Checkpoint Integrity Advanced Server Manuale utente

Installation Guide
Installing, Configuring, and Maintaining Integrity Advanced Server
1-0276-0650-2006-04-07

Editor's Notes: ©2006 CheckPoint Software Technologies Ltd. All rights reserved.
Check Point, Application Intelligence, Check Point Express, the Check Point logo, AlertAdvisor, ClusterXL, Cooperative Enforcement,
ConnectControl, Connectra, CoSa, Cooperative Security Alliance, FireWall-1, FireWall-1 GX, FireWall-1 SecureServer, FloodGate-1,
Hacker ID, IMsecure, INSPECT, INSPECT XL, Integrity, InterSpect, IQ Engine, Open Security Extension, OPSEC, Policy Lifecycle
Management, Provider-1, Safe@Home, Safe@Office, SecureClient, SecureKnowledge, SecurePlatform, SecurRemote, SecurServer,
SecureUpdate, SecureXL, SiteManager-1, SmartCenter, SmartCenter Pro, Smarter Security, SmartDashboard, SmartDefense,
SmartLSM, SmartMap, SmartUpdate, SmartView, SmartView Monitor, SmartView Reporter, SmartView Status, SmartViewTracker,
SofaWare, SSL Network Extender, TrueVector, UAM, User-to-Address Mapping, UserAuthority, VPN-1, VPN-1 Accelerator Card, VPN-1
Edge, VPN-1 Pro, VPN-1 SecureClient, VPN-1 SecuRemote, VPN-1 SecureServer, VPN-1 VSX, Web Intelligence, ZoneAlarm, Zone
Alarm Pro, Zone Labs, and the Zone Labs logo, are trademarks or registered trademarks of Check Point Software Technologies Ltd. or
its affiliates. All other product names mentioned herein are trademarks or registered trademarks of their respective owners. The
products described in this document are protected by U.S. Patent No. 5,606,668, 5,835,726 and 6,496,935 and may be protected
by other U.S. Patents, foreign patents, or pending applications.

Integrity Advanced Server Installation Guide iii
Contents
Chapter 1:
Integrity Advanced Server Overview .................................................1
Integrity Advanced Server system components ................2
System requirements ......................................................2
Single host deployments ................................................. 2
Clustered Integrity Advanced Server ................................3
Integrity Advanced Server communications ..................... 4
Integrity Advanced Server services and ports ....................4
IAS services details .........................................................6
Chapter 2:
Installing and Configuring the Integrity Advanced Server ......... 7
Clustering Integrity Advanced Servers .............................. 7
Backing up an existing installation ...................................7
Upgrading and Migrating Integrity Advanced Server ........8
Performing a New Integrity Advanced Server
Installation ......................................................................... 8
Configuring the databases and gathering information .....9
Synchronizing Clocks .......................................................12
Running the Installer .......................................................13
Installation Information ...................................................14
Installation types .......................................................... 14
Server Type .................................................................. 14
Server Properties ..........................................................15
Domain Options ............................................................15
Clustering Options ........................................................15
Clustering Information ..................................................15
Database Information ....................................................16
Setting Client Languages ..............................................17
Completing the installation ...........................................18
Configuring the RADIUS Server ......................................18
Prerequisites ................................................................18
Updating the configuration file ...................................... 19
Configuring the properties file .......................................19
Copying the files to the cluster ...................................... 20
Configuring Integrity Advanced Server Cluster Load
Balancer ...........................................................................20
Setting up the virtual server ..........................................20
Setting status verification ............................................21
Using Integrity with a proxy server ..................................22
Updating the logo ............................................................23

Integrity Advanced Server Installation Guide iv
Chapter 3:
Starting and Stopping Integrity Advanced Server ......................24
Managing a Windows Setup ............................................25
Stopping, starting, and resetting the services .................25
Managing a Linux Setup .................................................. 26
Starting, stopping, and restarting the Integrity Advanced
Server ..........................................................................26
Starting, stopping, and restarting the Apache server .......26
Chapter 4:
Migrating Data .................................................................................... 27
Understanding Data Migration ........................................27
Migrated data ...............................................................27
Data that is not migrated ..............................................28
Migrating your Data .........................................................28
Running the Installer .................................................... 29
Completing the Migration Pages ....................................29
Redeploy policies to users .............................................30
Chapter 5:
Setting Up System Event Logs ......................................................31
Understanding events and logging ..................................32
Recommended event logs .............................................33
Using SNMP with Integrity ..............................................36
General Information ......................................................36
Trap Formats ................................................................36
Managing events .............................................................. 37
Creating and editing events ...........................................37
Deleting event ..............................................................37
Sending Logs to the SmartCenter Server ........................ 38
Configuring SmartDashboard .........................................38
Configuring Integrity Advanced Server ...........................39
Creating a Custom Query ...............................................39
Chapter 6:
Testing Integrity Advanced Server ..................................................40
Setting up the Integrity Advanced Server test ................41
Logging on to the Integrity Advanced Server Administrator
Console ........................................................................ 41
Creating a custom user catalog ......................................43
Performing the Integrity Advanced Server Tests ............44
Create, deploy, and assign a new policy to the client ......44
Verifying the Integrity Advanced Server session on the
Integrity client .............................................................. 47

Integrity Advanced Server Installation Guide v
Chapter 7:
Maintaining Integrity Advanced Server .......................................48
Monitor your database tablespace ..................................48
Update your database statistics .....................................48
Optimize query performance .........................................48
Monitor your disk space ................................................48
Index .......................................................................................................50

Integrity Advanced Server Installation Guide 1
Chapter 1
Integrity Advanced Server Overview
This chapter describes Integrity Advanced Server components and communications.
“Integrity Advanced Server system components,” on page 2
“Integrity Advanced Server communications,” on page 4

Integrity Advanced Server Installation Guide 2
Integrity Advanced Server system components
This section provides an overview of the Integrity Advanced Server system components.
Integrity Advanced Server is scalable and can be deployed on one host in smaller
environments or clustered in a server farm on many hosts to support a high volume of
connections in a larger environment.
System requirements
For information about Integrity Advanced Server system requirements, see the Integrity
Advanced Server System Requirements Document on the Check Point Web site.
Single host deployments
Figure 1-1 shows the Integrity Advanced Server system installed on a single host and
configured with the additional components required to operate the system. The
Integrity Advanced Server system components are:
1. Integrity Advanced Server with a configured Apache httpd server
2. Integrity clients (Integrity Flex and/or Integrity Agent)
3. RADIUS server (optional)*
4. Database server*
Figure 1-1: Single Integrity Advanced Server host configuration

Integrity Advanced Server Installation Guide 3
Clustered Integrity Advanced Server
Figure 1-2 shows the Integrity Advanced Server system cluster. In a distributed
installation, Integrity Advanced Server is installed on several different hosts and
configured with the additional components required to operate the system.
The additional system components are:
Load balancer: Routes traffic to/from Integrity Advanced Server.
NTP server (Optional): An internal or external server that ensures all Integrity
Advanced Server hosts have the same time and date.
* These components are not supplied as part of the Integrity Advanced Server distribution, and
must be obtained from a third party. You may use a RADIUS server, or use the Integrity
Advanced Server’s Administrator Authentication feature for authentication.
Use the instructions in Chapter 2, ”Installing and Configuring the Integrity
Advanced Server” to set up all Integrity Advanced Server nodes in a cluster.
Differences between single and clustered configurations are noted.
Figure 1-2: Clustered Integrity Advanced Server Configuration

Integrity Advanced Server Installation Guide 4
Integrity Advanced Server communications
This section explains the internal and external communication protocols and ports
used by the Integrity Advanced Server and the Apache httpd server.
Integrity Advanced Server operations are implemented by separate Integrity services.
An Apache httpd server proxies requests to these services from entities external to
Integrity Advanced Server, such as Integrity clients or administrators logging on to
Integrity Advanced Server from remote computers. The Apache httpd server acts as a
single point of entry, managing requests using SSL, file caching, UDP, and/or TCP
socket off loading functionality (see page 4).
This service and proxy configuration enables Integrity Advanced Server to be set up in
a highly scalable and fault-tolerant clustered environment.
Integrity Advanced Server services and ports
The diagram below represents the services that make up Integrity Advanced Server and
shows which ports the services use.
The services are divided into two types:
Client services allow an Integrity client to get configuration information, policies,
and communicate session state information.
Administration services allow administrators to create groups and users; manage
policies; manage system configuration; and perform other administrative tasks.
Integrity Advanced Server uses the ports listed below to communicate with
Integrity clients. Make sure these ports are all available on the Integrity
Advanced Server:
80
443
6054

Integrity Advanced Server Installation Guide 5
Figure 1-3: Integrity Advanced Server services and ports
Questo manuale è adatto per i seguenti modelli
1
Indice
Altri manuali Checkpoint Server

Checkpoint
Checkpoint 21400 Platform Manuale utente

Checkpoint
Checkpoint 21000 Appliances G-70 Manuale utente

Checkpoint
Checkpoint Smart-1 50 Manuale utente

Checkpoint
Checkpoint Smart-1 25 Manuale utente

Checkpoint
Checkpoint Smart-1 150 Manuale utente

Checkpoint
Checkpoint QUANTUM SMART-1 6000-L Istruzioni operative e di sicurezza

















