CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point UTM-1 Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-11-08
Junior Member
 
Join Date: 2006-06-18
Location: Hong Kong
Posts: 13
Rep Power: 0
tzeon has an average reputation (10+)
Send a message via Skype™ to tzeon
Default How to Size UTM-1 appliance

We need to replace our existing firewall with UTM-1, my company main office have around 2000 users and UTM-1 will turn on AV and IPS features. Also the gateway will act as centre vpn hub(site-to-site IPSec VPN) to other remote offices.

I am thinking to choose either UTM-1 3070 or Power-1 5070, please give sme ome suggestion and comment.

Also anyone have on UTM-1 3070 specially the performance to share with me?
Reply With Quote
  #2 (permalink)  
Old 2008-11-08
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: How to Size UTM-1 appliance

AV is only rated for 500 users maximum - do NOT turn on this feature for 2000 users!

Beyond that, the key issues are connections and required bandwidth. A 3070 should be sufficient. Your next questions are around clustering, log management and whether you run management on box or invest in a SmartCenter server.

Note that the Power-1 5070 doesn't include management, so you definitely need an additional SmartCenter license for this. I would also strongly recommend that if you are going to use a UTM-1 3070 for management and gateway, that you invest an additional 1K in a CLM, and send your logging off the box.
Reply With Quote
  #3 (permalink)  
Old 2008-11-12
Junior Member
 
Join Date: 2006-06-18
Location: Hong Kong
Posts: 13
Rep Power: 0
tzeon has an average reputation (10+)
Send a message via Skype™ to tzeon
Default Re: How to Size UTM-1 appliance

Hi Thorpuse,

Thank you for your reply, I know the limitation of 500 users AV is applied to old UTM-1 xx50 appliance so this limitation still apply to new xx70 and Power-1 applicane?

Can I use externalize SmartCenter UTM to manage both Power-1 and UTM-1 2070 instead of SmartCenter Power license? Do I lose the smartmonitor feature on UTM-1 2070 if I am using SmartCenter UTM?
__________________
Simon
CCSE+ NGX, NCSM
Reply With Quote
  #4 (permalink)  
Old 2008-11-12
Senior Member
 
Join Date: 2007-06-04
Posts: 1,095
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: How to Size UTM-1 appliance

I believe that the 500 for AV limit is a UTM software issue and you would need UTM-Power for more then that.

In honesty I can't see any of the appliances coping doing UTM with 500+ users anyway.

If you use a SMARTCenter UTM license then this does not include the SMARTView Monitor for other then the basic functionality that used to be in SMARTView Status.

You would need a SMARTCenter Power for the feature.
Reply With Quote
  #5 (permalink)  
Old 2008-11-21
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 203
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: How to Size UTM-1 appliance

Quote:
Originally Posted by tzeon View Post

Can I use externalize SmartCenter UTM to manage both Power-1 and UTM-1 2070 instead of SmartCenter Power license? Do I lose the smartmonitor feature on UTM-1 2070 if I am using SmartCenter UTM?
Checkpoint TAC confirmed to me two weeks ago that a UTM SCS can manage a Power firewall
Reply With Quote
  #6 (permalink)  
Old 2008-11-21
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: How to Size UTM-1 appliance

Quote:
Originally Posted by tzeon View Post
Hi Thorpuse,

Thank you for your reply, I know the limitation of 500 users AV is applied to old UTM-1 xx50 appliance so this limitation still apply to new xx70 and Power-1 applicane?

Can I use externalize SmartCenter UTM to manage both Power-1 and UTM-1 2070 instead of SmartCenter Power license? Do I lose the smartmonitor feature on UTM-1 2070 if I am using SmartCenter UTM?
The AV restriction is with the engine - I wouldn't trust it on a large system. If Gateway AV is that important, I'd be offloading it to a dedicated system.

The SmartCentre UTM license does NOT include SmartMonitor (or LDAP, or SmartPortal, or all sorts of other useful things that should be standard....). If you use a software SmartCenter UTM to manage a UTM-1 2070, you lose the extra things that are provided in the UTM-1's management license (like Monitor, LDAP, SmartPortal etc....). This is one of the stupidest things about the UTM-1 systems - that you need to compromise your security design due to CP's reluctance to allow decoupling of management features from running on-box. I've complained about this for 2 years now, but CP isn't interested in listening. Thanks guys....
Reply With Quote
  #7 (permalink)  
Old 2008-11-23
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How to Size UTM-1 appliance

Quote:
Originally Posted by mcnallym View Post
I believe that the 500 for AV limit is a UTM software issue and you would need UTM-Power for more then that.

In honesty I can't see any of the appliances coping doing UTM with 500+ users anyway.
This is an OEM licensing issue. The system has been tested to >1000 users.
That said, I'd still go off-box for larger sites unless its low volume.
Reply With Quote
  #8 (permalink)  
Old 2008-12-03
Junior Member
 
Join Date: 2006-06-18
Location: Hong Kong
Posts: 13
Rep Power: 0
tzeon has an average reputation (10+)
Send a message via Skype™ to tzeon
Default Re: How to Size UTM-1 appliance

Thanks for all your reply!!!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:23.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0