150 likes | 338 Views
StoneBeat Training Classroom Requirements For StoneBeat FullCluster V2.0 and StoneBeat V3.1.5. SERVER. StoneBeat 4 Site Classroom. Site 1. Site 2. CLIENT. CLIENT. Site 4. Site 3. CLIENT. CLIENT. General issues. Each site consists of 2 firewall nodes and test client
E N D
StoneBeat Training Classroom Requirements For StoneBeat FullCluster V2.0 and StoneBeat V3.1.5
SERVER StoneBeat 4 SiteClassroom Site 1 Site 2 CLIENT CLIENT Site 4 Site 3 CLIENT CLIENT
General issues • Each site consists of 2 firewall nodes and test client • Firewall nodes in one site need to run identical OS’s (both Windows NT and Solaris are acceptable) • Maximum 3 students per site (2 recommended) • ie. maximum 12 students per 4 site classroom (8 recommended) • Firewall nodes have to run supported HW and SW • Stonesoft provides licenses for own products and underlying firewall SW, partner is responsible for OS licensing • Video projector for the training presentations • Instructor will use PowerPoint slides from laptop
General Issues • Instructor will need to have own laptop for presentation • Stonesoft will provide student handbooks and other printouts as agreed • Routing • Use static routes from firewall nodes to all others internal nets • Use static routes from FTP server to all internal nets
Example Configuration for StoneBeat FullCluster V2.0 Training (Site 1) FTP/WWW -SERVER 204.32.38.254 204.32.38.101 (204.32.38.1) 204.32.38.102 (204.32.38.1) SBFC101 192.168.1.101 SBFC102 192.168.1.102 (10.0.1.1)10.0.1.101 (10.0.1.1) 10.0.1.102 FTP-CLIENT1 SMTP SERVER 10.0.1.254 Cluster IP addresses will be added later (<IP address>)
Example Configuration for StoneBeat FullCluster V2.0 Training (Addressing) • IP addressing • External IP space • 204.32.38.0 mask 255.255.255.0 • Internal IP spaces • 10.0.1.0 mask 255.255.255.0 • 10.0.2.0 mask 255.255.255.0 • 10.0.3.0 mask 255.255.255.0 • 10.0.4.0 mask 255.255.255.0 • Control IP spaces • 192.168.1.0 mask 255.255.255.0
Classroom Requirements • Hardware • For each site • 2 firewall nodes with monitors, keyboards, mice • 3 supported ethernet interfaces in each • 1 client machine with monitor, keyboard, mouse • 1 external hub (100Mb recommended) • 1 internal hub (100Mb recommended) • 1 control hub or cross link ethernet cable • 6 - 8 ethernet cables (8 if control hub 6 if not) • Shared • 1 FTP/WWW -server • 1 hub for the FTP server (100Mb recommended)
Classroom Requirements • Software • Operating systems - choose from • Windows NT 4.0 with SP4 or later • Solaris 2.6 with suggested patches • Solaris 7 32-bit mode with cluster patches • Red Hat Linux 6.1 • The software that will be clustered • Firewall-1, Gauntlet, Raptor, • StoneBeat FullCluster V2.0 software • LICENSES for every product
Example Configuration of StoneBeat V3.1.5 (Site 1) FTP/WWW -SERVER 10.0.0.254 10.0.0.1 10.0.0.1 SBC101 204.32.38.101 SBC102 204.32.38.102 192.168.1.1 192.168.1.1 FTP-CLIENT1 192.168.1.254
Example Configuration of StoneBeat V3.1.5 (Addressing) • IP addressing • External IP space • 192.168.1.0 mask 255.255.255.0 • Internal IP spaces • 10.0.1.0 mask 255.255.255.0 • 10.0.2.0 mask 255.255.255.0 • 10.0.3.0 mask 255.255.255.0 • 10.0.4.0 mask 255.255.255.0 • Control IP spaces • 204.32.38.0 mask 255.255.255.0
Classroom Requirements • Hardware • For each site • 2 FW nodes with monitors, keyboards, mice • 3 supported ethernet interfaces in each • one serial interface for backup heartbeat (optional) • 1 client machine with monitor, keyboard, mouse • 1 external hub (10Mb or 100Mb) • 1 internal hub (10Mb or 100Mb) • 1 control hub or Cross link ethernet cable • 6 - 8 ethernet cables (8 if control hub 6 if not) • Shared • 1 FTP/WWW -server • 1 hub for the FTP server (100Mb recommended)
Classroom Requirements • Software • Operating system • Windows NT 4.0 with SP4 or later • Solaris 2.5.1, 2.6 or 7 SPARC • HP-UX 10.20 or 11 • IBM AIX 4.2.1, 4.3.2 or 4.3.3 • Check Point FireWall-1 • StoneBeat V3.1.5 software • LICENSES for FireWall-1 and StoneBeat
The basic tests • Always test the classroom before training begins • Ping every IP from every IP • Ping all FTP clients fron FTP server • Install firewall rulebases • See systemlog messages after boot • Check that there no issues with licenses