eBook | Guide to Hyperscale Network Security | Check Point Software

eBook | Guide to Hyperscale Network Security

THE GUIDE TO HYPERSCALE NETWORK SECURITY Learn how modern high-availability firewall clusters provide maximum security, resilience, and scalability for enterprises, e-commerce sites, service providers, data centers, and more.

Contents

Introduction: Achieving Maximum Security Resilience

Modern organizations need robust cyber security to protect their critical systems. At the same time, their security needs to scale performance up or down as network requirements change. Unfortunately, most organizations still rely on 15+ year old designs that use classic high availability (HA) firewall clustering to achieve a degree of resilience and failover - at the cost of overbuilding infrastructure that sits idle and is more complex.

In this paper, we’ll discuss the challenges in achieving 99.999% resilience and the key benefits of adopting hyperscale network security. Resilience is a measure of a security system’s ability to maintain critical capabilities quickly and effectively when faced with adverse events and conditions. Implicit in this definition is the idea that adverse events and conditions will occur. Therefore, system resilience is a system’s ability to detect, respond and recover when the unexpected happens.

Examples:

Real-world examples include mass scale events that require on-site staff to work from home, seasonal or unpredictable bursts of application traffic, a power blackout, a cut network cable, or a new zero-day vulnerability targeting critical applications. Smart organizations prepare and weigh the risk of these occurrences by designing and deploying resilient systems. The most basic designs eliminate single points of failure, yet often overlook the inability of their systems to easily scale capacity and manage increased load on the system.

This paper provides an overview of approaches for building resilient and scalable network security, starting with a review of High Availability (HA) firewalls and the different ways they can be configured to ensure resilience and graceful failover. We compare traditional HA firewalls with modern hyperscale network security which enables cloud-like elasticity and scalability for on-premises environments and private clouds. Finally, we discuss Check Point solutions for enterprises and service providers who need highly resilient and scalable network security solutions.

The Challenges with Traditional High Availability (HA) Designs

High Availability (HA) firewall clusters are designed to minimize downtime for critical systems through the use of redundant systems. The goal of a HA firewall deployment is to eliminate single points of failure within an organization’s network infrastructure. Instead of using a single firewall to protect the network, two or more firewalls are deployed in a group as a cluster.

Clustering Options for Failover and Redundancy

HA firewalls can maximize the availability of critical services using various clustering node configurations. Common configurations include:

Clustering Node Configurations

Levels of Redundancy

Figure 1: Active-Active vs Active-Passive Firewall Clusters

Load Balancing and Load Sharing for Maximum Security Performance

Load balancing implies that all nodes in the system are active all of the time. In addition to Active/Passive, most firewall vendors also offer an Active/Active solution which shares the aggregate traffic load across the cluster members using a load balancing technology. This can limit the ability to scale beyond a certain number of firewall members within the cluster.

Distributing traffic (load balancing) across firewalls requires some management overhead which can impact the firewall’s performance. The load sharing management overhead increases as members are added to the cluster. Therefore, there can be a tradeoff depending on the network and security design.

Figure 2: Load balancing single-vendor solution

However, this approach creates additional firewall management challenges, including asymmetric routing and managing encrypted traffic. Another challenge is that multiple products, i.e., the Load Balancers and the firewalls, increase the initial capital expense and the time and resources to manage and maintain the more complex solution.

The Problem with Asymmetric Routing

Asymmetric routing, simply stated, happens when packets of a session have different Forward and Return paths. The problem with asymmetric routing is that network devices such as firewalls must track the state information of packets, e.g., is the packet a first handshake or mid-stream in an established connection? For instance, a packet that exits a network through Firewall-A but returns to the network through another Firewall-B will get dropped on the return route because Firewall-B has no state information for the packet.

Another alternative to a single-vendor Active/Active load sharing cluster, is to deploy multiple firewalls “sandwiched” between Server Load Balancers, also called Application Delivery Controllers (ADC). In this architecture, network traffic is load balanced across the group of firewalls, providing a scalable and highly available security infrastructure. The Server Load Balancers direct traffic equally across the firewall members of the cluster.

Key Benefits of Hyperscale Network Security

Who Needs Resilient, Hyperscale Firewall Protection?

Whether starting out, or already a firmly established enterprise, a Hyperscale Network Security solution is the best way to secure and protect an organization’s current and future investments. Scenarios where highly resilient, load balancing, scalable firewall architectures are valuable include:

Check Point’s Intelligent HA and Hyperscale Network Security

Check Point offers multiple solutions for customers looking to deploy HA firewalls and implement load balancing with Hyperscale network security capabilities.

OPTION 1

HA with Intelligent Load Balancing Integrated into the Standalone Firewalls
If an organization wants to implement a simple HA firewall cluster with up to 5 nodes, this can be accomplished using Check Point’s built-in HA and load sharing functionality.

OPTION 2

Hyperscale for the Most Demanding Environments with Check Point Maestro
Check Point’s Quantum Maestro is a High-Availability firewall clustering solution that delivers fully integrated, scalable, intelligent load balancing that does not require third party Server Load Balancers. With Maestro, multiple firewalls can operate as a single unified system.

Maestro’s Key Benefits at a Glance

Maestro Feature Summary

Managing Risks Effectively Across On-Premises and Cloud with Consolidated Threat Prevention

Cyber hackers have evolved to using advanced technologies, including AI and internet bots, to attack at scale from multiple vectors simultaneously. For effective cyber defense, organizations need a multi-faceted approach that shifts the operating model from reactive fire-drills to proactive security.

Check Point leverages the power of AI, cloud, and global threat intelligence across its entire security portfolio to quickly block attacks...

Check Point’s Web Application Firewall
CloudGuard WAF is a cloud-native Web & API security solution that provides precise threat prevention using contextual AI to protect your Apps against known and unknown threats.

Advantages of a Unified Firewall Cluster Architecture

Consolidation offers a strong solution and Check Point has the first modern, consolidated security platform specifically designed to guard against modern-day threats.

Getting Started with Maestro

Data centers and other demanding environments will benefit from a highly resilient, load balancing, scalable firewall architecture. Maestro is also designed for businesses of all sizes who want to scale their protection according to their changing business needs.