45-Bridge Mode Lab

Download as pdf or txt
Download as pdf or txt
You are on page 1of 18

Bridge Mode:

If your Deployment having complex routing or You don’t want to change the existing network
ip/routing system. Then you can deploy checkpoint as a bridge mode for security. Bridges
operate at layer 2 of the OSI model, therefore adding a bridge to an existing network is
completely transparent and does not require any changes to the network's structure or IP
Network. Just you need place it before your gateway device and it will act as a transparent
firewall. Bridge interfaces connect two different interfaces (bridge ports). Bridging two
interfaces causes every Ethernet frame that is received on one bridge port to be transmitted to
the other port. Thus, the two bridge ports participate in the same Broadcast domain. Only two
interfaces can be connected by a single Bridge interface. These two interfaces can then be
thought of as a two-ports switch. Each port can be a physical, VLAN, or bond device. Bridge
interfaces can be configured on Check Point Security Gateway, and can be used for different
deployments. The Firewall inspects every Ethernet frame that passes through the bridge.

Using Checkpoint in Layer 2 can be used when you need a Checkpoint firewall that intercept
traffic between two sides of the same network. You configure two ports that acts as a switch in
the gateway itself and all traffic that traverses these two ports in both directions are inspected
by the Checkpoint Security Gateway firewall.

Some features, Software Blades and deployments are not supported in Bridge Mode:
Mobile Access Software Blade
IPsec VPN Software Blade
Full High Availability deployment
NAT on Gateways
Access to Portals from bridged networks, if the bridge does not have an assigned IP address
Anti-Virus Traditional Mode
Identity Awareness authentication other than AD Query

1 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Bridge Mode Lab:

Check Point MGMT IP Address 192.168.114.50


PC1 IP Address 192.168.1.10
PC2 IP Address 192.168.1.20
PC1 and PC2 Subnet 192.168.1.0/24
Smart Console IP Address 192.168.114.2
Dockers EVE-GUI-Server

First Time Wizard:


Type show interface eth0 command to find out Management IP Address of Firewall.

2 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


In any browser type https://192.168.114.50 to access Check Point Gaia Portal. Then you will get
Login Screen of Checkpoint Firewall. Now you can Login with your User Name and Password
which you have assign to your firewall in this case admin/Admin@12345

Now it will prompt you, First-time configuration wizard. Click on the Next to start your
configuration.

3 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Deployment Options choose Setup Continue with R80.40 configurations and click Next.

Now configure Network Connection of eth0 (Management Interface), and then Click on Next.

4 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Now provide the Host name, Domain name and Primary DNS address here.

5 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Now on the Next Screen Select your Time and set Time and Date Then Click on Next.

Choose the installation type, Select the Security gateway or Security management option here.

6 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Standalone deployment. Now on Product Wizard Select Security Gateway and Security
Management check box to install both in same machine. Then click on Next.

Put User name and password for your Security management. Then click on Next.

7 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


In my case Select any IP Address radio button. Then Click on Next.

Click on Finish button. Then you will see installation process going on wait until completion.

8 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


9 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717
After complete it will ask to reboot your firewall then click on Yes.

Now again Access Checkpoint firewall from your browser with Management IP Address
(https://192.168.114.50). Then put User name and password then Login. Now we successfully
Install and Configured Checkpoint Firewall Security Gateway. Now we are on Security Gateway
Dashboard.

10 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Configure Bridge Interfaces:
Connect over WebUI and navigate to Network Management > Network Interfaces. Click on Add
and then select Bridge.

Add eth1 and eth2 to Chosen Interfaces and click on OK.

11 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


The newly created Bridge interface is now visible over the Network Interfaces page.

SmartConsole:
Now, let’s download SmartConsole from Gaia Portal to manage software Blades and other
security settings. Click on main overview page Download Now.

Click Next… Next to install SmartConsole on Windows 10 Management PC, open SmartConsole
type username and password click LOGIN.

12 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


In next screen SmartConsole will show Fingerprint, you can verify them, Click PROCEED.

To verify the Certificate Fingerprints login to Security Gateway or Security Management Server
type command cpconfig type option 8.

13 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


After successfully login to SmartConsole where you can manage the Security Settings.

Security Policy:
In SmartConsole, go to Security Policies > Access Control > Policy and then configure the
required policies. In this case let’s modify the default cleanup rule change the action to Accept
and enable the logs click on track.

14 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Publish & Install Policy:
To make your changes available to other administrators, and to save the database before
installing a policy, you must publish the session. When you publish a session, a new database
version is created. Before you publish the session, you can add some informative attributes to
it. In the SmartConsole toolbar, click Publish.

When you select Install Policy, you are prompted to publish all unpublished changes. You
cannot install a policy if the included changes are not published.

15 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


On the Global Toolbar, click Install Policy. The Install Policy window opens showing the
installation targets (Security Gateways). From the Select a policy menu, select a policy package.
Select one or more policy types that are available in the package. Select the Install Mode.
Install on each selected gateway independently - Install the policy on each target gateway
independently of others, so that if the installation fails on one of them, it doesn't affect the
installation on the rest of the target gateways. Click Install.

16 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Configure Hosts:
Let’s assign IP address to PCs PC1 and PC2, in this case Dockers.
LAN PC1 IP Address 192.168.1.10
LAN PC2 IP Address 192.168.1.20

17 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717


Testing and Verification:
Go to PC1 and try to browse PC2 IP Address in the browser it will work.

Try to ping from PC2 to PC1 in this case, it will work.

18 | P a g e Created by Ahmad Ali E-Mail: [email protected] , WhatsApp: 0096656 430 3717

You might also like