EasyManua.ls Logo

Check Point MAESTRO R80.20SP - User Manual

Check Point MAESTRO R80.20SP
228 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Loading...
[Classification: Protected]
18 February2020
CHECK POINT MAESTRO
R80.20SP
Administration Guide

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Check Point MAESTRO R80.20SP and is the answer not in the manual?

Summary

Important Information

Latest Software

Recommends installing the most recent software release for improvements and protection.

Latest Version of this Document

Offers links to open the document in a web browser or download it in PDF format.

Introduction

Managing Security Groups

Global Commands

Explains global commands applicable to all or specified Security Appliances in a group.

Check Point Global Commands

Details global commands for working with Security Gateway and SecureXL.

Security Group Concepts

Single Management Object (SMO)

Explains SMO as a technology managing a Security Group as a single gateway.

Installing and Uninstalling Policies

Provides steps for installing and uninstalling policies on Security Groups via SmartConsole and CLI.

Security Appliance Policy Management

Synchronizing Policy and Configuration Between Security Appliances

Details manual synchronization of policies and configurations between Security Appliances.

MAC Addresses and Bit Conventions

Explains the types of MAC addresses and their bit conventions used in the system.

Working with the Distribution Mode

Automatic Distribution Configuration (Auto-Topology)

Describes automatic selection of distribution mode based on Security Group topology.

Configuring the Layer 4 Distribution Mode and Masks (set distribution l4-mode)

Guides on enabling/disabling Layer 4 distribution and setting masks for IP/port.

Logging and Monitoring

CPView

Introduces CPView, a utility for monitoring system statistics and Software Blades.

Network Monitoring

Working with Interface Status (asg if)

Details using the 'asg if' command to manage and view interface status.

Showing Bond Interfaces (asg_bond)

Bond Verification Test (asg_bond -v)

Explains running a bond verification test to check LACP packet tests and consistency.

Showing Traffic Information (asg_ifconfig)

Using the Analyze Option

Demonstrates using the 'analyze' option to view accumulated traffic statistics and distribution.

Showing Multicast Traffic Information

Showing PIM Information (asg_pim)

Provides PIM information in a tabular format, covering source, destination, mode, and state.

Monitoring VPN Tunnels

Performance Monitoring and Control

Global Operating System Commands

Details standard Linux commands that run on all or specified Security Appliances.

Performance Hogs (asg_perf_hogs)

Configuration

Explains how to configure 'asg_perf_hogs' using the performance_hogs.conf file.

The [tests] Section

Describes the [tests] section for enabling/disabling specific performance tests.

Searching for a Connection (asg search)

Searching with the Command Line

Guides on searching for connections using the 'asg search' command line syntax.

Searching with Interactive Mode

Explains how to interactively enter connection search parameters using 'asg search'.

Packet Drop Monitoring (drop_monitor and asg_drop_monitor)

The drop_monitor command

Details using 'drop_monitor' in Expert mode to monitor dropped packets on interfaces in real-time.

Hardware Monitoring and Control

Showing Hardware State (asg stat)

Describes using 'asg stat' to display system and hardware component status.

Monitoring System Resources (asg resource)

Showing System Serial Numbers (asg_serial_info)

Shows how to display serial numbers of all Security Appliances in the Security Group.

Collecting System Diagnostics (smo verifiers)

Diagnostic Tests

Details running diagnostic tests using 'smo verifiers' commands for system health.

Running all Diagnostic Tests

Guides on running all diagnostic tests and interpreting their summary output.

Alert Modes

Diagnostic Events

Discusses how alerts are triggered by failed diagnostic tests and how to manage them.

System Monitoring

Showing the Security Group Version (ver)

Explains how to use the 'ver' command to display the Security Group software version.

Showing System Messages (show smo log)

Details using 'show smo log' to view aggregated log file output from all Security Appliances.

Command Auditing (asg log audit)

Viewing a Log File (asg log)

Explains how to view contents of specified log files using the 'asg log' command.

Working with SNMP

Monitoring Maestro Hyperscale Orchestrators over SNMP

Details using SNMP to monitor Software Versions and Key Performance Indicators of Orchestrators.

Monitoring Security Groups over SNMP

Guides on using SNMP to monitor Software Versions, Hardware Status, and KPIs of Security Groups.

System Optimization

Firewall Connections Table Size for VSX Gateway

Explains configuring the Firewall Connections table limit on Virtual Systems via SmartConsole.

Working with Session Control (asg_session_control)

Session Control

Introduces session control for managing new communication session rates using 'asg_session_control'.

Defining Session Control Rules

Guides on defining session rate rules in the '$FWDIR/conf/control_rules' file.

Installing and Uninstalling a Hotfix

Installing and Uninstalling a Hotfix on Maestro Hyperscale Orchestrators

Provides instructions for installing/uninstalling hotfixes using CPUSE on Orchestrators.

Installing and Uninstalling a Hotfix on Maestro Security Appliances

Installing a Hotfix Package

Describes full connectivity installation of an Offline CPUSE package on Security Appliances.

Troubleshooting

Collecting System Information (asg_info)

Explains using 'asg_info' to collect log files, config, status, and diagnostics.

General Diagnostic in Security Groups

Configuration Verifiers

MAC Verification (mac_verifier)

Details using 'mac_verifier' to ensure virtual MAC addresses match across Security Appliances.

Layer 2 Bridge Verifier (asg_br_verifier, asg_brs_verifier)

Guides on using bridge verifiers to check for configuration problems in Bridge mode Virtual Systems.

Verifying VSX Gateway Configuration (asg vsx_verify)

Explains using 'asg vsx_verify' to confirm VSX configuration consistency across Security Appliances.

Installing the Gaia Operating System on a Maestro Hyperscale Orchestrator

RMA of a Maestro Hyperscale Orchestrator

Configuring High Availability

Setting Security Appliance Weights (Chassis High Availability Factors)

Explains configuring component weights to set relative importance for Chassis health.

Setting the Quality Grade Differential

Guides on setting the minimum quality grade differential that triggers failover.

IP and URL Block Feature

IP Block Feature

Describes using 'ip_block' to block malicious traffic to/from specific IP addresses via feeds.

URL Block Feature

Details using 'url_block' to block malicious traffic to/from specific URLs via feeds.

Check Point MAESTRO R80.20SP Specifications

General IconGeneral
VersionR80.20SP
Maximum Security Gateways per Hyperscale Orchestrator52
SoftwareCheck Point Gaia
Management SoftwareCheck Point Security Management Portal
High AvailabilityYes
Threat PreventionIPS, Anti-Virus, Anti-Bot, Threat Emulation, Threat Extraction
DeploymentData Center
Product TypeHyperscale Network Security Solution

Related product manuals