1. SSH
ip ssh source-interface <interface to use>
2. Telnet
ip telnet source-interface <interface to use>
R1#telnet 10.9.38.3 22 /source-interface l0
Trying 10.9.38.3, 22 ... Open
SSH-2.0-1.36 sshlib: GlobalScape
3. ping
ping <ip address> source <ip address / interface to use>
4. Traceroute
using extended traceroute:
R1#traceroute
Protocol [ip]:
Target IP address: 10.10.10.10
Source address: 10.11.11.11
Numeric display [n]:
Timeout in seconds [3]:
Probe count [3]:
Minimum Time to Live [1]:
Maximum Time to Live [30]:
Port Number [33434]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Type escape sequence to abort.
Tracing the route to 10.10.10.10
VRF info: (vrf in name/id, vrf out name/id)
1 * * *
The Palo Alto approach requires that traffic be allowed to determine the application, something the Network World Clear Choice test noted "could easily result in unintended consequences and insecure configurations – a valid concern."
--------------------------------------------------------------------------------------------------------------------------------
| PCI DSS Requirements | Testing Procedures |
|---|---|
| 1.3.6 Implement stateful inspection, also known as dynamic packet filtering. (That is, only "established" connections are allowed into the network.) | 1.3.6 Verify that the firewall performs stateful inspection (dynamic packet filtering). (Only established connections should be allowed in, and only if they are associated with a perviously established session.) |
Stateful inspection is being replaced with our new core technology called App-ID, which identifies and classifies applications on the network regardless of port, protocol, evasive tactic or SSL encryption.
CTO, Palo Alto Networks
-----------------------------------------------------------------------------------------------------------------------------
Palo Alto Networks is vulnerable to cache poisoning. For example, a Session Initiation Protocol (SIP) or any other protocol connection can be used as a channel for attacking a company's internal networks. The SIP session could initially be blocked accurately, but by taking advantage of the cache poisoning vulnerability, the SIP session could bypass a Palo Alto firewall. The vulnerability could be exploited as follows:
- HTTP is allowed with firewall policy
- Opening a SIP session typically used with VoIP communications is correctly blocked
- Generating HTTP traffic that causes the cache to hit its threshold – meaning traffic continues going through the cache but is no longer inspected by the firewall
- Switching the HTTP connection to SIP, which is then allowed – and exposes you to risk
Source:
Defcon 2011, Brad Woodberg, Juniper Networks
Defcon 2011, Brad Woodberg, Juniper Networks
---------------------------------------------------------------------------------------------------------------------------
| Product | IP Packet Fragmentation | TCP Stream Segmentation | RPC Fragmentation | URL Obfuscation | HTML Evasion | FTP Evasion | Total |
|---|---|---|---|---|---|---|---|
| Check Point | 100% | 100% | 100% | 100% | 100% | 100% | 100% |
Source: NSS Labs NGFW Test, 2012
| Product | Client Protection | Server Protection | Overall Protection |
|---|---|---|---|
| Check Point | 99% | 97% | 98.3% |
Source: NSS Labs IPS Test, 2012
NSS Labs has released the results of its 2012 IPS Group Test that reviewed Intrusion Prevention System products from eight vendors. Once again, the Check Point IPS performed exceptionally well in the tests, demonstrating top-ranked IPS protection. The Check Point 12600 Appliance IPS protected against 100% of the evasion techniques attempted by NSS Labs."Resistance to known evasion techniques was perfect... IP fragmentation, TCP stream segmentation, RPC fragmentation, URL obfuscation, HTML Evasion and FTP evasion all failed to trick the product into ignoring valid attacks. Not only were the fragmented and obfuscated attacks blocked successfully, but all of them were also decoded accurately."
The Check Point IPS scored an overall protection rating of 98.3%, improving its 97.3% overall protection rating from the 2011 NSS Labs IPS test.
Highlights of Check Point's performance in the NSS IPS Group Test include:
- Superior Security
- Top of the pack with overall protection score of 98.3%
- Strong security with 100% coverage of evasion techniques
- A top score for server protection, 97%
- Best in Class management system that is robust and granular
-------------------------------------------------------------------------------------------------------------------------
- Check Point tracks more than 531 file sharing apps (a critical application category for enterprises), Palo Alto tracks 170.
- Check Point tracks more than 4,733 total apps, Palo Alto tracks 1,511.
- Check Point tracks almost a quarter million widgets, Palo Alto tracks 0.
Check Point tracks more apps, and provides extra granularity of protection because attacks on widgets and configurations go after the individual or specific capabilities of some applications. Palo Alto is supposed to be an "application security expert," so wouldn't you expect its focus on the application layer to provide a complete solution? Consider three prominent examples, such as Poison Ivy, Access Remote PC and Anyplace Control. Check Point has application controls for all three; Palo Alto has none.
The numbers tell the story. Unfortunately, business owners using Palo Alto are left on their own to figure out what to do with untracked apps.
The numbers tell the story. Unfortunately, business owners using Palo Alto are left on their own to figure out what to do with untracked apps.
Palo Alto's limited application coverage is a visibility and security issue.
--------------------------------------------------------------------------------------------------------------------------
NO examination of data in PDF—only 9 file formats are supported
NO identification of non-English characters in .docx (Office 2007 and above documents)
NO protection for customer list or any dictionary larger than 350 items
NO protection for personally identifiable information other than US SSN & CCN
NO protection for HIPAA, GLBA, SEC filings
NO protection for source code, CAD-CAM, ASIC or FPGA designs, patent filings
NO validation for IBAN, tax numbers, service request numbers, etc.
The Palo Alto solution provides incomplete visibility for protecting information and inspecting content. Its technology has limited abilities to deeply inspect a variety of file formats and data types beyond the basics. Why risk your critical corporate data or intellectual property with Palo Alto Networks? Check Point provides you with complete visibility and comprehensive protection.We found that the file blocking was easily fooled. For example, putting a file into a zip archive effectively hid the file type, as did changing the first few bytes of the file (by adding blank lines) and, in one case, changing the filename—which we didn't expect to work.
PAN's promised functionality does not translate to reality in real-world deployments.
Leading Online Investment Firm
PAN's solution is full of holes.
International Film School
--------------------------------------------------------------------------------------------------------------------------
Palo Alto Networks has no built-in central monitoring tools for VPN configuration.
With Palo Alto Networks, each tunnel is configured separately.
A mesh of 30 gateways requires manual set-up of 870 tunnels!
Here's one example of a gap in Palo Alto's security management: its configuration and management of Virtual Private Networks. When setting up VPNs, tunnels must be defined for the VPN connectivity. When configuring Palo Alto VPNs, you are required to manually configure gateways for each tunnel. For 30 security gateways, this would require 870 tunnels. You would need to manually configure each one and develop scripts to stitch them together. Palo Alto does not have built-in centralized monitoring tools for VPN configuration.
Obviously, the manual effort required by Palo Alto will make large deployments very difficult. As noted in its latest Next Generation Firewall product review by Network World: "Large VPN deployments will not want to move to Palo Alto…any large deployment would have to be built entirely by hand".Check Point offers 1-click VPN configuration, which automates the process and improves your productivity. With Check Point, there is no need to manually build and configure 870 individual VPN tunnels! And our SmartView Monitor provides complete visibility into online tunnel status and VPN counters.
Large VPN deployments will not want to move to Palo Alto... any large deployment would have to be built entirely by hand.
Palo Alto Networks doesn't have anything comparable to Check Point Multi-Domain Management.
Major Energy Company












