CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-26
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 159
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default secure splat mgmt server

Hi all,

i would like to heare some meanings about relocate my splat mgmt from dedicated hw to ESX-Cluster.

The mgmt server is at the moment protected by the FW (direct connect with X-over cable). In case something happens the X-over can replaced with a small switch (one IP in the connect range has an entry in the gui-clients file).

If i relocate the mgmt into the ESX-Cluster i will loose this kind of protection but get all the benefits of the HA environment,with the advantage that other ESX-Admins can get (nearly phisical) access to the mgmt server.

My main question is about to protect the mgmt station with additional iptable, since the new network is also reachable for normal users.

Any suggestions/expirience ?
Reply With Quote
  #2 (permalink)  
Old 2008-05-27
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: secure splat mgmt server

Why not just build out a new management network on the ESX for Check Point? Secure that and make sure the permission on the VM for the SmartCenter is locked down.
Reply With Quote
  #3 (permalink)  
Old 2008-05-27
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 159
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: secure splat mgmt server

The comany was merged, every branch gets a limited IP space and the default routes at the network equipment are now pointed to mpls cloud.
The only networks without overlap is the ip range used for dmz networks.
mgmt network is also an overlap to important servers in the mpls cloud so i have to rebuild/reasign most everything.
Thanks for the tip, i will discuss to use one of the dmz networks as dedicated mgmt network at the ESX farm.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:47.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0