Foreword |
|
xix | |
|
Nokia Security Solutions Overview |
|
|
1 | (36) |
|
|
2 | (1) |
|
|
3 | (1) |
|
Introducing Nokia Firewall/VPN and UTM Appliances |
|
|
4 | (19) |
|
|
4 | (3) |
|
|
7 | (3) |
|
|
10 | (1) |
|
|
11 | (2) |
|
|
13 | (1) |
|
The IP290 Security Platform |
|
|
13 | (1) |
|
|
14 | (1) |
|
|
14 | (1) |
|
|
14 | (2) |
|
|
16 | (1) |
|
|
17 | (1) |
|
|
18 | (1) |
|
The IP690 Security Platform |
|
|
18 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
21 | (2) |
|
Introducing Additional Nokia Security Solutions |
|
|
23 | (9) |
|
Nokia Integrated Firewall |
|
|
23 | (1) |
|
|
24 | (4) |
|
Nokia Intrusion Prevention with Sourcefire |
|
|
28 | (1) |
|
|
29 | (3) |
|
|
32 | (1) |
|
|
32 | (2) |
|
Frequently Asked Questions |
|
|
34 | (3) |
|
|
37 | (28) |
|
|
38 | (1) |
|
Exploring the History of IPSO |
|
|
39 | (2) |
|
Understanding Specialized IPSO Releases |
|
|
40 | (1) |
|
Introducing Access and Security Features |
|
|
41 | (10) |
|
|
43 | (1) |
|
Understanding the Client/Server Model and Listening Sockets |
|
|
43 | (3) |
|
|
46 | (1) |
|
Using File Transfer Protocol (FTP) |
|
|
46 | (2) |
|
|
48 | (1) |
|
|
49 | (1) |
|
|
49 | (1) |
|
Using Other Security Features |
|
|
50 | (1) |
|
Understanding Users and Groups |
|
|
51 | (1) |
|
Learning the Directory Structure |
|
|
52 | (5) |
|
Understanding Special Directories and Disk Space |
|
|
55 | (1) |
|
Dealing with Floppy and CD-ROM Drives |
|
|
56 | (1) |
|
|
57 | (2) |
|
|
59 | (1) |
|
|
59 | (2) |
|
Frequently Asked Questions |
|
|
61 | (4) |
|
Initial IPSO Configuration |
|
|
65 | (28) |
|
|
66 | (1) |
|
Preparing to Boot for the First Time |
|
|
66 | (2) |
|
Workstation Configuration |
|
|
67 | (1) |
|
|
67 | (1) |
|
|
68 | (5) |
|
Booting into the Boot Manager |
|
|
68 | (5) |
|
Performing the First-Time Boot Configuration |
|
|
73 | (6) |
|
Using DHCP to Configure the System |
|
|
73 | (3) |
|
Configuring Manually with a Console Connection |
|
|
76 | (3) |
|
Continuing the Configuration |
|
|
79 | (3) |
|
|
82 | (4) |
|
|
86 | (1) |
|
|
87 | (2) |
|
Frequently Asked Questions |
|
|
89 | (4) |
|
|
93 | (72) |
|
|
94 | (1) |
|
Introducing Nokia Network Voyager |
|
|
94 | (5) |
|
|
94 | (1) |
|
|
95 | (1) |
|
Navigating Nokia Network Voyager |
|
|
96 | (2) |
|
Understanding the Interface Buttons |
|
|
98 | (1) |
|
Understanding the Web Browser Functions |
|
|
98 | (1) |
|
Accessing Help Documentation |
|
|
99 | (1) |
|
Understanding Hardware and Software Information |
|
|
99 | (1) |
|
Configuring Nokia Network Voyager Access |
|
|
99 | (10) |
|
Configuring Basic Nokia Network Voyager Options |
|
|
99 | (2) |
|
Generating and Installing SSL/TLS Certificates |
|
|
101 | (4) |
|
|
105 | (1) |
|
|
106 | (3) |
|
Configuring a Basic System |
|
|
109 | (8) |
|
Configuring Network Devices |
|
|
109 | (1) |
|
Configuring Ethernet Interfaces |
|
|
110 | (4) |
|
|
114 | (3) |
|
|
117 | (3) |
|
|
117 | (1) |
|
|
118 | (1) |
|
Enabling Sequence Validation |
|
|
119 | (1) |
|
Setting Delayed Notification and Auto-Expiry |
|
|
119 | (1) |
|
Using the Router Alert IP Option |
|
|
119 | (1) |
|
Using Optimize for Two-Port IP1260 |
|
|
120 | (1) |
|
Configuring System Options |
|
|
120 | (12) |
|
Configuring Banner and Login Messages |
|
|
120 | (1) |
|
Configuring Dynamic Host Configuration Protocol (DHCP) |
|
|
121 | (6) |
|
|
127 | (1) |
|
Configuring Disk Mirroring |
|
|
127 | (2) |
|
|
129 | (1) |
|
|
129 | (1) |
|
Configuring Daylight Savings Time |
|
|
130 | (1) |
|
Configuring Host Addresses |
|
|
130 | (2) |
|
|
132 | (1) |
|
|
132 | (2) |
|
Installing and Enabling Packages |
|
|
133 | (1) |
|
|
134 | (1) |
|
Configuring Static Routes |
|
|
134 | (7) |
|
Creating Backup Static Routes |
|
|
137 | (1) |
|
Creating Aggregate Routes |
|
|
137 | (2) |
|
|
139 | (1) |
|
|
139 | (2) |
|
Configuring System Backup and Restore |
|
|
141 | (12) |
|
|
141 | (2) |
|
Transferring Backup Files |
|
|
143 | (1) |
|
Restoring Files from Locally Stored Backup Files |
|
|
144 | (2) |
|
Configuring System Logging |
|
|
146 | (1) |
|
Configuring Logging on Disk-Based Systems |
|
|
147 | (1) |
|
Logging to a Remote System |
|
|
147 | (1) |
|
|
148 | (1) |
|
Configuring Logging on Flash-Based Systems |
|
|
149 | (1) |
|
Configuring Logging to Remote Log Servers |
|
|
149 | (1) |
|
Configuring Logging to an Optional Disk |
|
|
150 | (1) |
|
|
151 | (2) |
|
|
153 | (2) |
|
|
155 | (2) |
|
|
157 | (3) |
|
Frequently Asked Questions |
|
|
160 | (5) |
|
Security and Access Configuration |
|
|
165 | (62) |
|
|
166 | (1) |
|
Managing Accounts and Passwords |
|
|
166 | (15) |
|
Password and Account Management |
|
|
166 | (1) |
|
Configuring Password Strength |
|
|
167 | (2) |
|
Configuring Password History Check |
|
|
169 | (1) |
|
Configuring Mandatory Password Change |
|
|
170 | (5) |
|
Denying Access to Unused Accounts |
|
|
175 | (1) |
|
|
175 | (1) |
|
|
176 | (2) |
|
Adding and Deleting Users |
|
|
178 | (1) |
|
|
179 | (1) |
|
|
180 | (1) |
|
Managing Groups and Access |
|
|
181 | (6) |
|
|
182 | (3) |
|
Assigning Roles and Access Mechanisms to Users |
|
|
185 | (1) |
|
Creating Cluster Administrator Users |
|
|
186 | (1) |
|
Configuring Authentication, Authorization, and Accounting (AAA) |
|
|
187 | (13) |
|
Configuring AAA Service Modules |
|
|
187 | (6) |
|
|
193 | (2) |
|
Configuring Non-Local RADIUS Users |
|
|
195 | (1) |
|
|
196 | (2) |
|
Configuring Non-Local TACACS+ Users |
|
|
198 | (2) |
|
Logging in as a Superuser |
|
|
200 | (1) |
|
|
200 | (21) |
|
Understanding Transport and Tunnel Modes |
|
|
201 | (3) |
|
Understanding Protocol Negotiation and Key Management |
|
|
204 | (1) |
|
|
205 | (1) |
|
|
206 | (1) |
|
Defining Tunnel Requirements |
|
|
207 | (2) |
|
|
209 | (10) |
|
Using Miscellaneous Security Settings |
|
|
219 | (2) |
|
|
221 | (2) |
|
|
223 | (1) |
|
Frequently Asked Questions |
|
|
224 | (3) |
|
Advanced System Administration and Troubleshooting |
|
|
227 | (22) |
|
|
228 | (1) |
|
Understanding the Boot Manager |
|
|
228 | (6) |
|
Understanding Boot Manager Variables |
|
|
228 | (1) |
|
Understanding Boot Manager Commands |
|
|
229 | (2) |
|
Performing a Factory-Default Installation |
|
|
231 | (1) |
|
|
232 | (1) |
|
Resetting the Admin Password |
|
|
233 | (1) |
|
|
234 | (2) |
|
Understanding CLISH Basics |
|
|
234 | (1) |
|
Using show Command Completions in CLISH |
|
|
235 | (1) |
|
|
236 | (8) |
|
|
236 | (1) |
|
Searching and Displaying Log Files |
|
|
236 | (1) |
|
|
237 | (2) |
|
|
239 | (2) |
|
Using the Configuration Summary Tool (CST) |
|
|
241 | (1) |
|
Understanding Memory and Processes |
|
|
241 | (3) |
|
|
244 | (1) |
|
|
244 | (2) |
|
Frequently Asked Questions |
|
|
246 | (3) |
|
Advanced Routing Configuration |
|
|
249 | (32) |
|
|
250 | (1) |
|
Introducing Dynamic Routing |
|
|
250 | (6) |
|
|
250 | (1) |
|
|
251 | (2) |
|
|
253 | (1) |
|
Understanding Other Supported Protocols |
|
|
254 | (1) |
|
|
254 | (1) |
|
|
254 | (1) |
|
|
255 | (1) |
|
|
255 | (1) |
|
Understanding Routing Options |
|
|
255 | (1) |
|
|
256 | (3) |
|
Stepping through the Initial RIP Configuration |
|
|
256 | (2) |
|
|
258 | (1) |
|
Configuring Auto-Summarization |
|
|
259 | (1) |
|
|
259 | (12) |
|
Stepping through the Initial OSPF Configuration |
|
|
259 | (3) |
|
Configuring Virtual Links |
|
|
262 | (2) |
|
Configuring OSPF Interfaces |
|
|
264 | (4) |
|
Configuring Global Settings |
|
|
268 | (3) |
|
|
271 | (7) |
|
|
278 | (1) |
|
|
278 | (2) |
|
Frequently Asked Questions |
|
|
280 | (1) |
|
Configuring the Check Point NGX Firewall |
|
|
281 | (38) |
|
|
282 | (1) |
|
Preparing for the Firewall Implementation |
|
|
282 | (3) |
|
|
284 | (1) |
|
Configuring Your Hostname |
|
|
285 | (1) |
|
Configuring the Check Point NGX Firewall |
|
|
285 | (17) |
|
|
285 | (1) |
|
|
286 | (1) |
|
Understanding Environment and Path |
|
|
287 | (1) |
|
Understanding VPN-1 Pro/Express NGX Directory Structure |
|
|
287 | (1) |
|
Understanding IP Forwarding as It Pertains to Firewall Policies |
|
|
288 | (2) |
|
|
290 | (2) |
|
|
292 | (3) |
|
|
295 | (2) |
|
Understanding Certificate Authority Initialization |
|
|
297 | (3) |
|
Completing an Installation |
|
|
300 | (1) |
|
Getting Back to Configuration |
|
|
300 | (2) |
|
Testing the Firewall Configuration |
|
|
302 | (10) |
|
Testing SmartDashboard access |
|
|
302 | (5) |
|
Pushing and Fetching Policy |
|
|
307 | (5) |
|
|
312 | (3) |
|
Upgrading from NG AI R55 to NGX R62 |
|
|
313 | (1) |
|
Upgrading from NGX R62 to NGX R65 |
|
|
314 | (1) |
|
|
315 | (1) |
|
|
315 | (2) |
|
Frequently Asked Questions |
|
|
317 | (2) |
|
|
319 | (38) |
|
|
320 | (1) |
|
Monitoring System Utilization |
|
|
320 | (13) |
|
Viewing System Utilization Statistics |
|
|
320 | (4) |
|
Understanding IPSO Process Management |
|
|
324 | (2) |
|
Generating Monitor Reports |
|
|
326 | (3) |
|
|
329 | (2) |
|
Preventing Full Log Buffers and Related Console Messages |
|
|
331 | (2) |
|
|
333 | (5) |
|
Viewing Cluster Status and Members |
|
|
333 | (2) |
|
Viewing Routing Protocol Information |
|
|
335 | (3) |
|
|
338 | (6) |
|
|
340 | (4) |
|
|
344 | (8) |
|
|
352 | (1) |
|
|
353 | (1) |
|
Frequently Asked Questions |
|
|
354 | (3) |
|
|
357 | (28) |
|
|
358 | (1) |
|
Understanding Check Point High Availability |
|
|
358 | (4) |
|
Configuring the Nokia VRRP Implementation |
|
|
362 | (6) |
|
Understanding the VRRP Configuration |
|
|
362 | (1) |
|
Understanding the VRRP Protocol |
|
|
363 | (1) |
|
Implementing VRRP for XYZ Inc |
|
|
364 | (1) |
|
Understanding VRRP Monitored Circuits |
|
|
365 | (2) |
|
Comparing VRRP v2 to Monitored Circuits |
|
|
367 | (1) |
|
Configuring the Nokia VRRP Monitored Circuit |
|
|
368 | (6) |
|
Configuring All Interfaces |
|
|
368 | (1) |
|
|
369 | (1) |
|
Configuring the Host Table |
|
|
369 | (1) |
|
Configuring VRRP Settings Using Voyager |
|
|
369 | (5) |
|
Configuring Check Point Gateway Clusters to Use the Nokia VRRP |
|
|
374 | (6) |
|
Configuring a Gateway Cluster |
|
|
375 | (5) |
|
|
380 | (1) |
|
|
380 | (2) |
|
Frequently Asked Questions |
|
|
382 | (3) |
|
IPSO Command Interface Line Shell (CLISH) |
|
|
385 | (46) |
|
|
386 | (1) |
|
|
386 | (8) |
|
Configuring Ethernet Interfaces |
|
|
387 | (1) |
|
Configuring the Physical Interface |
|
|
387 | (2) |
|
Configuring the Logical Interface |
|
|
389 | (2) |
|
Showing Interface Configurations |
|
|
391 | (2) |
|
Deleting a Logical Interface |
|
|
393 | (1) |
|
|
394 | (1) |
|
Controlling Sequence Validation |
|
|
394 | (1) |
|
|
394 | (1) |
|
Using the Router Alert IP Option |
|
|
394 | (1) |
|
|
395 | (1) |
|
Configuring System Options |
|
|
395 | (13) |
|
Configuring the DHCP Server |
|
|
396 | (3) |
|
|
399 | (1) |
|
Configuring Date and Time |
|
|
400 | (2) |
|
Backing Up and Restoring Files |
|
|
402 | (1) |
|
|
403 | (1) |
|
|
404 | (2) |
|
Restoring Files from Locally Stored Backup Files |
|
|
406 | (1) |
|
Restoring Files from Backup Files Stored on Remote Server |
|
|
407 | (1) |
|
Configuring Network Security and Access |
|
|
408 | (8) |
|
Configuring Network Access and Services |
|
|
408 | (3) |
|
Managing Passwords and Account Management |
|
|
411 | (3) |
|
|
414 | (2) |
|
|
416 | (10) |
|
Configuring Static Routes |
|
|
416 | (2) |
|
|
418 | (1) |
|
|
418 | (2) |
|
Configuring OSPF Interfaces |
|
|
420 | (2) |
|
Changing Global OSPF Settings |
|
|
422 | (2) |
|
Using Route Summary Commands |
|
|
424 | (2) |
|
|
426 | (1) |
|
|
427 | (2) |
|
Frequently Asked Questions |
|
|
429 | (2) |
|
|
431 | (18) |
|
|
432 | (1) |
|
Understanding Files and Directories |
|
|
432 | (8) |
|
The UNIX Directory Hierarchy |
|
|
432 | (4) |
|
|
436 | (1) |
|
|
437 | (1) |
|
|
437 | (1) |
|
|
438 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
Understanding Users and Groups |
|
|
440 | (5) |
|
|
440 | (1) |
|
|
441 | (1) |
|
|
442 | (1) |
|
|
443 | (1) |
|
|
444 | (1) |
|
setuid and setgid Binaries |
|
|
445 | (1) |
|
Using the Shell and Basic Shell Utilities |
|
|
445 | (2) |
|
|
445 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
446 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (2) |
|
Appendix B Accessing Lab Videos |
|
|
449 | (4) |
|
Introduction and System Requirements |
|
|
450 | (1) |
|
|
450 | (3) |
Index |
|
453 | |