|
Home
>
Rex Global Solutions
>
Check Point Solutions
> Check Point Firewall-1
Checkpoint Firewall-1
VPN-1 Gateway
The Challenge
With its
worldwide reach, the Internet provides a flexible and cost-effective
infrastructure for extending the corporate network to all employees and
key business partners. In order for corporations to take full advantage
of the Internet, however, they must be able to guarantee both the
security of business communications and the protection of internal
network resources.
In
addition to security, companies
extending the reach of their
networks also face challenges of
availability, performance, and
scalability. For mission-critical
applications to utilize VPN (Virtual
Private Network) technologies, the
VPN must provide reliable
performance and seamless fault
tolerance. Extranet VPNs pose the
additional challenge of achieving
interoperability between solutions
from different vendors. Finally, all
components of a VPN must be easily
integrated and managed within the
overall enterprise security
infrastructure.

VPN-1 Gateway
Provides a scalable,
high-performance solution meeting
the needs of corporate networks,
remote and mobile workers, and
satellite offices.
The Solution
VPN-1
Gateway is a tightly integrated software solution combining the
market-leading FireWall-1 security suite with sophisticated VPN
technologies. The cornerstone of Check Point's Secure Virtual Network
architecture, VPN-1 Gateway meets the demanding requirements of
Internet, intranet, and extranet VPNs by providing secure connectivity
to corporate networks, remote and mobile users, satellite offices, and
key partners. VPN-1 Gateway software may be deployed on a range of
platforms for maximum flexibility and scalability.
VPN-1 Gateway supports sophisticated
high availability configurations for
IPSEC traffic, and provides built-in
resiliency for remote access VPNs.
Extranets are made possible through
support for industry standards as
well as all leading PKI products and
services. For superior performance,
VPN-1 Gateway solutions may also
include bandwidth management,
compression, and hardware-based VPN
acceleration.
|
Product Features |
-
Protects data communications
with industry-standard
encryption, authentication,
and key management schemes
-
Secures valuable corporate
resources with FireWall-1
-
Enables centralized,
integrated, policy-based
management of the entire
enterprise security policy
-
Includes advanced OpenPKI
support, integrated
bandwidth management,
compression, and
sophisticated High
Availability solutions
|
|
Product Benefits |
-
Ensures maximum security for
corporate resources and
Internet communications
-
Lowers cost of connecting
mobile workers,
telecommuters, and branch
offices
-
Eases network security
management and reduces
administrative overhead
-
Provides scalability,
reliability, and superior
performance for
mission-critical VPN's
|
Security
Check Point VPN-1 Gateway integrates
access control, authentication, and
encryption to guarantee the security
of network connections, the
authenticity of local and remote
users, and the privacy and integrity
of data communications.
Access Control
Based on the
market-leading FireWall-1, Check Point VPN-1 Gateway supports more than
150 pre-defined applications, services, and protocols out of the box.
VPN-1 Gateway secures all popular Internet services, including the most
commonly used applications like HTTP, SMTP, Telnet, and FTP; the entire
TCP family of applications; and connectionless protocols such as UDP. In
addition, VPN-1 Gateway supports important business applications such as
Oracle SQL, multimedia applications such as RealAudio, and Voice over IP
(VoIP) services such as H.323.
Supported User Authentication
Schemes
|
|
User Authentication Scheme |
Verification Mechanism |
|
RADIUS |
Supports multiple authentication
methods |
|
TACACS/TACACS+ |
Supports multiple authentication
methods |
|
Token-based (two factor) |
Uses hardware token and password |
|
Operating System Password |
Standard OS password |
|
FireWall-1 Password |
FireWall-1 gateway password |
|
S/Key |
Seed-based one-time passwords |
|
Digital Certificates |
Validated by checking the CA?s
signature |
|
|
Supported Data Authentication
Schemes
|
|
Data Authentication Scheme |
Key Length |
Hash Length |
|
CBC-DES-MAC |
56-bit |
64-bit |
|
MD5 |
128-bit |
128-bit |
|
SHA-1 |
160-bit |
160-bit |
|
|
Supported Key Management Schemes
|
|
Scheme |
Process |
Description |
|
IKE (ISAKMP/Oakley) |
Automatic |
Optional key management scheme
for IPv4, mandatory for IPv6 |
|
FWZ |
Automatic |
Internal or external CA/PKI
automatically establishes
security associations and
updates public keys |
|
SKIP |
Automatic |
Optional key management scheme
for IPv4 |
|
Manual IPSec |
Manual |
All security associations & keys
distributed manually |
Authentication
One of the
most important requirements of a VPN solution is the ability to verify
the identity of the person using the VPN. Once users successfully
authenticate themselves, they gain secure access to network resources
such as email, internal Web servers, NT domain resources, and database
applications.
For maximum
security and flexibility, VPN-1
Gateway provides integrated support
for multiple user authentication
methods. User authentication can be
accomplished using smart cards,
token-based products like SecurID,
LDAP-stored passwords, RADIUS or
TACACS+ servers, pre-shared secrets,
X.509 digital certificates, or even
advanced biometric techniques. In
addition, Check Point provides the
Secure Authentication API (SAA), an
open application programming
interface that enables third-party
security vendors to integrate their
leading-edge solutions with VPN-1.
VPN-1 Gateway
provides additional flexibility by
enabling organizations to utilize
any supported authentication method
in conjunction with the Internet Key
Exchange (IKE) for IPSec VPN
deployments.
Encryption
Once secure
network access has been granted, a VPN solution must protect the privacy
of the data being transmitted. By adhering to the IPSec standard, VPN-1
Gateway automatically negotiates the strongest possible encryption and
data authentication algorithms available between communicating parties.
This includes both DES and Triple DES for data encryption, and SHA-1 and
MD5 for data authentication. In addition, encryption keys are updated
frequently, ensuring maximum security and providing Perfect Forward
Secrecy (PFS) so that older encryption keys cannot be used to
decipher more recent communications.
Supported Encryption Algorithms
|
|
Encryption |
Key Length |
|
RC4-40 |
40-bit |
|
CAST-40 |
40-bit |
|
FWZ-1 |
48-bit |
|
DES-40 |
40-bit (32-bit IV) |
|
DES |
56-bit |
|
CAST |
128-bit |
|
Triple DES |
168-bit |
|
RSA Keys |
512/1024-bit |
|
Diffie-Hellman Keys |
512/1024-bit |
Public
Key Infrastructure (PKI) Support
Public Key Infrastructures provide
the necessary management
infrastructure for large IPSec VPN
deployments by enabling the use and
management of keys and digital
certificates. By adhering to
industry standards such as X.509,
PKIs also ensure the highest levels
of security and interoperability as
organizations expand their networks
through remote access and extranet
VPNs.
Interoperability Through OpenPKI
VPN-1's OpenPKI support allows
customers to choose the PKI solution
that best fits their needs. OpenPKI
ensures that VPN-1 Gateways, as well
as VPN-1 Appliances and client
solutions, are compatible with all
leading PKI products and services.
PKI solutions from vendors such as
Entrust, Verisign, Baltimore
Technologies, and Netscape are being
certified as part of Check Point's
OPSEC (Open Platform for Security)
Alliance.
Concurrent Support for Multiple Vendors Certificate Authorities
VPN-1 Gateway enables the
establishment of heterogeneous
extranets by supporting the
simultaneous use of digital
certificates from multiple CAs
(Certificate Authorities). This
capability is absolutely critical to
successful deployment of a VPN
involving multiple companies, since
each company may have a different
VPN solution in use. Concurrent
certificate support allows a single
VPN-1 Gateway to simultaneously
establish multiple IPSec connections
with gateways using different
vendors VPN and PKI solutions.
Scalability
Check Point
VPN-1 deployments scale to accommodate large numbers of VPN nodes either
users or remote sites. Because VPN-1 Gateway software runs on a variety
of platforms and operating systems, organizations can choose the
deployment platform that best meets their current and projected needs.
Furthermore, by supporting standards-based directory and PKI
infrastructures, VPN-1 solutions are able to support large, open VPN
communities with minimal management overhead.

|