Skip navigation
All Places > Threat Prevention

SandBlast Network

Log in to follow, share, and participate in this community.

Recent Activity

ae789f5d-8265-4053-98a8-099d937df02b
I would like to monitor emulation status on SandBlast appliance, so I want to run "tecli s e v s" by cron every x min. But if I start tecli command by cron, it ended with this error /opt/CPsuite-R77/fw1/bin/tecli: line 49: /teCurrentPack/temain: No such file or directory /opt/CPsuite-R77/fw1/bin/tecli: line 49: exec: /teCurrentPack/temain:… (Show more)
in SandBlast Network
Yanick DJINZOU
Hello Dear, I am newcomer to Checkpoint solutions but I always knew they were the best in the field of Firewall. My employer had a market in a bank which also its first market with the solution of Checkpoint and what made it possible to have this market is especially its "SandBlast" Blades Extraction & Emulation. But this has left grievances,… (Show more)
in SandBlast Network
Shahar Grober
Hi,    Can it be that Check Point Threat Prevention and Sandblast in MTA doesn't scan "*.msg" attachments inside an email?   I did the following tests:   First Test (Baseline) I sent a malicious .doc file attached to an email via the MTA  Result: email is scanned and find malicious by the Gateway AV which is great!   Second Test  I took the… (Show more)
in SandBlast Network
Prabulingam N
Dear All,   One of our customer have TE1000x dedicated appliance in Gaia R77.30. Mgmt server in R80.10 with Clusters as well. Since no internet connectivity for TE Appliance - we have manually downloaded the images (WinXP,Win7 etc) and followed as per sk92509. Engine version is fine, with tecli show advanced downloads images - Image status… (Show more)
in SandBlast Network
Miguel Barrios
Hi Checkmates!, please your help with the following question:   Sandblast (somewhere in the emulation process) can analyze links that comes within a .doc, .pdf, .xls files arriving through email attachment files (MTA) to detect if they lead to malicious sites or zero-day malware files?
in SandBlast Network
Kalyan Addenki
We have R77.30 management with TE250X appliances and recently purchased new TE1000X Sandblast Appliances.   I am not planning to migrate anything from TE250X to TE1000 appliances but build the TE1000 from scratch and swap the TE devices on the gateways. But these new TE1000 appliances shipped with R77.30, so not sure if they can be upgraded to… (Show more)
in SandBlast Network
santosh sahoo
If we have deployed Sand blaster at the gateway then why there is a need to enable IPS blade ?  I want to know whether we need both or not ?
in SandBlast Network
Thomas Werner
Click to view contentThis is available with R80.20 Mgmt & MTA running on R80.20 GW   1) MTA Logs Within your logs you now get Postfix logs in the GUI - just filter for blade:MTA     You can see mail queue ID and even the E-Mail headers in the log. Also it is possible to see all logs tied to an email by setting the "Original Queue ID" as a filter:   In the…
in SandBlast Network
Heiko Ankenbrand
Click to view contentICAP integration for R77.30 and R80.10   Configuring ICAP Server on Check Point Sandblast Appliance (TEX) or Gateway: Enable ICAP server on TEX appliance see SK111306 and configure thread rules in Smart DashBoard.  Use hotfix 286 or higher for R77.30.   Tip! You can use more ICAP Server in "Web Content Layer" on Bluecoat SG for example CAS…
in SandBlast Network
Shahar Grober
Click to view content  I have an ongoing case with TAC about emulation of links inside emails    R80.10 with MTA take 25    Issue: TE doesn't block Links with PDF inside emails    Scenario: I took a malicious PDF from the  Threat Emulation POC (http://poc-files.threat-cloud.com/demo/poc/)   Test #1:  download the malicious file through web browser - AV found it… (Show more)
in SandBlast Network
Load more items