tgreene
Executive Editor

Check Point bolsters LAN security

News
Oct 25, 20043 mins

Company's InterSpect software helps manage rogue PCs, virus protection.

Check Point is upgrading its application-layer security appliance with a management interface that makes it possible for customers to send updates to the machines as a group rather than one at a time.

Check Point is upgrading its application-layer security appliance with a management interface that makes it possible for customers to send updates to the machines as a group rather than one at a time.

InterSpect 2.0 software for the company’s InterSpect appliances integrates features with Check Point’s Smart Center management platform, which makes it possible to gather data to create reports and distribute updates for SmartDefense attack protection that is packaged with the device.

This capability is attractive to Kansas University in Lawrence, Kan., says Chuck Crawford, the school’s IT security officer. “It’s a challenge to do the SmartDefense signatures and do the changes individually. It’s more work and makes mistakes more possible,” he says.

The university installed six InterSpect devices last June to mitigate the flood of viruses that try to invade the network when 3,300 students return each fall. The device sits in line with LAN routers or switches where it can block suspicious traffic. The appliance can segment LANs to stop the spread of viruses, and can quarantine individual machines that it detects are generating suspicious traffic.

The device applies Check Point’s stateful firewall and deep inspection technology that looks into the application-layer activity of network traffic. The device also can be deployed with other vendors’ firewalls to provide application-layer inspection for traffic coming from the Internet.

When the students returned to campus this past August, Crawford says he only needed two staff members dedicated to chasing down infected machines, instead of eight he had last year. Virus incidents dropped from 3,000 last year to 300 this year, he says. “It kept bad traffic blocked and quarantined so it didn’t affect the rest of the network. It was confined to the dormitories,” he says.

The new InterSpect software also upgrades support for Check Point’s Integrity client software that checks whether a PC is compliant with network security policies before allowing it access.

If a rogue PC without an Integrity client is attached to the network, InterSpect can block or quarantine the device from gaining access and display a notice telling the user the machine fails inspection. Before it could block access but only if the device had the Integrity client installed and was found short of meeting security policies.

The InterSpect upgrade also boosts mail security by detecting e-mail-borne worms and viruses, as well as restricting access to certain mail servers, making it more efficient to search out and block malicious code.

Check Point is not alone offering this type of protection. Symantec, Network Associates and Trend Micro also sell gear to protect networks from attacks that manage to pierce perimeter firewalls.

Three versions of InterSpect appliances range in price from $9,000 to $39,000, depending on throughput and number of workgroups it protects.