|
For offshore access, we created a service group
and included all the services under that. Similarly,
we created a group for source networks and destination
hosts. All the offshore rules were thus consolidated
to one rule. This cut down the number of rules
for offshore access from about fifteen to one.
For communication between internal networks,
we created group objects instead of individual
host objects and cut down on number of rules.
Thirdly, we checked unused objects and deleted
all the unused rules and objects from the firewall
rule base to make the rule base clean and up-to-date.
Moreover, two new Nokia IP440 firewalls were
installed in High Availability fashion using Nokia
VRRP configured in monitored circuit option. Checkpoint
FW-1 was loaded on these firewalls in distributed
fashion. This firewall was intended for the new
company that had been created. The rule set from
the current firewalls was migrated to the new
firewall and functionality testing was carried
out to ensure that everything works after the
migration.
Finally, these two firewalls were put into production
and we ensured that the migration was successfully
completed well within the maintenance window.
|