto provide Secured Internal Communication (SIC) Certificatesfor the ponents in your System.Note that your ponents won39。在此處我們選擇(1)Enter your selection (13/aabort) [1]: 1IP forwarding disabledHardening OS Security: IP forwarding will be disabled during boot.Generating default filterDefault Filter installedHardening OS Security: Default Filter will be applied during boot.This program will guide you through several steps where youwill define your Check Point products configuration.At any later time, you can reconfigure these parameters byrunning cpconfigConfiguring Licenses...=======================Host Expiration FeaturesNote: The remended way of managing licenses is using SecureUpdate.This window can be used to manage local licenses only on this machine.Do you want to add licenses (y/n) [y] ? n(詢(xún)問(wèn)用戶(hù)是否需要安裝Checkpoint License,可以在此時(shí)輸入,也可在安裝完畢時(shí)用命令行方式輸入,因?yàn)槭褂妹钚蟹绞捷斎胼^為方便,建議用戶(hù)在安裝完畢后使用copy paste的方式輸入License。 to continue...(顯示Checkpoint License版權(quán)信息,敲回車(chē)?yán)^續(xù),敲q可直接跳過(guò)該License提示信息)Do you accept all the terms of this license agreement (y/n) ? y(輸入y同意該版權(quán)聲明)Which Module would you like to install ?