【正文】
Configuring Groups...=====================Check Point access and execution permissionsUsually, a Check Point module is given group permissionfor access and execution.You may now name such a group or instruct the installationprocedure to give no group permissions to the Check Point module.In the latter case, only the SuperUser willbe able to access and execute the Check Point module.Please specify group name [RET for no group permissions]:No group permissions will be granted. Is this ok (y/n) [y] ?Setting Group Permissions... Done.(為Checkpoint生成一個(gè)管理組,在此處不需要生成專門管理組,直接敲回車,不生成組)Configuring Random Pool...==========================You are now asked to perform a short random keystroke session.The random data collected in this session will be used invarious cryptographic operations.Please enter random text containing at least six differentcharacters. You will see the 39。2 Checkpoint的幾種典型配置 checkpoint 初始化配置過程:在安裝完Checkpoint軟件之后,需要在命令行使用cpconfig命令來完成Checkpoint的配置。如下圖所示,SSH連接到防火墻,在命令行中輸入以下命令:IP350[admin] cpconfigWele to Check Point Configuration Program=================================================Please read the following license agreement.Hit 39。*39。s Fingerprint...========================================The following text is the fingerprint of this Management machine:SODA KNEE MEAT LIEN ADD LAP WISH JIBE JIM AMEN EACH SAIDDo you want to save it to a file? (y/n) [y] ? n(詢問是否將Management Server上的指紋存儲(chǔ)到文件中)generating GUIclients INSPECT codeinitial_management:Compiled OK.Hardening OS Security: Initial policy will be applieduntil the first policy is installed(在配置完成Checkpoint后,Checkpoint會(huì)將操作系統(tǒng)做一個(gè)加固,除Checkpoint GUI外,其它的任何服務(wù)都不能連接到防火墻)In order to plete the installation of moduleyou must reboot the machine.Do you want to reboot? (y/n) [y] ? n(Checkpoint將詢問是否重新啟動(dòng),為便于使用命令行增加Checkpoint License,在此處點(diǎn)擊n)IP350[admin] cplic putlic eval 01Jan2003 dHEkKf7rtBN9eeqjJx9vxuF5EfNX5TxP4Mqp CPMPEVAL13DESNG CKCPHost Expiration Featureseval 1Jan2003 CPMPEVAL13DESNG CKCP(使用命令行增加Checkpoint License,該命令行可直接從Checkpoint 的正式License中Copy到命令行模式下)IP350[admin]syncIP350[admin]rebootcleaning up...syncing disks... doneRebooting...a) 重新啟動(dòng)后,整個(gè)CheckPoint VPN1/FW1 NG 安裝完成。只選擇Manager Clients,點(diǎn)擊Next繼續(xù)。該模塊需額外購買。此時(shí)完成Checkpoint GUI的安裝。策略還是處于空白狀態(tài)。這樣定義以后,所有來自非內(nèi)部網(wǎng)卡所有網(wǎng)段的數(shù)據(jù)包都將被防火墻內(nèi)部網(wǎng)卡丟棄掉。