Check Point Cloudguard for Microsoft Azure | Test Drive User Guide
Total Page:16
File Type:pdf, Size:1020Kb
Check Point CloudGuard for Microsoft Azure | Test Drive User Guide Check Point CloudGuard for Microsoft Azure R80.10 Test Drive User Guide Learn More: checkpoint.com ©2017 Check Point Software Technologies Ltd. All rights reserved Page | 1 Check Point CloudGuard for Microsoft Azure | Test Drive User Guide Content 1 INTRODUCTION ................................................................................................................................................................ 3 2 TEST DRIVE OVERVIEW ..................................................................................................................................................... 4 3 TEST DRIVE ....................................................................................................................................................................... 5 3.1 START THE TEST DRIVE ........................................................................................................................................................ 5 3.2 REVIEW THE CLOUDGUARD PRODUCT INFORMATION AND USE CASES .......................................................................................... 5 3.3 INFORMATION FOR ACCESSING THE TEST DRIVE ENVIRONMENT ................................................................................................... 6 3.4 CONNECTING TO THE TEST DRIVE ENVIRONMENT ..................................................................................................................... 6 3.4.1 Using the Windows Remote Desktop Client ......................................................................................................... 6 3.4.2 Using an Existing Check Point R80.10 SmartConsole Client ................................................................................. 8 3.5 REVIEW THE SECURITY POLICY ............................................................................................................................................... 9 3.6 VERIFY NORMAL WEB TRAFFIC ........................................................................................................................................... 12 3.7 BLOCK AN SQL INJECTION ATTACK ....................................................................................................................................... 14 3.8 BLOCK ACCESS TO SOCIAL NETWORKS .................................................................................................................................. 20 4 CLOUDGUARD FOR AZURE USE CASES OVERVIEW ......................................................................................................... 30 5 SUPPORT ........................................................................................................................................................................ 30 Figures Figure 1 Check Point CloudGuard for Microsoft Azure Test Drive Environment ......................................................................... 5 ©2017 Check Point Software Technologies Ltd. All rights reserved Page | 2 Check Point CloudGuard for Microsoft Azure | Test Drive User Guide 1 Introduction Welcome to Check Point CloudGuard for Microsoft Azure test drive! Check Point CloudGuard test drive for Microsoft Azure enables customers to rapidly try out CloudGuard enterprise security gateway features deployed on a virtual instance inside a Microsoft Azure IaaS (Infrastructure as a Service) virtual cloud. This test drive will allow you to experience the capabilities of the CloudGuard gateway in action using a real web server app, simulated attack vectors, and verification of activity in event logs. Why do I need CloudGuard for Azure when the cloud is already secure? Check Point CloudGuard allows you to protect your apps and data deployed in Azure. As you may well know, when you deploy a server in Azure configured with a public facing IP (even a private IP with NAT allowing for Internet access), it is exposed to cyber-attacks from the Internet, just like any server deployed in an on premise environment. Cloud providers provide cost efficient computing resources but only secure the infrastructure layer. Check Point CloudGuard allows you to secure the higher layers (network layer up to application layer) with advanced multi-layer security in order to gain visibility into traffic and threats as well as detect and prevent attacks inside and outside your cloud network and demonstrate compliance. Additionally, a perimeter based security gateway approach makes it easier to protect multiple virtual machine instances (with unknown security posture, software, and patch levels) in a highly dynamic cloud environment where VMs are constantly spun up and removed. It is the customer’s responsibility to protect their data and apps in the cloud. Activities included in this Test Drive At the end of the test drive, you will have accomplished the following: Remotely access and navigate the SmartConsole management user interface (UI) to provision and monitor the CloudGuard security gateway Enable internet/public facing app (web server) by provisioning a security policy and verify correct operation of the web server Simulate an SQL attack, watch it succeed, and then block the attack by provisioning Intrusion Prevention (IPS) functionality and verify correct operation in the SmartEvent logs Block all access to social networks (i.e. Facebook/LinkedIn/Twitter) by enabling Application and URL Filtering and verify correct operation using SmartEvent logs If you wish to purchase and deploy CloudGuard for Azure immediately in either “PAY as you Go” (PAYG) or “Bring Your Own License” (BYOL) licensing model, please visit the CloudGuard listing on Azure Marketplace which contains ARM templates for rapid single click provisioning and deployment. A reference architecture is available at: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondeta ils=&solutionid=sk109360&partition=General&product=CloudGuard Please note that Check Point CloudGuard is fully integrated with Azure Security Center as well, to automate and orchestrate the deployment. Follow the instructions below to begin your test drive. Enjoy your journey! ©2017 Check Point Software Technologies Ltd. All rights reserved Page | 3 Check Point CloudGuard for Microsoft Azure | Test Drive User Guide 2 Test Drive Overview This test drive will have you working on securing a single tier app environment where tier one is a web server deployed inside Azure cloud behind the Azure load balancer. This simulates a real- world scenario where the web server hosts dynamic content from the cloud but needs to be secured with advance threat protection using a virtual enterprise security gateway. In this scenario, all inbound/outbound (i.e. North/South) traffic to the web server is secured by the CloudGuard gateway. The test drive environment consists of the following components: ©2017 Check Point Software Technologies Ltd. All rights reserved Page | 4 Check Point CloudGuard for Microsoft Azure | Test Drive User Guide Figure 1 Check Point CloudGuard for Microsoft Azure Test Drive Environment An Azure Virtual Network with the following subnets: • A Gateway external subnet (10.0.0.0/24) • A Gateway internal subnet (10.0.1.0/24) • A Web Server Subnet (internal1-subnet) (10.0.2.0/24) • An Windows Machine Subnet (external1subnet (10.0.4.0/24) The test drive has 3 virtual machines: • A Linux machine • A Windows machine • A Check Point CloudGuard gateway The Linux machine is pre-configured as a web server listening on TCP port 80. The Windows machine is pre-installed with the Check Point SmartConsole (R80.10) Graphical User Interface clients. The Check Point CloudGuard gateway has two interfaces attached to external and internal subnets. The Windows machine is attached to external subnet. The Web Server is attached to the web server subnet. The CloudGuard external network interface has an extra public IP set up to receive HTTP traffic on a dedicated public address and forward it to through the Check Point CloudGuard security gateway to the web server. The Check Point CloudGuard Security gateway is pre-configured with security and Network Address Translation (NAT) policies to receive and forward this traffic. 3 Test Drive 3.1 Start the Test Drive Go to https://azuremarketplace.microsoft.com/en-us/marketplace/apps/checkpoint.vsec and click the TEST DRIVE button. You need to sign in for your test drive using your Microsoft account. If you don’t have a Microsoft account, you will need to create one. (An Azure account is not needed!) Click to start the free Test Drive. Note: It can take up to 13 minutes for your environment to be built. 3.2 Review the CloudGuard Product Information and Use Cases While your test drive environment is being built, you can: Read the short Check Point CloudGuard for Microsoft Azure Solution Brief https://www.checkpoint.com/downloads/products/cloudguard-microsoft-azure-solution- brief.pdf Visit the Check Point CloudGuard for Microsoft Azure page ©2017 Check Point Software Technologies Ltd. All rights reserved Page | 5 Check Point CloudGuard for Microsoft Azure | Test Drive User Guide https://www.checkpoint.com/products/iaas-public-cloud-security/ Review the key use cases described in section 4 CloudGuard for Azure Use Cases Overview at the end of this guide. 3.3 Information for Accessing the Test Drive Environment When you launch the test drive, you will receive an email containing information that will allow you to connect to your environment. This email includes: