Pages

Monday, July 24, 2017

Gartner Magic Quadrant for Unified Threat Management (2017, 2016, 2015, 2014, 2013, 2012, 2010,...)

Gartner defines the unified threat management (UTM) market as multifunction network security products used by small or midsize businesses (SMBs) (< 1000 employees).

2017 Gartner Magic Quadrant for Unified Threat Management (SMB Multifunction Firewalls)

Not much changes from 2016.
2017 Gartner Magic Quadrant for Unified Threat Management (SMB Multifunction Firewalls)




2016 - Fortinet in Leader Quadrant 7 Years in a Row since 2009

2016 Gartner Magic Quadrant for Unified Threat Management (SMB Multifunction Firewalls)
Fortinet, Check Point and Sophos are in Leader Quadrant this year.


Reference:




2015

Checkpoint named a leader in the Gartner UTM Magic Quadrant 5 years in a row, and since 2008, Checkpoint only missed Gartner UTM 2009's report in leader quadrant.

2015 August, Gartner Magic Quadrant for Unified Threat Management 2015
Reference:

2014 

Gartner has positioned Check Point as a Leader in the Magic Quadrant for the fourth consecutive year in Unified Threat Management (UTM)1.  Actually not big changes from 2013's report. Stormshield replaced Netasq into Visionaries quadrant. 

2013

Figure1: 2013 July, Gartner Magic Quadrant for UTM (Unified Thread Management)

According to Gartner, vendors in the UTM Leaders Quadrant are "at the forefront of making and selling UTM products that are built for midsize business requirements. The requirements necessary for leadership include a wide range of models to cover midsize business use cases, support for multiple features, and a management and reporting capability that's designed for ease of use. Vendors in this quadrant lead the market in offering new safeguarding features, and in enabling customers to deploy them inexpensively without significantly affecting the end-user experience or increasing staffing burdens. These vendors also have a good track record of avoiding vulnerabilities in their security products. Common characteristics include reliability, consistent throughput, and a product that's intuitive to manage and administer."


Checkpoint is continuing its leader position in 2013 Gartner's Unified Threat Management (UTM) Magic Quadrant for the third consecutive year.

2012

Figure2: 2012 March,  Gartner Magic Quadrant for UTM (Unified Thread Management)

2010 - Checkpoint Came back into Leader Quadrant

Figure 3: 2010 Oct, Gartner Magic Quadrant for UTM (Unified Thread Management)

2009 - Checkpoint was not named into leader, but in niche players quadrant. 


Figure 4: 2009 June Gartner Magic Quadrant for UTM (Unified Thread Management)
Note: This year, Checkpoint was not rated by Gartner as Leader Quadrant

2008


Figure 5: 2008 Nov, Gartner Magic Quadrant for UTM (Unified Thread Management)


Wednesday, July 5, 2017

Gartner Magic Quadrant for the Wired and Wireless LAN Access Infrastructure (2016, 2015, 2014, 2013, 2012, 2011, 2010)

Gartner’s Magic Quadrant for Wireless LAN Infrastructure has been released for a couple of years. This post listed all reports found from Internet since 2010. If you are not familiar with this research publication or Gartner, please see graphic below. Gartner places vendors in one of four quadrants – Leaders, Visionaries, Niche Players and Challengers based on their score system.

Understanding Gartner Magic Quadrant Report
Source: Gartner (July 2013)

2016

No changes on Leaders Quadrant. Fortinet got into challenger. 

2015

HP spent $2.7 billion to buy Aruba on March 2, 2015.   Huawei becomes challengers. 

Magic Quadrant for the Wired and Wireless LAN Access Infrastructure 2015

2014

In Gartner 2014 June's Magic Quadrant for Wired and Wireless LAN Infrastructure report, for the 3rd year in a row, Cisco, Aruba and HP Networking are positioning at Leaders quadrant, which are same as last two years. On May 19, 2015, HP completed the acquisition of Aruba Networks for a transaction value of $3 billion. In Gartner's 2015's report, there will be only two vendors showing in the Leaders quadrant.

Huawei, Dell and D-link lost their challengers position and become niche players. Aerohive, Acatel-Lucent Enterprise, Ximus and Avaya are in visionaries quadrant, which means they have innovated in one or more of the key areas of access layer technologies within the enterprise (e.g., convergence, security, management or operational efficiency).


2014 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2014 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure

2013 

2013 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2013 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure

2012


2012 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2012 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure

2011


2011 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2011 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure

2010

2010 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2010 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure


Reference:

1. 2014 Magic Quadrant for the Wired and Wireless LAN Access Infrastructure
2. Magic Quadrants and MarketScopes: How Gartner Evaluates Vendors Within a Market

Thursday, May 18, 2017

Using Artica Squid Open Source Project to Build Powerful and Safe but Simple to Use Proxy

Looking for a pre-installed GUI based Proxy for a while and found Artica recently. The feature is pretty attractive and GUI interface looks cool.

What is Artica?
"Artica Proxy is an appliance that claim to manage Squid-cache proxy with all features that Squid Cache provides.With the Artica Web interface you can monitor, manage get statistics of your proxy service.
Artica Proxy provides ISOs in order to build a full proxy appliance without any technical skills.
Artica Proxy allows to enable Web filtering engine with more than 30.000.000 categorized websites.

Other features included such as reverse-proxy, RDP proxy, VPN, DHCP, DNS..."
Here are some my experience on it.

1. Download Link:
 http://artica-proxy.com/telechargements/

There are ISO, ESXi, Hyperv, Xen versions to download.


2. Installation in Vmware Workstation 
In this post I am using Vmware Workstation 10 to do installation based on Artica Proxy CD-ROM ISO. The vm's configuration is set as following:


Hard Drive = 20G
CPU = Dual CPU with 2 Core
Memory = 3G
Delete other unused hardware such as printer, usb and sound card.



Full installation will take 15- 20 minutes depends on your host performance. Basic configuration wizard will take you 5 minutes to get a full functional Proxy for your internal machines.

2.1 Update to latest release



Current IOS version is 3.03.041314. It can be upgraded to 3.06.050915 by some clicks.


3. Test Proxy



Config client IE proxy with 192.168.236.100 on port 3128.


By default, Artica proxy will allow all internal machines to use proxy to surf internet. You wont need to do too much work to get all your clients to use this new proxy.


4. Artica Support

Artica Support is amazing. I have been tried to open tickets in their tracker system, in next a couple of hours they posted videos to answer my dummy questions. Artica also has a forum to let users discuss there.

5. Configuration Examples

Example 1: Using ACLs
1.1 Default block everything from Internal to Internet
1.2 Create a specific rule to allow one machine 192.168.5.53 to access some specific sites based on IP addresses or URL Domain names



Example 2: Using Web-Filtering
2.1 Default block everything from Internal to Internet
2.2 Create a specific rule to allow one machine 192.168.1.136 to access to categories News and Search Engines only





6. Reference























Friday, May 12, 2017

Configure Netflow on network devices for PRTG Netflow Monitoring

Netflow is a feature first introduced into Cisco routers and switches and then flow concept has been widely accepted by other network product vendors. Basically the network devices which support xflow feature can collect IP traffic statistics on the interfaces where xFlow is enabled, and export those statistics as xFlow records to remote defined xFlow collector.

PRTG can use this NetFlow feature for detailed bandwidth usage monitoring and it also shows you:
  • where your bandwidth is used
  • who is using it
  • how it is being used
  • why it is being used
It lets you see which specific applications are being used and how the usage might affect your network. NetFlow monitoring is included in all PRTG Network Monitor licenses, which means no special license to enable this feature. It will be counted into your sensors license.



PRTG support most xFlow (NetFlow, IPFIX, sFlow, jFlow)  protocols with their flow sensors.


1. Example Configuration for Cisco Routers and Switches:

1.1 Cisco Routers Example

This configuration is old platform and IOS. 
router-2621(config)#interface FastEthernet 0/1
router-2621(config-if)#ip route-cache flow
router-2621(config-if)#exit
router-2621(config)#ip flow-export destination 192.168.1.101 9995
router-2621(config)#ip flow-export source FastEthernet 0/1
router-2621(config)#ip flow-export version 5
router-2621(config)#ip flow-cache timeout active 1
router-2621(config)#ip flow-cache timeout inactive 15
router-2621(config)#snmp-server ifindex persist
router#show ip flow export
router#show ip cache flow

note: Please note that NetFlow data export has to be enabled on all interfaces of a router in order to see accurate IN and OUT traffic.


1.2 Cisco Switches (4510) Example

flow record PRTG-FLOW
match ipv4 tos
match ipv4 protocol
match ipv4 source address
match ipv4 destination address
match transport source-port
match transport destination-port
match interface input
collect interface output
collect counter bytes
collect counter packets
collect timestamp sys-uptime first
collect timestamp sys-uptime last
!
flow exporter PRTG-EXPORTER
description NETFLOW Export to PRTG
destination xxx.xxx.xxx.xxx
source Loopback0
transport udp 2055
export-protocol netflow-v9
!
flow monitor PRTG-MONITOR
description PRTG Netflow Monitor
record PRTG-FLOW
exporter PRTG-EXPORTER
!
interface vlan xxxx
ip flow monitor PRTG-MONITOR input
!ip flow monitor PRTG-MONITOR output
! Cisco switch 4510 does not support Netflow output option

2. Configuration for Cisco ASA firewalls

access-list global_mpc extended permit ip any any
!
flow-export destination inside 192.168.1.101 9995
!
class-map global_class
  match access-list global_mpc
!
policy-map global_policy
  class global_class
   flow-export event-type all destination 192.168.1.101
note:In fact Cisco ASA only support version 9. ASA NetFlow was never intended to be used for real time/live traffic analysis. On the Cisco forums web page the official statement is: "[...] NetFlow on the ASA does not provide the ability to see this data in real time. The data can be collected after the flow has been terminated and analyzed but we do not support real time viewing of the NetFlow records. [...] The total bytes transferred can only be seen after the flow is torn down. [...] Lastly, all flows on the ASA are bidirectional. All counters for a flow will increase for traffic flowing from A->B or B->A. [...] NetFlow has a significant performance impact."

3. Configuration for Check Point Gaia Firewalls

SecurePlatform doesn't support NetFlow but Gaia is fully supporting it.


Check Point CLI Commands Example:

To add a collector:

add netflow collector ip VALUE port VALUE [srcaddr VALUE export-format VALUE]

To delete a collector:

delete netflow collector [for-ip VALUE [for-port VALUE]] 

To change settings of a collector:

set netflow collector [for-ip VALUE [for-port VALUE]]
   export-format VALUE
   srcaddr VALUE

set netflow collector [for-ip VALUE]
   port VALUE

set netflow collector
   ip VALUE

To see NetFlow configurations:

show netflow all
show netflow collector [for-ip VALUE [for-port VALUE]]
show netflow collector [for-ip VALUE [for-port VALUE]]
   export-format
   srcaddr
show netflow collector [for-ip VALUE] port
show netflow collector ip

4. Configuration Example for Juniper SRX Firewalls

Jflow Version 9
set services flow-monitoring version9 template ipv4-test ipv4-template
set forwarding-options sampling input rate 100
set forwarding-options sampling input run-length 0
set forwarding-options sampling family inet output flow-server 10.9.1.13 port 9996
set forwarding-options sampling family inet output flow-server 10.9.1.13 version9 template ipv4-test
set forwarding-options sampling family inet output inline-jflow source-address 10.9.1.26
set interfaces reth2 unit 0 family inet sampling input

Jflow Version 5
set interfaces reth2 unit 0 family inet sampling input
set interfaces reth2 unit 0 family inet sampling output
set forwarding-options sampling input rate 100 
set forwarding-options sampling family inet output flow-server 10.9.1.13 port 9996
set forwarding-options sampling family inet output flow-server 10.9.1.13 version 5

5. PRTG Sensor Configuration





Reference:

1. Configuring Cisco ASA NetFlow via ASDM
2. Check Point GAiA NetFlow Configuration
3. Configuring Netflow Export - CLI (netflow)
4. How can I use a trusted SSL certificate with the PRTG web interface?

Monday, April 17, 2017

Check Point Firewall Memory Issue


During regular firewall health check , I found one Check Point firewall cluster has a abnormal virtual memory usage from System Counters - System History view.  The cluster is 5600 Security Appliance.

It looks the memory usage is going up significantly recently. There is no recent changes on hardware, software and configuration except normal firewall changes. I am afraid of Check Point gateway will freeze after this counter reached certain high number based on some SKs such as sk66482, sk110362,

sk35496 lists a bunch of methods how to detect memory leak. In my this specific case, the fix was simple, just installed a latest Jumbo Hotfix 205 for R77.30.



Sympotoms: 
Here are some screenshots I took from Smartview Monitor
System Memory Going High for last 30 days


System Memory Going High for six months

Solution:
Suggestion I got from Check Point is to apply latest Jumbo Hotfix 205 rather than existing Jumbo Hotfix 159.


Install Latest Jumbo Hotfix from CPUSE
You may get some issues while installing your new patches/hotfixes. Here is what I met.
Patch/Hotfix Installation Failed
 I have to unintall Jumbo Hotfix 159 first. Unfortunately, uninstall Jumbo Hotfix 159 also failed from CPUSE.

Uninstall Hotfix Failed

I had another post regarding "How to uninstall a CheckPoint Hotfix after a failed installation". But in this case, the cause is hotfix for sk112829 is installed after Jumbo Hotfix 159 applied. After I uninstalled Hotfix for SK112829, uninstall Jumbo Hotfix 159 was able to complete. Also Installation Jumbo Hotfix 205 was successful too.

Uninstall Successed


Waited a couple of days , I checked the used virtual memory is normal now.
Memory High Issue Fixed


Reference: