58
Kako povečati varnost omrežja s Forefront TMG Jože Markič, Kompas Xnet d.o.o. [email protected]

Kako povečati varnost omrežja s Forefront TMG

  • Upload
    oren

  • View
    44

  • Download
    0

Embed Size (px)

DESCRIPTION

Kako povečati varnost omrežja s Forefront TMG. Jože Markič, Kompas Xnet d.o.o. joze.markic@kompas - xnet.si. Agenda. Kaj je TMG? TMG postavitve Primerjava z ISA Subscriptions Secure Web Gateway HTTPS inspection URL filtering Malware protection Intrusion prevention. - PowerPoint PPT Presentation

Citation preview

Page 1: Kako povečati varnost omrežja s  Forefront  TMG

Kako povečati varnost omrežja s Forefront

TMG

Jože Markič, Kompas Xnet [email protected]

Page 2: Kako povečati varnost omrežja s  Forefront  TMG

2

Agenda

• Kaj je TMG?• TMG postavitve• Primerjava z ISA• Subscriptions• Secure Web Gateway

o HTTPS inspectiono URL filteringo Malware protectiono Intrusion prevention

Page 3: Kako povečati varnost omrežja s  Forefront  TMG

Forefront Edge Security and Access Products

Before Now

Network Protection

Network Access

The Forefront Edge Security and Access products provide enhanced network edge protection and application-centric, policy-based access to corporate IT infrastructures

Integrated and comprehensive protection from Internet-based threats

Unified platform for all enterprise remote access needs

Page 4: Kako povečati varnost omrežja s  Forefront  TMG

Forefront TMG Value PropositionFirewall – Control network policy access at the edge

Secure Web Gateway – Protect users from Web browsing threats

Secure E-mail Relay – Protect users from e-mail threatsRemote Access Gateway – Enable users to remotely access corporate resourcesIntrusion Prevention – Protect desktops and servers from intrusion attempts

Comprehensive

Integrated

Simplified

Page 5: Kako povečati varnost omrežja s  Forefront  TMG

Forefront TMG Deployment Scenarios• All-in-one solution for medium

businesses• Firewall, VPN, Web security, IPS, e-mail

relay in a single box

Unified Threat Management

(UTM)

• Authenticating proxy with security• Web antivirus and URL filtering• Inspection of HTTP and HTTPS traffic

Secure Web Gateway

• Secure Web publishing• Dial-in VPN• Site to site VPN

Remote Access Gateway

• Antispam• Antivirus• E-mail filtering

Secure E-mail Relay

Page 6: Kako povečati varnost omrežja s  Forefront  TMG

Features Summary

• VoIP traversal• Enhanced NAT• ISP link redundancy

Firewall

• HTTP antivirus/antispyware

• URL filtering• HTTPS forward inspection

Secure Web Access

• Exchange Edge integration

• Antivirus• Antispam

E-mail Protection

• Network inspection system

Intrusion Prevention

• NAP integration with client VPN

• SSTP integration

Remote Access

• Array management• Change tracking• Enhanced reporting• W2K8, native 64-bit

Deployment and Management

• Malware protection

• URL filtering• Intrusion prevention

Subscription Services

Page 7: Kako povečati varnost omrežja s  Forefront  TMG

Network layer firewallApplication layer firewallInternet access protection (proxy)Basic OWA and SharePoint publishing

IPSec VPN (remote and site-to-site)

Web caching, HTTP compression

Web antivirus, antimalware

URL filtering

E-mail antimalware, antispamNetwork intrusion prevention

Features SummaryComparing with ISA Server 2006ISA Server

2006ForefrontTMG

NewNewNewNew

Enhanced UI, management, reporting New

Exchange publishing (RPC over HTTP)

Windows Server® 2008 R2, 64-bit (only) New

Page 8: Kako povečati varnost omrežja s  Forefront  TMG

E

Forefront TMG LicensingTwo editions and Two Client Access Licenses (CALs)

Standard EditionFull UTM

Enterprise Edition Scalability and management

Web protection E-mail protection

Subscriptions

Page 9: Kako povečati varnost omrežja s  Forefront  TMG

Comparing Forefront TMG EditionsStandard Edition Enterprise Edition

Number of CPUs Up to 4 CPUs Unlimited

Array/NLB/CARP support

Enterprise management

Yes, with added ability for EMS to manage SEs

Publishing

VPN support

Forward proxy/cache, compression

Network IPS (NIS)

E-mail protection Requires Microsoft® Exchange Server License (Server + CALs)

and installation by the admin

Page 10: Kako povečati varnost omrežja s  Forefront  TMG

Subscriptions

• Subscription-based licenseso Sold as Client Access Licenses (CALs) o Charged per user/per year

• Protection Componentso E-mail protection

• Antispam• Antivirus

o HTTP protection• Antimalware• URL filtering

o Network Inspection System is free!

Page 11: Kako povečati varnost omrežja s  Forefront  TMG

11

Single Adapter Scenario

• Forefront TMG supports using a single network adapter

• Supported scenarioso Secure Web Gateway (forward Web proxy and cache)o Web Publishing (reverse Web proxy and cache)o Remote client VPN access

• Unsupported scenarioso Application layer inspection (except for Web proxy)o Server publishingo Non-Web clients

• Firewall client• Secure NAT

o Site-to-site VPNs

Page 12: Kako povečati varnost omrežja s  Forefront  TMG

12

Secure Web Gateway

Page 13: Kako povečati varnost omrežja s  Forefront  TMG

Threats and Controls

ThreatsApplication Layer Firewall

HTTPS Inspectio

n

Anti-malwar

eURL

Filtering NIS

Malware

Phishing

Liability

Data Leakage

Lost ProductivityLoss of Control

Full Partial Enabler

Page 14: Kako povečati varnost omrežja s  Forefront  TMG

Forefront TMG HTTPS Traffic Inspection

• HTTPS Inspection terminates the SSL traffic at the proxy for both ends, and inspects the traffic against different threatso Trusted certificate generated by proxy matching the URL expected by the client

14

Internet

Contoso.com

SIGNED BY

VERISIGN

SSL

Contoso.com

SIGNED BY TMG

SSL SSL

URL Filtering

Malware Inspection

Network Inspection System

Page 15: Kako povečati varnost omrežja s  Forefront  TMG

15

Enabling HTTPS Traffic Inspection

Contoso.com

SIGNED BY TMG

Internet

Contoso.com

SIGNED BY

VERISIGN

Certificate deployment(via Active Directory® or Import/Export)

Configure HTTPS Inspection:• Proxy certificate

generation/import and customization.

• Source and destination exclusions

• Validate only option• Notification

Client notifications about HTTPS inspection (via Firewall client)

Certificate validation (revocation, trusted, expiration validation, etc.)

Page 16: Kako povečati varnost omrežja s  Forefront  TMG

16

Configuring HTTPS Inspection

Page 17: Kako povečati varnost omrežja s  Forefront  TMG

17Configuring HTTPS

Inspection

Page 18: Kako povečati varnost omrežja s  Forefront  TMG

18Configuring HTTPS

Inspection

Page 19: Kako povečati varnost omrežja s  Forefront  TMG

19HTTPS Inspection

Notifications• Notification provided

by Forefront TMG cliento Notify user of inspectiono History of recent notificationso Management of Notification

Exception List• May be a legal

requirement in some geographies

Page 20: Kako povečati varnost omrežja s  Forefront  TMG

20

HTTPS Inspection NotificationUser Experience

Page 21: Kako povečati varnost omrežja s  Forefront  TMG

Forefront TMG URL Filtering

Internet

• 91 built-in categories• Predefined and

administrator defined category sets

• Integrates leading URL database providers• Subscription-based

• URL category override• URL category query• Logging and reporting

support• Web Access Wizard

integration

• Customizable, per-rule, deny messages

URL DB

Microsoft ReputationService

TMG

Page 22: Kako povečati varnost omrežja s  Forefront  TMG

URL Filtering Benefits

• Control user web access based on URL categories• Protect users from known malicious sites• Reduce liability risks• Increase productivity• Reduce bandwidth and Forefront TMG resource

consumption• Analyze Web usage

Page 23: Kako povečati varnost omrežja s  Forefront  TMG

What Makes MRS Compelling?

• Existing URL filtering solutionso Single vendor cant be expert in all categorieso Categorization response time

• MRS unique architectureo MRS merges URL databases from multiple sources/vendors

• Multi-vendor AV analogyo Based on Microsoft internal sources as well as collaboration with third

party partnerso Scalable

• Ongoing collaborative efforto Recently announced an agreement with Marshal8e6o More announcements to follow

Page 24: Kako povečati varnost omrežja s  Forefront  TMG

Feedback mechanism on Category overrides

• Fetch on cache miss• SSL for auth &

privacy• No PII

How Forefront TMG Leverages MRSMultiple Vendors

MicrosoftDatacenters

MRS

Query (URL)

CategorizerFetchURL

Policy

Cache

SSL Telemetry Path(also SSL)

FederatedQuery

Cache:• Persistent• In-memory• Weighted TTL

Combines with Telemetry Data

Page 25: Kako povečati varnost omrežja s  Forefront  TMG

URL Filtering Categories

Liability

Security

Productivity

Page 26: Kako povečati varnost omrežja s  Forefront  TMG

26

URL Filtering category precedence

• No. Category• 1 "Malicious"• 2 "Pornography"• 3 "Botnet"• 4 "Phishing"• 5 "Criminal Activities"• 6 "Hate/Discrimination„• …• 75 "Unknown"

http://www.microsoft.com/security/portal/mrs/

Page 27: Kako povečati varnost omrežja s  Forefront  TMG

Categories and Inheritance

Page 28: Kako povečati varnost omrežja s  Forefront  TMG

URL Filtering Policy• URL categories are standard network objects• Administrator can create custom URL category

sets

Page 29: Kako povečati varnost omrežja s  Forefront  TMG

29

URL Filtering Policy

Page 30: Kako povečati varnost omrežja s  Forefront  TMG

30Contoso’s Web Access

Policy• Access rule allowing

users in the Research group to access gambling and gambling-related sites

Access rule denying everyone access to Liability and Security sites

Page 31: Kako povečati varnost omrežja s  Forefront  TMG

Per-rule Customization• TMG administrator

can customize denial message displayed to the user on a per-rule basiso Add custom text or HTMLo Redirect the user to a

specific URL

Page 32: Kako povečati varnost omrežja s  Forefront  TMG

32

URL Filtering Configuration

Page 33: Kako povečati varnost omrežja s  Forefront  TMG

Category Query• Administrator can

use the URL Filtering Settings dialog box to query the URL filtering databaseo Enter the URL or IP address

as inputo The result and its source

are displayed on the tab

Page 34: Kako povečati varnost omrežja s  Forefront  TMG

34

URL Category Override

• Administrator can override the categorization of a URLo Feedback to MRS

via Telemetry

Page 35: Kako povečati varnost omrežja s  Forefront  TMG

User Experience

http://www.phishingsite.com

Page 36: Kako povečati varnost omrežja s  Forefront  TMG

36

User Experience

36

HTML tags

Page 37: Kako povečati varnost omrežja s  Forefront  TMG

37

Novost v SP1

Page 38: Kako povečati varnost omrežja s  Forefront  TMG

38

Page 39: Kako povečati varnost omrežja s  Forefront  TMG

HTTP Malware Inspection

Internet

Third party plug-ins can be used (native Malware inspection must be disabled)

• Integrates Microsoft Antivirus engine

• Signature and engine updates• Subscription-based

• Source and destination exceptions• Global and per-rule inspection options

(encrypted files, nested archives, large files…)

• Logging and reporting support • Web Access Wizard integration

Content delivery methods by content type

SignaturesDB

MU or WSUS

TMG

Page 40: Kako povečati varnost omrežja s  Forefront  TMG

Content Trickling

40

Firewall ServiceWeb ProxyMalware Inspection Filter

Request Context

Scanner

GET msrdp.cabGET msrdp.cab

200 OK

Accumulated ContentAccumulated ContentAccumulated ContentAccumulated ContentAccumulated Content

200 OK

Page 41: Kako povečati varnost omrežja s  Forefront  TMG

Progress Notification41

Firewall ServiceWeb ProxyMalware Inspection Filter

Primary Request Context

Secondary Request Context

Downloads Map

Scanner

GET setup.exeGET setup.exe

200 OK (setup.exe)

Accumulated ContentAccumulated ContentAccumulated Content

200 OK (HTML)

GET GetDownloadStatus

200 OK (Retrieving)

GET GetDownloadStatus

200 OK (Scanning)

GET GetDownloadStatus

200 OK (Ready)

GET FinalDownload

200 OK (setup.exe)

Page 42: Kako povečati varnost omrežja s  Forefront  TMG

42

Enabling Malware Inspection• Activate the Web

Protection license• Enable malware

inspection on Web access ruleso Web Access Policy

Wizard or New Access Rule Wizard for new rules

o Rule properties for existing rules

Page 43: Kako povečati varnost omrežja s  Forefront  TMG

43Malware Inspection Global

Settings• Administrator can

configure malware blocking behavior:o Low, medium and high

severity threatso Suspicious fileso Corrupted fileso Encrypted fileso Archive bombs

• Too many depth levels or unpacked content too large

o File size too large

Page 44: Kako povečati varnost omrežja s  Forefront  TMG

44Malware Inspection Per-

rule Overrides

Page 45: Kako povečati varnost omrežja s  Forefront  TMG

User ExperienceContent Blocked

Page 46: Kako povečati varnost omrežja s  Forefront  TMG

User ExperienceProgress Notification

46

Page 47: Kako povečati varnost omrežja s  Forefront  TMG

Network Inspection System (NIS)• Protocol decode-based traffic inspection system

that uses signatures of known vulnerabilitieso Vulnerability-based signatures (vs. exploit-based signatures used by

competing solutions)o Detects and potentially block attacks on network resources

• NIS helps organizations reduce the vulnerability windowo Protect machines against known vulnerabilities until patch can be

deployedo Signatures can be released and deployed much faster than patches,

concurrently with patch release, closing the vulnerability window• Integrated into Forefront TMG

o Synergy with HTTPS Inspection

47

Page 48: Kako povečati varnost omrežja s  Forefront  TMG

48

• Vulnerability is discovered• Response team prepares and tests the vulnerability

signature• Signature released by Microsoft and deployed through

distribution service, on security patch release• All un-patched hosts behind Forefront TMG are protected

Corporate Network

New Vulnerability Use Case

SignatureAuthoring Testing

TMGSignatureDistribution

Service

VulnerabilityDiscovered

Signature AuthoringTeam

Page 49: Kako povečati varnost omrežja s  Forefront  TMG

NIS Response ProcessThreat

Identification

Threat Research

Signature Developme

nt

Signature Testing

Encyclopedia Write-up

Signature Release

Targeting 4 hours

Page 50: Kako povečati varnost omrežja s  Forefront  TMG

Enabling and Configuring NIS

Page 51: Kako povečati varnost omrežja s  Forefront  TMG

51

Client Types

• Web proxy cliento CERN-compatible browsers/applications

• SecureNAT cliento Any host supporting IP

• Forefront TMG cliento Formerly ISA firewall cliento Windows computers

Page 52: Kako povečati varnost omrežja s  Forefront  TMG

Client Comparison

FeatureSecureNAT

ClientForefront

TMG ClientWeb Proxy

ClientInstallation required

IP Routing configuration

Yes Web browser configuration

OS Support Any OS supporting

TCP/IP

Windows only Any proxy-aware Web application

Protocol support

Requires application filters for multiple-

connection protocols

All Winsock applications

HTTP, HTTPS, and FTP

download

User-level authentication

No Yes Yes

Page 53: Kako povečati varnost omrežja s  Forefront  TMG

53

Web Proxy Client Configuration

• Generate configuration• Discover configuration

o Automatic configuration scripto Web Proxy Auto Discovery (WPAD)o Static proxy configuration

• Enforce configurationo Manualo Group policyo Forefront TMG client

Page 54: Kako povečati varnost omrežja s  Forefront  TMG

SecureNAT clients

• Only requires proper routing• Clients perform DNS resolution• Limitations:

o No user information passedo No support for secondary connections

(without application filter)• Use for:

o Non-Web protocolso Simple, unauthenticated protocolso Non-Windows systems

Page 55: Kako povečati varnost omrežja s  Forefront  TMG

55

Forefront TMG Client

• Formerly known as ISA Firewall client• Supports all WinSock-based applications

o FwcWsp.dll registered with WinSock protocol stacko FwcWsp tracks all WinSock callso All remote TCP calls sent to FWC listener (TCP 1745)o User information passed on all requests

• Use for:o User-based access authentication to non-Web protocolso Complex protocols with secondary connections

Page 56: Kako povečati varnost omrežja s  Forefront  TMG

56

Forefront TMG Client Discovery• Secure discovery using

Active Directory, with fallback to DHCP and DNSo Secure discovery uses AD to

store discovery information for domain members

o Forefront TMG client and Web proxy discovery

o Allows global and site-specific markers

o Configured using TmgAdConfig.exe

TmgAdConfig add –site <Site> -type <winsock|webproxy> -url <URL>

Page 57: Kako povečati varnost omrežja s  Forefront  TMG

57

Server-side Configuration• Domains and Addresses

tabs determine routing

Page 58: Kako povečati varnost omrežja s  Forefront  TMG

58

?